Beruflich Dokumente
Kultur Dokumente
ABSTRACT
There is no common practice of structured transfer of results from risk and reliability analysis in design to operation
requirements in shipping. There is also a general lack of experience feedback from operation to design.
This paper describes a method for utilisation of results from Fault Tree Analysis, FTA, in Reliability Centered Maintenance,
RCM, to improve operational performance, in terms of increased availability and reliability and reduced maintenance costs.
The paper also presents a methodology for continuous improvement of both operation and design. Continuous improvement
necessitates sufficient relevant data, which again requires a rigid regime for data collection. In order to gather sufficient
number of data, data from additional sources may be required. A data collection from various sources will be eased by
applying standardised data formats.
Rules governing shipping have traditionally been prescriptive. In an attempt to address this issue, IMO (UN maritime body)
has arrived at an interim set of guidelines for the application of Formal Safety Assessment, FSA, in the rule-making process.
This paper describes how requirements from an FSA can be applied in FTA.
The issues raised above have been developed and implemented in the EU-founded project MOSys (Models for Operational
Reliability, Availability and Integrity Analysis of Ship Machinery Systems). Experiences from MOSys are presented in the
paper.
1
• Function/system breakdown
To achieve these goals, MOSys will develop • Function analysis
techniques and tools for: • Criticality analysis (FMECA)
• Maintenance assignment
- RAM and maintenance cost analysis, based on • Job packing
ship machinery historical data, FMEA and
criticality analysis. Criticality analysis
The Criticality analysis is a major part of the RCM
- Survey, Inspection and Repair (SIR) planning, analysis, since the criticality of failure modes often
for harmonisation of the logistic support for ship affects the maintenance strategy. Criticality is often
survey, inspection and repair in support of derived from the following formula:
operational availability.
CR = P( xi ) ×S [Ref: 4]
- Technical asset management with assets’ design,
functional and operational data capture and data CR = Criticality
analysis capability in support of RAM, SIR, P(Xi) = Probability of occurrence of the failure mode
maintenance cost analysis, and the life-cycle Xi for component i.
tracking of the asset’s conditions. This is targeted S = Severity factor (function of consequences)
at the ship operation phase.
In many cases the system architecture is complex, and
- The above modules will be supported by a single failure mode does not always lead to a system
development of a distributed SEMDR (Ship failure (e.g. two pumps may stand in parallel, and
Equipment and Machinery Data Repository) that both pumps must stop to cause a critical situation).
will be based on the ISO 10303 (STEP)
Application Protocol 226 (Ship Mechanical A more explicit measure for criticality may therefore
Systems) [Ref: 2]. be derived from the following formula:
∂Q0 (t )
I B (i | t ) = for i = 1,2,..., n [Ref: 5]
Data capture ∂qi (t )
and preparation
2
An alternative definition of Birnbaum's measure is: Each new fault tree is connected to a function in the
function hierarchy. Figure 3 shows how the function
Birnbaum's measure of reliability importance of hierarchy appears in RCMTool. The fault tree can be
component i at time t is equal to the probability that linked to any function at any level in the function
the system is in such a state at time t that component t hierarchy.
is critical for the system [Ref: 5].
There can be no exact recipe for linking fault trees to
We can therefore say that: the functional hierarchy. This excerise must be
P(H|xi) = IB performed on a case to case basis; it is, however,
possible to give some rules of thumb.
Practical implementation
The integration between RCM and FTA is The fault tree methodology should mainly be used on
implemented in a software prototype, where the the most critical functions, since it is time consuming
prototype version of RCMToolII and CARA Fault to analyse all functions. The functions where fault
TreeIII are linked together. The RCM analysis is trees are used should also be complicated enough to
performed in RCMTool, while fault tree definition justify the use of fault tree analysis. The fault trees
and fault tree calculations are performed by CARA should be linked to a level in the functional hierarchy,
Fault Tree. All data for RCMTool is stored in a which give useful results. This will probably vary in
database. In the same database the name of the fault the systems life cycle. In the design phase, one might
trees is defined with connections to specified be interested in comparing the reliability of two
functions in the function hierarchy. RCMTool different lubrication oil systems. In such a case,
comprises the following main parts: lubrication of main engines, may be an appropriate
function level. In another cases, one might be
-Function tree interested in identifying the main contributors to risk
-Equipment assignment for grounding. In such a study propulsion might be a
-Function analyses more suitable level.
