Fault Tree Analysis
General Description
• Fault Tree Analysis (FTA) is a deductive reasoning technique that focuses on
one particular accident event.
• The fault tree itself is a graphic model that displays the various combinations
of equipment faults and failures that can result in the accident event.
• The solution of the fault tree is a list of the sets of equipment failures and
human/operator errors that are sufficient to result in the accident event of
interest.
• The strength of FTA as a qualitative tool is its ability to break down an
accident into basic equipment failures and human errors. This allows the
safety analyst to focus preventive measures on these basic causes to reduce
the probability of an accident.
• Purpose: Identify combinations of equipment failures and
human errors that can result in an accident event.
• When to Use:
a. Design: FTA can be used in the design phase of the plant to uncover
hidden failure modes that result from combinations of equipment
failures.
b. Operation: FTA including operator and procedure
characteristics can be used to study an operating
plant to identify potential combinations of failures
for specific accidents.
• Type of Results: A listing of sets of equipment and/or
operator failures that can result in a specific accident.
These sets can be qualitatively ranked by importance.
• Nature of Results: Qualitative, with quantitative potential. The fault tree
can be evaluated quantitatively when probabilistic data are available.
• Data Requirements:
a. A complete understanding of how the plant/system
functions.
b. Knowledge of the plant/system equipment failure
modes and their effects on the plant/system.
Staffing Requirements
• One analyst should be responsible for a single fault tree, with frequent
consultation with the engineers, operators, and other personal who have
experience with the systems/equipment that are included in the analysis.
• A team approach is desirable if multiple fault trees are needed, with each
team member concentrating on one individual fault tree. Interactions
between team members and other experienced personnel are necessary for
completeness in the analysis process.
Time and Cost Requirements: Time and cost
requirements for FTA are highly dependent on
the complexity of the systems involved.
Modeling a small process unit could require a
day or less with an experienced team. Large
problems, with many potential accident events
and complex systems, could require several
weeks even with an experienced analysis team.
Classification of Failures
• Sudden versus gradual failures
• Hidden versus evident failures
• According to effects (critical, degraded or incipient)
• According to severity (catastrophic, critical, marginal or negligible)
• Primary failure, secondary failure and command fault
Component Failure
Characteristics
• Primary failure: component within design envelope (natural aging)
• Secondary failure: excessive stresses (neighboring components, environment,
plant personnel)
• Command fault: inadvertent control signals or noises (neighboring
components, environment, plant personnel)
•COMPONENT FAILURE
CHARACTERISTICS
• Primary Faults and Failures
• Primary faults and failures are equipment malfunctions that occur in the
environment for which the equipment was intended. These faults or failures
are the responsibility of the equipment that failed and cannot be attributed to
some external force or condition.
• Secondary Faults and Failures
• Secondary faults and Failures are equipment malfunctions that occur in an
environment for which the equipment was not intended. These faults or
failures can be attributed to some external force or condition.
•COMPONENT FAILURE
CHARACTERISTICS
• Command Faults and Failures
• Command faults and failures are equipment malfunctions in which the
component operates properly but at the wrong time or in the wrong
place.
• These faults or failures can be attributed to the source of
the incorrect command.
• when the exact failure mode for a primary or secondary failure is identified,
and failure data are obtained, primary and secondary failure events are the
same as basic failures and are shown as circles in a fault tree.