Definition
An aerospace assurance concept defining processes used to demonstrate safety, compliance, and readiness for flight or mission operations. It governs hazard identification, verification evidence, configuration control, and formal reviews that gate progression to operation. It does not guarantee success without robust design margins and rigorous completion of test and review actions. It materially affects operational safety and certification outcomes by structuring risk reduction and verification completeness. The concept is generally stable, though assurance practices and regulatory guidance evolve over time.
Principle
Principle
Start from a defined top event, decompose into immediate causes using AND/OR logic, continue to component level to obtain minimal cut sets, and combine qualitative structure with quantitative failure data while explicitly noting assumptions about independence and common causes.
Demonstration
Demonstration
Construct a fault tree for an 'uncommanded thrust reduction' top event; OR gates combine different failure modes (fuel control, sensor fault, software anomaly), AND gates represent required simultaneous faults, and minimal cut sets identify combinations requiring mitigation such as redundancy or monitoring.
Misapplication
Misapplication
Applying standard fault tree probability formulas while assuming independent failures where common‑cause effects exist, or using a static fault tree to represent dynamic, mission‑dependent sequences without temporal modeling.
Consequence
Consequence
Proper FTA identifies critical failure combinations, supports allocation of redundancy and test strategy, informs safety requirements, and feeds into system safety assessments and certification evidence.
Reversal
Reversal
Bottom‑up methods such as FMEA list single‑point failures and effects but do not by themselves show how combinations of failures interact to cause a system‑level top event.
Boundary
Boundary
FTAs are best suited for statically analyzable combinations of failures and for quantifying top‑event probability given credible failure rates; they are not a complete replacement for dynamic or human‑error modeling and should be complemented by other techniques where appropriate.
Semantic Tension
Semantic Tension
Tension exists between FTA (top‑down combinatorial causality) and FMEA (bottom‑up component failure effects); each addresses different analysis questions and they are complementary rather than interchangeable.
Synthesis
Synthesis
Fault Tree Analysis provides a rigorous logical and probabilistic framework to trace how component faults and events combine to produce system‑level failures, enabling targeted mitigations, quantitative risk estimates and integration into broader safety assurance activities.