Failure Conditions and System Safety
A failure condition is the effect on the aeroplane and its occupants of one or more failures or errors. Certification classifies each by severity, from no safety effect to catastrophic, and requires the more severe ones to be less probable, down to extremely improbable, or 10⁻⁹ per flight hour, for catastrophic conditions.
No aircraft system is perfectly reliable, so certification does not ask for systems that never fail. It asks instead that the probability of each failure be acceptable for the harm it would do. A failed reading light may happen often; a failure that could destroy the aeroplane must be so rare that it is not expected to happen once in the life of the whole fleet. This inverse relationship between severity and probability is the heart of paragraph 25.1309 of CS-25 and 14 CFR Part 25, the large aeroplane codes described in large aeroplane certification, and of its advisory material, AMC 25.1309.
For pilots the subject explains why systems are built the way they are: why flight control computers come in dissimilar sets, why some failures leave the crew a simple checklist while others are simply designed out, and why certification treats some combinations of failures as so improbable that they need not be designed for. It is also a standard ATPL topic, with fixed words and figures.
System safety assessment
The traditional wording of the rule, as in JAR 25.1309 and FAR 25.1309, requires aeroplane systems and components to be designed so that any failure condition which would prevent continued safe flight and landing is extremely improbable, and any other failure condition which would reduce the capability of the aeroplane or the ability of the crew to cope with adverse operating conditions is improbable. The same paragraph requires equipment to perform its intended function under all foreseeable operating conditions, and the crew to be warned of unsafe system conditions so that they can act. EASA's current CS 25.1309 and AMC 25.1309 grade the requirement by severity: a catastrophic failure condition, for example, must be extremely improbable and must not result from a single failure.
Compliance is shown by a system safety assessment, carried out alongside the design:
- A functional hazard assessment (FHA) lists the functions of the aeroplane and of each system, identifies how each can fail (lost, or working wrongly), and classifies the effect of each failure condition in each phase of flight.
- The design is then given an architecture able to meet the targets, and a preliminary assessment checks that it can.
- The final assessment shows, by analysis, that the design as built meets them. The main tools are the failure modes and effects analysis (FMEA), which works upwards from each component's failure modes, and the fault tree analysis, which works downwards from a failure condition to the combinations of failures that can cause it. Common cause analyses look for single events that could defeat redundancy: fire, an engine rotor burst, a bird strike, a shared power supply or a design error repeated in every channel.
Industry guidance for the process is in SAE ARP4754A and ARP4761. The analysis may be qualitative for simple systems or less severe conditions, and is usually quantitative where a failure could be catastrophic. When the A320's reinforced cockpit door used electrical latches, released by a pressure sensor signal so that the door would give way in a rapid decompression, for instance, the authority required a quantitative safety assessment, because a door that failed to open when needed could cause a catastrophic failure.
Note: the traditional design principle behind all this is fail-safe design. The failure of any single element is assumed, however reliable it is, and no single failure may cause a catastrophic failure condition. Redundancy, isolation between redundant channels, monitoring and warnings, and checks for hidden failures are the usual means.
