MADE Training > Session 3 > Session 3.5: Failure Conditions (FHA)
Session 3.5: Failure Conditions (FHA)
Note: This training deck is primarily composed of instructional screenshots (numbered dialog boxes, toolbar callouts, field highlights). The text below preserves all extractable slide text — titles, bullet points, discussion/exercise headings, and table content. Where a slide is dominated by an unlabeled screenshot, only the caption and step-list text could be extracted; screenshot visual detail itself is not represented.
Session 3.5: Failure Conditions (FHA)
SESSION 3.5 OUTLINE 3.5.11: Initial Criticality Assessment 3.5.12: Assign Control Measures 3.5.1: Prepare Failure Conditions 3.5.13: Revised Criticality Assessment 3.5.2: Define Safety Criteria 3.5.14: Assign Assumptions 3.5.3: Define Assumptions 3.5.15: Assign Substantiation Actions 3.5.4: Define Control Measures 3.5.16: Multiple Failure Event 3.5.5: Define Substantiation Actions 3.5.17: Failure Association 3.5.6: Failure Modes & Failure Conditions 3.5.18: Link Functions to System Model 3.5.7: Assign Mission Profile 3.5.19: FHA Output (Report and Export) 3.5.8: Assign Events & Conditions 3.5.9: Assign Safety Criteria 3.5.10: Failure Effects Assessment
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.1 PREPARE FAILURE CONDITIONS
Define Safety Criteria, Assumptions, Control Measures, and Substantiation Actions for the functional modelling in Project Preferences
Failure Conditions page in Functional Diagram is used to: Associate Failure conditions to individual Functional Failures Associate a Failure Condition with Mission Profile Phases/Segments/Specialised Phases Associate a Failure Condition with Mission Events and Mission Conditions Associate a Failure Condition with Safety Criteria
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.1 PREPARE FAILURE CONDITIONS
For this section we will need to change the criticality profile to PHMT Risk Assessment Criteria (FAA).
Select Preferences Criticality Profile Editor from the menu bar Select PHMT Risk Assessment Criteria (FAA) as the Active Project Profile
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.2 DEFINE SAFETY CRITERIA
Safety Criteria: A description of benchmark to ensure safety of the system Identifies collections of potential high-level hazards applicable for the functional modelling Assign criticality to each high-level hazard Define safety criteria and minimum safety criteria
Note: One Safety Criteria can be associated with multiple failure conditions in Functional Diagram. New safety criteria can be created in Functional Diagram, if required.
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.2 DEFINE SAFETY CRITERIA
Navigate to Safety Criteria,
Select Preferences Project Preferences Select Functional Hazard Assessment Safety Criteria
To create a Safety Criteria,
Select
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.2 DEFINE SAFETY CRITERIA (CONTINUED)
Enter the following details for the collection of potential high-level hazards Category ID: ACC Category Name: Adaptive Cruise Control
Select to create high-level hazards
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.2 DEFINE SAFETY CRITERIA (CONTINUED)
Enter the following details for the hazards for `Adaptive Cruise Control' category
Hazard ID Hazard Name Description Criticality
ACC_01 False sensing Incorrect or unreliable sensor readings leading to Catastrophic improper vehicle speed adjustments.
ACC_02 System lag Delays in the ACC system's response to changing traffic Hazardous ACC_03 conditions, potentially leading to unsafe situations. Major Unintended acceleration/deceleration ACC system malfunction causing sudden and unexpected acceleration or deceleration.
Enter
Safety Criteria: ACC system should maintain a safe and consistent following distance from the vehicle ahead,
taking into account the vehicle's speed and traffic conditions
Minimum Safety Criteria: ACC system must maintain a minimum following distance from the vehicle ahead, as
specified by relevant safety standards and regulations
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.2 DEFINE SAFETY CRITERIA (CONTINUED)
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.2 DEFINE SAFETY CRITERIA (CONTINUED)
Create another Safety Criteria with the following details:
Category ID: REPD
Category Name: Reliable and efficient power delivery
Hazard ID Hazard Name Description Criticality REPD_01 Fuel Leaks Minor Leaks in the fuel system can pose fire hazards and REPD_02 Turbocharger Issues reduce fuel efficiency.
Turbocharger failures or malfunctions can affect engine Hazardous
performance and lead to potential safety concerns.
