MEE40002 – MECHANICAL SYSTEMS DESIGN
ASSOCIATE PROFESSOR AMBARISH KULKARNI
LECTURE - 9
RISK ENGINEERING
ambarishkulkarni@[Link]
CRICOS provider 00111D
1
TUTORIAL-LECTURE CORRELATION
• In week 8 lecture and tutorial you have learned about the Australian
design for standards, and how to access them.
• In week 9 lecture you will explore about the Risk engineering.
Understanding risks and its analysis associated with the projects is
crucial for success of the project.
• In week 9 tutorial you will get insights on fatigue failure which is
necessary in risk mitigation.
Stress analysis will be utilized for the fatigue failure.
2
RISK ENGINEERING
The project report is due in 3 weeks…..
3
RISK ENGINEERING
This week we will look at:
• Failure Mode and Effect Analysis
• Fault Tree Analysis
• Event Symbols
• Gate Symbols
• Event Tree Analysis
• Minimising Risk
4
RISK ENGINEERING
• Failure Mode and Effect Analysis
• [Link]
5
RISK ENGINEERING
6
RISK ENGINEERING
• The Challenger Space Shuttle….
• On January 28th, 1986, at 11.39 EST, the Challenger Space Shuttle
launched a crew of seven into space. On board was the first civilian
passenger, Christa McAuliffe.
• 73 seconds into the flight, the Shuttle broke apart, and disintegrated
over the Atlantic Ocean.
• The exact time of death for the crew is unknown, but it is expected
that they would have survived the initial break up of the shuttle. 7
RISK ENGINEERING
• So, what happened?
• NASA was under huge pressure to make space travel as cheap and as
routine aircraft travel.
• This was caused by a failure of an o-ring…..
8
RISK ENGINEERING
• The launch had been postponed for 6 days. On the day of the launch, the
shuttle had sat out on the launch pad overnight. Ice had formed on the
launch pad and the entire vehicle had temperature soaked. The overnight
temperature was in the vicinity of -8 degrees Celsius. Previously the coldest
launch was at 12 deg Celsius.
9
RISK ENGINEERING
• The morning of the launch, the manufacturers (Thiokol) of the o-ring tried to prevent the
launch from happening. Their engineers (Robert Boisjoly) tried to convince NASA to postpone
the launch, as they argued they didn’t have enough data for such cold temperatures and the
risk of the bearings was known to be great.
• There had been evidence of o-ring burnout in the past and the concern was that the cold
would make the o-ring so brittle it would fail. NASA’s infamous response? “I am appalled! I am
appalled by your recommendation. My God, Thiokol, when do you want me to launch - next
April?” NASA went with the belief that if the first o-ring failed, the second would hold.
10
RISK ENGINEERING
• NASA did however listen and postpone the launch for 2
hours when they were alerted to the ice on the launch
pad. It was feared that during launch the ice would
damage parts of the shuttle.
11
RISK ENGINEERING
12
RISK ENGINEERING
• The shuttle didn’t explode, the fuel was released into the
atmosphere through a hole that was burned through the casing
from the failed o-ring and the liquid hydrogen and liquid oxygen
were released into the atmosphere and ignited in a fire ball. There
is evidence to suggest the crew survived the breakup of the shuttle
and were conscious for at least part of the decent.
13
RISK ENGINEERING
14
RISK ENGINEERING
15
RISK ENGINEERING
16
RISK ENGINEERING
17
RISK ENGINEERING
• Failure Mode and Effect Analysis Or FMEA
• FMEA is the reason no one at Morton Thiokol was prosecuted for the
deaths of the crew of the Space Shuttle Challenger.
• Historically, FMEA comes from the Space Industry.
• They use this more than other risk engineering.
• Probabilistic Risk Engineering is said to be superior, but FMEA is still
used because you are looking at what you are going to do rather than
the statistics of if you can do something. 18
FAILURE MODE AND EFFECT ANALYSIS
• FMEA’s are usually done as a team.
• Arguments should occur, it is a good way of working through a possible issue.
• You need a level head. Look at all possibilities. You may miss some, but an
FMEA is a living breathing document, you don’t do it once and forget it
exists…..
• [Link]
19
FAILURE MODE AND EFFECT ANALYSIS
• You use an FMEA in the following circumstances:
• When a process, product or service is being designed or redesigned.
• When an existing process, product or service is being used or applied in a
new way.