Failure condition categories
AMC 25.1309 classifies failure conditions into five categories, by their effect on the aeroplane, the crew and the occupants:
| Category | Effect | Allowed probability |
|---|---|---|
| No safety effect | No effect on operational capability or crew workload | No requirement |
| Minor | Slight reduction in safety margins or functional capabilities; slight increase in crew workload, such as routine flight plan changes; some physical discomfort to passengers or cabin crew | Probable |
| Major | Significant reduction in safety margins or functional capabilities; significant increase in workload or conditions impairing crew efficiency; discomfort to the flight crew; physical distress to passengers or cabin crew, possibly with injuries | Remote, ≤ 10⁻⁵ per flight hour |
| Hazardous | Large reduction in safety margins or functional capabilities; physical distress or excessive workload such that the flight crew cannot be relied on to perform their tasks accurately or completely; serious or fatal injury to a relatively small number of occupants other than the flight crew | Extremely remote, ≤ 10⁻⁷ per flight hour |
| Catastrophic | Multiple fatalities, usually with the loss of the aeroplane | Extremely improbable, ≤ 10⁻⁹ per flight hour |
Probability terms
Each probability class has a qualitative meaning, tied to the life of one aeroplane or of the whole fleet of the type, and a numerical range expressed as an average probability per flight hour:
| Term | Qualitative meaning | Per flight hour |
|---|---|---|
| Probable | Expected to occur one or more times during the operational life of each aeroplane | More than about 10⁻⁵ |
| Remote | Unlikely to occur to each aeroplane during its life, but may occur several times in the lives of a number of aeroplanes of the type | 10⁻⁵ to 10⁻⁷ |
| Extremely remote | Not expected to occur to each aeroplane during its life, but may occur a few times in the life of all aeroplanes of the type | 10⁻⁷ to 10⁻⁹ |
| Extremely improbable | Not expected to occur during the entire operational life of all aeroplanes of the type | 10⁻⁹ or less |
The 10⁻⁹ figure is not arbitrary. An acceptable rate of serious accidents caused by aircraft systems is taken as about 1 in 10 million flight hours, 10⁻⁷, and a typical large aeroplane may have around 100 potential catastrophic failure conditions. Sharing the risk between them leaves about 10⁻⁹ per flight hour for each.
Exam tip: catastrophic, extremely improbable, 10⁻⁹; hazardous, extremely remote, 10⁻⁷; major, remote, 10⁻⁵; minor, probable. The more severe the condition, the lower its allowed probability.
Severity against probability
Plotted on a graph, the five categories form a stepped line: severity rises along one axis, the allowed probability falls along the other, and every failure condition must sit on the safe side. A designer can therefore make a severe effect acceptable only by making it rare enough, and it is the combination, not the component, that is judged.
The A320's thrust reversers show the reasoning. The large aeroplane code required either that a reverser deployed in flight could be restored to forward thrust, or that the aeroplane could continue safe flight and landing with the reverser in any position. The A320 met the first option with an automatic restow function. When Airbus proposed deleting it on some models, the authority accepted an equivalent safety finding (see type certification), because inadvertent in-flight deployment of any reverser had been shown to be extremely improbable, and deleting the restow function actually improved protection against inadvertent deployment.

Redundancy that looks independent on a diagram can still be defeated by one physical event, which is why common cause analysis matters. On United Airlines Flight 232 in 1989, the uncontained failure of a fan disc in the tail engine of a DC-10 severed the lines of all three hydraulic systems, leaving the crew to steer with the thrust of the two wing engines. Such events drive the physical separation of redundant systems and the analysis of particular risks such as rotor bursts.
Catastrophic and hazardous conditions
A catastrophic condition prevents continued safe flight and landing. Such conditions must be extremely improbable and must not result from any single failure, so functions whose loss would be catastrophic, such as the flight controls of a fly-by-wire aeroplane, are built from several independent channels. Dissimilarity guards against a common error: the A320's two ELACs and three SECs come from different suppliers and use different microprocessors (see fly-by-wire).
A hazardous condition is defined partly by what it does to the crew: workload or distress so high that they cannot be relied on to perform their tasks accurately or completely. Alerting the crew when protection is lost is part of the design. For the A320's electronic flight controls, the certification basis requires suitable alerting whenever single or multiple failures that are not extremely improbable change the flight envelope limiting or the manoeuvrability available.
Major and minor conditions
Major and minor conditions are the ground of normal crew procedures. They reduce margins or add workload but leave the aeroplane controllable and the crew able to cope, so their allowed probabilities are higher. Most ECAM, EICAS and QRH procedures deal with conditions of this kind: the loss of one generator, one hydraulic system or one air data source.
