Skip to content

Fault Tree Analysis

A deductive failure-analysis method that decomposes a defined undesired top event through Boolean event logic into basic causes for cut-set, dependency, and risk evaluation.

Version
v1 · 2026-09-28 · History
Domain-specific #
9417
Domain group
Applied Sciences & Engineering
Origin domain
Engineering & Design (beyond software)
Subdomains
Systems Engineering, Safety and Reliability Analysis → Engineering & Design (beyond software)
Aliases
FTA, Fault-tree analysis

Core Idea

Fault tree analysis begins with a specific unwanted system state and asks what combinations of lower-level events could produce it. AND, OR, voting, and conditional gates make the combination logic explicit until justified basic events are reached.

Minimal cut sets reveal sufficient failure combinations; probability and importance measures are optional quantitative layers. Boundaries, completeness, dependencies, common causes, dynamic effects, and data uncertainty must be reviewed before numerical precision is trusted.

Structural Signature

Sig role-phrases:

  • Top event — Defines one system failure, boundary, mission phase, and severity. It is analysis target. Counterfactual: A vague hazard yields an incoherent tree.
  • Intermediate events — State subsystem conditions requiring further decomposition. It is causal structure. Counterfactual: Labels must be events, not component names alone.
  • Boolean gates — Specify AND, OR, voting, or conditional combination logic. It is composition rule. Counterfactual: A tree picture without semantics cannot be calculated.
  • Basic events — Stop decomposition at justified initiating failures or conditions. It is leaf evidence. Counterfactual: Arbitrary stopping hides common or actionable causes.
  • Dependencies and common causes — Correct false independence across branches. It is validity control. Counterfactual: Duplicated components can distort probabilities and cut sets.
  • Cut sets and quantitative inputs — Identify sufficient combinations and estimate likelihood/importance. It is output. Counterfactual: Numbers inherit every boundary and independence assumption.

What It Is Not

  • It is not an event tree.
  • It is not FMEA.
  • A causal sketch without Boolean semantics is incomplete.
  • Quantification is not valid without data and dependence assumptions.
  • Closest near-miss. FTA reasons backward from a top failure; event-tree analysis reasons forward from initiating events through barriers and outcomes.

Scope of Application

  • Safety engineering. Analyzes hazardous top events.
  • Reliability engineering. Finds failure combinations.
  • System assurance. Demonstrates requirement compliance.
  • Software and operations. Structures debugging and control failures.

Clarity

State top event, system and mission phase, success/failure convention, interfaces, gate definitions, decomposition rules, stopping criteria, dependencies, common causes, data sources, uncertainty, cut-set treatment, and model review.

Manages Complexity

FTA converts many interacting component and condition failures into auditable Boolean structure while exposing how modeling choices govern risk results.

Abstract Reasoning

  1. Define one bounded top event.
  2. Decompose immediate sufficient causes.
  3. Assign correct gate logic.
  4. Continue to evidence-supported basic events and model dependencies.
  5. Review cut sets, uncertainty, and risk controls.

Knowledge Transfer

A tree transfers only with matching architecture, interfaces, operating phase, failure definitions, dependencies, data, and controls; generic branches cannot be copied safely.

Examples

Canonical

For 'loss of braking during landing,' analysts define phase and boundary, decompose hydraulic and control paths with gates, identify common power causes, and compute minimal cut sets before considering event data.

Mapped back: top → loss of braking in phase; intermediates → hydraulic/control; gates → explicit; leaves → basic failures; dependencies → common power; output → cut sets.

Applied / In Practice

A chronological branch diagram beginning with a fire and tracking alarm success/failure is an event tree, not a fault tree.

Mapped back: direction → forward; start → initiator; form → event tree.

Structural Tensions

T1 — Tractable Boolean Model versus Dynamic Reality. Static gates clarify combinations while order, repair, software states, and human adaptation may be dynamic.

Diagnostic: Does the top event require sequence-aware modeling?

T2 — Quantitative Ranking versus Data And Dependence Uncertainty. Numbers aid prioritization but rare-event rates and common causes can dominate error.

Diagnostic: Are uncertainty and dependence propagated rather than hidden?

Structural–Framed Character

Fault Tree Analysis is structural as top-down Boolean failure decomposition and framed by system boundary and evidence.

Structural Core vs. Domain Accent

The core is top event, event nodes, gates, leaves, and cut sets. Safety practice supplies hazards, data, common-cause models, and assurance use.

This entry is a kind of Decomposition.

  • Approved root. No reviewed parent entails this deductive risk method.

  • Related — event tree, FMEA, minimal cut set, Boolean logic, common-cause failure, and hazard analysis. They provide contrasts, outputs, mechanism, and context.

Relationships to Other Abstractions

Local relationship map for Fault Tree AnalysisParents appear above the current abstraction, mutual partners to the right, and children below. Node labels state whether each abstraction is prime or domain-specific; colors identify relation types.Fault Tree AnalysisDOMAINPrime abstraction: Decomposition — is a kind ofDecompositionPRIME

Current abstraction Fault Tree Analysis Domain-specific

Parents (1) — more general patterns this builds on

  • Fault Tree Analysis is a kind of Decomposition Prime

    Fault Tree Analysis is a strict kind of Decomposition: it decomposes an undesired top event through Boolean logic into basic causes and cut sets.

Hierarchy path (1) — routes to 1 parentless root

Neighborhood in Abstraction Space

Fault Tree Analysis sits in a crowded region of the domain-specific corpus (39th percentile for distinctiveness): several abstractions share nearly its structure, so a description that fits it tends to fit its neighbors too.

Family — Decision & System Modeling Frameworks (30 abstractions)

Nearest neighbors

Computed from structural-signature embeddings · 2026-10-08

Not to Be Confused With

  • Event tree analysis. Tell: Projects forward from an initiating event.
  • FMEA. Tell: Inductively reviews component failure modes.
  • Bow-tie analysis. Tell: Combines causal and consequence sides around an event.
  • Fishbone diagram. Tell: Organizes possible causes without formal gate logic.

References

  • Frozen Wikipedia discovery revision: https://en.wikipedia.org/wiki/Fault_tree_analysis (revision 1356229526).
  • Preserved source candidate: https://ntrs.nasa.gov/search.jsp?R=19950012517
  • Preserved source candidate: http://www.aiche.org/ccps/publications/books/guidelines-hazard-evaluation-procedures-3rd-edition
  • Preserved source candidate: http://www.aiche.org/ccps/publications/books/guidelines-chemical-process-quantitative-risk-analysis-2nd-edition
  • Preserved source candidate: https://www.osha.gov/Publications/osha3133.pdf
  • Preserved source candidate: http://www.ich.org/fileadmin/Public_Web_Site/ICH_Products/Guidelines/Quality/Q9/Step4/Q9_Guideline.pdf
  • Preserved source candidate: https://ftvisualisations.wixsite.com/ftvisualisations/fault-tree-information
  • Preserved source candidate: https://ftvisualisations.wixsite.com/ftvisualisations/projects-1
  • Preserved source candidate: http://www.fault-tree.net/papers/ericson-fta-history.pdf

The frozen Wikipedia revision is discovery provenance. The retained source set was reviewed for identity, formal or operational relation, and scope. The encyclopedia's structural synthesis is bounded to those claims; a thin authority surface is recorded as a nonblocking source-strengthening repair rather than concealed.