{"id":81035,"date":"2026-09-18T10:06:33","date_gmt":"2026-09-18T13:06:33","guid":{"rendered":"https:\/\/a3aengenharia.com\/?post_type=articles&#038;p=81035"},"modified":"2026-09-18T10:06:33","modified_gmt":"2026-09-18T13:06:33","slug":"fault-tree-analysis-fta-method-logic-gates-calculation-application","status":"publish","type":"articles","link":"https:\/\/a3aengenharia.com\/en-us\/content\/technical-articles\/fault-tree-analysis-fta-method-logic-gates-calculation-application\/","title":{"rendered":"Fault Tree Analysis (FTA): Method, Logic Gates, Calculation, and Application"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">FTA \u2014 Fault Tree Analysis \u2014 is a deductive technique used to study how failures, conditions, and combinations of events can produce a previously defined undesired event. The analysis starts from the effect to be understood, called the <strong>top event<\/strong>, and proceeds from top to bottom by decomposing its causes through logical relationships until events sufficiently elementary for analysis and treatment are reached.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The technique is especially useful when loss of a function does not depend on a single failure but on the interaction among redundancies, protections, utilities, interfaces, software, human error, and common conditions. Instead of merely listing possible causes, the tree shows <strong>which isolated events are sufficient<\/strong>, <strong>which events must occur together<\/strong>, and <strong>which dependencies can invalidate apparently robust redundancy<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An FTA can be qualitative or quantitative. In qualitative analysis, the objective is to identify failure paths, single points, dependencies, and minimal sets capable of leading to the top event. In the quantitative approach, probabilities, unavailabilities, or frequencies can be propagated through the tree logic, provided that the data, units, and independence assumptions are technically appropriate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">FTA is not synonymous with FMEA or root cause analysis. FMEA starts from component failure modes and analyzes their effects; FTA starts from an undesired event and searches for the combinations capable of producing it. RCA normally investigates an actual occurrence to prevent recurrence. The choice of technique depends on the engineering question that needs to be answered.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Top Event and Boundary: Where FTA Really Begins<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Tree quality depends on how the problem is defined. A top event such as \u201csystem failure\u201d is too broad to guide consistent decomposition. A formulation such as <strong>\u201ctotal loss of power to the critical load for a period longer than the allowable transfer time during normal operation\u201d<\/strong> defines the function, condition, and failure criterion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Before building the logic, it is also necessary to establish the system boundary. External sources, utilities, people, software, environment, protection, telecommunications, and auxiliary systems may be inside or outside the scope. An element placed outside the boundary may appear as a basic event; the same element, when part of the system being studied, needs to be developed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An adequate definition records at least:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>the function or condition lost;<\/li><li>the system and interfaces considered;<\/li><li>the operating state analyzed;<\/li><li>the relevant duration or limit, when applicable;<\/li><li>redundancy and repair assumptions;<\/li><li>elements explicitly excluded.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This formalization prevents trees from growing without criteria and allows another team to understand exactly which condition was modeled.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Events and Logic Gates in a Fault Tree<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The tree uses events and gates to represent causal relationships. A basic event is one that will not be decomposed further within the objective of the analysis; this does not mean that it is physically indivisible, only that it has reached the level of detail considered sufficient.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Element<\/td><td>Practical interpretation<\/td><\/tr><tr><td>Top event<\/td><td>undesired condition that starts the analysis<\/td><\/tr><tr><td>Intermediate event<\/td><td>condition resulting from the combination of lower-level events<\/td><\/tr><tr><td>Basic event<\/td><td>event treated as elementary within the tree scope<\/td><\/tr><tr><td>Undeveloped event<\/td><td>event whose decomposition was not performed, with justification<\/td><\/tr><tr><td>OR gate<\/td><td>any one input can produce the output<\/td><\/tr><tr><td>AND gate<\/td><td>all inputs must occur to produce the output<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Consider a ventilation system whose loss may occur because of fan failure, loss of its power supply, or blocked control. If any one of these conditions is sufficient, the relationship is represented by an <strong>OR<\/strong> gate. In another situation, a load supplied by two independent paths may be lost only if path A <strong>and<\/strong> path B are unavailable; the relationship is represented by an <strong>AND<\/strong> gate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The logic should represent the real physical condition, not the appearance of the diagram. If both paths share the same busbar, controller, or environment, the independence assumption needs to be reviewed before treating them simply as independent AND events.