It's establishing that what it computes is what was specified. That question arrives in a different form for an accelerator vendor, an operator running its own parts, and a program approaching tapeout, but it's the same question, and it's where the schedule goes.
A new part reaches first output quickly. The work that follows is establishing that the output is correct, and that work is done by testing: differential comparison against a reference, coverage over representative inputs, and engineering judgment about when enough is enough.
Testing closes slowly, it reopens on the next release, and it never reaches certainty. Every vertical below is a different team meeting that same property from a different direction, with a different amount already committed by the time they meet it.
And the bottleneck each one hits
These are situations rather than industries. A team recognizes its own by the bottleneck rather than by the label, so the bottleneck is what each entry leads with, and each has a page of its own.
A new dataflow architecture arrives without a mature compiler behind it, and the long half of bring-up is showing the numbers match the reference.
Answered by Model bring-up
The team that designed the part is rarely the team that has to trust it in production, and a test report does not carry the reasoning across.
Answered by How we prove it
A custom extension is one nobody upstream will verify, so the specification, the reference and the compiler are kept in agreement by the vendor alone.
Answered by LOGOS, the language
A program carrying an evidence requirement needs correct behavior on inputs nobody wrote a test for, and a simulation campaign establishes the other thing.
Answered by Design signoff
Some obligations have no short proof in the system a solver searches, so the run never returns and the team falls back to a coverage argument.
Answered by The LOGOS Proof Kernel
Every vertical above is served by one of two engagements, and which one depends on where the silicon is in its life rather than on the industry it ships into. Model bring-up is for a part that has already been bought and is waiting to earn. Design signoff is for a part that is still a netlist, where what can be claimed at tapeout is still being decided.
Both run the same four products against a device the customer names. The technical argument does not change between them. The cost of being wrong does.
Want the tools before the engagement? The four products
Does one of these describe the program in front of you?