-FMECA (Failure Mode Effect and Criticality
Analysis)
-Maintenance task assignment
Function code
Part #1
Function
failure #2
Part #2
Function
failure #3
Part #3
Failure mode #1
Failure mode #2
Failure mode #3
II
RCMTool is a software product developed by
MARINTEK
III
CARA Fault Tree is a software product developed
by SINTEF
3
Figure 3: Screen picture from Function Tree part of RCMTool
4
Definitions of new fault trees is performed in the categories as it may be used later in the FMECA
screen picture shown in Figure 4. Function code part of RCMTool.
and name is automatically displayed in the first
field, and top event must be chosen from a set of When all attributes have been defined, it is possible
predefined top events in the following field. to start constructing the fault tree. So far the new
fault tree and its attributes have been defined in the
The weight factor, which is assigned to each fault RCMTool database, and the fault tree name is
tree, is a consequence measure, for comparison of linked to function code. Construction of the new
results from different fault trees. This is useful if fault tree is done manually, meaning the user
e.g. a failure mode is part of two different fault defines appropriate gates and basic events in the
trees. In one fault tree, the failure mode is a big fault tree. However, some support from RCMTool
contributor to the probability of the top event, while is offered. When basic events have been defined it
the failure mode is ranked low in the other fault is necessary to supply them with data. These data
tree. In such an example the result from the fault are often already entered into the RCM database
tree with highest weight factor should be paid most during the FMECA. This integrated software makes
attention. it possible to retrieve data from the RCM database
to ease the FTA.
The fault tree must be assigned to at least one of the
four categories (Safety, Environment, Production An example of a fault tree is showed in Figure 5.
Down Time, Maintenance Cost). The categories
found here are the same as the criticality codes used
in RCMTool. It is important to select the correct
5
The data presented in Figure 6 come from Criticality is often expressed with respect to the
RCMTool, and all equipment and assigned failure following four parameters:
modes that are found below selected function (in
this example function 1.1.7) will be in this list. • Safety (S)
Basic events in the fault tree often correspond with • Environment (E)
the identified failure modes in RCMTool, and it is • Production down time (P)
therefore possible to reuse much of the information • Maintenance cost, incl. equipment damage (M)
entered during the RCM analysis. Basic events in a
fault tree may also be human failures that seldom Criticality is determined for each of the four
are considered in an RCM analysis. Data for such parameters, in this case the values 0,1,2 or 3 are
basic events must therefore be entered manually. used, but other parameters may also be used.
When data for all basic events have been defined, it Results from fault tree analysis is intended to
is possible to perform calculations for the fault tree support the user in determining the criticality. This
using available functions in CARA. These functions can be done in cases where selected equipment and
are found in the “Analysis” menu, but the functions functional failure in FMECA is also found in one or
will not be discussed here. Results from fault tree more fault trees. When defining new fault trees
calculations will be performed automatically when some equipment and functional failure is included
the FMECA is carried out in RCMTool at a later in fault trees as basic events. In such cases it is
stage. possible to perform fault tree analysis from FMECA
without having to remember details from definition
In the FMECA part of RCMTool, criticality of fault trees. The system will automatically find all
analysis is performed. The criticality is a measure of fault trees where selected equipment and functional
the product of the consequence and its related failures were included, and then present results from
frequency, as a result of an equipment failure, fault tree calculations.
which in next turn causes a functional failure.
6
"Reliability" and "Weight" are therefore not
discussed further.
Continuous Improvement
As stated in the introduction, there is, within the
maritime industry, a strong need for a more
systematic feedback of historical data from
operation to design. In order to improve equipment
design based on experience data, a system must be
Figure 8: Example of result from fault tree available for collection and analysis of failure data.
analysis for use in criticality assessment in
FMECA part of RCMTool In addition to the continuous improvement of
design based on operational data, there is a
significant potential for improvement of
Figure 8 shows results from fault tree calculations. maintenance and spare part stock in operation.
