Nine steps, and the discipline of the method is in the first three. A tree built on a vague top event or a drifting boundary can be quantified perfectly and still answer nothing.
1. State the top event exactly
One failure condition, with its effect, its phase and its annunciation state in the wording, and with the objective it will be judged against written beside it. Take it from the FHA rather than inventing it, because a top event that does not match a classified failure condition has no budget and no reason to exist.
2. Fix the boundaries and write them down
Physical scope, resolution, the initial state and the configuration. Two conventions in particular decide whether the tree can be compared with anything: what counts as a basic event (item, board, or mode), and what is treated as an external input rather than developed. Both belong in the report's assumptions, not in the analyst's head.
3. Develop downward, one immediate cause at a time
At every node, ask what is immediately, necessarily and sufficiently required to produce this event. Not the root cause: the next cause. Skipping levels is how branches lose their common events and how independence gets assumed by accident.
Two habits keep the structure honest. An OR gate's inputs are restatements of the output, more specific; an AND gate's inputs are causes. And no gate feeds another gate directly: every gate produces a named event, which is what makes the tree readable a year later.
4. Choose the gate the logic actually requires
- A voting gate where a k-of-n comparison decides the output, rather than drawing every combination.
- A priority AND where the order matters, most often a monitor that must fail before what it monitors for the failure to stay hidden.
- An inhibit where one input plus a conditional probability produces the output: a phase, a crew response, a coincidence. Its condition is a judgement, and it must be reported as one.
- A house event to switch a configuration on and off, so one model answers both the normal and the dispatched-with-an-item-inoperative question.
5. Put the right quantity on every basic event
Each basic event gets a failure rate, an exposure time and a statement of which of the two it is:
| The event is | Exposure | Comes from |
|---|---|---|
| Revealed at once | The mission or flight time | The mission definition |
| Latent until a test | The test or inspection interval | The maintenance programme |
| Already failed and waiting | An unavailability, dimensionless | Availability modelling |
The exposure choice is worth more than the rate choice, routinely by two orders of magnitude, and it is the one most often made by default.
6. Reduce to minimal cut sets before quantifying
Boolean reduction, not gate-by-gate multiplication. Reduction is what removes repeated events, and a tree with the same basic event in two branches will be under-reported by any arithmetic that walks the gates instead.
7. Quantify, and know which approximation you used
Sum the minimal cut set probabilities for the rare event approximation, or evaluate exactly by inclusion-exclusion where the sets are not small. Report which. Then convert to the units the objective is stated in: a per-flight probability against a per-flight-hour objective needs the average flight length, and it needs it to be the same number the FHA used.
8. Read the cut sets before reading the number
Three checks, in this order:
- Any order-one cut set? For a catastrophic condition that is a finding on its own, whatever the arithmetic says.
- Does every order-two set survive the independence question? Shared power, shared cooling, shared maintenance, shared calibration, shared development. Where independence cannot be shown, the pair is a single failure by definition, and the zonal, particular-risk and common-mode analyses are where that gets settled.
- Which sets carry the probability? Rank them, and check whether the ranking is stable against the assumptions underneath it.
9. Report the assumptions with the number
The report carries the top event and its objective, the cut sets by order and contribution, the exposure times and where they came from, every conditional probability used in an inhibit, the independence claims and their evidence, and the maintenance intervals the analysis now requires. An interval assumed inside a fault tree is a safety requirement: if it later slips, the compliance argument goes with it, and the only way anybody will know is if the tree said so out loud.