Hidden, or latent, failures need particular care, because a backup that has failed without anyone knowing turns the next failure into a double one. System safety assessments therefore specify how often such failures must be exposed, by built-in tests, crew checks or maintenance tasks. The same reasoning supports the master minimum equipment list: an item may be inoperative at dispatch only where the aeroplane still keeps an acceptable level of safety without it, often with added operational or maintenance procedures (see technical log, MEL and deferred defects).
Software assurance levels
Software does not wear out or fail at random, so no failure probability can be calculated for it. Its errors are design errors, present in every copy. Certification therefore controls the process by which it is written and verified. The standard is RTCA DO-178, published in Europe as EUROCAE ED-12. ATPL questions quote the levels as defined in version B of both (DO-178B / ED-12B). EASA and the FAA accept the standard as a means of compliance.
Each software item receives a software level, or design assurance level, according to the worst failure condition its anomalous behaviour could cause or contribute to:
| Level | Failure condition |
|---|---|
| A | Catastrophic |
| B | Hazardous |
| C | Major |
| D | Minor |
| E | No safety effect |
Fly-by-wire flight control software is level A. The higher the level, the more demanding the planning, independent review, testing and coverage analysis required. Because a single software error would be repeated in every identical computer, level A functions also rely on the dissimilar architectures described above (see avionics computers and data buses).
Exam tip: ED-12B / DO-178B level A = catastrophic, B = hazardous, C = major, D = minor, E = no effect. The software level follows the severity classification of the failure condition, not the probability.
Frequently asked questions
What does extremely improbable mean in aircraft certification?
Extremely improbable is the probability class required for catastrophic failure conditions on large aeroplanes. It means a condition so unlikely that it is not expected to occur during the entire operational life of all aeroplanes of the type. Quantitatively, it corresponds to an average probability of not more than 1 × 10⁻⁹ per flight hour.
What are the five failure condition categories?
From least to most severe: no safety effect, minor, major, hazardous and catastrophic. Minor conditions slightly reduce safety margins or add slight workload, major ones reduce them significantly, hazardous ones reduce them greatly, overload the crew or seriously or fatally injure a few occupants, and catastrophic ones result in multiple fatalities, usually with loss of the aeroplane.
Why is the catastrophic target 10⁻⁹ per flight hour?
The figure comes from sharing out an acceptable risk. An acceptable rate of serious accidents caused by aircraft systems is taken as about 1 in 10 million flight hours, 10⁻⁷, and a typical large aeroplane may have around 100 potential catastrophic failure conditions. Giving each a share leaves about 10⁻⁹ per flight hour for each condition.
What are the DO-178 software levels?
RTCA DO-178 and its European twin EUROCAE ED-12 assign airborne software a level from A to E according to the worst failure condition its malfunction could cause or contribute to: A catastrophic, B hazardous, C major, D minor and E no safety effect. The higher the level, the more rigorous the required development and verification. Flight control software is level A.
What is a functional hazard assessment?
A functional hazard assessment (FHA) is the first step of a system safety assessment. It lists the functions of the aeroplane or of a system, identifies how each can fail, for example by being lost or by working wrongly, and classifies the effect of each failure condition in each phase of flight. The classifications then set the probability and design assurance targets for the design.
Test yourself on Failure Conditions and System Safety
The v1prep banks cover this topic in Air Law (010), with a worked explanation for every answer. EASA ATPL, PPL, IR and CPL, the FAA written tests and A320/B737 type ratings.
Start practising →Sources and further reading
- EASA Easy Access Rules for Large Aeroplanes (CS-25), CS 25.1309 and AMC 25.1309
- 14 CFR 25.1309, Equipment, systems, and installations
- FAA AC 20-115D, Airborne Software Development Assurance Using EUROCAE ED-12( ) and RTCA DO-178( )
- EASA TCDS EASA.A.064, Annex I, Special Conditions and Equivalent Safety Findings
- NTSB AAR-90-06, United Airlines Flight 232, Sioux City, Iowa, 19 July 1989
Library articles are written for study and exam preparation. They do not replace your aircraft's approved documentation, your operator's procedures or the regulations themselves.