Aircraft Electrical Systems and EWIS · Lesson 5 of 5 · 18 min read
System safety: the 25.1309 approach
Fail-safe design, the five failure condition classes and their probability targets, the safety assessment toolkit, and why some maintenance tasks are part of the certified safety case.
Failures will occur
Modern transport aircraft are designed around a simple principle: failures will occur, so the aircraft must remain safe when they do. System safety engineering ensures that no single equipment failure, wiring fault, software error, maintenance mistake or foreseeable combination of failures can lead directly to a catastrophic outcome. The foundation of this philosophy is 14 CFR 25.1309, which governs the safety assessment of aircraft systems.
Rather than asking "Can this component fail?", system safety asks: "What happens if it fails, how severe would the consequences be, and how likely is that failure to occur?" This approach drives everything from aircraft architecture and redundancy to maintenance requirements and crew procedures.
The fail-safe philosophy
Transport-category aircraft are not designed on the assumption that components never fail. They are designed on the assumption that the things below will happen, and the aircraft must still maintain an acceptable level of safety. This is known as fail-safe design, and in most cases safety is achieved not through a single protective feature but through multiple overlapping layers of protection.
- Components will fail.
- Sensors will fail.
- Wiring will fail.
- Software will malfunction.
- Humans will make mistakes.
Fail-safe design principles
- Designed integrity and quality: the first defense is preventing failures, through robust engineering, material selection, environmental qualification testing, quality control and life-limited components. Critical parts may be removed before they are expected to fail.
- Redundancy: alternative means of performing a function if one component fails, such as multiple hydraulic systems, flight computers, generators and navigation sources. If one system fails, another takes over.
- Isolation and segregation: redundant systems must not share a common vulnerability. Physically separated wire bundles, independent hydraulic routing, separate equipment bays and independent power sources prevent a single event, such as a fire or fluid leak, from disabling all backups simultaneously.
- Proven reliability: safety assessments use reliability data to demonstrate that combinations of failures are sufficiently unlikely. A backup system is only useful if it can be relied upon to function when needed.
Detection, checkability and margins
- Failure detection and annunciation: many failures are acceptable as long as they are detected, through MASTER CAUTION messages, EICAS alerts, ECAM warnings, fault indications and crew checklists. The crew must know a failure has occurred before they can respond appropriately.
- Checkability and error tolerance: systems are designed so that faults can be detected, isolated, tested and corrected. Many aircraft also incorporate fault-tolerant design, where the failure of a component does not immediately create a hazardous condition.
- Safety margins: designers intentionally incorporate margins into systems and structures, so that normal wear, manufacturing variation and unexpected loads do not immediately compromise safety.
Failure condition classification
Not all failures have the same consequences. A cabin reading light failure is very different from the loss of all flight displays. For this reason, system failures are classified according to their effects on the aircraft and occupants. The more severe the consequences, the less frequently the failure may be allowed to occur.
No safety effect and minor
- No safety effect: the failure has no meaningful impact on safety, such as the loss of a passenger entertainment function or the failure of a non-safety-related indication. There is no specific probability target.
- Minor: minor failures may slightly increase crew workload, cause minor inconvenience or create small operational limitations, but safety margins remain essentially unaffected. They may be probable, generally on the order of 10⁻³ to 10⁻⁵ per flight hour, or roughly 1 in 1,000 to 1 in 100,000 flight hours.
Major
Major failures significantly increase crew workload or reduce safety margins. The flight remains controllable, but safety margins are reduced. They must be remote: 10⁻⁵ to 10⁻⁷ per flight hour, or approximately 1 in 100,000 to 1 in 10 million flight hours. Examples may include:
- Loss of some flight instrument capability
- Significant workload increase
- Reduced operational capability
Hazardous
A hazardous failure creates a substantial reduction in safety. The aircraft may still be recoverable, but the situation becomes serious. It must be extremely remote: 10⁻⁷ to 10⁻⁹ per flight hour, or approximately 1 in 10 million to 1 in a billion flight hours. Consequences may include:
- Serious crew workload
- Major reduction in aircraft capability
- Potential injuries to occupants
- Significant difficulty maintaining control
Catastrophic
Catastrophic failures prevent continued safe flight and landing, for example through loss of the aircraft, multiple fatalities or complete loss of flight control. They must be extremely improbable: 10⁻⁹ per flight hour or less, or about 1 in a billion flight hours.
Additionally, no single failure may result in a catastrophic condition. This principle drives much of the redundancy and segregation seen in transport aircraft designs.
