Knowledge / Risk and reliability
FTA house events: modelling operating modes and maintenance states
Use deterministic house events to condition a fault tree on operating and maintenance states, and distinguish a demand-weighted mixture from time averaging.
On this page
A fault tree may be valid in normal service and wrong during maintenance because the available equipment has changed. A house event can select a configuration without pretending that the selected condition is a random component failure. The important discipline is to solve the tree for each defined state first, then combine states only with weights that match the question being asked.
Separate configuration from failure uncertainty
In this article H is a deterministic switch: H=1 means train B is deliberately unavailable for the analyzed configuration; H=0 means it is available to perform its function. The NASA handbook describes house events as conditions that are not themselves faults. Software conventions differ, so record the truth value and its engineering meaning explicitly.
A switch is not evidence that the actual valve lineup or maintenance status matches the model. If that state is unknown, calculate plausible configurations or introduce a justified uncertainty model. Setting H=0.1 within a tree is not automatically equivalent to saying maintenance occupies ten percent of the year; it changes a deterministic input into a random variable with additional assumptions.
Build one tree that exposes the removed train
Assume two full-capacity pumps, local failure events A and B, and a shared-support failure C. The top event is inability to supply a defined demand. Use T=C OR [A AND (B OR H)]. B OR H means that the second pump is unavailable either because it fails or because the selected configuration removes it. A and B represent failure conditional on otherwise being available, not maintenance-inclusive probabilities.
For H=0, the expression reduces to C OR AB. For H=1 it reduces to C OR A. The single-pump condition appears directly; it is not represented by adding an arbitrary penalty to the normal-service result. If the maintenance isolation also removes common suction or power, the configuration requires another change to the tree.
Quantify each state under stated assumptions
Use invented independent demand probabilities a=0.02, b=0.03 and c=0.001. In normal service Q0=c+(1−c)ab=0.0015994. During B maintenance Q1=c+(1−c)a=0.02098. All quantities are dimensionless demand-failure probabilities, and the latter is about 13.1 times the former under this particular model.
The result does not say that any real maintenance activity increases risk by that factor. A planned maintenance window may reduce the required load, restrict operations or provide another approved arrangement. Those changes alter the success criterion or model. Conversely, maintenance can introduce additional errors or shared disturbances that the simple H switch does not represent.
Choose weights from the population of interest
If a randomly selected demand has probability w of occurring during the maintenance state, the total probability is Q=(1−w)Q0+wQ1. With w=0.10, Q=0.00353746. This is the law of total probability over two mutually exclusive, exhaustive configurations. It needs no assumption that state and failure are independent because Q0 and Q1 are already conditional probabilities.
But ten percent of calendar time need not mean ten percent of demands. Suppose thirty percent of demands occur during that same maintenance state because the activity produces more starts or transients. Then w=0.30 and Q=0.00741358. Using time fractions in that case would understate the demand-weighted result by more than a factor of two.
Convert to frequency only after defining demand counts
If there are 200 modeled demands per year, with 140 in normal service and 60 during maintenance, expected failed demands are 140Q0+60Q1=1.482716 per year. Equivalently, 200Q gives the same result for w=0.30. This expected count can exceed one; it is not a probability and should not be capped at one.
A probability of at least one failed demand in a year requires assumptions about repeated demands, persistent faults, restoration and dependence. Reusing one unrepaired failure on several demands is not equivalent to drawing a fresh independent failure each time. A configuration mixture describes a sampled demand; it does not by itself supply a full-year stochastic process.
Prevent impossible and overlapping mode selections
A larger tree may have switches for port, sea, bunkering, test and maintenance conditions. Some can coexist, while others are alternatives. Write a configuration table defining permitted combinations. If port and sea are mutually exclusive, both being true should trigger a model-validation error rather than a plausible-looking result.
A label such as maintenance may hide several physically different states: isolated for inspection, partly reassembled, being tested, or returned to service awaiting verification. Grouping them is reasonable only if their success logic and data are compatible. Where transition states have distinct vulnerabilities, give them explicit rows and appropriate weights instead of averaging them invisibly into a broad category.
Keep data conditioning consistent
A failure probability taken from all service records may already include maintenance unavailability. Inserting it as b and then adding H can count maintenance twice. Conversely, a bench-test probability may exclude installed utilities, environmental conditions and human setup errors. The event dictionary should state what the probability includes and what the configuration logic supplies separately.
Mode-dependent loads can change a, b or c as well as the gate structure. A reduced cooling requirement may allow a smaller pump to count as successful; a hot environment may increase the probability of failure. Do not assume that selecting a different H value is sufficient when the operating state also changes component stress or the required response time.
Check transitions and restoration explicitly
Changing a model switch from one to zero is instantaneous; restoring equipment is a physical process. Valve alignment, removal of temporary connections, protection reinstatement and functional verification may occur at different times. The analysis should identify the evidence that makes the modeled available state credible, without treating a maintenance completion timestamp as proof of every function.
If a protective function is needed during restoration, a separate transition analysis may be required. The static tree can describe a snapshot, but not automatically the order in which functions return. A state model or event sequence is more suitable when an early restart can create a hazard before a later verification or isolation step is complete.
Validate combinations when both trains can be isolated
Introduce two configuration switches, HA for deliberate removal of A and HB for deliberate removal of B. The corresponding expression is T=C OR [(A OR HA) AND (B OR HB)]. With both switches zero it returns the normal redundant model. With only HA true it becomes C OR B; with only HB true it becomes C OR A. With both true, the top event is certain for the unchanged demand because neither train is available.
This last result is a valuable validation test. If the software still reports a small random-failure probability when both full-capacity trains are removed, the configuration logic is wrong or the demand definition has changed without being documented. Planned restrictions may legitimately eliminate the demand during that state, but then the study must represent absence of demand separately. It must not make the unavailable equipment appear reliable.
Distinguish an uncertain present state from a changing population
Sometimes the analyst does not know whether maintenance is active now. Weighting possible states then represents uncertainty about one present configuration. In a yearly demand mixture, the same mathematical weights represent the fraction of demands actually exposed to different configurations. The numerical formula can look identical while the evidence and interpretation differ.
For the present-state question, a verified status observation may resolve the uncertainty. For the yearly mixture, one observation is insufficient; a history of states and demands is needed. Preserve timestamp, equipment scope and the meaning of each status record. A completion message may cover one work order while another isolation remains. The appropriate modeled state follows physical availability for the required function, not the most convenient administrative label.
Present state results before the average
Report Q0 and Q1, the meaning and origin of w, and any changes in required performance. An acceptable-looking weighted mean can hide a poorly protected short interval. Operational decisions may depend on that interval itself rather than its contribution to a yearly average. The relevant criterion must be chosen by the applicable engineering and safety framework.
The public example is an accounting exercise, not permission to operate with one pump unavailable. Its value is to reveal what a maintenance assumption changes, which demands see that change, and what evidence is needed before the model can describe a real vessel. A house event is a transparent modeling control when those boundaries remain visible.
Sources
- Fault Tree Handbook with Aerospace Applications · NASA · Source check date: 2026-10-06
- SAPHIRE technical-reference public abstract · US Nuclear Regulatory Commission / Idaho National Laboratory · Source check date: 2026-10-06