BlueFlash
teach preview

Now, here's where the arbitrary assumption comes in — Page 37, Lesson 47

Now, here's where the arbitrary assumption comes in — Page 37, Lesson 47BlueFlash
Let me walk you through the tail end of the safety analysis, because this is where the numbers actually get set. We've been talking about Catastrophic Failure Conditions and the target for how often they can happen. The key point here is that you can't just look at one system in isolation and say "yes, we've met the target." You can only say whether the target has been met when all the systems on the aeroplane are collectively analysed numerically. That's a crucial idea — the whole aeroplane has to be analysed as a complete set of systems, not one at a time. Now, here's where the arbitrary assumption comes in. Because we can't analyse an infinite number of possible failures, it was assumed, arbitrarily, that there are about one hundred potential Failure Conditions in an aeroplane which could be Catastrophic. So the target allowable Average Probability per Flight Hour of 1 x 10⁻⁷ — that's one in ten million per flight hour — was apportioned equally among these one hundred Failure Conditions. When you divide 1 x 10⁻⁷ by 100, you get an allocation of not greater than 1 x 10⁻⁹ to each. That's one in a billion per flight hour. So the upper limit for the Average Probability per Flight Hour for Catastrophic Failure Conditions would be 1 x 10⁻⁹. And that number establishes an approximate probability value for the term "Extremely Improbable." That's the definition you need to hold onto: Extremely Improbable corresponds to a probability of about 1 x 10⁻⁹ per flight hour. And note the contrast — Failure Conditions having less severe effects could be relatively more likely to occur. So the less severe the consequence, the more probability you can tolerate. Now let's move to the Fail-Safe Design Concept. This is the heart of Part 25 airworthiness standards. The Part 25 standards are based on, and incorporate, the objectives and principles or techniques of the fail-safe design concept. And the concept considers the effects of failures and combinations of failures in defining a safe design. So it's not just about single failures — it's about how failures combine. There are two basic objectives pertaining to failures. First: In any system or subsystem, the failure of any single element, component, or connection during any one flight should be assumed, regardless of its probability. That's a strong statement — you assume a single failure will happen, no matter how unlikely you think it is. And such single failures should not be Catastrophic. So a single failure must never bring the aeroplane down. Second objective: Subsequent failures during the same flight, whether detected or latent, and combinations thereof, should also be assumed, unless their joint probability with the first failure is shown to be extremely improbable. So after that first failure, you have to assume more failures can happen — and some of them might be latent, meaning they're hidden, not detected by the crew. You have to assume those combinations too, unless you can show that the joint probability — the probability of the first failure and the subsequent failure happening together — is extremely improbable, which we now know means about 1 x 10⁻⁹ per flight hour. Now, how does the fail-safe design concept actually ensure a safe design? It uses design principles or techniques. And here's an important caveat: the use of only one of these principles or techniques is seldom adequate. A combination of two or more is usually needed to provide a fail-safe design. And the goal of that combination is to ensure that Major Failure Conditions are Remote, Hazardous Failure Conditions are Extremely Remote, and Catastrophic Failure Conditions are Extremely Improbable. So you're mapping each severity level to a probability level. The first principle is Designed Integrity and Quality, including Life Limits, to ensure intended function and prevent failures. So you design the component with enough integrity and quality — and you set life limits, meaning you retire parts after a certain number of hours or cycles — so that the part does what it's supposed to do and doesn't fail in the first place. That's the foundation of the fail-safe concept. Let me make sure you've got the probability ladder straight, because it's the backbone of everything: Extremely Improbable is about 1 x 10⁻⁹ per flight hour, and that's the ceiling for Catastrophic Failure Conditions. Hazardous conditions get Extremely Remote, Major conditions get Remote. And the whole thing rests on assuming single failures happen, and then showing that combinations are extremely improbable.

This is one saved preview. Continue from this exact book or paper with BlueFlash voice AI.

Continue in BlueFlash