SiliciumHex FieldKit

Problem Solving & Quality · Root Causes

Fault Tree Analysis

Start from the undesired top event and break it down with AND / OR gates into the combinations of failures that can produce it.

  • Time1 h 30
  • FormatSolo
  • StageRoot Causes

Fault Tree Analysis: what it is and why it works

Fault tree analysis (FTA) starts from an undesired top event and breaks it down, level by level, into the combinations of lower-level events that can produce it. An OR gate means any one input is enough; an AND gate means all inputs must occur together. Branches are developed down to basic events such as component failures, human errors and external conditions, and in an investigation each basic event is marked confirmed, excluded or unknown from the evidence. The analysis then identifies the minimal cut sets: the smallest combinations of basic events that lead to the top event.

FTA suits failures that need several conditions at once, which is typical of trips, leaks and protective systems with redundancy. Its logic shows not only what went wrong but how many barriers had to fail, and where a single failure is enough: an OR path straight to the top is a warning sign. It is more rigorous and more demanding than a fishbone. Gates must be defined precisely, and common-cause failures, where one event disables two supposedly independent inputs, must be looked for explicitly. With failure data the tree can be quantified: for independent events, AND-gate probabilities multiply, and for rare events an OR gate is close to the sum of its inputs. In investigations it builds on the event timeline; in design it complements FMEA and guides the choice of controls.

What you need

  • A precise definition of the top event and the system boundary
  • P&IDs, logic diagrams and design documents
  • Evidence from the investigation: timeline, parts, data
  • Knowledge of component failure modes, and failure data if the tree will be quantified
  • Specialists for the equipment and control systems involved

What you get

  • A fault tree with defined gates and basic events
  • A status for each basic event: confirmed, excluded or unknown
  • The minimal cut sets leading to the top event
  • Identified single points of failure and common-cause vulnerabilities
  • Countermeasures targeted at the credible paths

When to use it

When a failure needs several conditions at once — typical of trips, leaks and safety systems.

How to do it, step by step

  1. Define the top event precisely, with its boundary: “loss of containment at pump P-12 seal”, not “leak”.
  2. Ask what immediate events could cause it, and whether they act alone (OR gate) or together (AND gate).
  3. Develop each branch down to basic events: component failures, human errors, external conditions.
  4. Mark each basic event with evidence from the investigation: confirmed, excluded, unknown.
  5. Identify the minimal combinations that lead to the top event and target the countermeasures there.

Worked example: Chemical tank overflow during a delivery

Illustrative scenario — figures are realistic but not from a real company.

A 12,000-gallon ferric chloride storage tank at a regional water treatment plant overflows into its secondary containment during a truck delivery. Nobody is hurt and the containment holds, but the release has to be reported. The tank has a level transmitter with a control-room high alarm and an independent high-level switch meant to warn the driver at the fill point.

  1. Top event: 'ferric chloride overflow from tank T-3 during delivery', bounded to the tank, its instruments and the fill station.
  2. First level: an AND gate. The tank must be overfilled AND the filling must not be stopped in time. Overfilling sat under an OR gate: wrong estimate of available volume, or wrong delivered volume.
  3. 'Not stopped' needed both protection layers to fail, another AND gate: the control-room alarm not acted on, AND the high-level switch not warning the driver.
  4. Evidence: the available volume had been estimated from a level reading taken before an internal transfer; the transmitter alarmed correctly, but the only operator was handling an upset elsewhere; the high-level switch failed its post-event test, stuck by crystallized deposits.
  5. Minimal cut set confirmed: wrong volume estimate AND alarm not acted on AND switch failed. A common-cause check found no shared cause among the three.

Result. Because the path ran through AND gates, breaking any one input would have prevented the overflow. The plant added cleaning and proof-testing of the switch to its maintenance program, required a live level reading at the fill point before each delivery, and routed the high alarm to a horn at the fill station. The tree showed the plant had relied on three layers, each weaker than assumed.

Common pitfalls and how to avoid them

  • A vague top event.Define the event and its boundary precisely: equipment, substance and failure mode.
  • Confusing AND and OR gates.For each gate, ask whether any one input is enough on its own; if it is, the gate is an OR.
  • Ignoring common-cause failures.Check whether redundant inputs share a power supply, a maintenance practice, a location or a design, and model the shared cause if they do.
  • Stopping at a basic event that is still an explanation.Develop each branch until the basic event can be confirmed or excluded with evidence, or acted on directly.

Frequently asked questions

What is the difference between FTA and FMEA?

FMEA works bottom-up: it starts from each component or process step, lists how it could fail and assesses the effects. FTA works top-down: it starts from one undesired event and traces the combinations of failures that could cause it. FMEA is broad and suits design and process reviews; FTA is focused and suits understanding how several failures combine into one serious event.

What is a minimal cut set in fault tree analysis?

A minimal cut set is a smallest combination of basic events that, if all occur, causes the top event: remove any one event from the set and the top event no longer follows. A cut set containing a single event is a single point of failure. Listing the minimal cut sets shows where the system is most vulnerable and which countermeasure breaks the most paths.

Can fault tree analysis be used for incident investigation?

Yes. The tree is built from the top event down, and each basic event is then marked confirmed, excluded or unknown based on the evidence. The confirmed path shows which combination actually occurred, and the unknown events become investigation questions. It pairs well with an event timeline: the timeline gives the order of events, the tree gives their logic.

Origin

Fault tree analysis — H. A. Watson, Bell Telephone Laboratories, 1962 (Minuteman launch control study).

Used in these playbooks

Major breakdown investigation 1 week

One week after a trip, a leak or a critical equipment failure: rebuild the sequence, map the failure combinations, dig to the cause, choose strong barriers and record the lesson.

  1. Event Timeline Reconstruction
  2. Fault Tree Analysis
  3. 5 Whys
  4. Hierarchy of Controls
  5. Lessons Learned Register

Related methods

More in “Root Causes”

List the possible causes, dig down the chains and prove the real one before acting.