In ISO-26262, the Automotive safety integrity level (ASIL) represents the degree of rigour that should be applied in the development, implementation and verification of a requirement in order to reduce and control the risk in the final product. The ASILs are allocated to the safety requirements which are inherited by the subsystems and components in a hierarchical approach. During the allocation process, the safety requirements could be decomposed over redundant elements. It is referred to as ASIL decomposition and is an important feature, as it helps to reduce the complexity and the development cost of the design. The decomposition could lead, however, to different allocations. In this paper, we propose an approach to find all the possible...