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">How to Build an FTA Step by Step<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A technically consistent sequence is:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li><strong>Define the objective of the analysis.<\/strong> Determine whether the tree will be used for design, safety, availability, diagnosis, comparison of alternatives, or risk quantification.<\/li><li><strong>Define the top event.<\/strong> Specify the lost function, operating condition, limit, and duration when relevant.<\/li><li><strong>Establish the boundary.<\/strong> Record systems, interfaces, external sources, and included conditions.<\/li><li><strong>Identify immediate causes.<\/strong> Ask which conditions are necessary or sufficient to produce the top event.<\/li><li><strong>Apply the logic gates.<\/strong> Connect events using relationships consistent with physical and functional behavior.<\/li><li><strong>Decompose intermediate events.<\/strong> Continue until reaching basic events appropriate to the purpose of the study.<\/li><li><strong>Analyze dependencies and common causes.<\/strong> Verify shared elements across apparently redundant paths.<\/li><li><strong>Generate and review cut sets.<\/strong> Identify minimal combinations that produce the top event.<\/li><li><strong>Quantify when necessary.<\/strong> Apply probability, unavailability, or frequency data with explicit assumptions.<\/li><li><strong>Turn results into decisions.<\/strong> Evaluate redesign, monitoring, maintenance, barriers, tests, or procedures.<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Decomposition should stop when the level reached enables a decision. Developing irrelevant components down to microscopic levels does not necessarily improve the analysis; stopping too early, on the other hand, may hide common causes or possible engineering actions.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Minimal Cut Sets and Qualitative Analysis<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A <strong>cut set<\/strong> is a set of basic events whose joint occurrence is sufficient to produce the top event. A <strong>minimal cut set<\/strong> is minimal in the logical sense: if any event is removed, that combination is no longer sufficient.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Imagine a tree in which the top event occurs if <strong>A and B<\/strong> fail simultaneously or if <strong>C<\/strong> fails alone. The minimal sets are:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>{A, B};<\/li><li>{C}.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The second is a first-order set: a single event is sufficient to produce the top event. In systems intended to tolerate one failure, this result deserves immediate analysis because it may represent a <strong>Single Point of Failure \u2014 SPOF<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cut-set order alone is not a measure of risk. A first-order set with an extremely low probability may contribute less to total risk than a second-order combination composed of frequent events. Qualitative analysis identifies the logical structure; prioritization also needs to consider probability, consequence, detectability, and operating context.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This type of reasoning complements <a href=\"\/conteudo\/artigos-tecnicos\/analise-criticidade-ativos-criterios-matriz-priorizacao\/\">Asset Criticality Analysis<\/a>, which helps determine where detailed failure analysis creates the greatest value.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">How to Calculate Probabilities in AND and OR Gates<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Quantification requires attention to the variable being used. Probability of failure during a mission, unavailability at a given instant, and occurrence frequency are related quantities, but they are not automatically interchangeable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For two independent events A and B connected by an <strong>AND<\/strong> gate:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>P(A \u2229 B) = P(A) \u00d7 P(B)<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If each path has an unavailability probability of 0.01 under the condition analyzed and independence is technically valid:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>P(AND) = 0.01 \u00d7 0.01 = 0.0001<\/strong>, or 0.01%.