MADEKnowledge

MADE Training > Session 3 > Session 3.5: Failure Conditions (FHA)

Session 3.5: Failure Conditions (FHA)

Note: This training deck is primarily composed of instructional screenshots (numbered dialog boxes, toolbar callouts, field highlights). The text below preserves all extractable slide text — titles, bullet points, discussion/exercise headings, and table content. Where a slide is dominated by an unlabeled screenshot, only the caption and step-list text could be extracted; screenshot visual detail itself is not represented.

Session 3.5: Failure Conditions (FHA)

SESSION 3.5 OUTLINE 3.5.11: Initial Criticality Assessment 3.5.12: Assign Control Measures 3.5.1: Prepare Failure Conditions 3.5.13: Revised Criticality Assessment 3.5.2: Define Safety Criteria 3.5.14: Assign Assumptions 3.5.3: Define Assumptions 3.5.15: Assign Substantiation Actions 3.5.4: Define Control Measures 3.5.16: Multiple Failure Event 3.5.5: Define Substantiation Actions 3.5.17: Failure Association 3.5.6: Failure Modes & Failure Conditions 3.5.18: Link Functions to System Model 3.5.7: Assign Mission Profile 3.5.19: FHA Output (Report and Export) 3.5.8: Assign Events & Conditions 3.5.9: Assign Safety Criteria 3.5.10: Failure Effects Assessment


Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.1 PREPARE FAILURE CONDITIONS

Define Safety Criteria, Assumptions, Control Measures, and Substantiation Actions for the functional modelling in Project Preferences

Failure Conditions page in Functional Diagram is used to: Associate Failure conditions to individual Functional Failures Associate a Failure Condition with Mission Profile Phases/Segments/Specialised Phases Associate a Failure Condition with Mission Events and Mission Conditions Associate a Failure Condition with Safety Criteria


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.1 PREPARE FAILURE CONDITIONS

For this section we will need to change the criticality profile to PHMT Risk Assessment Criteria (FAA).

Select Preferences Criticality Profile Editor from the menu bar Select PHMT Risk Assessment Criteria (FAA) as the Active Project Profile


Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.2 DEFINE SAFETY CRITERIA

Safety Criteria: A description of benchmark to ensure safety of the system Identifies collections of potential high-level hazards applicable for the functional modelling Assign criticality to each high-level hazard Define safety criteria and minimum safety criteria

Note: One Safety Criteria can be associated with multiple failure conditions in Functional Diagram. New safety criteria can be created in Functional Diagram, if required.


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.2 DEFINE SAFETY CRITERIA

Navigate to Safety Criteria,

Select Preferences Project Preferences Select Functional Hazard Assessment Safety Criteria

To create a Safety Criteria,

Select


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.2 DEFINE SAFETY CRITERIA (CONTINUED)

Enter the following details for the collection of potential high-level hazards Category ID: ACC Category Name: Adaptive Cruise Control

Select to create high-level hazards


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.2 DEFINE SAFETY CRITERIA (CONTINUED)

Enter the following details for the hazards for `Adaptive Cruise Control' category

Hazard ID Hazard Name Description Criticality

ACC_01 False sensing Incorrect or unreliable sensor readings leading to Catastrophic improper vehicle speed adjustments.

ACC_02 System lag Delays in the ACC system's response to changing traffic Hazardous ACC_03 conditions, potentially leading to unsafe situations. Major Unintended acceleration/deceleration ACC system malfunction causing sudden and unexpected acceleration or deceleration.

Enter

   Safety Criteria: ACC system should maintain a safe and consistent following distance from the vehicle ahead,
     taking into account the vehicle's speed and traffic conditions

   Minimum Safety Criteria: ACC system must maintain a minimum following distance from the vehicle ahead, as
     specified by relevant safety standards and regulations

Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.2 DEFINE SAFETY CRITERIA (CONTINUED)


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.2 DEFINE SAFETY CRITERIA (CONTINUED)

Create another Safety Criteria with the following details:

   Category ID: REPD
   Category Name: Reliable and efficient power delivery

Hazard ID Hazard Name Description Criticality REPD_01 Fuel Leaks Minor Leaks in the fuel system can pose fire hazards and REPD_02 Turbocharger Issues reduce fuel efficiency.

                         Turbocharger failures or malfunctions can affect engine Hazardous
                         performance and lead to potential safety concerns.