• When developing control plans for a new or modified process.
• When improving a product, process or service
• Periodically through the life of a product, process or service.
20
FAILURE MODE AND EFFECT ANALYSIS
• Where to start??
• Start with a list of possible ‘Failure Modes’.
• Failure modes are all the ways that something might go wrong. Errors and
defects should be included.
• What is the ‘Effects Analysis’ of these Failure Modes?
• What are the consequences of the failures you’re looking at?
21
FAILURE MODE AND EFFECT ANALYSIS
22
FAILURE MODE AND EFFECT ANALYSIS
• Look at the severity of the effect of the failure. Is it catastrophic? Will
someone die? Will they lose a limb? Will they get a fright? Will a major
piece of equipment be damaged?
23
FAILURE MODE AND EFFECT ANALYSIS
• Next comes the Characteristics – leave that one until a little later…..
24
FAILURE MODE AND EFFECT ANALYSIS
• Think about what the possible causes of the failure are? Write
them down.
• Are there any controls in place to stop that failure?
• What is the occurrence rating? Is it rare? Is it common? Is it daily?
Or weekly? Yearly?
25
FAILURE MODE AND EFFECT ANALYSIS
• How can we tell when this failure has occurred or is likely to occur?
This is your controls or detection method.
• Write down your detection number. This statistical and industry
dependent. (Detection using people and manual detection
methods is rated a 7 in automotive. Can be as low as 1 if the failure
detection is automated and ‘error proof’)
26
FAILURE MODE AND EFFECT ANALYSIS
• Multiply your severity occurrence detection to get your RISK
PRIORITY NUMBER or RPN
• There is no mandated threshold for action, but rule of thumb
says the top 20% should be dealt with or if the severity is high.
27
FAILURE MODE AND EFFECT ANALYSIS
28
ENGINEERING FAILURE ANALYSIS – CASE STUDY
29
ENGINEERING FAILURE ANALYSIS – CASE STUDY
30
ENGINEERING FAILURE ANALYSIS – CASE STUDY
31
ENGINEERING FAILURE ANALYSIS – CASE STUDY
• Motor design was fine-tuned
and the following assembly
sequence was established
using DFMEA
32
RISK ENGINEERING
• Fault Tree Analysis
• Often, we need to determine the probability of an event or a failure.
Once you identify a failure mode in your FMEA, you might need to
determine the probability of the failure occurring.
• A Fault Tree Analysis is a good way of working out the probability of a
scenario or failure.
33
RISK ENGINEERING
• What does a Fault Tree look like?
34
RISK ENGINEERING
• Where does it come from?
• Fault tree analysis was done during the Apollo project to find the
probability of getting someone to the moon and returning safely to
earth as less than 5%.
• This method was rejected until after the Challenger disaster.
• It can be used in conjunction with an FMEA.
• Fault Tree Analysis is a top-down approach – you start with the event
you don’t want to happen and then work down through the causes. 35
RISK ENGINEERING
• How do you construct a Fault Tree Analysis?
• There are three types of Symbols used in Fault Tree
Analysis.
• Event Symbols
• Gate Symbols
• Transfer Symbols
36
RISK ENGINEERING
• Event Symbols
• Basic Event – the failure or error in a system or element
• External Event – expected to occur, not a fault or failure or an initiating
event
37
RISK ENGINEERING
• Event Symbols
• Undeveloped Event – an event that you have insufficient
knowledge about or is of no consequence
• Conditioning Event – conditions that affect or restrict the
logic gates, or mode of operation
• Intermediate Event – this can be used above a primary event to provide more
information
38
RISK ENGINEERING
• Gate Symbols – Gate Symbols are derived from Boolean logic symbols
• OR Gate – the output occurs is and input occurs
• AND Gate – the output occurs only if all the inputs occur
39
RISK ENGINEERING
• Gate Symbols – Gate Symbols are derived from Boolean logic symbols
• Inhibit Gate – The output occurs if the input occurs under and enabling
condition as specified by a conditioning event
40
RISK ENGINEERING
• Gate Symbols – Gate Symbols are derived from Boolean logic symbols
• Exclusive OR Gate – the output occurs if exactly one output occurs
• Priority AND Gate – the output occurs if the inputs occur in a specific
order as specified by a conditioning event
41
RISK ENGINEERING
• Transfer Symbols are used to connect the inputs and outputs of related
fault trees. For example, you might have a fault tree for a subsystem,
you’d use a transfer symbol to connect it to the fault tree for the system.
