Académique Documents
Professionnel Documents
Culture Documents
Risk analysis
Lecture 8
Failure modes and effect analysis (FMEA)
• Why: to identify contribution of components failures to
system failure
A conveyor system consists of a feed belt and an elevating rotary table. The feed belt
transports objects placed on its left end to the right end and then on the table. The table
then elevates and rotates an object to make it available for processing by further
machines. The belt has photo-electric cells, which signals when an object has arrived at
its ends. The motor of the belt may be switched on and off: it has to be on while
waiting for a new object and has to be switched off when an object is at the end
of the belt but cannot be delivered onto the table because the table is not in
proper position. The table lifts and rotates an object clockwise to a position for
further processing. When an object is taken the table moves down and
counterclockwise to accept another object. For the brevity we omit the details
of table’s implementation. We merely observe that the table moves between
two positions: one for loading an object from the feed belt and another for
unloading an object for further machines. Initially the table is in its loading
position and the feed belt is running empty while waiting for an object to be
placed.
Hazards:
Constants
/*Maximal time to reload object from feed belt to table */
MaxDeliveringTime
/*Maximal time for object to come from beginning to end of feed belt */
MaxTranspDelivTime
Procedures
…
/* Halts feed belt */
HaltFB = if FB=VACANT ∧ FB_st=VACANT
then FB := HALTINGV || FB_st := HaltedVac
elseif FB=FBLOADED ∧ FB_st=StartTransporting
then FB := HALTINGL || FB_st := HStartTransporting
/* Immediately stops feed belt */
StopFB = if (FB=VACANT ∨ FB=FBLOADED)
then FB := FBSTOPPED || FB_ST := FBSTOPPED
/* Object passed the exit sensor while the motor was supposed to be OFF */
23
Risk
24
Example
• Failure of a particular component is likely
to result in an explosion that could kill 100
people. It is estimated that this component
will fail once in every 10000 years. What is
the risk associated with that component?
• Risk= severity x frequency =
100 x 0.0001 = 0.01 deaths per year
25
Categories of severity for military
systems
Category Definition
Catastrophic Multiple deaths
Critical A single death, and/or multiple severe
injuries or severe occupational illnesses
Marginal A single severe injury or occupational
illness, and/or multiple minor injuries or
minor occupational illnesses
Negligible At most a single injury or minor
occupational illness
26
Accident probability ranges for
military systems
Accident Occurrence during operational life
frequency considering all instances of the system
27
Risk classification
Severity of
hazardous
event Risk classification
Frequency of
hazardous
event
28
Why classifying risks?
• Risks can be expressed qualitatively and
quantitatively
• Calculation of risk results in a risk class (or
risk level).
• Most standards define a number of risk
classes and then set out development and
design techniques appropriate for each
category of risk
29
Risk classes and interpretations for military
systems
30
As Low As is Reasonably Practicable (ALARP) principle
31
The process of risk reduction
32
Difference between criticality of
systems
• Both an electric toaster and a nuclear reactor
protection system should be adequately safe but
meaning of “adequately” would be different for
these two cases
• Hence the importance of safe operation differs
widely between applications
• Different safety requirements for different
projects mean different levels of risk reduction
required
33