BlueFlash
teach preview

These tests are what you use to support compliance — Page 41, Lesson 60

These tests are what you use to support compliance — Page 41, Lesson 60BlueFlash
I want to walk you through the compliance requirements for CS 25.1309, which is the regulation that governs the safety of equipment, systems, and installations on transport category aeroplanes. We're looking at the environmental and operational qualification requirements, and then the failure condition probability requirements. Let's start with the environmental side. The regulation addresses variations in fluid pressure and electrical power, and also fluid or vapour contamination. These variations can come from two sources: either the normal environment, or accidental leaks, spillage, and handling by personnel. So when we qualify equipment, we have to consider both the everyday operating environment and the possibility of something going wrong, like a hydraulic fluid leak or fuel spillage. The regulation references a document that defines a series of standard environmental test conditions and procedures. These tests are what you use to support compliance. Now, here's an important point: equipment covered by Technical Standard Orders, or TSOs, that contain environmental test procedures can be used to support compliance. Also, equipment qualified to other environmental test standards can be used. But there's a critical condition attached to this: the conditions under which the installed equipment will be operated must be equal to or less severe than the environment for which the equipment is qualified. In other words, you can't take equipment qualified for a benign environment and install it somewhere harsher. The qualification envelope must cover or exceed the actual operating environment. Now let's move to the substantiation requirement. The proper functioning of equipment, systems, and installations under the operating and environmental conditions approved for the aeroplane must be shown. This can be demonstrated by test, by analysis, or by reference to comparable service experience on other aeroplanes. But if you use service experience, you must show that the comparable service experience is valid for the proposed installation. You can't just say "it worked on another aircraft" — you have to prove the experience actually applies to your specific installation. There's also an interference requirement. For equipment, systems, and installations covered by CS 25.1309(a)(1), the compliance demonstration must confirm that the normal functioning of such equipment does not interfere with the proper functioning of other equipment, systems, or installations also covered by that paragraph. So we're checking that systems don't conflict with each other during normal operation. Now, let's contrast that with CS 25.1309(a)(2). Equipment covered by this paragraph is typically associated with passenger amenities — things like passenger entertainment systems and in-flight telephones. The key characteristic here is that their failure or improper functioning, in itself, should not affect the safety of the aeroplane. Because they don't affect safety directly, the operational and environmental qualification requirements are reduced. They're reduced to only the tests necessary to show that their normal or abnormal functioning does not adversely affect the proper functioning of the equipment covered by CS 25.1309(a)(1), and does not otherwise adversely influence the safety of the aeroplane or its occupants. What are examples of adverse influences? The regulation gives us specific ones: fire, explosion, and exposing passengers to high voltages. So a passenger entertainment system, for instance, must be tested to ensure it can't start a fire, can't explode, and can't expose passengers to dangerous electrical voltages. That's the reduced qualification standard for amenity equipment. Now let's move to compliance with CS 25.1309(b), which deals with failure conditions and their probabilities. This paragraph requires that aeroplane systems and associated components, considered separately and in relation to other systems, must be designed so that any Catastrophic Failure Condition is Extremely Improbable and does not result from a single failure. Let me define these terms carefully. A Catastrophic Failure Condition is one that would prevent continued safe flight and landing. "Extremely Improbable" is a probability term — it means the failure condition is so unlikely that it's not anticipated to occur during the entire operational life of all aeroplanes of one type. And the requirement that it does not result from a single failure means we need redundancy — no single component failure should be able to bring the aircraft down. The regulation also requires that any Hazardous Failure Condition is Extremely Remote. A Hazardous Failure Condition is one that would reduce the capability of the aeroplane or the ability of the crew to cope with adverse operating conditions, to the extent that there would be a large reduction in safety margins. "Extremely Remote" means unlikely to occur to each aeroplane during its total life, but which may occur a few times in the total operational life of all aeroplanes of the type. And finally, any Major Failure Condition must be Remote. A Major Failure Condition is one that would reduce the capability of the aeroplane or the ability of the crew to cope with adverse operating conditions, to the extent that there would be a significant reduction in safety margins. "Remote" means unlikely to occur to each aeroplane during its total life, but which may occur several times in the total operational life of all aeroplanes of the type. Now, there's an important analytical requirement here. The analysis should always consider the application of the Fail-Safe design concept. Fail-Safe means the design ensures that a failure doesn't cause a catastrophic outcome — the system fails in a safe manner. And special attention must be given to ensuring the effective use of design techniques that would prevent single failures or other events from causing catastrophic outcomes. So to summarize the probability hierarchy: Catastrophic must be Extremely Improbable and not from a single failure, Hazardous must be Extremely Remote, and Major must be Remote. Each failure condition has a probability target, and the analysis must demonstrate compliance using Fail-Safe design principles. That figure shows the relationship between probability and severity of failure conditions — it's the classic risk matrix that ties together what we just discussed.

This is one saved preview. Continue from this exact book or paper with BlueFlash voice AI.

Continue in BlueFlash