MADE Workflows > Perform System Hazard Analysis
WF72: Perform System Hazard Analysis
Pre-Requisites
- A. Hazard Diagram(s): Hazard diagram(s) with connectivity.
- B. SRA Module: access enables Hazard analysis to be performed.
- C. Criticality Profile Selected: Hazard path requires that the correct OSD-supported criticality profile is selected.
Detailed Steps
- Access Hazard Diagram — using the project explorer, select a model item and right-click to select "Hazard Diagram".
- Select Risk Profile — to perform the hazard analysis, select the desired risk profile or 'Risk Assessment Method' profile. Accessed through Preferences -> Criticality profile editor.
- Assign Hazard Concept Criticality Parameters — return to the hazard diagram and select a hazard concept; Criticality parameters (Probability, Severity, Software Control) can then be assigned through the 'MIL-STD-882E' tab of the Properties viewer. If the hazard is related to software, update the software control parameter value to be greater than or equal to 1 in the 'MIL-STD-882E' section.
- Decision — Existing Hazard Control Measures? If yes, proceed to Step 4a (Assign Hazard Control Measures): if control measures exist for concepts within the hazard diagram, right-click the concept and select control measure. Select from predefined control measures (Compensating Provisions, Detection Methods, Prevention Controls, Substantiation Actions) or create a custom control provision. Criticality parameters can be revised through the Barrier matrix inside the control measures window. If no, skip to Step 5.
- Perform Hazard path analysis — using the project explorer, select the system-level item and right-click to select "Hazard Path Analysis".
- Review Hazard Path Analysis — for each row in the hazard path analysis, review the initial risk value (Hazard Sources, Initiating Mechanisms, Target/Threat Outcomes, Initial Risk) and determine if it meets safety requirements.
- Decision — Initial Risk Acceptable? If no, Assign Hazard Concept Control Measures: if the risk is above the required threshold, hazard control measures can be assigned to the appropriate concept within the hazard path (right-click the concept, select control measures, choose predefined or custom control provision). If yes, System Hazard Analysis Complete.
- Revise Hazard Concept Criticality Parameters — upon assignment of a hazard control measure, criticality parameters (Probability, Severity) can be revised through the Barrier matrix inside the control measures window. Loop back to Criticality Editor (WF09) as needed.
Screen-by-screen detail (from embedded screenshots)
- Step 1: Access Hazard Diagram Viewer — Project Explorer, right-click model item (e.g. "Control Unit") > "Hazard Diagram". Canvas shows existing concept graph (Dielectric strength decreased -> Intermittent operation; Property mismatch, Electrical potential decreased, Open circuit -> Process Continuous Amplitude).
- Step 2: Select Risk Profile — Main menu: Preferences > Criticality Profile Editor. "Criticality Profile Editor" Overview tab: "Project Profiles" list (e.g. PHMT Fuzzy Criticality, PHMT Risk Assessment Criteria (FAA), Custom ARP Profile, PHMT Risk Assessment Method (RAC) [selected], PHMT ISO26262 Criticality, PHMT RPN Criticality, PHMT 1629A Criticality) — set "Active Project Profile" dropdown. "Risk Assessment Matrix" tab shows a MIL-STD-882E Risk Assessment Matrix (Probability Level: Frequent, Probable, Occasional, Remote, Improbable, Eliminated x Severity Category: Catastrophic, Critical, Marginal, Negligible) color-coded High/Serious/Medium/Low/Eliminated.
- Step 3: Assign Hazard Concept Criticality Parameters — Select a concept (e.g. "Electromagnetic Interference") in Properties > MIL-STD-882E tab: Probability slider (e.g. 10.0 "Very High"), Software Control slider (e.g. 8.5 "Autonomous"). Similarly for "High Temperature" (Probability 10.0 "Very High", Software Control 7.0 "Semi-Autonomous") and a target/threat outcome "Severe Financial Impact" (Probability 4.0 "Remote", Severity 7.0 "Moderate", no Software Control field).