Enter criteria details:

   Safety Criteria: The fuel system should be leak-proof and equipped with safeguards to prevent fuel leaks,
     minimizing fire hazards and ensuring efficient fuel utilization.

   Minimum Safety Criteria: The fuel system must meet safety standards that prevent fuel leaks and meet efficiency
     requirements to minimize environmental impact.

Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.2 DEFINE SAFETY CRITERIA (CONTINUED)


Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.3 DEFINE ASSUMPTIONS

Assumption: A statement, principle, and/or premises offered without proof. Define assumptions for the functional modelling when any consideration MADE during the assessment that

was not based on validated functional information.

Note: One Assumption can be associated with multiple failure conditions in Functional Diagram. New assumptions can be created in Functional Diagram, if required.


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.3 DEFINE ASSUMPTIONS

Select Preferences Project Preferences Select Functional Hazard Assessment Assumptions

To create an Assumption,

Select

Note: Assumption will be reviewed and substantiated while performing the assessment.


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.3 DEFINE ASSUMPTIONS (CONTINUED)

Enter ID, Name, and Description for the assumption:

ID: ASM_01 Name: Engine's horsepower and torque Description: The engine's horsepower and torque output are

sufficient to meet the vehicle's performance requirements and allow it to accelerate and maintain desired speeds under typical driving conditions

Note: Assumption will be reviewed and substantiated while performing the assessment.


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.3 DEFINE ASSUMPTIONS (CONTINUED)

Create another assumption with the following information:

ID: ASM_02 Name: Fuel efficiency Description: The fuel system and combustion process are

optimized to provide efficient fuel consumption, and the vehicle meets emission standards without excessive emissions of harmful pollutants.

Note: Assumption will be reviewed and substantiated while performing the assessment.


Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.4 DEFINE CONTROL MEASURES

Control Measures: A concept that is implemented to reduce risk in the system. Compensating Provisions taxonomy is used for defining control measures for the functional modeling.

Note: Navigate to Preferences > Customise Taxonomy to view/create taxonomy. One Control Measure can be associated with multiple failure conditions in the Functional Diagram. New control measures can be created in Functional Diagram, if required.


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.4 DEFINE CONTROL MEASURES

Select Preferences Project Preferences Select Functional Hazard Assessment Control Measures

To create a Control Measure,

Select


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.4 DEFINE CONTROL MEASURES (CONTINUED)

Enter ID, Name, and Narrative for the control measure:

ID: CM_01 Name: Automated Power Limitation Description: Implementing automated systems that can limit engine

power output in specific situations to prevent overloading or overheating. Control Measure Type: Safety Devices


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.4 DEFINE CONTROL MEASURES (CONTINUED)

Create another Control Measure with the following information:

ID: CM_02

Name: Regular Maintenance and Inspections

Description: Establishing a comprehensive maintenance schedule for the vehicle's powertrain components, including the engine, transmission, and associated systems. Regular inspections and servicing help identify and address wear and tear before it escalates into more significant problems.

Control Measure Type: Procedures


Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.5 DEFINE SUBSTANTIATION ACTIONS

Substantiation Actions: All the activities performed to produce evidence that an FHA is complete and correct.

According to ARP4761 Rev A, substantiating data for FHA should be collected, showing that

   All the aircraft/system level functions have been considered
   All failure conditions have been identified for each aircraft /system function
   The failure effects on the aircraft /system, crew and occupants are complete and correct for each failure condition

     occurring during each flight phase
   The correct failure classification has been selected based on the failure effects
   The assumptions used to develop the assessment are confirmed and evidence is provided. In cases where an

     assumption is incorrect, the correct information should be provided and the FHA updated

Note: Navigate to Preferences > Customize Taxonomy to view/create taxonomy. One Substantiation Action can be associated with multiple failure conditions in Functional Diagram. New Substantiation Actions can be created in Functional Diagram, if required.