Enter criteria details:
Safety Criteria: The fuel system should be leak-proof and equipped with safeguards to prevent fuel leaks,
minimizing fire hazards and ensuring efficient fuel utilization.
Minimum Safety Criteria: The fuel system must meet safety standards that prevent fuel leaks and meet efficiency
requirements to minimize environmental impact.
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.2 DEFINE SAFETY CRITERIA (CONTINUED)
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.3 DEFINE ASSUMPTIONS
Assumption: A statement, principle, and/or premises offered without proof. Define assumptions for the functional modelling when any consideration MADE during the assessment that
was not based on validated functional information.
Note: One Assumption can be associated with multiple failure conditions in Functional Diagram. New assumptions can be created in Functional Diagram, if required.
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.3 DEFINE ASSUMPTIONS
Select Preferences Project Preferences Select Functional Hazard Assessment Assumptions
To create an Assumption,
Select
Note: Assumption will be reviewed and substantiated while performing the assessment.
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.3 DEFINE ASSUMPTIONS (CONTINUED)
Enter ID, Name, and Description for the assumption:
ID: ASM_01 Name: Engine's horsepower and torque Description: The engine's horsepower and torque output are
sufficient to meet the vehicle's performance requirements and allow it to accelerate and maintain desired speeds under typical driving conditions
Note: Assumption will be reviewed and substantiated while performing the assessment.
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.3 DEFINE ASSUMPTIONS (CONTINUED)
Create another assumption with the following information:
ID: ASM_02 Name: Fuel efficiency Description: The fuel system and combustion process are
optimized to provide efficient fuel consumption, and the vehicle meets emission standards without excessive emissions of harmful pollutants.
Note: Assumption will be reviewed and substantiated while performing the assessment.
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.4 DEFINE CONTROL MEASURES
Control Measures: A concept that is implemented to reduce risk in the system. Compensating Provisions taxonomy is used for defining control measures for the functional modeling.
Note: Navigate to Preferences > Customise Taxonomy to view/create taxonomy. One Control Measure can be associated with multiple failure conditions in the Functional Diagram. New control measures can be created in Functional Diagram, if required.
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.4 DEFINE CONTROL MEASURES
Select Preferences Project Preferences Select Functional Hazard Assessment Control Measures
To create a Control Measure,
Select
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.4 DEFINE CONTROL MEASURES (CONTINUED)
Enter ID, Name, and Narrative for the control measure:
ID: CM_01 Name: Automated Power Limitation Description: Implementing automated systems that can limit engine
power output in specific situations to prevent overloading or overheating. Control Measure Type: Safety Devices
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.4 DEFINE CONTROL MEASURES (CONTINUED)
Create another Control Measure with the following information:
ID: CM_02
Name: Regular Maintenance and Inspections
Description: Establishing a comprehensive maintenance schedule for the vehicle's powertrain components, including the engine, transmission, and associated systems. Regular inspections and servicing help identify and address wear and tear before it escalates into more significant problems.
Control Measure Type: Procedures
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.5 DEFINE SUBSTANTIATION ACTIONS
Substantiation Actions: All the activities performed to produce evidence that an FHA is complete and correct.
According to ARP4761 Rev A, substantiating data for FHA should be collected, showing that
All the aircraft/system level functions have been considered
All failure conditions have been identified for each aircraft /system function
The failure effects on the aircraft /system, crew and occupants are complete and correct for each failure condition
occurring during each flight phase
The correct failure classification has been selected based on the failure effects
The assumptions used to develop the assessment are confirmed and evidence is provided. In cases where an
assumption is incorrect, the correct information should be provided and the FHA updated
Note: Navigate to Preferences > Customize Taxonomy to view/create taxonomy. One Substantiation Action can be associated with multiple failure conditions in Functional Diagram. New Substantiation Actions can be created in Functional Diagram, if required.