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For an <strong>OR<\/strong> gate with two independent events:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>P(A \u222a B) = P(A) + P(B) \u2212 P(A)P(B)<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With several independent events, the probability that at least one occurs can be written as:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>P(OR) = 1 \u2212 \u220f(1 \u2212 Pi)<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When all events are rare, the sum of probabilities can be used as an approximation in certain analyses, but this simplification needs to be explicitly recognized as an approximation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The most relevant problem, however, is usually not the algebra: it is the validity of the assumptions. Multiplying probabilities for two paths that share the same auxiliary power supply or the same software can produce an apparently excellent but technically misleading result.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Common-Cause Failures and Dependencies Between Redundant Paths<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Equipment redundancy does not mean functional independence. Two paths may share elements capable of taking both down simultaneously:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>busbar or auxiliary power supply;<\/li><li>room or environmental condition;<\/li><li>physical cable route;<\/li><li>control logic or firmware;<\/li><li>cooling system;<\/li><li>grounding;<\/li><li>maintenance team and procedure;<\/li><li>common configuration;<\/li><li>external utility.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Consider two sources A and B supplying a critical load but converging into a single output panel. A simplified tree may represent load loss as:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>common panel failure OR (path A failure AND path B failure)<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The architecture has source redundancy, but the common panel creates a first-order path to the top event. FTA makes explicit what a diagram showing \u201ctwo sources\u201d may hide.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The same reasoning applies to networks with two switches connected through a single fiber route, redundant pumps with a common suction line, or duplicated controllers running the same incorrect configuration. Engineering needs to evaluate independence of <strong>function<\/strong>, not merely the number of devices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This principle is central to <a href=\"\/conteudo\/artigos-tecnicos\/reliability-by-design-projetar-sistemas-confiabilidade-manutenibilidade\/\">Reliability by Design<\/a>, especially in architectures that depend on fault tolerance.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Normal Condition, Maintenance, and Degraded States<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A tree represents a defined state. A system may meet the redundancy criterion during normal operation and lose that characteristic during maintenance, testing, or contingency.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Critical systems may therefore require specific trees or scenarios for conditions such as:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>State<\/td><td>Engineering question<\/td><\/tr><tr><td>Normal operation<\/td><td>which combinations lead to loss of function with all paths available?<\/td><\/tr><tr><td>One path under maintenance<\/td><td>which additional events become sufficient to produce the top event?<\/td><\/tr><tr><td>Degraded operation<\/td><td>which barriers remain effective?<\/td><\/tr><tr><td>Startup or transfer<\/td><td>are there specific sequence, control, or synchronization failures?<\/td><\/tr><tr><td>Manual mode<\/td><td>does human intervention introduce new failure paths?<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This approach avoids assessing availability only in the nominal configuration. In mission-critical facilities, concurrent maintenance and state transitions can be as important as the static architecture.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">FTA, FMEA, RCA, and RAM: Which Technique Answers Which Question?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The techniques are complementary and should be selected according to the question being answered.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Technique<\/td><td>Direction \/ focus<\/td><td>Typical question<\/td><\/tr><tr><td>FTA<\/td><td>deductive, top-down<\/td><td>which combinations can produce this top event?<\/td><\/tr><tr><td>FMEA<\/td><td>inductive, bottom-up<\/td><td>what happens when this failure mode occurs?<\/td><\/tr><tr><td>RCA<\/td><td>investigative<\/td><td>why did this occurrence happen and how can recurrence be prevented?<\/td><\/tr><tr><td>RAM<\/td><td>system performance<\/td><td>what reliability, availability, and maintainability does the architecture deliver?