The characteristic failure of an FHA is not a wrong number. It is a missing row, and a missing row costs more than every other error in the safety programme combined, because nothing downstream can find it.
| Pitfall | What it looks like | The guard |
|---|---|---|
| Analysing boxes | A worksheet whose first column is a list of equipment | The first column is a function; the equipment does not exist yet |
| Only loss | Every row begins "loss of" | Generate the grid: loss, partial, misleading, inadvertent, mistimed |
| Misleading output missed | No row where the system is confidently wrong | The row that usually carries the catastrophic classification |
| Phase ignored | One row per functional failure, one class | Same failure, two phases, two rows, two classes |
| Annunciation ignored | No distinction between a flagged failure and a silent one | Two rows, and the difference is usually a whole class |
| One function at a time | Every row is a single function failing on its own | The grid cannot generate combinations; add the pairs where one function is the fallback for the other |
| Classifying before describing | Column 5 filled, column 4 thin | The effect is the evidence; write it first, in the aeroplane's terms |
| Severity deflation | An argued path from Catastrophic down to Hazardous, one adjective at a time | Classify from consequence alone; mitigation moves probability, not severity |
| Crew action assumed silently | A reversion to the standby buried inside the effect text | State it as an assumption; it becomes a requirement on training and layout |
| Benign conditions assumed | Effects written for daylight, calm air and a rested crew | Reasonably expected adverse operational and environmental conditions |
| At-risk time abused | A phase-limited condition averaged over the whole flight | Apply the criterion per flight or per cycle for phase-limited conditions |
| At-risk time invented | A window justified by a fleet-average weather statistic | Windows are defined phases, not statistics; otherwise carry the whole flight |
| The band read as a rule | "It is 1.2E-9, so we fail" | The bands are orders of magnitude; the guidance allows a factor on them |
| The single-failure rule negotiated | An extremely improbable single failure argued as acceptable | No probability argument buys relief, and a set of dependent failures is one failure |
| DAL treated as a budget | An assurance level quoted as though it were a failure rate | It governs process rigour against errors, which have no rate |
| Sharing a level without independence | A + C claimed with no argument for how the two developments differ | The independence argument is the deliverable, not the assignment |
| No verification column | Conditions with objectives and no plan for showing compliance | Every condition names its fault tree, test or analysis |
| Written once | An assessment dated at concept, never reopened | Allocation and integration both create new conditions; re-run at both |
| No merge record | Fewer rows than the grid, no explanation | Record why rows were combined; it is the first question a reviewer asks |
Four of these are worth a sentence more.
Missing the misleading row is the expensive one. Everything else in the assessment can be corrected later at the cost of rework. A missing failure condition produces an architecture with no defence against it, discovered either in a late review or in service, and both discoveries arrive after the design is fixed.
Severity deflation is structural, not personal. A catastrophic classification triggers the most expensive obligations in the programme, so the pressure to argue it down is permanent and comes from people acting reasonably. The only defence is procedural: classify from the consequence before any mitigation is considered, and require that a change of class be justified by a change in what actually happens, not by a change in how likely it is.
The single-failure rule is not a probability statement, and treating it as one is the most common misreading in this material. It is a statement about structure, and the definition of a single failure includes any set of failures that cannot be shown independent. That is why it is answered with a cut-set order and a common cause analysis rather than with a number.
An assurance level is not an item property. Saying an item "is DAL B" says how carefully it was developed. It does not say how reliable it is, it does not imply a failure rate, and it cannot be substituted for one in an availability argument. The two columns come from the same classification and answer different questions.