Fault Tree Analysis
Also known as: FTA
Top-down deductive analysis of paths to a specified failure event.
Fault Tree Analysis (FTA) is the systematic top-down deductive reliability-engineering tool for analyzing the combinations of component failures, human errors, and environmental conditions that could produce a specified undesired top-level event (system failure, accident, hazard). The technique was substantially developed by H.A. Watson at Bell Telephone Laboratories in 1962 for analyzing the Minuteman intercontinental ballistic missile launch control system, with substantial subsequent development at Boeing and broader aerospace and nuclear industries. Foundational systematization came through David Haasl's 1965 Boeing development of FTA methodology and the substantial 1981 NUREG-0492 Fault Tree Handbook published by the US Nuclear Regulatory Commission, which substantially codified FTA methodology for nuclear safety analysis. FTA's central methodology: (1) define the top event (the undesired outcome to be analyzed); (2) decompose the top event into immediate causes connected by logic gates (AND gate — all inputs must occur for output; OR gate — any input produces output; plus conditional gates and other variants); (3) continue decomposition until reaching basic events (component failures, human errors, environmental conditions) for which probability data is available; (4) compute top-event probability through Boolean algebra and probability calculations on the resulting tree; (5) identify minimal cut sets (smallest combinations of basic events that produce the top event) for risk-mitigation prioritization. FTA distinguishes from FMEA (separately enriched) by its top-down deductive approach (start from undesired event, analyze backward to causes) versus FMEA's bottom-up inductive approach (start from components, analyze forward to system effects). FTA is foundational across nuclear safety analysis (substantial NRC requirements), aerospace, defense, chemical process industry, medical devices, and other safety-critical contexts. The technique has substantial methodological refinement including dynamic fault trees (handling time-dependent and sequence-dependent failures), Bayesian network extensions, and software-supported fault-tree analysis tools. Critics note that completeness of fault-tree analysis depends substantially on analyst's ability to identify all possible cause paths, that complex software and human-organizational failures often resist clean fault-tree decomposition, and that probability data for basic events is often more uncertain than fault-tree calculations suggest.
Core components
- Top-down deductive analysis from undesired event to basic causes
- Logic gates (AND, OR, conditional, others) connecting events
- Decomposition to basic events with probability data
- Boolean algebra and probability calculations for top-event probability
- Minimal cut sets for risk-mitigation prioritization
- Distinction from FMEA (top-down deductive vs bottom-up inductive)
- Substantial nuclear, aerospace, defense, chemical-process, medical-device adoption
- Modern extensions: dynamic fault trees, Bayesian network integration, software tools
Primary use case
Foundational reliability-engineering tool across nuclear safety, aerospace, defense, chemical-process industry, medical devices; basis for substantial NRC nuclear safety analysis; reference framework in reliability-engineering education; foundation for substantial commercial FTA software and consulting industry; integration with broader risk-analysis frameworks; pedagogical foundation in safety-engineering and reliability-engineering curricula; influence on probabilistic risk assessment (PRA) in nuclear and aerospace; foundation for ISO/IEC 31010 risk-management standard inclusion; basis for many regulatory safety analyses globally.
Common criticisms
- Completeness of fault-tree analysis depends substantially on analyst's ability to identify all possible cause paths — substantial empirical research has documented that fault trees miss substantial cause paths, particularly for novel scenarios, complex software failures, and human-organizational dynamics
- probability data for basic events is often more uncertain than fault-tree calculations suggest, with substantial confidence intervals around basic-event probabilities producing substantially uncertain top-event probabilities that fault-tree presentations sometimes obscure
- complex software failures often resist clean fault-tree decomposition — software failures involve substantial state, configuration, and timing dependencies that classical fault-tree logic doesn't capture cleanly
- human-organizational failures (operator errors, management decisions, safety-culture issues) fit awkwardly into fault-tree framework — substantial subsequent development of organizational and human-factors analysis has supplemented FTA in safety-critical contexts
- commercial FTA software has produced compliance-style adoption with varying analytical fidelity
- integration with substantively different risk-analysis tools (FMEA, Bowtie Analysis, system-theoretic accident model and process — STAMP) creates which-when ambiguity
- the technique works better for hardware systems with well-understood failure modes than for software-intensive systems where failure modes are emergent
- cybersecurity threats fit awkwardly into traditional FTA framework — substantial subsequent development of attack-tree variants for cybersecurity analysis
- AI/ML-enabled systems raise substantial questions about whether traditional FTA framework adequately addresses emergent-behavior risks
- substantial nuclear-industry critique that probabilistic risk assessment (PRA) using FTA may produce false confidence in calculated risk levels (Fukushima 2011, Three Mile Island, and other accidents involved substantial scenarios PRA had not adequately analyzed).
Lineage
- Child of
- Reliability Engineering
- Siblings
- Failure Mode and Effects Analysis, Bowtie Analysis
- Derived from
- Reliability Engineering