• Transfer In
• Transfer Out
42
RISK ENGINEERING
• Boolean Logic
• This deals with statistical probability.
• For AND Gates
• 𝑃 𝐴∩𝐵 =𝑃 𝐴 𝑃 𝐵
• For OR Gates
• 𝑃 𝐴∪𝐵 =1− 1−𝑃 𝐴 1−𝑃 𝐵
• Where 1 − 𝑃 𝐴 is the probability of A not
occurring
43
RISK ENGINEERING
44
RISK ENGINEERING
• Event Tree Analysis is a forward, bottom-up logical modelling technique.
It is used to look at the affects of a system given a failure.
• So, if a Fault Tree Analysis helps us find the probability of an identified
failure mode, the Event Tree Analysis helps us work out what will
happen after a failure, and it helps us work out the seriousness of that
failure.
45
RISK ENGINEERING
46
RISK ENGINEERING
• Event Tree Analysis
• From the Initial Event, we are trying to manage the failure.
47
RISK ENGINEERING
• Event Tree Analysis
• We also add in the probabilities of the success and failure of the event
we are looking at.
• As with the above example, the probability of the fuel feed to the
engine stopping might be 10% or 0.1, which means the probability that
the fuel feed won’t stop would be 0.9.
48
RISK ENGINEERING
• Event Tree Analysis
• You can assign the correct probabilities to the success
and failure of each event, and then you can follow
through and determine the probability of each outcome.
49
RISK ENGINEERING
50
[Link]
RISK ENGINEERING
• Minimising Risk
• Fault Tree Analysis and Event Tree Analysis can help you
determine the size and nature of a risk. Sometimes the action
you need to take to minimise a risk is obvious, but sometimes
you find you need to think more closely on this.
• Here are some things to help you think about the course of
action that you might be able to take…..
51
RISK ENGINEERING
• Minimising Risk – Reduce the Potential Energy
• Risk can occur when there is energy of some sort.
• Usually, the energy is stored and controlled.
• If control is lost, the energy source will keep releasing
until it is exhausted.
52
RISK ENGINEERING
• Minimizing Risk – Reduce the Potential Energy
• Some examples are:
• Pressure
• Gravitational Potential Energy (Think Heights!)
• Thermal Energy
• Inert Gases (Think suffocation)
• Sharp Edges
• Poison
• Chemical
• Electrical (know that some things work in reverse – RF)
53
RISK ENGINEERING
• Minimising Risk – Barriers
• You can implement multiple barriers around a potentially
hazardous situation, you limit the chances of it releasing in an
undesirable fashion.
54
RISK ENGINEERING
• Minimising Risk – Backup
• If the main system fails, do you implement a back up system – for
example UPS.
55
RISK ENGINEERING
• Minimising Risk – Safe by Default
• The starting position in a Safe by Default system is safe – for example a
self-locking brake, until you initiate the lever, nothing moves.
56
RISK ENGINEERING
• Minimising Risk – Known Weak Points.
• If your system has a known weak point, then you control the failure.
• Think fuses and shear pins.
• If you incorporated a known weak point, make sure the parts cannot
be easily replaced with stronger parts or someone will replace them.
57
RISK ENGINEERING
• Minimising Risk – Known Weak Points.
• If your system has a known weak point, then you control the
failure.
• Think fuses and shear pins
• If you incorporated a known weak point, make sure the parts
cannot be easily replaced with stronger parts or someone will
replace them.
58
LEARNING AND ACADEMIC SKILLS
LAS assists students to develop and improve their
academic and study skills, including:
• Understanding assessment requirements.
• Researching finding information from different sources
and referencing
• Writing academic reports essays and reflections
• Preparing and delivering effective presentations
• improving Literary and writing skills QR code for Log in
• Preparing for exams and tests
LAS Drop-in Advice
• Hawthorn library Mon 11:30am-1:30pm | Tue – Fri 11:30 am-3:30 pm
• Wantirna library Tue 11:30am-1:30pm
• Croydon library Mon11:30am-1:30pm
• Online Tue-Fri 3:30pm-5:30pm Via Collaborate Ultra
Site: [Link]/lasstudy 59
THANK YOU!
ASSOCIATE PROFESSOR AMBARISH KULKARNI
ambarishkulkarni@[Link]
CRICOS provider 00111D