<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">An <a href=\"\/conteudo\/artigos-tecnicos\/fmea-engenharia-modos-efeitos-causas-falha\/\">FMEA<\/a> can provide failure modes relevant to the tree. A <a href=\"\/conteudo\/artigos-tecnicos\/analise-causa-raiz-rca-metodologia-tecnicas-falhas-engenharia\/\">Root Cause Analysis<\/a> may use similar logic to test hypotheses after an occurrence, but it does not automatically become a formal FTA. A <a href=\"\/conteudo\/artigos-tecnicos\/analise-ram-reliability-availability-maintainability-engenharia\/\">RAM Analysis<\/a> may use failure and repair models to evaluate overall architecture performance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Separating these responsibilities prevents producing several different analyses with the same content and different names.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">FTA in Design, Design Review, and Maintenance<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">FTA can be applied before a failure occurs. In design and Design Review, the technique helps verify single points, common dependencies, protection coverage, and behavior in degraded states. An architecture change can then be compared by the reduction or elimination of critical paths.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During operation, the tree can also support the definition of tests and maintenance strategies. If a protective function remains hidden until demanded, FTA can highlight the importance of functional testing. If certain basic events dominate the cut sets, condition monitoring, spare parts, or frequency review may be more effective than indiscriminately increasing preventive maintenance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When the analysis indicates a need for structured strategy review, the natural interface is with <a href=\"\/servicos\/operacao\/engenharia-de-confiabilidade-e-disponibilidade\/\">Reliability and Availability Engineering<\/a>, <a href=\"\/servicos\/servicos-transversais\/gerenciamento-de-riscos-de-engenharia\/\">Engineering Risk Management<\/a>, and <a href=\"\/servicos\/planejamento\/revisao-validacao-tecnica-projetos-design-review\/\">Design Review<\/a>, depending on the lifecycle phase.<\/p>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\"><strong>FTA does not need to end with the diagram.<\/strong> When integrated with technical governance, it can support design decisions, independent review, risk prioritization, redundancy requirements, and acceptance criteria.<\/p>\n\n\n<p class=\"wp-block-paragraph\"><a href=\"\/servicos\/contratacao-integrada\/engenharia-do-proprietario\/\"><strong>Explore A3A Owner\u2019s Engineering \u2192<\/strong><\/a><\/p>\n<\/div>\n\n\n\n\n<h2 class=\"wp-block-heading\">FTA as an Instrument for Governance, Assurance, and Engineering Decisions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">FTA creates greater value when it stops being treated as an isolated diagram and becomes part of the engineering decision system. Brazilian reliability and maintainability terminology itself associates reliability management with planned activities, control, auditing, supervision, and design review. In this context, a fault tree can serve as technical evidence to justify requirements, verify architectures, prioritize risks, and support decisions across different lifecycle phases.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In organizations with structured technical governance, the model can be incorporated into <a href=\"\/servicos\/operacao\/engenharia-de-confiabilidade-e-disponibilidade\/\">Reliability and Availability Engineering<\/a>, <a href=\"\/servicos\/servicos-transversais\/gerenciamento-de-riscos-de-engenharia\/\">Engineering Risk Management<\/a>, <a href=\"\/servicos\/planejamento\/revisao-validacao-tecnica-projetos-design-review\/\">Design Review<\/a>, and <a href=\"\/servicos\/contratacao-integrada\/engenharia-do-proprietario\/\">Owner\u2019s Engineering<\/a> processes. Each discipline uses the analysis for a different purpose, but all depend on requirements, decision criteria, and traceability.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Phase<\/td><td>FTA use<\/td><td>Decision supported<\/td><\/tr><tr><td>Concept \/ FEED<\/td><td>compare architectures, redundancies, and single points<\/td><td>alternative selection and reliability requirements<\/td><\/tr><tr><td>Design<\/td><td>verify interfaces, protections, and common causes<\/td><td>redesign, segregation, instrumentation, and test criteria<\/td><\/tr><tr><td>Procurement<\/td><td>translate risks into verifiable requirements<\/td><td>specifications, guarantees, FAT\/SAT, and responsibilities<\/td><\/tr><tr><td>Implementation<\/td><td>validate whether barriers and redundancies were materialized<\/td><td>acceptance, punch list, integrated testing, and corrections<\/td><\/tr><tr><td>Operation<\/td><td>reassess scenarios with field data and degraded states<\/td><td>maintenance, monitoring, spares, and contingency<\/td><\/tr><tr><td>Change \/ retrofit<\/td><td>compare risk before and after modification<\/td><td>change approval and residual risk<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This integration turns FTA into part of <a href=\"\/conteudo\/artigos-tecnicos\/project-assurance-engenharia-revisao-independente-governanca\/\">Project Assurance<\/a>: the analysis is not used merely to \u201cshow risk,\u201d but to verify whether the proposed solution meets requirements and whether decisions have a sufficient technical basis. In critical projects, an <a href=\"\/servicos\/levantamento-e-diagnostico\/auditoria-tecnica\/\">Engineering Technical Audit<\/a> can use existing trees, assumptions, test records, and field evidence to assess consistency among design, installed condition, and performance.