- Step 4a: Assign Hazard Concept Control Measures — Right-click a concept (e.g. "High Temperature") > "Control Measures". "Control Measures - High Temperature" dialog: table (Enabled/Name, Type, Mitigation, Narrative) — example: "Abort Mission" (Type Abort Mission, Mitigation Software Control), "Procedures" (Mitigation Software Control, Narrative "Operator actions in response to failure whi..."), and under "Detection Methods" a "Sensing Device" measure ("A method that involves the use of a sensin..."). Click the "Create a new Control Measure" icon to browse the full taxonomy tree (Compensating Provision > Observation, Redundancy, Abort Mission, Change System Configuration, Modify Mission, Modify Sensor Set, Override System, Procedures, Redesign Component, Relief Devices, Safety Devices; Detection Methods > Equipment Testing, Inspection, On Demand, Operator Observation, Sensing Device, Warning Device; Prevention Controls > Benchmarking studies, Breakdown Repair).
- Step 5: Perform System Hazard Path Analysis — Project Explorer, right-click system-level item (e.g. "Vehicle System") > "Hazard Path Analysis" (alongside System Model, Failure Diagram, Bond Graph, Functions, Requirements, Functional Diagram, Mission Profiles, Hazard Diagram, Maintenance Actions, Cut/Copy/Paste, Delete, End Effect Item, Fault Tree, Response Paths, Save to Library, Advanced Properties).
- Step 6: Review Hazard Path Analysis (Initial Risk) — "Hazard Path Analysis" view: first table shows Hazard Cause / Hazard Cause Control Measure / Initiating Mechanism / Init. Mechanism Control Measure / Threat Outcome / Threat Outcome Control Measure hierarchy (e.g. Vehicle System > Power Generation > Control Unit > Property mismatch (Hazard Cause) -> Extreme Heat (Initiating Mechanism) -> Major Loss of Operational Capability (Threat Outcome); Open circuit -> High Temperature [Control Measures: Procedures, Sensing Device, Abort Mission] -> Severe Financial Impact [Control Measure: Safety Devices]). Second table: Subsystem, System, Initial Risk, Revised Risk, Initial/Revised Severity, Initial/Revised Severity Class, Initial/Revised Probability, Initial Probability Class — example: Power Generation/Vehicle System, Initial Risk "High (1A)", Revised Risk "High (1A)", Initial Severity 10.0, Initial Severity Class "Catastrophic", Initial Probability 10.0, Initial Probability Class "Frequent"; second row Initial Risk "High (2A)", Revised Risk "Serious (3A)", Initial Severity 7.0, Severity Class "Critical" -> Revised "Marginal". Additional columns: Revised Probability Class, Initial/Revised Software Control, Initial/Revised Software Control Level, Software Control Index (SwCI), Software Risk Level, Hazard Code (hash IDs).
- Step 7-8: Assign System Hazard Concept Control Measures & Revise Criticality Parameters (if Initial Risk not acceptable) — Right-click a target/threat node (e.g. "Major Loss of Operational Capability" or "Severe Financial Impact") on the hazard diagram > Copy/Control Measures. "Control Measures - Major Loss of Operational Capability" dialog: add "Abort Mission" (Compensating Provision) with Narrative. "Control Measures - Severe Financial Impact" dialog: add "Safety Devices" and "Warning Device" (Detection Methods). Click "Barrier Matrix" to open a flow view: No Control -> Safety Devices -> Warning Device -> Revised Control, with editable deltas for Probability/Occurrence and Severity (e.g. -4.0 at Safety Devices reducing Probability from 4.0 to 1.0; -4.0 at Warning Device reducing Severity from 7.0 to 3.0). Updated Hazard Path Analysis table shows Revised Risk values recalculated (e.g. High (1A) -> Serious (3A) with Revised Risk 5.0 / 3.0).
Source: Local MADE 3.9.1 installation: com.phm.made.help.plugin/documents/help/pdf/Workflows/WF72-Perform System Hazard Analysis.pdf · retrieved 2026-07-09