Knowledge / Risk and reliability
FTA importance measures: what different rankings actually measure
Distinguish Birnbaum sensitivity, perfect-improvement benefit and risk-reduction worth with a worked redundant-system ranking and realistic intervention checks.
On this page
A component can be highly important for preserving present performance while offering little practical improvement because it already fails very rarely. Another can offer a larger reduction even though the top event is less sensitive to each unit change in its probability. Fault-tree importance measures answer different questions. Reading their definitions is more useful than asking for one universal list of critical equipment.
State the model and the intervention
Use a hypothetical service with top event T=C OR AB. A and B are local train failures; C is a separate common-support failure. Either local train can meet the specified demand. Assume independent basic-event probabilities a=0.20, b=0.01 and c=0.0005. The values are invented to make ranking differences visible, not to represent marine failure data.
The exact top probability is Q=c+(1−c)ab=0.002499. Every importance result below refers to that one demand, architecture and joint model. Improving a pump may change several failure modes, maintenance requirements or support dependencies; setting one abstract probability to zero represents only an idealized intervention on that event.
Calculate Birnbaum importance as a sensitivity
For event i in this independent coherent model, Birnbaum importance is Ii=Q(qi=1)−Q(qi=0), with all other probabilities held fixed. It equals the partial derivative of Q with respect to qi. The NASA handbook describes this zero-to-one sensitivity. Here IA=(1−c)b=0.009995, IB=(1−c)a=0.1999 and IC=1−ab=0.998.
C ranks first, then B, then A. This means the top probability is most responsive to an equal absolute probability change in C. It does not mean that C currently contributes the largest avoidable probability. The measure depends on the other event probabilities and the structure; calling it purely structural without that qualification would conceal an important dependence.
Measure the ideal removable contribution
Define the absolute ideal reduction Di=Q−Q(qi=0). In this model Di=qiIi. Eliminating A gives DA=0.001999; eliminating B gives the same DB=0.001999. Eliminating C gives DC=0.000499. A and B therefore tie for ideal improvement, ahead of C, even though their Birnbaum scores differ twentyfold.
The reason is direct: removing either A or B eliminates the same AB route. C has a larger sensitivity per unit probability, but its starting probability is much smaller. Do not add DA and DB as though they were separate benefits. Removing both cannot remove the AB route twice, and the shared C route remains.
Define the ratio before calling it risk-reduction worth
Here the ratio form of risk-reduction worth is RRWi=Q/Q(qi=0). It equals 4.998 for A and B because the residual probability is c=0.0005. For C it is 0.002499/0.002=1.2495. Some references also discuss absolute worth, so write the equation alongside the label rather than relying on the acronym.
The fractional ideal reduction Di/Q is approximately 0.800 for A or B and 0.200 for C. Such fractions describe counterfactual changes, not an allocation of mutually exclusive accident causes. Across overlapping event contributions they need not sum to one. If Q(qi=0)=0, the ratio is unbounded; that mathematical result is not evidence that an attainable modification makes real risk vanish.
Evaluate achievable changes instead of perfect components
Halving a from 0.20 to 0.10, while retaining the other assumptions, gives Q=0.0014995 and a reduction of 0.0009995. Halving c from 0.0005 to 0.00025 gives Q=0.0022495 and a reduction of 0.0002495. The same relative fifty-percent improvement therefore produces four times more modeled benefit for A in this example.
The calculation says nothing yet about cost, feasibility, new hazards or evidence that either improvement can be achieved. A larger pump might change starting demand on a shared supply; a more complex sensor might add maintenance errors. Compare the complete proposed configuration with the baseline, keeping required function and consequence boundary consistent.
Distinguish improvement from preserving performance
For a different question, set an event probability to one and compare Q(qi=1) with baseline Q. This explores the modeled effect of losing that feature. A low present probability can give modest improvement potential while failure of that feature would be severe. The NRC importance-measures report abstract distinguishes improvement priorities from reliability-assurance priorities.
A maintenance decision that removes C protection cannot be justified solely by its small ideal reduction DC. In the example, C occurring makes T certain, so Q(c=1)=1. That is a property of this top event, not an assertion that every shared-support failure causes a major accident. The consequence analysis remains a separate part of the risk picture.
Treat groups and dependencies as actual interventions
A common maintenance procedure may affect several events at once. The benefit of changing that procedure is not the sum of separately calculated event benefits because the same top-event states can be removed by several interventions. Recalculate the group change directly. If improving one event changes another event's probability, a one-at-a-time derivative no longer describes the full change.
The NRC advisory discussion notes that individual rankings can miss group significance and that model scope influences results. For a ship, a shared compartment fire or restoration error should not disappear merely because the equipment list allocates each component to a different department.
Check ranking stability under uncertain inputs
For T=C OR AB, IC=1−ab while IA=(1−c)b. Changing b changes A's sensitivity even though A's own probability is untouched. If input intervals are broad, report the ranges of benefits or test a set of coherent parameter combinations. Ranking the means alone can hide a different ordering under credible conditions.
Separate numerical precision from decision precision. Reporting RRW=4.998 is useful for reproducing this arithmetic, but it does not imply field data support four significant figures. A stable broad priority with uncertain exact magnitude is often more defensible than a sharply ordered list whose middle positions exchange under minor assumptions.
Name the parameter being improved
A derivative with respect to demand-failure probability is different from a derivative with respect to a failure rate. If q=1−e^(−λt) for a nonrepairable constant-rate model, then dq/dλ=t e^(−λt). Sensitivity of the top probability to λ is therefore the Birnbaum sensitivity to q multiplied by this factor. Its units are time because λ has inverse-time units.
Consequently, ranking equal absolute changes in failure rates need not give the same order as ranking equal changes in probabilities, especially when missions differ. A maintenance proposal may instead reduce repair time or test interval, requiring the relationship between that parameter and unavailability. Start from the actual change being considered and propagate it through the model. A list of probability sensitivities cannot be relabeled as maintenance effectiveness without that connection.
Distinguish forcing an event from observing it
In the independent worked model, fixing A true while retaining the other probabilities is a clean counterfactual calculation. In a dependent system, learning that A failed can also change what is known about B or C. For instance, observing a pump failure during a common flood may imply a different condition for the other train. Conditional observation and a hypothetical design intervention are then different questions.
An importance report should say what remains fixed and what is allowed to change. Replacing a shared component can alter the joint distribution, not merely one marginal probability. If the software's importance routine freezes dependencies or substitutes a basic event mechanically, interpret the output under those conventions. The ranking is useful as a model sensitivity, but its physical improvement meaning requires a compatible intervention model.
Report the question answered by every score
An importance record should include the top-event definition, observation interval, baseline, exact formula, changed event set, residual probability and practical intervention being considered. Keep consequence severity visible: a ranking for loss of a minor service is not automatically a ranking for personnel or environmental harm. Different top events may need separate evaluations.
These measures help explain where a model is sensitive and where modeled improvement is available. They do not authorize maintenance deferral, removal of redundancy or acceptance of a vessel. Their most useful role is to turn a broad claim of criticality into a precise, reviewable statement about a defined change and its assumed effect.
Sources
- Fault Tree Handbook with Aerospace Applications · NASA · Source check date: 2026-10-06
- Measures of Risk Importance and Their Applications: public abstract · US Nuclear Regulatory Commission · Source check date: 2026-10-06
- Importance Measures Derived from Probabilistic Risk Assessments · US Nuclear Regulatory Commission, Advisory Committee on Reactor Safeguards · Source check date: 2026-10-06