Grouping event-tree outcomes: consequence bins without double counting

Build mutually exclusive terminal outcomes, retain overlapping consequence attributes and preserve the information needed for later consequence calculations.

On this page

An event tree may produce many terminal sequences that are too detailed for one summary. Grouping them is useful, but only if the meaning of the group is explicit. A list of damaged systems, a set of final physical states and a set of consequence labels are not automatically the same classification. The task is to simplify the result while preserving the probability accounting and the differences that still matter to the next decision.

Define the endpoint before the bin name

A terminal sequence ends at a defined analytical boundary, such as a specified time or established system condition. Its name should make that boundary understandable. A label such as release may mean material leaving a pipe, crossing a local containment boundary or reaching the sea. Those are different endpoints and can occur within the same physical scenario.

NRC’s SAPHIRE summary distinguishes sequence analysis from end-state analysis and partitioning. The transferable lesson is to keep a traceable mapping from detailed sequences to the summary they support. A maritime consequence label needs its own physical definition; software terminology or a nuclear damage-state label cannot supply that definition by itself.

Begin with mutually exclusive sequences

The disjoint-event sum rule in MIT’s probability notes states the mathematical basis for adding separate paths. In an original example, assume four exhaustive terminal sequences after one specified initiator have probabilities 0.70, 0.20, 0.08 and 0.02. Each occurrence belongs to exactly one sequence, and their total is one.

Define them as: no release beyond the normal process boundary; a release retained within the intended secondary boundary; an uncontained release without the specified injury endpoint; and an uncontained release with that injury endpoint. The terms are hypothetical and require a consistent observation horizon. An injury occurring after that horizon would require extending the model or clearly limiting the claim.

Separate bins from overlapping attributes

The four bins are mutually exclusive, but useful reporting attributes can overlap. Uncontained release occurs in the last two bins, so its conditional probability is 0.08 + 0.02 = 0.10. The specified injury occurs in the last bin, with probability 0.02. In this model every injury outcome is already an uncontained-release outcome.

Adding 0.10 and 0.02 would incorrectly report 0.12 for uncontained release or injury. The correct union is 0.10 because the injury set is a subset. It is legitimate to display both attributes in separate columns, provided the table tells the reader that they overlap. A chart whose slices are intended to represent a whole must instead use an exclusive partition.

Retain the frequency basis

If the defined initiator frequency is an invented 0.50 per operating year, the four terminal frequencies are 0.35, 0.10, 0.04 and 0.01 per operating year. They sum to 0.50. The uncontained-release frequency is 0.05 per operating year and the specified-injury frequency is 0.01 per operating year. The latter remains included in the former.

A probability conditional on one initiating event and a frequency per operating year have different units and interpretations. A summary should preserve both the endpoint and exposure basis. If the model covers only one operating mode, its operating-year basis must not be presented as a calendar-year fleet frequency without the additional exposure information and compatible initiating-event model.

Keep the attributes needed for the next model

The public NUREG-1150 Appendix B example describes grouping accident sequences into plant damage states as one stage of a larger analysis. For a maritime analogue, grouping should retain the attributes needed by the subsequent consequence calculation, such as location, inventory, boundary condition and relevant timing. Nuclear consequence definitions and numerical thresholds are not transferred.

Two releases can share the same total mass yet differ in duration, ventilation, ignition opportunity or route to people and the environment. If those differences change the next calculation, a single averaged release label is insufficient. Either preserve separate subgroups or carry the relevant conditional distribution into the next stage. Reducing the number of rows is not the same as demonstrating that the rows are equivalent.

Show what is lost by a premature merge

In the four-bin example, the probability of the specified injury given an uncontained release is 0.02/0.10 = 0.20. Multiplying the uncontained-release frequency 0.05 per operating year by that conditional value returns 0.01 per operating year. This works because the conditional number was derived from the same detailed model, population and endpoint.

If a proposed change alters which uncontained sequences occur, the old 0.20 may no longer apply. A change that preferentially prevents the injury-bearing sequence changes the composition of the group. Holding the old averaged consequence probability fixed would then hide part of the effect. Retain the sequence-to-bin map so that changes can be propagated through the grouping rather than applied only to the headline total.

Use expected loss only with a defined quantity

For a separate numerical illustration, assign the four bins 0, 2, 10 and 100 equipment-restoration labour-hours per occurrence. Assume these are the complete conditional mean values for the chosen labour measure. Expected labour per initiator is 0.70 × 0 + 0.20 × 2 + 0.08 × 10 + 0.02 × 100 = 3.2 labour-hours. At 0.50 initiators per operating year, the expected amount is 1.6 labour-hours per operating year.

These invented labour figures are not valuations of injury or environmental harm. The expectation summarizes only the stated labour measure; it says nothing about whether the severe bin is acceptable. A mean can be unchanged while the tail of the consequence distribution changes substantially. Preserve severe-outcome frequencies and other relevant endpoints alongside any aggregate expectation.

Four mutually exclusive invented bins have probabilities.70,.20,.08,.02 and restoration labour 0,2,10,100 hours per occurrence. Their expected contributions 0,.4,.8,2 sum to 3.2 labour-hours per initiator. The rare 2% bin contributes 62.5% of that mean.
Original expectation-contribution bars, all at 140 drawing units per labour-hour/initiator. Bin definitions follow the article’s exclusive partition:1 no release,2 retained release,3 uncontained release without the specified injury,4 uncontained release with that injury. Labour values are assumed complete conditional means for equipment restoration only; they do not price injury or environmental harm. At an assumed 0.50 initiators/operating year, expected labour is 1.6 hours/operating year. A mean does not establish acceptability or erase the severe-outcome frequency.

Audit omissions, overlaps and unknown states

A useful audit assigns a stable sequence identifier and checks that every terminal sequence maps to exactly one exclusive bin. Sum the probability or frequency before and after grouping. Separately check each overlapping reporting attribute against the underlying sequence set. If an outcome is unresolved, retain an explicit unresolved classification instead of silently placing it in the favourable bin.

Normalization alone cannot prove completeness of the initiating-event set or physical adequacy of the consequences. It checks the accounting inside the modelled sample space. A perfectly normalized tree can omit an important initiator, apply the wrong observation horizon or misunderstand a boundary. Record such scope limits separately from numerical checks so that a passing sum is not mistaken for a complete risk assessment.

Make the summary reversible

A well-designed summary lets a reader move from a group total back to its contributing sequences, original assumptions and consequence attributes. Changes to bin definitions should be versioned and applied consistently to all relevant paths. If a bin is split, the child totals should reproduce the old parent total for unchanged inputs; if bins merge, explain which distinctions remain available elsewhere.

The purpose of grouping is to communicate and carry analysis forward. It should make significant outcomes easier to understand while preserving the evidence needed to challenge them. A concise table of exclusive bins, a separate table of overlapping attributes and a traceable sequence map often communicate more honestly than one impressive total called risk without a defined consequence measure.

Sources