Fault Tree Analysis

Also known as: FTA

tool · engineering · organizing-schema

Top-down deductive analysis of paths to a specified failure event.

Fault Tree Analysis (FTA) is the systematic top-down deductive reliability-engineering tool for analyzing the combinations of component failures, human errors, and environmental conditions that could produce a specified undesired top-level event (system failure, accident, hazard). The technique was substantially developed by H.A. Watson at Bell Telephone Laboratories in 1962 for analyzing the Minuteman intercontinental ballistic missile launch control system, with substantial subsequent development at Boeing and broader aerospace and nuclear industries. Foundational systematization came through David Haasl's 1965 Boeing development of FTA methodology and the substantial 1981 NUREG-0492 Fault Tree Handbook published by the US Nuclear Regulatory Commission, which substantially codified FTA methodology for nuclear safety analysis. FTA's central methodology: (1) define the top event (the undesired outcome to be analyzed); (2) decompose the top event into immediate causes connected by logic gates (AND gate — all inputs must occur for output; OR gate — any input produces output; plus conditional gates and other variants); (3) continue decomposition until reaching basic events (component failures, human errors, environmental conditions) for which probability data is available; (4) compute top-event probability through Boolean algebra and probability calculations on the resulting tree; (5) identify minimal cut sets (smallest combinations of basic events that produce the top event) for risk-mitigation prioritization. FTA distinguishes from FMEA (separately enriched) by its top-down deductive approach (start from undesired event, analyze backward to causes) versus FMEA's bottom-up inductive approach (start from components, analyze forward to system effects). FTA is foundational across nuclear safety analysis (substantial NRC requirements), aerospace, defense, chemical process industry, medical devices, and other safety-critical contexts. The technique has substantial methodological refinement including dynamic fault trees (handling time-dependent and sequence-dependent failures), Bayesian network extensions, and software-supported fault-tree analysis tools. Critics note that completeness of fault-tree analysis depends substantially on analyst's ability to identify all possible cause paths, that complex software and human-organizational failures often resist clean fault-tree decomposition, and that probability data for basic events is often more uncertain than fault-tree calculations suggest.

Originators

H.A. Watson at Bell Telephone Laboratories (1962 foundational for Minuteman ICBM launch control); David Haasl at Boeing (1965 substantial methodology development); subsequent US Nuclear Regulatory Commission codification (1981 NUREG-0492 Fault Tree Handbook); broader nuclear, aerospace, and defense industry development high

Year / Decade

1962 (Watson foundational at Bell Labs); 1965 (Haasl Boeing development); 1981 (NUREG-0492 substantial codification); ongoing development high

Primary sources

Watson, H.A. (1962). Foundational Bell Labs Minuteman work, Haasl, D.F. (1965). Boeing fault tree development, US Nuclear Regulatory Commission (1981). NUREG-0492: Fault Tree Handbook, Vesely, W.E. et al. (2002). Fault Tree Handbook with Aerospace Applications (NASA), Ericson, C.A. (multiple editions). Hazard Analysis Techniques for System Safety high

Core components

Primary use case

Foundational reliability-engineering tool across nuclear safety, aerospace, defense, chemical-process industry, medical devices; basis for substantial NRC nuclear safety analysis; reference framework in reliability-engineering education; foundation for substantial commercial FTA software and consulting industry; integration with broader risk-analysis frameworks; pedagogical foundation in safety-engineering and reliability-engineering curricula; influence on probabilistic risk assessment (PRA) in nuclear and aerospace; foundation for ISO/IEC 31010 risk-management standard inclusion; basis for many regulatory safety analyses globally.

Common criticisms

Lineage

Child of
Reliability Engineering
Siblings
Failure Mode and Effects Analysis, Bowtie Analysis
Derived from
Reliability Engineering