Severity against probability
The central concept of system safety can be summarized as: the more severe the consequence, the less often it may be allowed to occur. This relationship ensures that risks are controlled to a level appropriate to their potential consequences.
- No safety effect: no requirement
- Minor: may be probable
- Major: remote
- Hazardous: extremely remote
- Catastrophic: extremely improbable
Numbers support engineering judgement
Safety analysis is not purely a mathematical exercise. While probability targets are important, they do not replace engineering judgement. The numbers support the safety argument. They do not replace it. For example:
- A calculated probability may appear acceptable.
- A design flaw may still exist.
- A common-cause failure may invalidate assumptions.
- Human factors may introduce additional risk.
Functional hazard assessment (FHA)
Engineers use several structured methods to evaluate system safety. The FHA begins by asking: what functions does the aircraft perform, and what happens if each function fails? Examples include loss of hydraulic power, loss of navigation and loss of flight controls. The failure condition classification is established during this process.
Failure modes and effects analysis (FMEA)
FMEA works from the component level upward. This method helps identify weak points before certification. It examines:
- How each component can fail
- What effects the failure creates
- Whether additional protections are needed
Fault tree analysis (FTA)
Fault tree analysis starts with an undesired event and works backward. For example, it starts from a loss of electrical power and traces the possible causes, such as generator failures, battery failures, bus failures and common-cause failures. The probability of each failure combination can then be calculated. Fault trees are widely used to demonstrate compliance with probability requirements.
Common cause analysis (CCA)
Redundancy only works if systems fail independently. Common cause analysis looks for hidden links between redundant systems. Without it, redundancy may be misleading. Examples include:
- Shared wire bundles
- Shared power supplies
- Common software errors
- Fire zones
- Structural damage paths
Zonal analysis
Aircraft are divided into zones. Engineers then ask what systems share each space, and whether one event could affect multiple systems, such as a tire burst, fluid leak, fire or structural failure. Zonal analysis helps verify that physical separation is adequate.
The maintenance connection
Many safety assessments depend on certain failures being found before they combine with other failures. These are known as latent failures. The certification process may require periodic inspections to find these hidden failures. Examples include:
- A backup channel failing silently
- A standby sensor becoming inaccurate
- A redundant power source becoming unavailable
Certification maintenance requirements (CMRs)
Some maintenance tasks are incorporated directly into the system safety case. These intervals are not arbitrary. They are part of the evidence demonstrating compliance with 25.1309, and skipping them can invalidate the assumptions used during certification. They are often known as:
- Certification maintenance requirements (CMRs)
- Airworthiness limitation items (ALIs)
- Required inspection tasks
25.1309 in practice
The influence of system safety can be seen throughout modern aircraft. Each layer exists because a single component failure cannot be allowed to create an unacceptable hazard.
- Flight controls: multiple computers, multiple sensors and multiple power sources.
- Electrical systems: multiple generators, backup batteries and a ram air turbine (RAT).
- Navigation: GPS, inertial systems and radio navigation backups.
- Fire detection: multiple loops, fault monitoring and crew alerts.
Key takeaways
- System safety assumes failures will occur and designs around them.
- No single failure may produce a catastrophic outcome.
- Fail-safe design uses redundancy, segregation, reliability, annunciation and fault tolerance.
- Five failure classifications exist: no safety effect, minor, major, hazardous and catastrophic.
- The more severe the consequence, the lower the allowable probability.
- Catastrophic conditions must be extremely improbable, approximately 10⁻⁹ per flight hour or less.
- Functional hazard assessments, FMEA, fault trees and common cause analyses support certification.
- Some maintenance tasks are part of the aircraft's certified safety case and must not be skipped.
The bottom line
The 25.1309 approach is the foundation of modern transport-aircraft safety. Rather than attempting to prevent every failure, it assumes failures will occur and ensures that their consequences remain acceptable. Through redundancy, separation, fault detection, reliability analysis and rigorous maintenance requirements, the system safety process ensures that the most severe failure conditions become extraordinarily unlikely. The result is an aircraft that can continue safe flight and landing even when components, systems or people do not perform perfectly.
Check your understanding
Answer 2 of 3 correctly to complete this lesson.
Further reading
- AC 25.1309-1B, System Design and Analysis (August 30, 2024)
- 14 CFR 25.1309, as amended by Amendment 25-152 (2024)
FAA handbooks and advisory circulars are free to download from faa.gov.
General educational content, not reproduced from any manufacturer manual. Limits and procedures vary by aircraft type and change with revisions. Always work to the current approved data for your aircraft and your organisation's procedures.