The control systems for airplanes often have a significant number of mathematical proofs.
Formal verification is only as good as your model, anyway. Problem comes from outside your model? Formal verification won't save you.
The level he works at might be higher level though. It sounds like control systems for airplanes are fairly modular.
Software is highly unusual in that proofs can even be deployed. Most highly safe processes can't even use proofs. How do you prove that a dam won't fail? It is impossible.
Me shit posting is not a life or death situation so a bug here or there is fine