Download as pdf or txt
Download as pdf or txt
You are on page 1of 11

For personal use only.

Reproduction is
strictly prohibited

AE5045 System Safety Engineering

Functions and Failure Conditions

In this lecture, you will learn about:

 Defining a Function

 Identifying Hazard or Failure Conditions

 Failure Cause and Effect Analysis

 Identifying Failure Modes

AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 2

©Hisar M. Pasaribu, 2019 1


For personal use only. Reproduction is
strictly prohibited

Functions and Failure Conditions

 In conducting a system safety assessment, it is important to


clearly define and describe the system and its components.

 When the system is well defined, the next step is to identify and
clearly defined the intended function of the system.

A function is a goal intended for the system or


process under study.

 By clearly defining the functions, the failure conditions associated


with each function can be easily identified.

AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 3

Functions and Failure Conditions

 A failure condition is a condition

 with an effect on the system (e.g. aircraft) and its occupants,

 both direct and consequential,

 caused or contributed by one or more failures,

considering relevant adverse operation or environmental


conditions.

 For each failure conditions, the failure modes that are possibly
contributing to the conditions can be identified and addressed.

 A failure mode is the way in which the failure of an item occurs.

AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 4

©Hisar M. Pasaribu, 2019 2


For personal use only. Reproduction is
strictly prohibited

Function Defines Failure Modes


 Failure is nonperformance or inability of system or
component to perform its intended function for a
specified time under specified environmental
conditions . FUNCTION

 Hence, a Failure Mode can be called as an Anti-


Function.

 A well defined function will inherently describe the


way the item fails.

 5 categories of failure modes:


 complete failure. FAILURE
MODE
 partial failure.
 intermittent failure.
 failure over time.
 over-performance of Function
AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 5

Failures and Faults


Failure: Nonperformance or inability of system or
component to perform its intended function for a
specified time under specified environmental
conditions.
A basic abnormal occurrence, e.g., burned out bearing
in a pump relay not closing properly when voltage
applied
Fault: Higher−order events, which are undesired
anomalies in an item or system, e.g., relay closes at
wrong time due to improper functioning of an
upstream component.
All failures are faults but not all faults are failures.

AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 6

©Hisar M. Pasaribu, 2019 3


For personal use only. Reproduction is
strictly prohibited

Failure Definitions
Failure :
a loss of function or a malfunction of a system or a part thereof.

Fault :
an undesired anomaly in an item or system.

Malfunction :
the occurrence of a condition whereby the operation is outside
specified limits.

Defect :
state of an item consisting of the non-performance of specified
requirements by a characteristics of the item. A defect may, but need
not, lead to failure.

AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 7

Failure Definitions
Error :
(1) an occurrence arising as a result of an incorrect action or decision
by personnel operating or maintaining a system;

(2) a mistake in specification, design, or implementation.

Failure condition :
a condition with an effect on the aircraft and its occupants, both
direct and consequential, caused or contributed by one or more
failures, considering relevant adverse operation or environmental
conditions.

A failure condition is classified in accordance to the severity of its


effects as defined in FAA AC 25.1309-1A or JAA AMJ 25.1309.

AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 8

©Hisar M. Pasaribu, 2019 4


For personal use only. Reproduction is
strictly prohibited

Failure Definitions
Failure mode (FM) :
the way in which the failure of an item occurs.

Failure effect (FE) :


a description of the operation of a system or an item as the result
of a failure; i.e. the consequence(s) a failure mode has on the
operation, function or status of a system or an item.

Hazard :
a potentially unsafe condition resulting from failures,
malfunctions, external events, errors, or a combination thereof.

Event :
an occurrence which has its origin distinct from the system. This
describes an “External Event”. There are other uses of “event” that
covers other aspects, e.g. FTA Hisar
events.
M. Pasaribu/ITB
AE5045 System Safety Engineering Function and Failure Conditions 9

System and Independence

System : a combination of inter-related items arranged to


perform a specific function(s).

