Navigate / EASA

GM1 MMEL.145(f) Justification of MMEL items

ED Decision 2020/012/R

QUANTITATIVE ASSESSMENT CRITERIA FOR AIRCRAFT CERTIFIED AGAINST REQUIREMENTS OTHER THAN CS 25/29.1309

For simple and conventional installations (that is, those with low complexity and with similarity in the relevant attributes), it may be possible during the type design certification to assess the probability of a hazardous or catastrophic failure condition as being extremely remote (refer to the TC basis) or extremely improbable (refer to the TC basis), respectively, on the basis of experienced engineering judgement, using only qualitative analysis. The basis for such an assessment will be the degree of redundancy, the established independence and isolation of the channels, and the reliability record of the technology involved. Satisfactory service experience on similar systems commonly used in many aircraft may be sufficient when a close similarity is established regarding both the system design and the operating conditions.

A similar approach may be used for the justification of MMEL items. In particular:

(a)     For MMEL items involved in catastrophic failure conditions:

(1)     It should be demonstrated that the degree of redundancy under the MMEL dispatch configuration remains adequate to ensure that the involved catastrophic failure condition is still extremely improbable (refer to the applicable type-certification basis definition). This demonstration may be, in some cases, limited to the demonstration that a combination of a minimum of two independent failure(s) or external event(s) is necessary to lead to the catastrophic failure condition. It will take into account that the reliability of the involved systems, based on experienced engineering judgement and service history, would allow the occurrence of the failure condition to continue to meet the qualitative objective used for the type design certification.

(2)     No catastrophic failure condition should result from the failure of a single component, part, or element of a system under any MMEL dispatch configuration. The logic and rationale used in the assessment should be straightforward, and should obviously substantiate that the failure mode simply would not occur unless it is associated with an unrelated failure condition that would, in itself, be catastrophic.

(3)     The MMEL entry should use standard rectification interval B, or a more restrictive interval, for items that leave the aircraft two independent failure(s) or external event(s) away from a catastrophic failure condition. If there is no reduction in safety margins compared with the full-up configuration, category C may be acceptable.

(b)     For MMEL items involved in hazardous failure conditions:

(1)     It should be demonstrated that a degree of redundancy under the MMEL dispatch configuration remains available so that a combination of a minimum of two independent failure(s) or external event(s) is necessary to lead to the hazardous failure condition. In such a case, there is no need to demonstrate (even qualitatively) that the failure condition remains extremely remote (refer to the applicable type-certification basis definition) under the MMEL dispatch configuration, as the fact that no single failure or external event exists is sufficient to grant an adequate probability of occurrence under the MMEL dispatch configuration, or

(2)     It should be demonstrated, using experienced engineering judgement and service history, that the single failure or external event has a probability of occurrence that is compatible with the safety objectives used for the type design certification, taking into account the proposed rectification interval.

(3)     The MMEL entry should use standard rectification interval B, or a more restrictive interval, for items that leave the aircraft one failure(s) or external event(s) away from a hazardous failure condition. If there is no reduction in safety margins compared with the full-up configuration, category C may be acceptable.

Issue No: MMEL/2