Bounded scenario calculation
PSA selected-consequence contribution workbench
Explore the annual frequency contribution to one selected FF end state from three disjoint invented leak-origin classes and all 12 conditional paths. This is not a full-vessel PSA or total-risk calculation.
PSA: build a bounded scenario contribution model
Three initiating-event classes, four conditional paths each, one precisely defined end state. Trace where every frequency comes from, then explore input ranges and sensitivity. This is a small, transparent part of probabilistic safety assessment, not a full vessel PSA.
A deliberately limited maritime question
Consider an invented shipboard fuel-transfer compartment with 400 transfer-duty hours in one synthetic vessel-year. A release starts at exactly one of three origins. Isolation succeeds if transfer is isolated by 30 s. Fire prevention succeeds if no sustained fire lasting more than 10 s occurs during the first 10 min. These windows define the teaching model; they are not operating instructions or approved response targets.
Selected end state FF: transfer is not isolated by 30 s AND a sustained fire occurs during the first 10 min. The sum below includes only this end state for the three listed origins. It excludes other fires, other hazards and omitted initiators.
Define a partition before adding anything
- IE-LINE: initial release from the rigid line, excluding the pump shaft seal and flexible hose.
- IE-SEAL: initial release from the pump shaft seal only.
- IE-HOSE: initial release from the flexible transfer hose only.
Assign each included initiating occurrence to exactly one origin. These categories are mutually exclusive per occurrence, not mutually exclusive across a year. Multiple different occurrences may happen during the year. Events with multiple initial origins, unknown origins or an external impact are explicitly excluded. Their omission is a scope gap, never evidence of zero risk.
λ is an already annualized initiating frequency in events per the same synthetic vessel-year and duty profile. a, bS and bF are dimensionless conditional success probabilities for the stated origin and time windows. No rate, operating hour or per-demand conversion is performed. Editable notes document the basis; they do not change the fixed event definitions.
Read the tree as conditional statements
- aᵢ = P(I = S | IEᵢ): isolation succeeds given origin i.
- bSᵢ = P(E = S | IEᵢ, I = S): no sustained fire given that isolation succeeds.
- bFᵢ = P(E = S | IEᵢ, I = F): no sustained fire given that isolation fails.
- S = success; F = failure. I has identity I-F30; E has identity E-NF10. Each origin conditions the same response definitions, not an independent copy of the equipment.
P(FF | IEᵢ) = (1 − aᵢ)(1 − bFᵢ)
fᵢ,FF = λᵢ P(FF | IEᵢ)
F_FF = Σᵢ fᵢ,FF
Σₚ P(p | IEᵢ) = 1; Σₚ fᵢ,ₚ = λᵢ
- First enumerate the four terminal paths. SS has probability a bS; SF has a(1 − bS); FS has (1 − a)bF; FF has (1 − a)(1 − bF). A path probability is conditional on its initiating event.
- The tree partitions defined outcomes; it does not establish causal chronology or simulate fire progression. The 30 s isolation window lies within the 10 min observation window, and fire may begin before isolation is completed.
- The chain rule gives P(I=F, E=F | IEᵢ) = P(I=F | IEᵢ) × P(E=F | IEᵢ, I=F). The second factor already conditions on isolation failure. Multiplication here does not assume independent barriers.
- Multiply each path probability by the corresponding initiating frequency: fᵢ,path = λᵢ × P(path | IEᵢ). The units remain events per vessel-year. A frequency of 0.01/year is not automatically a 1% chance of at least one event in a year; converting it requires a justified occurrence-process model.
- For each origin, all four path probabilities must sum to 1 and all four path frequencies must sum to λᵢ. These closure checks catch arithmetic or tree-partition errors; they do not establish that the model describes a real vessel.
- Sum only like end states over the disjoint included initiating-event classes: F_FF = Σᵢ λᵢ(1 − aᵢ)(1 − bFᵢ). This is an aggregate contribution for the stated scope. It is not total ship risk and it does not quantify injury, pollution, fire size or loss.
- The annual event counts need not be statistically independent for their expected counts to add. What matters here is avoiding duplicate assignment of the same occurrence and using matching exposure and consequence definitions. Overlapping scenario lists require a valid partition or explicit overlap treatment before addition.
Try the synthetic model
Audit the current result
The complete lesson and worked example are available without JavaScript. Interactive controls require JavaScript.
All calculations and CSV generation run locally in this page. No calculator data is sent or persistently stored. CSV contains current inputs, source notes, assumptions, all paths, closure checks, range corners and sensitivity. Displayed numbers are rounded to ten significant digits; CSV retains the computed numeric precision.
Reproduce the synthetic benchmark
- IE-LINE: 0.12 × (1 − 0.90) × (1 − 0.70) = 0.0036 events/vessel-year.
- IE-SEAL: 0.30 × (1 − 0.95) × (1 − 0.85) = 0.00225 events/vessel-year.
- IE-HOSE: 0.08 × (1 − 0.85) × (1 − 0.60) = 0.0048 events/vessel-year.