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.5 DEFINE SUBSTANTIATION ACTIONS
Select Preferences Project Preferences Select Functional Hazard Assessment Substantiation Actions
To create a Substantiation Action,
Select
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.5 DEFINE SUBSTANTIATION ACTIONS
Enter ID, Name, and Narrative for the Substantiation Action:
ID: SA_01 Name: Engine Performance Testing Description: Conducting thorough testing of the engine's
horsepower and torque output under various load conditions to validate its capability to meet performance requirements. Substantiation Action Type: Test
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.5 DEFINE SUBSTANTIATION ACTIONS
Create another Substantiation Action with the following information:
ID: SA_02
Name: Combustion Process Analysis
Description: Analyzing the combustion process in the engine to ensure it is optimized for efficient fuel utilization and minimized emissions.
Substantiation Action Type: Analysis
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.6 FAILURE MODES & FAILURE CONDITIONS
Open the Functional Diagram editor to access Failure Conditions page:
Select the System in Project Explorer, Modeling Functional Diagram
Open Functional Diagram of the Provide Thrust function
Open Failure Condition page for Distribute Mechanical Motion Right-click Distribute Mechanical Motion then select Failure Condition from menu
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.6 FAILURE MODES & FAILURE CONDITIONS
The Failure Condition page enables user to create:
1 or more Failure Modes per Function
1 or more Failure Conditions per Failure Mode
The Failure Condition tabs helps to associate/assess
Mission Phases/Specialised Phases
Events & Conditions
Safety Criteria
Failure Effects
Criticality
Control Measures
Assumptions
Substantiation Actions
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.6 FAILURE MODES & FAILURE CONDITIONS
To create a new Failure Mode:
In the Distribute Mechanical Motion Failure Conditions page:
Select to add a new Failure Mode
From the Create new Failure Mode dialog:
Enter name: Inability to Distribute Mechanical Motion (Forward)
Select the newly created Failure Mode In the Properties, enter
ID: FF01
Failure Effect: Failure of this function will prevent forward movement of the vehicle system.
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.6 FAILURE MODES & FAILURE CONDITIONS
To create a new Failure Condition:
Select the newly created Failure Mode Select the Add new Failure Condition icon Select the newly added Failure Condition
Enter the following details in Properties:
ID: FC1
Name: Failure Condition 1
Type: Loss of Output
Narrative: Loss of output due to power source failure.
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.7 ASSIGN MISSION PROFILE
This tab allows the user to select applicable mission profiles to a selected failure condition User selects applicable mission phases/segments and specialised phases where the failure condition occurs
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.7 ASSIGN MISSION PROFILE
To edit the Mission Profile details for the Failure Condition:
Select Failure Condition 1
Select the Mission Profile tab
From the drop-down menu and select Regular Trip
Select the following Mission Phases:
2 - Acceleration
5 - Cruise
6 - Deceleration
Select the following Specialized Phases:
Autonomous Parking
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.8 ASSIGN EVENTS & CONDITIONS
This tab allows the user to assign applicable Mission Events & Conditions and capture Operator awareness relating to the selected Failure Condition.
Mission Events & Conditions are by default filtered by the assigned Mission Sections and Specialised Phases.
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.8 ASSIGN EVENTS & CONDITIONS
Select Events & Conditions tab Operator awareness: Not relevant Select the following Mission Events and Conditions:
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.9 ASSIGN SAFETY CRITERIA
Select Safety Criteria tab Select to view all the Safety Criteria created for the functional model
Select `Reliable and efficient power delivery' applicable for the selected failure condition
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.9 ASSIGN SAFETY CRITERIA
Delete will remove the assigned safety criterion from the selected failure condition. Select to create new /edit / delete safety criteria in Project Preferences.
Changes to safety criteria will be reflected within the Functional Diagram.
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.10 FAILURE EFFECTS ASSESSMENT
The assessment examines each failure condition and determines the effects should the failure condition occur in each of the selected mission sections.
The assessment of the effects begins with a narrative description of the consequences of the failure condition followed by a statement summarizing the failure condition's overall impact.
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.10 FAILURE EFFECTS ASSESSMENT
Failure effects can be captured in additional categories, for example: Effect on Vehicle and/or Effect on Occupants.
Select Preferences > Project Preferences Select Functional Hazard Assessment > Failure Effects Select to add an additional category Select Effect on Occupants Enter the following details:
Description: Description of effect on the occupants
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.10 FAILURE EFFECTS ASSESSMENT
Enter the following failure effect narratives
Mission Profile / Overall Effect Effect on Occupants Section The effects of the failure condition on the occupants in the selected Regular Trip The overall effect of the failure condition in the selected mission profile. mission profile. The effects of the failure condition on the occupants in Acceleration phase. Acceleration The overall effect of the failure condition in Acceleration The effects of the failure condition on the occupants in Cruise phase. phase. The effects of the failure condition on the occupants in Deceleration phase. Cruise The overall effect of the failure condition in Cruise phase.
