BlueFlash
teach preview

Fuselage, Wings and Stabilizing Surfaces — Page 41, Lesson 55

Fuselage, Wings and Stabilizing Surfaces — Page 41, Lesson 55BlueFlash
I want to walk you through the heart of how we certify a transport aeroplane's safety — specifically, how we classify failure conditions and what probability we allow for each. This is CS-25 Book 2, the certification standard for large aeroplanes, and it's the backbone of everything we'll do in airframes and systems. Let me start with the regulatory text, because it sets the rule. For a Catastrophic Failure Condition — that's the worst class, where the failure could normally result in hull loss — the safety objectives can be satisfied by demonstrating two things. First, that no single failure will result in a Catastrophic Failure Condition. Second, that each Catastrophic Failure Condition is Extremely Improbable. So we design so one failure can't kill the aeroplane, and we prove that the chance of the catastrophic event is vanishingly small. Now, there's an exception. If it's not technologically or economically practicable to meet the numerical criteria for a Catastrophic Failure Condition, we can still meet the safety objective by using well proven methods for the design and construction of the system. That's the fallback — proven practice instead of a hard number. Now let me bring in the figure, because it ties everything together. It's a table that relates probability on one axis to severity on the other. Let me walk you through the rows. First, the effect on the aeroplane. It ranges from no effect on operational capabilities or safety, through a slight reduction in functional capabilities or safety margins, then a significant reduction, then a large reduction, and finally normally with hull loss. Next, the effect on occupants excluding flight crew. That goes from inconvenience, to physical discomfort, to physical distress, possibly including injuries, to serious or fatal injury to a small number of passengers or cabin crew, and finally multiple fatalities. Then the effect on flight crew. From no effect on flight crew, to a slight increase in workload, to physical discomfort or a significant increase in workload, to physical distress or excessive workload that impairs ability to perform tasks, and finally fatalities or incapacitation. Now the key part — the allowable qualitative probability. For the mildest conditions there's no probability requirement. Then we go from Probable, to Remote, to Extremely Remote, and finally Extremely Improbable. Notice the arrows — they show the progression from left to right. And the allowable quantitative probability — this is the average probability per flight hour. Again, no probability requirement for the mildest. Then we have less than 10⁻³, that's one in a thousand per flight hour. Then less than 10⁻⁵, one in a hundred thousand. Then less than 10⁻⁷, one in ten million. And finally less than 10⁻⁹, one in a billion per flight hour. Now let me tie the classification to the rows. The classification of failure conditions runs from No Safety Effect, through Minor, then Major, then Hazardous, and finally Catastrophic. So you can see the alignment — Minor conditions align with the Probable range, Major with Remote, Hazardous with Extremely Remote, and Catastrophic with Extremely Improbable, which is the 10⁻⁹ per flight hour figure. There's an important note on the figure, and I want you to understand it precisely. For Minor Failure Conditions, the numerical probability range of 10⁻³ is provided as a reference only. The applicant is not required to perform a quantitative analysis, nor substantiate by such an analysis, that this numerical criterion has been met. Current transport category aeroplane products are regarded as meeting this standard simply by using current commonly-accepted industry practice. So for Minor conditions, we don't do the math — proven practice suffices. This whole table comes from the Annex to ED Decision 2007/010/R, Amendment 3 — that's the European Aviation Safety Agency's regulatory decision that adopted this material. It's the legal basis for what we're reading. So the big picture: we classify every failure condition by its severity — from No Safety Effect all the way to Catastrophic — and we assign an allowable probability to each. The more severe the consequence, the lower the allowed probability, down to Extremely Improbable for Catastrophic. And the rule for Catastrophic is that no single failure can cause it, and it must be Extremely Improbable — unless we fall back on well-proven design methods when the numbers aren't practicable. That's the certification logic that governs how we design and analyse every system on a transport aeroplane.

This is one saved preview. Continue from this exact book or paper with BlueFlash voice AI.

Continue in BlueFlash