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.5 DEFINE SUBSTANTIATION ACTIONS

Select Preferences Project Preferences Select Functional Hazard Assessment Substantiation Actions

To create a Substantiation Action,

Select


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.5 DEFINE SUBSTANTIATION ACTIONS

Enter ID, Name, and Narrative for the Substantiation Action:

ID: SA_01 Name: Engine Performance Testing Description: Conducting thorough testing of the engine's

horsepower and torque output under various load conditions to validate its capability to meet performance requirements. Substantiation Action Type: Test


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.5 DEFINE SUBSTANTIATION ACTIONS

Create another Substantiation Action with the following information:

ID: SA_02

Name: Combustion Process Analysis

Description: Analyzing the combustion process in the engine to ensure it is optimized for efficient fuel utilization and minimized emissions.

Substantiation Action Type: Analysis


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.6 FAILURE MODES & FAILURE CONDITIONS

Open the Functional Diagram editor to access Failure Conditions page:

Select the System in Project Explorer, Modeling Functional Diagram

Open Functional Diagram of the Provide Thrust function

Open Failure Condition page for Distribute Mechanical Motion Right-click Distribute Mechanical Motion then select Failure Condition from menu


Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.6 FAILURE MODES & FAILURE CONDITIONS

The Failure Condition page enables user to create:

   1 or more Failure Modes per Function
   1 or more Failure Conditions per Failure Mode

The Failure Condition tabs helps to associate/assess

   Mission Phases/Specialised Phases
   Events & Conditions
   Safety Criteria
   Failure Effects
   Criticality
   Control Measures
   Assumptions
   Substantiation Actions

Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.6 FAILURE MODES & FAILURE CONDITIONS

To create a new Failure Mode:

In the Distribute Mechanical Motion Failure Conditions page:

   Select to add a new Failure Mode

From the Create new Failure Mode dialog:

  Enter name: Inability to Distribute Mechanical Motion (Forward)

Select the newly created Failure Mode In the Properties, enter

   ID: FF01
   Failure Effect: Failure of this function will prevent forward movement of the vehicle system.

Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.6 FAILURE MODES & FAILURE CONDITIONS

To create a new Failure Condition:

Select the newly created Failure Mode Select the Add new Failure Condition icon Select the newly added Failure Condition

Enter the following details in Properties:

   ID: FC1
   Name: Failure Condition 1
   Type: Loss of Output
   Narrative: Loss of output due to power source failure.

Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.7 ASSIGN MISSION PROFILE

This tab allows the user to select applicable mission profiles to a selected failure condition User selects applicable mission phases/segments and specialised phases where the failure condition occurs


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.7 ASSIGN MISSION PROFILE

To edit the Mission Profile details for the Failure Condition:

   Select Failure Condition 1
   Select the Mission Profile tab
   From the drop-down menu and select Regular Trip
   Select the following Mission Phases:

          2 - Acceleration
          5 - Cruise
          6 - Deceleration

   Select the following Specialized Phases:

          Autonomous Parking

Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.8 ASSIGN EVENTS & CONDITIONS

This tab allows the user to assign applicable Mission Events & Conditions and capture Operator awareness relating to the selected Failure Condition.

Mission Events & Conditions are by default filtered by the assigned Mission Sections and Specialised Phases.


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.8 ASSIGN EVENTS & CONDITIONS

Select Events & Conditions tab Operator awareness: Not relevant Select the following Mission Events and Conditions:


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.9 ASSIGN SAFETY CRITERIA

Select Safety Criteria tab Select to view all the Safety Criteria created for the functional model

Select `Reliable and efficient power delivery' applicable for the selected failure condition


Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.9 ASSIGN SAFETY CRITERIA

Delete will remove the assigned safety criterion from the selected failure condition. Select to create new /edit / delete safety criteria in Project Preferences.

   Changes to safety criteria will be reflected within the Functional Diagram.

Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.10 FAILURE EFFECTS ASSESSMENT

The assessment examines each failure condition and determines the effects should the failure condition occur in each of the selected mission sections.

The assessment of the effects begins with a narrative description of the consequences of the failure condition followed by a statement summarizing the failure condition's overall impact.


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.10 FAILURE EFFECTS ASSESSMENT

Failure effects can be captured in additional categories, for example: Effect on Vehicle and/or Effect on Occupants.

Select Preferences > Project Preferences Select Functional Hazard Assessment > Failure Effects Select to add an additional category Select Effect on Occupants Enter the following details:

   Description: Description of effect on the occupants

Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.10 FAILURE EFFECTS ASSESSMENT

Enter the following failure effect narratives

Mission Profile / Overall Effect Effect on Occupants Section The effects of the failure condition on the occupants in the selected Regular Trip The overall effect of the failure condition in the selected mission profile. mission profile. The effects of the failure condition on the occupants in Acceleration phase. Acceleration The overall effect of the failure condition in Acceleration The effects of the failure condition on the occupants in Cruise phase. phase. The effects of the failure condition on the occupants in Deceleration phase. Cruise The overall effect of the failure condition in Cruise phase.