Deceleration The overall effect of the failure condition in Deceleration phase.
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.11 INITIAL CRITICALITY ASSESSMENT
Criticality tab allows the user to perform initial criticality assessment (before any Control Measure is applied) by setting:
An applicable criticality profile
Assign a severity class to the selected failure condition & view corresponding Design Assurance Level (DAL)
Assign a maximum probability for the failure condition
Enter an annotation regarding the criticality entry
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.11 INITIAL CRITICALITY ASSESSMENT
Select the Criticality tab Verify Criticality Profile is set to PHMT Risk Assessment Criteria (FAA), if not, set it in the Criticality Profile Editor
Select the Criticality Profile icon
Set the Active Project Profile as PHMT Risk Assessment Criteria (FAA)
Set Severity Class as Hazardous Enter Annotation: Severity classification is based on ENG Dept criticality rating table. Verify DAL: Level B Set Max. Probability: 1E-2
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.12 ASSIGN CONTROL MEASURES
Select Control Measures tab Select to view all the Control Measures created for the
functional model
Select `Automated Power Limitation' applicable for the selected failure condition
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.12 ASSIGN CONTROL MEASURES
Delete will remove the assigned control measure from the selected failure condition. Select to create new /edit / delete control measures in Project Preferences.
Changes to control measures will be reflected within the Functional Diagram.
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.13 REVISED CRITICALITY ASSESSMENT
Revised Criticality tab allows the user to perform revised criticality assessment (after any Control Measure is applied) by setting:
An applicable criticality profile
Assign a severity class to the selected failure condition & view corresponding Design Assurance Level (DAL)
Assign a maximum probability for the failure condition
Enter an annotation regarding the criticality entry
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.13 REVISED CRITICALITY ASSESSMENT
Select the Revised Criticality tab Verify Criticality Profile is set to PHMT Risk Assessment Criteria (FAA) Set Severity Class as Minor Enter Annotation: Revised severity classification is based on ENG Dept criticality rating table. Verify DAL: Level D Set Max. Probability: 1E-8
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.14 ASSIGN ASSUMPTIONS
Select Assumptions tab Select to view all the Assumptions created for the functional model
Select `Fuel efficiency' applicable for the selected failure condition
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.14 ASSIGN ASSUMPTIONS (CONTINUED)
To review an Assumption,
Select to create new /edit / delete assumptions in Project Preferences Select to edit `Fuel efficiency' Enter the following details
Comments: Include data or metrics that demonstrate the fuel
system's efficiency and its impact on overall fuel consumption
Remarks: Assumption is acceptable for the training model.
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.15 ASSIGN SUBSTANTIATION ACTIONS
Select Substantiation Actions tab Select to view all the Substantiation Actions created for the
functional model
Select `Engine Performance Testing' applicable for the selected failure condition
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.15 ASSIGN SUBSTANTIATION ACTIONS (CONTINUED)
Select to associate assumptions with the selected substantiation action. Select Fuel efficiency assumption OK
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.16 MULTIPLE FAILURE EVENT
Multiple Failure Event: A combination of failure conditions that may affect the function.
Multiple Failure Event is assessed like any other failure condition (e.g. assign mission profile, mission events and conditions, failure effects, criticality assessment, etc).
The failure conditions involved in creating a Multiple Failure Event retains all the information and can only be edited in the functions they are created in.
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.16 MULTIPLE FAILURE EVENT
Create a new failure condition in Convert Fuel to Mechanical Motion function
Select Functional Diagram tab Right-click on Convert Fuel to Mechanical Motion and select Failure Conditions Select to create a new failure condition
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.16 MULTIPLE FAILURE EVENT (CONTINUED)
Rename to Failure Condition for Convert Fuel in Properties
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.16 MULTIPLE FAILURE EVENT (CONTINUED)
Select to create a new multiple failure event
Select the below failure conditions to be included in the event
Failure Condition for Convert Fuel
Failure Condition 1
Update the following details in Properties
ID: MFE01
Name: MFE for MADE training
Type: Failure to cease operation
Narrative: This MFE is created to demonstrate Multiple Failure Event functionality.