<\/p>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\"><strong>A fault tree used for decision-making needs to be controlled as engineering information.<\/strong> Assumptions, versions, owners, data sources, and review criteria should remain traceable throughout system changes.<\/p>\n\n\n<p class=\"wp-block-paragraph\"><a href=\"\/solucoes\/gestao-e-governanca-de-engenharia\/gestao-requisitos-evidencias-criterios-aceite\/\"><strong>Explore Requirements, Evidence, and Acceptance Criteria Management \u2192<\/strong><\/a><\/p>\n<\/div>\n\n\n\n\n<h2 class=\"wp-block-heading\">Model Governance: Owners, Assumptions, Versions, and Changes<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An FTA used for decision-making needs to be governed as engineering information. There should be a model owner, a clear definition of the top event, control of assumptions, identification of data sources, versioning, and review criteria. Without this, two teams may analyze the same system using different boundaries and hypotheses and produce results that appear comparable but are not.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This need connects the analysis with <a href=\"\/solucoes\/gestao-e-governanca-de-engenharia\/governanca-documental-sistema-gestao-documentos\/\">Document Governance<\/a>, <a href=\"\/solucoes\/gestao-e-governanca-de-engenharia\/gestao-requisitos-evidencias-criterios-aceite\/\">Requirements, Evidence, and Acceptance Criteria Management<\/a>, and <a href=\"\/solucoes\/gestao-e-governanca-de-engenharia\/gestao-processos-workflows-aprovacoes-tecnicas\/\">Process, Workflow, and Technical Approval Management<\/a>. The model can have drafting, independent review, approval, and obsolescence states, just like other engineering documents that support critical decisions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Changes also need to trigger reassessment. Changing firmware, control logic, auxiliary power, network topology, physical route, protection configuration, maintenance strategy, or supplier can modify dependencies represented in the tree. <a href=\"\/solucoes\/gestao-e-governanca-de-engenharia\/gestao-pendencias-rfis-nao-conformidades\/\">Pending Items, RFIs, and Nonconformity Management<\/a> helps keep identified deviations visible, while formal approval processes prevent a modification from invalidating reliability assumptions without anyone noticing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During the transition from implementation to operation, the tree should be reconciled with the condition actually built. <a href=\"\/servicos\/implementacao\/comissionamento\/\">Engineering Commissioning<\/a>, <a href=\"\/servicos\/implementacao\/as-built-documentacao-tecnica-encerramento\/\">As-Built<\/a>, <a href=\"\/servicos\/implementacao\/recebimento-tecnico-obras-servicos-engenharia\/\">Technical Acceptance<\/a>, and <a href=\"\/servicos\/operacao\/recomissionamento-sistemas-instalacoes\/\">Recommissioning<\/a> are natural points for confirming whether the redundancies, protections, and interfaces represented in the model exist and work as intended.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">FTA Integrated with Asset Management and Maintenance Engineering<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In asset management, the objective is not to eliminate every possibility of failure, but to decide where to apply resources to create value considering performance, risk, cost, and lifecycle horizon. FTA contributes to this decision by showing which events and combinations dominate a given scenario. This result can feed <a href=\"\/servicos\/operacao\/engenharia-de-manutencao\/\">Maintenance Engineering<\/a>, <a href=\"\/servicos\/operacao\/gestao-de-ativos-de-engenharia\/\">Engineering Asset Management<\/a>, and reliability plans.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If a first-order basic event is associated with a nonredundant component, the response may be redesign. If the risk results from a latent failure in a protection function, the response may be periodic testing. If the main contribution comes from a common environmental cause, the solution may be segregation or monitoring. If unavailability depends on long logistical delays, the decision may involve spare parts, a support contract, or a repair strategy. The same tree can therefore guide design, maintenance, supply, and operation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This perspective is especially important for critical assets and systems, where an analysis performed only by equipment may miss functional dependencies. Content on the <a href=\"\/conteudo\/artigos-tecnicos\/plano-gestao-ativos-samp-amp-objetivos-riscos-roadmap\/\">Asset Management Plan<\/a>, <a href=\"\/conteudo\/artigos-tecnicos\/engenharia-manutencao-planejamento-confiabilidade-backlog-desempenho\/\">Maintenance Engineering<\/a>, and <a href=\"\/conteudo\/artigos-tecnicos\/analise-ram-reliability-availability-maintability-engenharia\/\">RAM Analysis<\/a> complements FTA by connecting the failure scenario to objectives, performance, and lifecycle.