- Sum: 0.0036 + 0.00225 + 0.0048 = 0.01065 events/vessel-year. The largest base contribution is the hose-origin scenario, under these invented assumptions.
- The rectangular-range lower corner is 0.00026 and upper corner is 0.1026 events/vessel-year. Their width reflects chosen input ranges, not a measured confidence level.
| Origin | FF probability | FF frequency | Share of selected sum |
|---|---|---|---|
| IE-LINE | 0.03 | 0.0036 | 33.8028169% |
| IE-SEAL | 0.0075 | 0.00225 | 21.12676056% |
| IE-HOSE | 0.06 | 0.0048 | 45.07042254% |
| Origin / path | End-state criteria | Conditional product | P(path | origin) | Frequency [events/vessel-year] |
|---|---|---|---|---|
| IE-LINE / SS | Isolated; no sustained fire | 0.9 × 0.97 | 0.873 | 0.10476 |
| IE-LINE / SF | Isolated; sustained fire | 0.9 × 0.03 | 0.027 | 0.00324 |
| IE-LINE / FS | Not isolated; no sustained fire | 0.1 × 0.7 | 0.07 | 0.0084 |
| IE-LINE / FF | Not isolated; sustained fire · selected | 0.1 × 0.3 | 0.03 | 0.0036 |
| IE-SEAL / SS | Isolated; no sustained fire | 0.95 × 0.99 | 0.9405 | 0.28215 |
| IE-SEAL / SF | Isolated; sustained fire | 0.95 × 0.01 | 0.0095 | 0.00285 |
| IE-SEAL / FS | Not isolated; no sustained fire | 0.05 × 0.85 | 0.0425 | 0.01275 |
| IE-SEAL / FF | Not isolated; sustained fire · selected | 0.05 × 0.15 | 0.0075 | 0.00225 |
| IE-HOSE / SS | Isolated; no sustained fire | 0.85 × 0.95 | 0.8075 | 0.0646 |
| IE-HOSE / SF | Isolated; sustained fire | 0.85 × 0.05 | 0.0425 | 0.0034 |
| IE-HOSE / FS | Not isolated; no sustained fire | 0.15 × 0.6 | 0.09 | 0.0072 |
| IE-HOSE / FF | Not isolated; sustained fire · selected | 0.15 × 0.4 | 0.06 | 0.0048 |
Uncertainty and dependency are part of the model
A point estimate hides uncertainty. Here low/base/high are authored scenario assumptions. They are not observed frequencies, Bayesian posterior summaries, distribution quantiles or a Monte Carlo calculation. Aleatory variability concerns event occurrence; epistemic uncertainty concerns imperfect information about parameters and model form. This worksheet only explores bounded parameter choices.
The all-low and all-high input vectors are not the minimum and maximum outcome vectors: success probabilities act in the opposite direction from initiating frequency. The displayed envelope uses the correct monotone corners. If shared evidence or physics correlates the uncertain parameters, those corners may be jointly infeasible. A full uncertainty analysis needs defensible joint distributions or constrained scenarios and a method for structural uncertainty.
Shared power, detection, crew actions, environment or maintenance may affect both isolation and fire prevention. Those effects must be represented consistently inside the origin- and history-conditioned values or through explicit linked failure models. This calculator does not estimate such values or verify dependencies. Giving the same barrier a second name does not create an independent protection layer.
The excluded multi-origin/common-cause initiators remain a missing contribution. Common causes within an included origin can still affect the response tree and must be represented in its conditional data. These are two different issues. Acknowledgment cannot repair missing evidence or a missing scenario.
What a complete PSA would still need
- A justified system boundary, hazard inventory, end-state taxonomy, operational modes and exposure profile; systematic initiating-event identification and completeness review.
- Success criteria supported by physical analysis; equipment and human reliability models; explicit shared support, common-cause, functional, environmental and time-dependent dependencies; recovery and maintenance where relevant.
- Traceable representative data, demand/exposure normalization, parameter estimation, model verification, independent peer review and configuration control.
- Propagation of parameter and model uncertainty, treatment of correlations and excluded hazards, consequence magnitude and affected populations or environment where the assessment question requires them.
- Appropriate maritime engineering and regulatory review. This workbench supplies no universal tolerability threshold, monetary damage estimate, SIL classification, certification or operational advice.
Where the other methods fit
HAZOP structures the search for deviations; FMEA examines component failure modes; FTA can develop the failure logic of a response function; ETA organizes initiating-event sequences; LOPA evaluates explicitly defined protection-layer scenarios. A PSA integrates suitable models, evidence, dependencies, consequences and uncertainties to answer a defined safety question. Producing one product or a list of scores is not a complete PSA.
Primary method sources
NRC and IAEA sources address nuclear safety; NASA addresses aerospace/system risk. Only the general scenario, probability and dependency methods are transferred here. They provide no maritime approval, no marine failure data and no prescribed values for this example. All numbers, scenario names and diagrams are original teaching material.
The calculation interface could not load. The example and explanation below remain readable; reload the page to recalculate.
Related context
The method explanation and worked example are on this page. The articles below provide additional context.
All calculators