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.16 MULTIPLE FAILURE EVENT
Complete the assessment of Multiple Failure Event by updating information in each of the failure condition tabs Mission Profile Events & Conditions Safety Criteria Failure Effects Criticality Control Measures Revised Criticality Assumptions Substantiation Actions
Select to add / remove failure conditions included in the multiple failure event.
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.17 FAILURE ASSOCIATION
Failure Association: Associate one failure condition to multiple functions The associated failure condition(s) retains all the information captured and can only be edited in the
functions they are created in.
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.17 FAILURE ASSOCIATION
Open Failure Conditions of Control Vehicle function: Select Vehicle System functional diagram window Right-click on Control Vehicle Select Failure Conditions
Select to link failure conditions that may impact Control Vehicle
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.17 FAILURE ASSOCIATION (CONTINUED)
Select Failure Condition 1 in Distribute Mechanical Motion Failure Condition 1 created in Distribute Mechanical Motion is
associated with Control Vehicle.
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.18 LINK FUNCTIONS TO SYSTEM MODEL
This functionality associates FHA functions with the system model items. All the failure conditions created within the function except Multiple Failure Events and associated failure
conditions are transferred to the Failure Diagram of the model item Functional failures and Control Measures are not included in this association.
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.18 LINK FUNCTIONS TO SYSTEM MODEL
Open Functional Diagram of Vehicle System. (Control Vehicle Failure Conditions can now be closed)
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.18 LINK FUNCTIONS TO SYSTEM MODEL (CONTINUED)
Right-click on the Functional Diagram canvas to open the menu and select Link to System Model option A new window Functional Model Linking opens
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.18 LINK FUNCTIONS TO SYSTEM MODEL (CONTINUED)
Associate Convert Fuel to Mechanical Motion function with Engine
Select Convert Fuel to Mechanical Motion function in Functional Model section In System Model section, expand Engine Component Select Convert Function Click on Link icon Click Finish
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.18 LINK FUNCTIONS TO SYSTEM MODEL (CONTINUED)
Failure Diagram and Logical Functions editor opens as a result of the association
Navigate to Engine Failure Diagram Connect Failure Condition for Control Fuel to Convert Mechanical � rotational Torque
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.6 FHA REPORT
This Report Summarises the Function List & Failure Condition pages for all Functions in the Functional Model Report is divided into sections:
Function List
Environment & Emergency Configuration List
Derived Safety Requirements List
Functional Hazard Assessment
Session 3.5: Failure Conditions (FHA)
EXERCISE 3.5.6 GENERATE FHA REPORT
To generate an FHA report:
Select Report Wizard from the icon toolbar Select Functional Hazard Assessment (SAE ARP4761 REV: A) Select Verify FHA Analysis: Vehicle System Select Mission Profile: Regular Trip Select
Session 3.5: Failure Conditions (FHA)
DISCUSSION 3.5.6 FHA EXPORT
This FHA .csv export includes all the information displayed in the Functions List
Select to configure the columns to display information
Select to export FHA in .csv format
Session 3.5: Failure Conditions (FHA)
SESSION 3.5 OUTLINE 3.5.11: Initial Criticality Assessment 3.5.12: Assign Control Measures 3.5.1: Prepare Failure Conditions 3.5.13: Revised Criticality Assessment 3.5.2: Define Safety Criteria 3.5.14: Assign Assumptions 3.5.3: Define Assumptions 3.5.15: Assign Substantiation Actions 3.5.4: Define Control Measures 3.5.16: Multiple Failure Event 3.5.5: Define Substantiation Actions 3.5.17: Failure Association 3.5.6: Failure Modes & Failure Conditions 3.5.18: Link Functions to System Model 3.5.7: Assign Mission Profile 3.5.19: FHA Output (Report and Export) 3.5.8: Assign Events & Conditions 3.5.9: Assign Safety Criteria 3.5.10: Failure Effects Assessment
Source: Local MADE 3.9.1 installation: com.phm.made.help.plugin/documents/help/pdf/MADE Training Session 3.pdf · retrieved 2026-07-09