Knowledge / Risk analysis methods
Event-tree event ordering: chronology, function and conditional structure
How event-tree headings represent physical demands, how equivalent reorderings change conditional probabilities, and when timing requires a richer model.
On this page
The left-to-right order of an event tree influences how a reader understands an accident sequence. It can also influence which dependencies the analyst remembers to model. Yet a heading is not necessarily a timestamp, and moving a column does not physically move an event. A defensible tree distinguishes the order of demands on protective functions from the mathematical order used to factor a joint probability. Confusing those two orders can give a neat diagram with an incorrect meaning.
Begin with a demand narrative
The NRC event-tree definition describes sequences arising from an initiator and subsequent functional successes or failures. For a maritime study, first write the physical narrative in ordinary language. Define the initial configuration, the disturbance, which quantities change, which protective functions become necessary and the unacceptable outcome being examined. A list of equipment names does not establish that narrative.
For an invented machinery-space liquid-release scenario, the analysis might ask whether detection occurs, whether the relevant source is isolated in time, and whether retained liquid remains within the intended boundary. Detection, isolation and retention have different success conditions. The actual ship arrangement may use other functions, and some may act continuously rather than wait for a command. The example organizes a question; it specifies no emergency response procedure.
Use chronology without mistaking it for a rigid drawing rule
IAEA SSG-3 (Rev. 1), paragraph 5.61 allows chronological headings and justified alternative orders that simplify dependencies or model size. It is nuclear guidance, used here only for its modelling principle. A chronological presentation is often readable because each branch can be explained as the system state that exists when the next demand arrives.
A support-power condition may be shown before a detector heading even though that power has existed throughout the scenario. Conversely, a continuously available boundary may be drawn after an active isolation function because that makes the outcome logic easier to read. Explain such choices. Readers should not infer that a late column means the component remained irrelevant or unavailable until that moment.
Write the conditioning history
The multiplication rule in MIT’s conditional-probability notes provides the mathematical basis. Given initiating event I, a three-outcome path has probability P(A,B,C|I) = P(A|I) P(B|A,I) P(C|A,B,I), where A, B and C each denote the particular branch outcome, not necessarily success. Multiplying conditional factors is valid without an independence assumption.
The conditioning includes more than the preceding column label. It can include operating mode, remaining support, damage caused by the initiator and the time available. A number estimated for ordinary operation may therefore be unsuitable after a blackout or a fire. Document what each factor is conditional on before choosing its value. Omitting that record is particularly dangerous when the same heading appears on several different paths.
Reorder one joint event correctly
Consider invented failure events A and B, all probabilities conditional on one specified initiator. Let P(A) = 0.10, P(B|A) = 0.40 and P(B|not A) = 0.02. The joint probability of both failures is 0.10 × 0.40 = 0.040. The marginal probability of B is 0.10 × 0.40 + 0.90 × 0.02 = 0.058.
If B is drawn first, preserving the same joint model requires P(A|B) = 0.040/0.058, approximately 0.689655. The product 0.058 × 0.689655 is approximately 0.040, with the small discrepancy due only to displayed rounding. Moving B left while retaining 0.10 as the following A probability would produce 0.0058 and silently replace the dependency model. The error is not a property of the drawing; it is the unaltered conditional input.
Audit the complete partition
The same example has four mutually exclusive outcomes: both failures 0.040; A failure with B success 0.060; A success with B failure 0.018; and both successes 0.882. Their sum is one. A reordering must preserve those four joint probabilities and their outcome definitions, even though the branch factors and visual layout change.
For the B-success branch, P(A|not B) = 0.060/0.942, approximately 0.063694. Checking this second branch catches a common partial repair: an analyst recalculates one conspicuous failure path but leaves its complement inconsistent. Compare the full outcome vector before and after a reordering. Equality of only the final severe-outcome total can hide compensating errors in different paths.
Do not create a demand where none exists
If successful isolation removes the need for a later recovery action, the corresponding branch can terminate or use a clearly defined not-required state. Assigning the recovery action its ordinary failure probability even when it is not demanded creates an artificial failure opportunity. Conversely, removing a heading is justified only if the preceding conditions really make its outcome irrelevant to the defined endpoint.
A deterministic branch probability of zero or one is a statement about the modelled condition. For example, if the previous path explicitly establishes loss of the sole supply needed by a function, success of that function can be impossible within that simplified model. The claim requires a verified boundary; an unexamined alternate supply or stored-energy interval would invalidate the asserted certainty.
Separate order from duration
A conventional binary tree can distinguish success before a deadline from failure to meet it, but its left-to-right spacing does not calculate elapsed time. Suppose an illustrative function is useful only if completed within 20 s. Completion at 12 s and at 28 s cannot be put on the same success branch merely because both eventually occur. The physical endpoint defines which completion matters.
When two actions overlap, compete for one person or change the conditions for each other, a static ordering may hide important behaviour. A supporting time-line, state model or dynamic analysis may be needed. Choosing a more elaborate tool is justified by the question and evidence, rather than by assuming every event tree is inadequate or every chronology can be captured by adding columns.
Keep physical and informational causation distinct
Knowing that B failed can increase the inferred probability that A had already failed. That is an update of information, not proof that the later observation caused the earlier failure. The reordered numerical example illustrates this distinction. A physical narrative still needs mechanisms such as a shared supply, an environmental challenge or failure propagation.
The same caution applies to human response. An alarm becoming available may enable diagnosis, while an alarm recorded after the event may only reveal what happened. Treating either as a generic detection-success label loses the difference. Record the cue that is available to the person at the decision time, not information reconstructed afterwards from a complete incident record.
Make the ordering decision reviewable
A useful review record pairs each heading with its function, demand condition, success criterion, time window and dependencies. It identifies any compound heading that combines several actions and states why that combination preserves the outcomes of interest. The supporting calculation should show branch normalization, terminal coverage and the joint probabilities preserved by any alternative ordering.
An event tree is strongest when another analyst can reconstruct the same scenario without guessing what the column order meant. The objective is an explicit account of how the system responds to a challenge. Probabilities and consequences remain conditional on the stated ship configuration, evidence and modelling scope; an internally consistent tree alone does not establish that the real operation is acceptable.
Sources
- Event tree · US NRC · Source check date: 2026-10-06
- SSG-3 (Rev. 1), 2024 · IAEA · Source check date: 2026-10-06
- Lecture 19: Conditional Probability, Spring 2024 · MIT OpenCourseWare · Source check date: 2026-10-06