With something safety-critical like an ECU, I'd be surprised if they left formal proof out of their software design and testing. This would make unexpected hardware behaviour much more likely imo. I guess I'd get around it by setting up automated hardware-in-the-loop simulators for testing every possible environment and input. Surely the cost would be worth it for F1 as a whole.
At a startup I worked at, we jerry-rigged Pi 5's with commercial of-the-shelf environmental sim software to achieve this. Very cost effective, lol.