
Let's pick this up right where the regulatory text leaves off. We're inside CS 25.1309 and its Acceptable Means of Compliance, and I want to walk you through the two ways the regulation classifies failure conditions.
First, the qualitative definitions. These are the plain-language categories used to judge how often a failure might happen. There are four of them, and they're ranked by likelihood.
(1) Probable Failure Conditions — these are anticipated to occur one or more times during the entire operational life of each aeroplane. So if you have a fleet, every single aircraft in that fleet is expected to see this failure at least once in its life. That's the baseline.
(2) Remote Failure Conditions — these are unlikely to occur to each aeroplane during its total life, but they may occur several times when you consider the total operational life of a number of aeroplanes of the type. So a single aircraft probably won't see it, but across a fleet of many aircraft, you'd expect it to happen several times.
(3) Extremely Remote Failure Conditions — not anticipated to occur to each aeroplane during its total life, but may occur a few times when considering the total operational life of all aeroplanes of the type. Notice the escalation: "several times" for Remote, "a few times" for Extremely Remote, and now we're looking at the entire fleet of that type, not just a number of them.
(4) Extremely Improbable Failure Conditions — these are so unlikely that they are not anticipated to occur during the entire operational life of all aeroplanes of one type. That's the top of the scale — the whole fleet, the whole life, and we still don't expect to see it.
Now, those are qualitative — they use words like "several" and "few." But the regulation also gives us quantitative definitions, and this is where we get numbers you'll actually use in engineering judgement.
The quantitative terms are expressed as acceptable ranges for the Average Probability Per Flight Hour. That's the key metric — the probability of the failure occurring in a single hour of flight, averaged out.
Here are the three ranges:
(i) Probable — Average Probability Per Flight Hour greater than of the order of 1 x 10⁻⁵. So anything more likely than one in a hundred thousand per flight hour.
(ii) Remote — of the order of 1 x 10⁻⁵ or less, but greater than of the order of 1 x 10⁻⁷. So between one in a hundred thousand and one in ten million per flight hour.
(iii) Extremely Remote — of the order of 1 x 10⁻⁷ or less, but greater than of the order of 1 x 10⁻⁹. So between one in ten million and one in a billion per flight hour.
Notice what's missing — there's no quantitative range given for Extremely Improbable in this excerpt. That's because it's defined qualitatively as "so unlikely they're not anticipated to occur during the entire operational life of all aeroplanes of one type." The quantitative scale stops at Extremely Remote, and anything below that — below 1 x 10⁻⁹ — falls into the Extremely Improbable category by implication.
Now, the critical thing to understand: these are aids to engineering judgement. The regulation itself, CS 25.1309(b), sets the compliance requirement, but these probability ranges are the commonly accepted way to interpret it. They're not hard legal limits — they're the agreed-upon yardsticks that engineers use to decide whether a failure condition is acceptable.
And one more important detail: this text comes from the Annex to ED Decision 2007/010/R, Amendment 3. That's the European Aviation Safety Agency's formal adoption of this AMC material. So when you're working under EASA rules, this is the authoritative version of these definitions.
Let me make sure you've got the full picture. You have four qualitative categories — Probable, Remote, Extremely Remote, Extremely Improbable — each defined by how often they're expected across the life of one aircraft versus the life of a fleet. And you have three quantitative ranges, all expressed as Average Probability Per Flight Hour, with the boundaries at 1 x 10⁻⁵, 1 x 10⁻⁷, and 1 x 10⁻⁹. The qualitative and quantitative definitions align — Probable is the most likely, Extremely Improbable is the least — but the quantitative scale only explicitly covers the first three.
That's the complete framework. When you're doing a safety assessment for a system, you'll use these categories to classify each failure condition, and that classification drives what level of design assurance and redundancy you need. That's the foundation we're building on.
This is one saved preview. Continue from this exact book or paper with BlueFlash voice AI.
Continue in BlueFlash