RAMSynapse
Log inSign up

Availability · Worked example

Automotive

Electric vehicle brake system

Industry overview: Automotive at RAMSynapse

An electro-hydraulic brake actuator, two brake ECUs, four wheel-speed sensors, an independent backup hydraulic path and the regenerative torque interface, fitted to 200,000 vehicles that each run about 500 hours a year. The repair takes 1.2 hours. The car is off the road for a day and a half, and the owner's memory of the event is the day and a half.

That gap is the whole page. Availability in a consumer fleet is not a percentage and cannot usefully be made into one, because the denominator that matters is not the calendar but the handful of mornings during the outage when somebody wanted to drive. Getting that denominator wrong produces a number that is arithmetically flawless and commercially meaningless, and the industry's decision to report vehicle-off-road days instead is a considered rejection of the availability formula rather than an ignorance of it.

The technique, and why this one

Event-based downtime accounting in vehicle-off-road days, built as a rate-times-duration renewal calculation on a user-demand denominator, with a first-visit-fix multiplier applied to convert downtime per visit into downtime per fault. The choice is forced by three features. The duty cycle is 6% of the calendar, so any clock-based ratio is dominated by hours in which the vehicle's availability was never tested. The events are rare and independent, so a renewal calculation (rate times duration, summed across the fleet) is exact and needs nothing more elaborate. And the diagnostic process generates repeat visits, which a naive per-visit metric silently discards.

ItemAvailability modelParameters
Brake ECU (2 fitted)exponentialλ = 60 per 10⁶ h each
Electro-hydraulic actuatorWeibull in service (β = 1.4, η = 9,500 h), constant rate at designλ = 180 per 10⁶ h
Wheel-speed sensor set (4)exponentialλ = 90 per 10⁶ h
Backup hydraulic pathdormant, periodically testedλ = 20 per 10⁶ h; exercised at the annual service, T = 500 h
Event durationempirical, decomposed1.4 VOR days (33.6 h), of which 0.9 days (21.6 h) is parts
First-visit fixbinomial multiplierisolation to one replaceable unit 82% of the time
Denominatoruser demand500 operating hours per vehicle-year

The percentage, computed and discarded

Do the conventional calculation first, precisely so that it can be rejected. The system's series failure rate is 410 per 10⁶ hours, which at 500 operating hours a year is

incidents = 410 × 10⁻⁶ × 500 = 0.205 per vehicle-year

Each costs 1.4 days off the road, so

downtime = 0.205 × 33.6 = 6.9 hours per vehicle-year

A_clock = 1 − 6.9 / 8,760 = 0.99921

Three nines and change, which sounds excellent and settles nothing. The vehicle is parked for 94% of the year, so almost the entire numerator of that fraction is time nobody was going to use it. Move to the operating clock and the same 6.9 hours against 500 hours gives 0.9862, an availability an order of magnitude worse, and that number is not right either, because the outage does not consume operating hours; it consumes days. The measure has to match the demand the user actually makes, and the user makes a demand shaped like a morning, not like an hour. That is why the fleet reports 1.4 vehicle-off-road days and refuses to divide it by anything.

Where the 33.6 hours go

The owner's clock, split by who controls each part. Parts logistics is 64.3% and the appointment book is 32.1%. The 1.2 hours of actual work is 3.6% of the event, which is why the availability programme lives in depot planning rather than in the workshop.
The owner's clock, split by who controls each part. Parts logistics is 64.3% and the appointment book is 32.1%. The 1.2 hours of actual work is 3.6% of the event, which is why the availability programme lives in depot planning rather than in the workshop.

The event decomposes cleanly, and the decomposition is the finding:

ElementHoursShare
Parts logistics21.664.3%
Diagnosis, booking, workshop scheduling, handover10.832.1%
Active repair1.23.6%

Multiplied across the fleet, 200,000 vehicles at 0.205 incidents each generate

41,000 incidents a year × 1.4 days = 57,400 vehicle-days off road

of which

41,000 × 0.9 = 36,900 vehicle-days are spent waiting for a component to arrive

No plausible reduction in repair time competes with that. Halving the 1.2-hour active repair, an ambitious maintainability programme in its own right, saves 41,000 × 0.6 hours, about 1,025 vehicle-days a year out of 57,400: under two per cent. The availability improvement plan for this system is a distribution-network plan, and it is the same finding the aircraft reached at the other end of this column, arriving from an industry three orders of magnitude larger in unit count and with nothing else in common.