Risk : the frequency (probability) of occurrence and the


associated level of hazard.

Independence :

(1) a design concept which ensures that the failure of one


item does not cause a failure of another item;

(2) separation of responsibilities that assures the


accomplishment of objective evaluation.

AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 10

©Hisar M. Pasaribu, 2019 5


For personal use only. Reproduction is
strictly prohibited

Failure Modes, Causes and Effects


A failure mode lies between
a Cause and an Effect.
FUNCTION

Potential FAILURE Effects


Causes MODE

A Cause is a way in which a An Effect is an adverse


certain element in the design of consequence that may be
an item or process produces a experienced by the Customer as
Failure Mode a result of a Failure Mode.
AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 11

Failure Modes, Causes and Effects

Potential FAILURE Effects


Causes MODE

 A single Cause may result in multiple Effects.


 A Cause may produce another Cause, as well as an Effect may yield a
further Effect.
 A Cause may not directly be the factor that produce a Failure Mode;
hence the term ‘Potential or Probable Cause’ indicates this
uncertainty.
 But, an Effect is a definite consequence of a Failure Mode.

AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 12

©Hisar M. Pasaribu, 2019 6


For personal use only. Reproduction is
strictly prohibited

Understanding Failure Modes


 Say, the system under study is a disposable flashlight.

 Say, “Giving a light with an intensity of 3 ± .5 candela" is defined as


a Function.

 The five categories of failure modes may help identify the probable
failure modes.

 The following failure modes can be identified:


 no light.
 dim light.
 erratic blinking light.
 gradual dimming of light.
 too bright.

AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 13

Understanding Failure Modes


 The categories may expose all the possible failure modes including
those never thought of before.

 For example, a light that cannot be turned off is an over-


performance. This is in fact a design failure, although it is not a
functional failure.

 Hence, we need an additional or secondary function – ‘automatically


off when not in use’ – to cater for the problem.

 The function can be redefined as “Giving a light with an intensity of


3 ± .5 candela when in use."

AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 14

©Hisar M. Pasaribu, 2019 7


For personal use only. Reproduction is
strictly prohibited

Understanding Failure Modes


 The following may illustrate a series of events that occur in the life of
a disposable flashlight.
Design
 The events may expose the
Environmental item to other failure modes.
Exposure
Excessive  For example, the failure of the
Moisture casing to prevent excessive
Corrosion moisture during normal
operation is a failure mode.
Poor Contact

Insufficient
Current

Bulb Dim

 Therefore, a critical step in safety assessment is to clearly describe


the function, process and environment of the system under study.
AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 15

System Safety Revisited

 Emphasizes building in safety rather than adding it on


to a completed design.
 Looks at systems as a whole, not just components
 Takes a larger view of hazards than just failures.
 Emphasizes hazard analysis and design to eliminate or
control hazards.
 Emphasizes qualitative rather than quantitative
approaches.

AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 16

©Hisar M. Pasaribu, 2019 8


For personal use only. Reproduction is
strictly prohibited

Identifying Hazards

In any situation, ask yourself:

 What can go wrong?


 How bad could it be?
 How likely is it to happen?
 What should we do about it?

AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 17

Identifying Hazards
Action or Hazards Control
Situation A hazard is a potential source of harm or Control measures include actions that can be
adverse effect on a system or persons taken to reduce the potential of exposure to the
hazard, or the control measure could be to
remove the hazard or to reduce the likelihood
of the risk of the exposure to that hazard being
realised.

AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 18

©Hisar M. Pasaribu, 2019 9


For personal use only. Reproduction is
strictly prohibited

Identifying Hazards
Action Hazards Control

AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 19

Identifying Hazards
Action Hazards Control

AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 20

©Hisar M. Pasaribu, 2019 10


For personal use only. Reproduction is
strictly prohibited

Identifying Hazards
Action Hazards Control

AE5045 System Safety Engineering Hisar M. Pasaribu/ITB Function and Failure Conditions 21

©Hisar M. Pasaribu, 2019 11

You might also like