BlueFlash
teach preview

Fuselage, Wings and Stabilizing Surfaces — Page 37, Lesson 45

Fuselage, Wings and Stabilizing Surfaces — Page 37, Lesson 45BlueFlash
I want to walk you through the tail end of the heavy-landing inspection procedure, and then we're going to step into something completely new — the failure statistics and the EASA policy on failure conditions. First, let's finish the inspection logic. On some aircraft, the maintenance manual specifies that if no damage is found in the primary areas, the secondary areas don't need to be inspected at all. But if damage is found in the primary areas, then the inspection must be continued into those secondary areas. The precise details vary from aircraft to aircraft, so you must always reference the appropriate maintenance manual for that specific type. Never assume the procedure is the same across different aeroplanes. Now, two specific heavy-landing scenarios you need to know cold. The first is a nose wheel landing. There's a real danger of structural damage here. This will usually affect the front pressure bulkhead in the fuselage and the nose wheel strut. In addition to defects in the strut itself, there may also be damage to the drag link — that's the link that ties the nose gear to the airframe and controls its fore-and-aft motion. And there's also a possibility of nose wheel collapse. So when you inspect after a nose wheel landing, you're looking at the front pressure bulkhead, the strut, the drag link, and the potential for the gear to have collapsed. The second scenario is a tail strike. The risk of a tail strike is higher on an approach and landing below Vref — that's the reference landing speed — and also during over-rotation of any flare, meaning you've pulled the nose up too far. A tail strike may lead to structural damage to the empennage — that's the tail assembly — and to the rear pressure bulkhead in the fuselage. So the rear pressure bulkhead is the mirror image of the front one we just talked about. Now we shift gears entirely. The next pages are an extract from the EASA CS-25 document, which details the EASA policy on failure conditions. CS-25 is the certification specification for large aeroplanes. This is the regulatory backbone for how we decide whether a system design is acceptable. Here's the background. For a number of years, aeroplane systems were evaluated to specific requirements, to the "single fault" criterion, or to the fail-safe design concept. Let me unpack those. The single fault criterion means the system had to survive one specific failure. The fail-safe design concept means the system is designed so that if a failure occurs, the aeroplane remains safe — the failure doesn't lead to a catastrophe. As later-generation aeroplanes developed, more safety-critical functions were required to be performed. That generally resulted in an increase in the complexity of the systems designed to perform those functions. And with that complexity came a new problem: you had to consider the potential hazards to the aeroplane and its occupants that could arise if one or more functions provided by a system were lost, or if that system malfunctioned. You also had to consider the interaction between systems performing different functions — because systems don't operate in isolation. This led to a general principle, and I want you to remember this because it's the heart of the whole policy: an inverse relationship should exist between the probability of a failure condition and its effect on the aeroplane and/or its occupants. In plain terms — the more severe the consequence, the lower the probability must be. A catastrophic failure must be extremely improbable. A minor failure can be more likely. That inverse relationship is the design philosophy. Now, how do we put numbers on that? When assessing the acceptability of a design, it was recognised that rational probability values would have to be established. Historical evidence indicated that the probability of a serious accident due to operational and airframe-related causes was approximately one per million hours of flight. That's 1 x 10⁻⁶ per flight hour. Furthermore, about 10 percent of the total were attributed to failure conditions caused by the aeroplane's systems. So of that one-in-a-million serious accident rate, roughly ten percent came from systems failures. It seems reasonable, then, that serious accidents caused by systems should not be allowed a higher probability than this in new aeroplane designs. So the target became: the probability of a serious accident from all such failure conditions should be not greater than one per ten million flight hours — that's 1 x 10⁻⁷ per flight hour — for a newly designed aeroplane. Now here's the difficulty, and it's an important one. It is not possible to say whether that target has been met until all the systems on the aeroplane are collectively analysed numerically. You can't just look at one system in isolation. You have to analyse every system together, numerically, as a whole, before you can know whether the 1 x 10⁻⁷ target has actually been achieved. And that's precisely why this analysis is so demanding — it's a collective, numerical, whole-aeroplane assessment. So to tie it together: we've covered the inspection logic for heavy landings, the two specific damage scenarios — nose wheel landing affecting the front pressure bulkhead, strut, drag link, and possible collapse, and tail strike affecting the empennage and rear pressure bulkhead. Then we moved into the EASA CS-25 failure condition policy, with the inverse relationship between probability and severity, the historical one-per-million serious accident rate, the ten percent systems attribution, and the 1 x 10⁻⁷ per flight hour target for new designs — a target that can only be verified by collective numerical analysis of all systems.

This is one saved preview. Continue from this exact book or paper with BlueFlash voice AI.

Continue in BlueFlash