The multiplier that hides in the visit count

Fault isolation reaches a single replaceable unit 82% of the time. The remaining 18% of visits fit a component that was not the cause, and the customer returns. Expected visits per fault is the geometric mean of that process:

visits per fault = 1 / 0.82 = 1.22

downtime per fault = 1.22 × 1.4 = 1.71 VOR days

fleet visits = 41,000 / 0.82 = 50,000 a year

fleet downtime on a per-fault basis = 41,000 × 1.71 = 70,100 vehicle-days

So the honest fleet figure is 70,100 vehicle-days, not 57,400: counting downtime per visit rather than per fault flatters the metric by 12,700 vehicle-days a year, and the customer counts the days end to end. The second visit is not a rounding error either, because it carries its own 0.9-day parts wait; a misdirected diagnosis does not lengthen an event, it manufactures a new one.

The no-fault-found rate compounds it. Twenty-one per cent of returned brake ECUs have nothing wrong with them, which means a fifth of the ECU replacements in that 50,000-visit stream consumed a part, a bay and a customer's day without addressing a fault. The testability page owns both the 82% and the 21% and shows what closes them; from the availability side they are simply a 22% inflation of the fleet's downtime and a 22% inflation of its spares consumption at the same time.

The path nobody measures

The backup hydraulic path is dormant. It is exercised only at the annual service, so its unavailability is governed by the test interval, not by any repair:

Q_backup = λT / 2 = 20 × 10⁻⁶ × 500 / 2 = 5.0 × 10⁻³

Half a per cent of the time the vehicle's independent backup braking path is not there, and nothing in the vehicle or in the dealer's records will say so. Against a fleet availability that the owner experiences as essentially perfect, this is the least available element of the system by a factor of six (5.0 × 10⁻³ against the 7.9 × 10⁻⁴ the clock-based figure implies), and it is the one the ASIL D decomposition leans on. It does not belong in the VOR ledger, because it never puts a car off the road; it belongs in a second ledger kept in a different currency, and the discipline of keeping both is the point.

What the analysis tells the engineer to do

Forward-stock the actuator and the ECU at regional level so the 0.9-day parts wait becomes a next-morning delivery. At 41,000 incidents a year, each day removed from the parts tail is 41,000 vehicle-days, which dwarfs anything the workshop can contribute; this is a level-of-repair and stocking decision, made once, with fleet-wide effect.

Then attack the 18%. Raising first-visit fix from 82% to 92% takes visits per fault from 1.22 to 1.09 and fleet downtime per fault from 70,100 to 62,600 vehicle-days, a 7,500-day saving from a diagnostic improvement with no logistics content at all. And treat the 10.8 hours of booking, scheduling and handover as a real line rather than an overhead: it is a third of the event, larger than everything the design team controls, and it is the cheapest slice in the ledger to measure and the most embarrassing to leave unmeasured.

Finally, note what the Weibull fit does to the forecast. The actuator's warranty returns fit β = 1.4, η = 9,500 hours, so its arrival rate is not stationary: the fleet's incident rate, and therefore its VOR consumption, rises as the population ages. A budget built on 0.205 incidents per vehicle-year is a budget for a young fleet.

What a different technique would have given

The alternative is the one the formula invites: steady-state availability on the calendar clock, A = MTBF/(MTBF + MDT), giving 0.99921. It is not an approximation of the right answer; it is an answer to a question nobody asked. It would rank a fault that strands 41,000 customers for a day and a half as a 0.08% problem, it would improve if owners drove less, and it offers no way to see that two thirds of the loss is a parts network. Worse, it invites the nines vocabulary from the storage array at the other end of this column, where five nines is a meaningful engineering target because the machine runs continuously and the outage is measured in minutes. Borrowing that vocabulary here produces a number with three nines in it and no information.

A second candidate, an availability model that credits the dual ECUs and the backup hydraulic path as parallel redundancy, would have been worse still: it would multiply unavailabilities, report that the brake system is effectively never unavailable, and miss the fact that redundancy in this vehicle exists to preserve safe braking, not to keep the car out of the workshop. A car with one failed ECU and a working backup is safe, drivable in the engineering sense, and still going to the dealer.


Want to see this on a live system model? Request a walkthrough.