Fault Tree Analysis (FTA) is a systematic, deductive system safety engineering methodology used to model, analyze, and evaluate the unique interrelationships of component failures, software bugs, environmental factors, and human errors leading to a specified system-level Undesired Event.
Fault Tree Analysis (FTA) is an essential system safety analysis tool defined across four key operational dimensions: evaluation tool, root cause analysis engine, graphical logic model, and mathematical reliability engineering methodology:
Functions as a visual, top-down diagnostic evaluation tool for complex engineering systems. In Fault Tree Analysis (FTA), safety engineers isolate multi-component failure paths leading to an Undesired Event to evaluate safety, reliability, system unavailability, and perform accident investigations.
Executes deductive root cause analysis by tracing high-level system hazards down to fundamental component failure modes. A Fault Tree Analysis provides dual analytical outputs: qualitative risk insights via Minimal Cut Sets (MCS) and quantitative metrics via failure probability calculations.
Delivers a clear, standardized schematic mapping cause-and-effect relationships between basic events, environmental conditions, logical gates, and probability values—embodying the principle that a visual Fault Tree diagram provides instant technical clarity across engineering teams.
Establishes a structured, repeatable, and audit-ready methodology for system safety engineering and risk assessment. Grounded in Boolean algebra, probability theory, and physical system laws, Fault Tree Analysis offers a standardized procedure for evaluating mission-critical hardware, software, and human factors.
To build, read, and evaluate Fault Trees accurately, safety engineers must master standardized terminology. The fundamental distinction in Fault Tree Analysis (FTA) lies between a Failure and a Fault.
A Failure is the occurrence of a basic component failure caused by an internal, inherent failure mechanism that cannot be broken down any further.
Fault Tree Example: Resistor R77 fails in an open-circuit mode due to internal material breakdown.
A Fault is the occurrence or existence of an undesired state for a component, subsystem, or system caused by an external failure or chain of upstream events.
Fault Tree Example: A lamp is in a "failed off" fault state because an upstream switch failed open, removing power.
All failures are faults, but not all faults are failures. In many command fault states, a component operates correctly according to its design, but operates at the wrong time because it was incorrectly commanded to do so by upstream controls.
Developed originally at Bell Laboratories in 1961 for the Minuteman Launch Control System, Fault Tree Analysis provides a graphical model that displays cause-consequence relationships. It uses Boolean algebra to analyze cut sets—the specific combinations of primary component failures and state conditions required to trigger a top hazard.
Unlike inductive, bottom-up methods like FMEA, Fault Tree Analysis operates top-down. It asks "Immediate, Necessary, and Sufficient" questions to break down high-level hazardous events into basic, measurable component parameters.
- Qualitative Evaluation: Isolates Minimal Cut Sets (MCS) to pinpoint single point failures and design weak points in Fault Tree Analysis models.
- Quantitative Evaluation: Computes top event probabilities, availability metrics, and component importance measures using exact failure rates.
- Cross-Boundary Coverage: Evaluates combined hardware failures, software faults, human errors, and environmental states across system boundaries.
Fault Trees are developed in hierarchical layers:
- Top Structure: Shapes the overall Fault Tree and defines system-level top undesired events.
- Middle Structure: Models subsystem functional states, operating phases, and intermediate gate conditions.
- Bottom Structure: Establishes basic primary events, component failure rates, and exposure times.
Fault Tree Analysis models rely on standardized logic operators and event classification nodes to establish precise cause-consequence relationships.
- AND Gate: Output occurs only if all input events happen simultaneously.
- OR Gate: Output occurs if at least one input event happens.
- Inhibit Gate: Output occurs if the input event happens under a specific conditional requirement.
- Priority AND Gate: Output occurs only if input events happen in a specific sequential order.
- Exclusive OR Gate: Output occurs if exactly one input event happens, but not both.
- Top Event: The ultimate system failure or hazard being analyzed (root of the Fault Tree).
- Intermediate Event: A fault state caused by a combination of preceding events; leads to a logic gate.
- Basic Event: The lowest-level physical component failure or human error; requires no further decomposition.
- Undeveloped Event: An un-analyzed fault state represented by a diamond symbol (secondary fault).
- External/House Event: A condition expected to occur normally (true/false state, e.g., power is ON).
Quantitative Fault Tree Analysis in Safety Commander calculates basic event probabilities from constant failure rates (λ) and exposure times (T), then propagates these metrics through Boolean logic using exact inclusion-exclusion expansions.
Calculates unreliability Q for a primary component operating over mission time interval T with failure rate λ.
Computes independent output probabilities for two input events A and B passed through fundamental gates.
P(AND) = P(A) · P(B)
Inclusion-Exclusion expansion formula evaluated across all minimal cut sets (MCS) to compute exact Top Event probability.
Eliminates redundant events (MOEs) and super cut sets to prevent erroneous over-estimation of system risk in Fault Tree Analysis.
A + A · B = A (Absorption Law)
Fault Tree Analysis (FTA) provides engineering teams with a proven, rigorous framework for modeling complex system interactions, evaluating risk, and driving system-level decisions.
- Strengths: Methodical, structured, graphical, quantitative, and easy to model complex systems.
- Coverage: Encompasses hardware, software, humans, procedures, and timing.
- Application: Like any specialized tool, the user must know when, why, and how to use Fault Tree Analysis correctly.
- Safety: Identifies and evaluates hazardous and catastrophic events.
- Reliability: Models and measures system unavailability using Fault Trees.
- Performance: Analyzes unintended functions and abnormal operational states.
- Root Cause Analysis: Traces parallel and sequential event chains back to fundamental causes.
- Risk Assessment: Computes probability levels and evaluates risk tolerance.
- Design Assessment: Demonstrates requirement compliance and evaluates design options or fixes.
Explore Safety Commander Fault Tree Analysis features or request a live web walk-through with ALD safety experts.