Navigate / EASA

MOC 5 VTOL.2300 Hidden Failures in Fly-by-Wire flight control systems

n/a

To demonstrate compliance with VTOL.2300, in line with VTOL.2510, and to reach an acceptable level of safety, specific attention should be paid to latent failures.

The objective is to obtain a design with a minimum number of significant latent failures. Each significant latent failure should be highlighted in the system safety assessment and subject to review by the Agency.

In addition to the general considerations in Section 12 of MOC VTOL.2510, the following applies for fly-by-wire flight control systems:

(a)     Definitions:

(1)     Latent = dormant = hidden for more than one flight.

(2)     A failure is latent until it is made known to the flight crew or maintenance personnel.

(3)     A significant latent failure is one, which would in combination with one or more specific failures, or events result in a Hazardous or Catastrophic Failure Condition.

(4)     A significant failure condition is one which is classified Hazardous or Catastrophic and contains one or more significant latent failures.

(b)     The following approach should be followed:

(1)     Double failures, with either one latent, that can lead to a Catastrophic Failure Condition should be avoided as far as practicable in system design. Deviations should be presented and accepted by the Agency.

(2)     Latent failures that contribute to Hazardous or Catastrophic effects at aircraft level should be avoided in system design.

(3)     The use of periodic maintenance or flight crew checks to detect significant latent failures when they occur is undesirable and should not be used in lieu of practical and reliable failure monitoring and indications.

(4)     It is recognised that, on occasion, it would be impracticable to meet (1) and (2). In such cases:

(i)      The remaining latent failures should be recorded and justified in the PSSA/SSA and reviewed during the design review process for compliance,

(ii)     Compliance should be based on both previous experience and sound engineering judgement and should assess:

(A)     the failure rates and service history of each component,

(B)     the inspection type and interval for any component whose failure would be latent, and

(C)     any possible common cause of cascading failure modes.

(iii)     The integrity of the evident part of the significant failure condition should meet a minimum standard:

(A)     For Catastrophic failure combinations comprising of only one evident failure, the probability per flight hour of the evident part should be:

a.       <= 10-5/Fh for Category Enhanced and Basic 7 to 9 passengers or

b.       <= 10-4/Fh for Category Basic below 7 passengers.

(B)     For Hazardous failure combinations comprising of only one evident failure, the probability per flight hour of the evident part should be:

a.       <= 10-4/Fh for Category Enhanced and Basic 7 to 9 passengers or

b.       <= 10-3/Fh for Category Basic below 7 passengers.

(iv)     In addition, a Specific Risk calculation should be performed to demonstrate compliance with the presence of a latent failure. For each combination composed of one evident failure and latent failures and leading to a Catastrophic Failure Condition the probability of the latent part of the combination (e.g. “Sum of the products of the failure rates multiplied by the exposure time” of any latent failure) should be on average equal to or less than 1x10-3 (=1/1000).

(v)      The periodic maintenance checks, which may result from the compliance to this Specific Risk criterion in (b)(4)(iv)), should be considered as candidates for required maintenance tasks, in addition to the candidates for required maintenance tasks already selected for compliance to VTOL.2510.