Theoretically it is possible to rank all failure modes Normally in shipping and most industries,
with respect criticality using the following formula: continuous improvement of maintenance is based
on deviation analysis on macro level, e.g.
m
Crit i = ∑ P( xi ) × P( H j | xi ) ×S j
Ratio Planned Maint./Corrective Maint. or
Back-log - (jobs not carried out according to plan).
j =1
Unfortunalely, corrective actions are, more the rule
than the exception, characterised as accidental,
Criti = Criticality measure for failure mode i unsystematic, time and cost intensive.
P(xi) = Probability of occurrence of failure mode i.
P(Hj|xi) = The conditional probability of top event The TAIM module in MOSys includes among other
j, given failure mode Xi for component i. features, a solution for continuous improvement of
S = Severity factor for top event j maintenance. The idea is to analyse extensive
m = number of top events amounts of historical data in order to reveal
deviations between planned and reported
This formula assume that all critical events are maintenance.
modelled by means of FTA.
The methods for continuous improvement analysis
Within MOSys the following syntax is used: of RAM data, is conceptually shown in Figure 9.
m
Crit i = ∑ lambda × I B ×weight j
Title:
contimp.eps
IV Creator:
Micrografx Graphics Engine
Preview:
This EPS picture was not saved
j =1
with a preview included in it.
Comment:
This EPS picture will print to a
PostScript printer, but not to
other types of printers.
7
RAM/SHIPNET was established in the US under design applications, and in addition extend the
the umbrella of the Ship Operations Cooperative AP226 to embrace operational data.
Program (SOCP). The project was set up as an
information network, which should support the FTA - FSA
optimisation of reliability, safety and the operation Rules governing shipping have traditionally been
costs of the ship operation. Involved in this project prescriptive. In an attempt to address this issue,
are a number of government organisations and IMO (UN maritime body) has arrived at an interim
regulatory bodies as well as ship operators and set of guidelines for the application of Formal
research institutes. Consisting of a distributed and Safety Assessment, FSA, in the rule-making
shared Reliability, Availability and Maintainability process.
(RAM) database, RAM/SHIPNET was designed to
collect, process, disseminate and to store marine The FSA is in principle a guideline for carrying out
equipment failure informations. risk analyses.
Data input for this database is coming from Chief One of the activities in MOSys regarding FSA, was
Engineers, ship-operation managers, regulatory identify information types by applying the FSA
agencies, equipment manufacturer and shipyards. guideline on a selected case (ship propulsion
Software to ease the data collection has been system).
developed within RAM/SHIPNET, and these
software products are today used on several ships to The FSA comprises five steps:
collect data. • Hazard identification
• Risk Assessment
The MOSys consortium soon realised the need for • Evaluation of risk-control options
RAM data, and MOSys has therefore formalised co- • Cost-benefit assessment
operation with RAM/SHIPNET. • Recommendations for decision-making
Conclusion
8
The aircraft industry, nuclear industry and space Specifications”, Svein Inge Masdal, Roar Bye & al.,
industry has applied RAM analyses in design and MOSys Report D2.2-1, 1998.
operation great success.
Ref: 4 “Reliability Centred Maintenance”,
MARINTEK has, through the MOSys project, Anderson and Neri, ELSEVIER Applied Science
presented a methodology for integrating fault tree 1990
analysis and RCM analyses. The intention has been
to improve the decision base upon which the Ref: 5 “System Reliability Theory, Models and
maintenance plan has been founded. We have in Statistical Methods”, Arnljot Høyland & Marvin
addition demonstrated that a link between a Rausand, John Wiley & Sons, 1994.
prototype RCMTool and a commercial FTA tool
(CARA) can be established and operate Ref: 6 “Interim Report of SOCP Reliability”,
satisfactory. Availability, Maintainability Data Bank for Ships,
Dr. Bahadir Inozu, Nov. 1993.
The integration has been based on the fact that in
accordance with the definition, maintenance is
needed to ensure availability, and is thus also Ref: 7 “Reliability Data Collection for Ship
directly influencing - and influenced by - the Machinery”, Dr. Bahadir Inozu & al., Marine
reliability of an item. The worse the reliability, the Technology, April 1998.
more maintenance is required.
References
Ref: 1 “Evaluation of Existing RAM and
Maintenance Cost Analysis Concepts”, Alfred
Mechsner & al., MOSys Report D2.1-1, 1998.