Deceleration The overall effect of the failure condition in Deceleration phase.


Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.11 INITIAL CRITICALITY ASSESSMENT

Criticality tab allows the user to perform initial criticality assessment (before any Control Measure is applied) by setting:

   An applicable criticality profile
   Assign a severity class to the selected failure condition & view corresponding Design Assurance Level (DAL)
   Assign a maximum probability for the failure condition
   Enter an annotation regarding the criticality entry

Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.11 INITIAL CRITICALITY ASSESSMENT

Select the Criticality tab Verify Criticality Profile is set to PHMT Risk Assessment Criteria (FAA), if not, set it in the Criticality Profile Editor

  Select the Criticality Profile icon
  Set the Active Project Profile as PHMT Risk Assessment Criteria (FAA)

Set Severity Class as Hazardous Enter Annotation: Severity classification is based on ENG Dept criticality rating table. Verify DAL: Level B Set Max. Probability: 1E-2


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.12 ASSIGN CONTROL MEASURES

Select Control Measures tab Select to view all the Control Measures created for the

functional model

Select `Automated Power Limitation' applicable for the selected failure condition


Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.12 ASSIGN CONTROL MEASURES

Delete will remove the assigned control measure from the selected failure condition. Select to create new /edit / delete control measures in Project Preferences.

   Changes to control measures will be reflected within the Functional Diagram.

Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.13 REVISED CRITICALITY ASSESSMENT

Revised Criticality tab allows the user to perform revised criticality assessment (after any Control Measure is applied) by setting:

   An applicable criticality profile
   Assign a severity class to the selected failure condition & view corresponding Design Assurance Level (DAL)
   Assign a maximum probability for the failure condition
   Enter an annotation regarding the criticality entry

Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.13 REVISED CRITICALITY ASSESSMENT

Select the Revised Criticality tab Verify Criticality Profile is set to PHMT Risk Assessment Criteria (FAA) Set Severity Class as Minor Enter Annotation: Revised severity classification is based on ENG Dept criticality rating table. Verify DAL: Level D Set Max. Probability: 1E-8


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.14 ASSIGN ASSUMPTIONS

Select Assumptions tab Select to view all the Assumptions created for the functional model

Select `Fuel efficiency' applicable for the selected failure condition


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.14 ASSIGN ASSUMPTIONS (CONTINUED)

To review an Assumption,

Select to create new /edit / delete assumptions in Project Preferences Select to edit `Fuel efficiency' Enter the following details

   Comments: Include data or metrics that demonstrate the fuel
     system's efficiency and its impact on overall fuel consumption

   Remarks: Assumption is acceptable for the training model.

Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.15 ASSIGN SUBSTANTIATION ACTIONS

Select Substantiation Actions tab Select to view all the Substantiation Actions created for the

functional model

Select `Engine Performance Testing' applicable for the selected failure condition


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.15 ASSIGN SUBSTANTIATION ACTIONS (CONTINUED)

Select to associate assumptions with the selected substantiation action. Select Fuel efficiency assumption OK


Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.16 MULTIPLE FAILURE EVENT

Multiple Failure Event: A combination of failure conditions that may affect the function.

Multiple Failure Event is assessed like any other failure condition (e.g. assign mission profile, mission events and conditions, failure effects, criticality assessment, etc).

The failure conditions involved in creating a Multiple Failure Event retains all the information and can only be edited in the functions they are created in.


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.16 MULTIPLE FAILURE EVENT

Create a new failure condition in Convert Fuel to Mechanical Motion function

Select Functional Diagram tab Right-click on Convert Fuel to Mechanical Motion and select Failure Conditions Select to create a new failure condition


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.16 MULTIPLE FAILURE EVENT (CONTINUED)

Rename to Failure Condition for Convert Fuel in Properties


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.16 MULTIPLE FAILURE EVENT (CONTINUED)

Select to create a new multiple failure event

Select the below failure conditions to be included in the event

   Failure Condition for Convert Fuel
   Failure Condition 1

Update the following details in Properties

   ID: MFE01
   Name: MFE for MADE training
   Type: Failure to cease operation
   Narrative: This MFE is created to demonstrate Multiple Failure Event functionality.

Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.16 MULTIPLE FAILURE EVENT

Complete the assessment of Multiple Failure Event by updating information in each of the failure condition tabs Mission Profile Events & Conditions Safety Criteria Failure Effects Criticality Control Measures Revised Criticality Assumptions Substantiation Actions

Select to add / remove failure conditions included in the multiple failure event.


Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.17 FAILURE ASSOCIATION

Failure Association: Associate one failure condition to multiple functions The associated failure condition(s) retains all the information captured and can only be edited in the

functions they are created in.


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.17 FAILURE ASSOCIATION

Open Failure Conditions of Control Vehicle function: Select Vehicle System functional diagram window Right-click on Control Vehicle Select Failure Conditions

Select to link failure conditions that may impact Control Vehicle


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.17 FAILURE ASSOCIATION (CONTINUED)

Select Failure Condition 1 in Distribute Mechanical Motion Failure Condition 1 created in Distribute Mechanical Motion is

associated with Control Vehicle.


Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.18 LINK FUNCTIONS TO SYSTEM MODEL

This functionality associates FHA functions with the system model items. All the failure conditions created within the function except Multiple Failure Events and associated failure

conditions are transferred to the Failure Diagram of the model item Functional failures and Control Measures are not included in this association.


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.18 LINK FUNCTIONS TO SYSTEM MODEL

Open Functional Diagram of Vehicle System. (Control Vehicle Failure Conditions can now be closed)


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.18 LINK FUNCTIONS TO SYSTEM MODEL (CONTINUED)

Right-click on the Functional Diagram canvas to open the menu and select Link to System Model option A new window Functional Model Linking opens


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.18 LINK FUNCTIONS TO SYSTEM MODEL (CONTINUED)

Associate Convert Fuel to Mechanical Motion function with Engine

Select Convert Fuel to Mechanical Motion function in Functional Model section In System Model section, expand Engine Component Select Convert Function Click on Link icon Click Finish


Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.18 LINK FUNCTIONS TO SYSTEM MODEL (CONTINUED)

Failure Diagram and Logical Functions editor opens as a result of the association

Navigate to Engine Failure Diagram Connect Failure Condition for Control Fuel to Convert Mechanical � rotational Torque


Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.6 FHA REPORT

This Report Summarises the Function List & Failure Condition pages for all Functions in the Functional Model Report is divided into sections:

   Function List
   Environment & Emergency Configuration List
   Derived Safety Requirements List
   Functional Hazard Assessment

Session 3.5: Failure Conditions (FHA)

EXERCISE 3.5.6 GENERATE FHA REPORT

To generate an FHA report:

Select Report Wizard from the icon toolbar Select Functional Hazard Assessment (SAE ARP4761 REV: A) Select Verify FHA Analysis: Vehicle System Select Mission Profile: Regular Trip Select


Session 3.5: Failure Conditions (FHA)

DISCUSSION 3.5.6 FHA EXPORT

This FHA .csv export includes all the information displayed in the Functions List

   Select to configure the columns to display information
   Select to export FHA in .csv format

Session 3.5: Failure Conditions (FHA)

SESSION 3.5 OUTLINE 3.5.11: Initial Criticality Assessment 3.5.12: Assign Control Measures 3.5.1: Prepare Failure Conditions 3.5.13: Revised Criticality Assessment 3.5.2: Define Safety Criteria 3.5.14: Assign Assumptions 3.5.3: Define Assumptions 3.5.15: Assign Substantiation Actions 3.5.4: Define Control Measures 3.5.16: Multiple Failure Event 3.5.5: Define Substantiation Actions 3.5.17: Failure Association 3.5.6: Failure Modes & Failure Conditions 3.5.18: Link Functions to System Model 3.5.7: Assign Mission Profile 3.5.19: FHA Output (Report and Export) 3.5.8: Assign Events & Conditions 3.5.9: Assign Safety Criteria 3.5.10: Failure Effects Assessment

Source: Local MADE 3.9.1 installation: com.phm.made.help.plugin/documents/help/pdf/MADE Training Session 3.pdf · retrieved 2026-07-09