23-Ind-B10 Workplace Health and Safety · December 2016
Question 3 of 7: Fault Tree Analysis — Purpose, Application to Accident Investigation, and Limitations
Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)
Notes on this paper
National Exams — December 2016 — 98-Ind-B10 Industrial Safety and Health. Closed book; no calculators permitted. Any five of the seven questions constitute a complete paper; all questions are of equal value (20 marks each). Answers are written in point form but fully, as instructed. Complete answers to all seven questions follow, with assumptions stated where the question invites them.
Reference texts: Brauer, Safety and Health for Engineers, 4th ed.; CCPS (Center for Chemical Process Safety), Guidelines for Risk Based Process Safety / Guidelines for Hazard Evaluation Procedures; CSA Z1002 Occupational health and safety — Hazard identification and elimination and risk assessment and control; CSA Z1006 Management of work in confined spaces.
Question 3: Fault Tree Analysis — Purpose, Application to Accident Investigation, and Limitations (20 marks: 8/6/6)
Fault tree analysis is a deductive, top-down logic-diagram technique whose purpose is to identify and organize every combination of component failures, human errors, and environmental conditions (basic events) that can combine — through AND-gates (all required) and OR-gates (any one sufficient) — to produce a specific, defined undesired top event (a system failure, accident, or catastrophic loss). Its purpose is threefold: to reveal the causal logic of how a top event can occur, to quantify the top event's probability when basic-event failure rates are known, and to identify which combinations of failures (minimal cut sets) are the most critical, so that design or procedural attention can be directed at breaking those specific combinations rather than hazards in general.
(ii) Application of FTA to Accident Investigation
Define the top event as the accident that actually occurred (e.g. "worker struck by falling load"), stated precisely enough to bound the analysis.
Work backward through intermediate events, asking at each level what combination of failures could have produced the event immediately above it, connecting them with AND/OR logic gates that reflect whether all or any one of the contributing events was necessary.
Continue decomposing until basic events are reached — individual component failures, a specific human error, or an environmental condition that is not further broken down, each ideally traceable to physical evidence, witness statements, or records from the actual incident.
Identify the minimal cut sets — the smallest combinations of basic events that, together, are sufficient to reproduce the accident — which tells the investigator exactly which barriers/safeguards failed (and, importantly, which held, since a barrier that functioned is not part of any surviving cut set).
Compare the tree against the physical evidence from the actual event to confirm which cut set(s) actually occurred, distinguishing the realized cause from other paths that were merely possible.
Use the tree to direct corrective action — since a cut set shows every event that had to occur together, breaking any single basic event within it (fixing that specific failure) prevents that path from recurring; a tree with several separate cut sets shows the investigator that more than one corrective action is needed.
(iii) Limitations of Fault Tree Analysis
Completeness depends entirely on the analyst's foresight — a failure mode or combination not conceived of when building the tree cannot appear in it; FTA cannot discover a cause the investigator did not think to include.
Complex systems produce very large trees that are difficult and time-consuming to construct, validate, and keep current as the system changes.
Quantitative results depend on basic-event probability data that is often poorly known, especially for rare or catastrophic failure modes, which limits confidence in a computed top-event probability even when the logic structure itself is correct.
Standard Boolean-gate logic assumes basic events are independent, which understates true risk when a common-cause failure (a single power loss, a single flood, a single operator error across multiple "independent" branches) can defeat several basic events simultaneously.
Retrospective construction can be biased — an investigator who already has a hypothesis about what happened can unconsciously build a tree that confirms it, rather than genuinely exploring alternative causal paths.
FTA analyzes one defined top event at a time — it does not, by itself, catalogue every way a system can fail (that is FMEA's strength), so relying on FTA alone can miss failure modes that were never selected as a top event to investigate.