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Cross-Disciplinary Applications in Critical Infrastructure<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The technique is cross-disciplinary because functional reasoning is independent of discipline. In a substation, the top event may be loss of remote assistance, protection unavailability, or loss of auxiliary power. In a Data Center, it may be loss of power to a critical load or thermal unavailability. In electronic security, it may be loss of coverage in an area or inability to record. In telecommunications, it may be loss of connectivity between critical points.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This cross-disciplinary nature appears in solutions such as <a href=\"\/solucoes\/engenharia-de-automacao-industrial\/teleassistencia-monitoramento-operativo-subestacoes\/\">Remote Assistance and Operational Monitoring in Substations<\/a>, <a href=\"\/solucoes\/gestao-e-governanca-de-engenharia\/engenharia-integrada-para-data-centers\/\">Integrated Engineering for Data Centers<\/a>, <a href=\"\/solucoes\/engenharia-eletrica\/instalacoes-eletricas-de-media-tensao-mt\/\">Medium-Voltage Electrical Installations<\/a>, and integrated security systems, where availability depends on multiple technical interfaces.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In A3A&#8217;s published projects, this type of complexity can be observed in different contexts. The <a href=\"\/projetos\/projeto-de-monitoramento-operativo-para-suporte-a-teleassistencia-em-subestacao-londrina-parana\/\">operational monitoring project supporting remote assistance at a transmission substation<\/a> combines remote operation, networks, and monitoring systems; turnkey monitoring projects in <a href=\"\/projetos\/projeto-turnkey-de-sistema-de-monitoramento-patrimonial-perimetral-em-subestacao-de-transmissao-de-energia-londrina-parana\/\">Londrina<\/a>, <a href=\"\/projetos\/projeto-turnkey-epc-de-sistema-de-monitoramento-patrimonial-em-subestacao-de-transmissao-de-energia-umuarama-parana\/\">Umuarama<\/a>, and <a href=\"\/projetos\/projeto-turnkey-epc-de-sistema-de-monitoramento-patrimonial-em-subestacao-de-transmissao-de-energia-guaira-parana\/\">Gua\u00edra<\/a> show distributed architectures in transmission environments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In another typology, the <a href=\"\/projetos\/front-end-engineering-design-para-sistema-de-vigilancia-eletronica-em-usina-hidreletrica-braunas-minas-gerais\/\">FEED for an electronic surveillance system at a hydroelectric plant<\/a> and the <a href=\"\/projetos\/front-end-engineering-design-para-sistema-de-telecomunicacoes-em-usina-hidreletrica-braunas-minas-gerais\/\">telecommunications FEED for the same facility<\/a> demonstrate the need to analyze interfaces from the definition stages. The <a href=\"\/projetos\/implantacao-turnkey-de-sistema-integrado-de-videomonitoramento-inteligente-em-complexo-governamental-brasilia-distrito-federal\/\">turnkey implementation of an integrated system at a government complex<\/a> demonstrates application in an environment with multiple subsystems, infrastructure, networks, and operations.<\/p>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\"><strong>When potential failure affects continuity, safety, or performance, the analysis needs to move from the conceptual field into an engineering decision.<\/strong> FTA can be combined with RAM, FMEA\/FMECA, criticality, field data, and architecture review to form a technically defensible reliability study.<\/p>\n\n\n<p class=\"wp-block-paragraph\"><a href=\"\/servicos\/operacao\/engenharia-de-confiabilidade-e-disponibilidade\/\"><strong>Explore Reliability and Availability Engineering \u2192<\/strong><\/a><\/p>\n<\/div>\n\n\n\n\n<h2 class=\"wp-block-heading\">How a Reliability Analysis Can Be Contracted<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An FTA engagement does not need to be limited to delivery of a tree. In an engineering consulting approach, the work may include requirements gathering, boundary definition, technical workshops, modeling, cut-set analysis, quantification where applicable, independent review, recommendations, an action matrix, and integration with risk and change registers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Depending on the asset stage, this scope may be developed as <a href=\"\/servicos\/servicos-transversais\/consultoria-tecnica\/\">Engineering Technical Consulting<\/a>, within a <a href=\"\/servicos\/planejamento\/revisao-validacao-tecnica-projetos-design-review\/\">Design Review<\/a>, in support of <a href=\"\/servicos\/contratacao-integrada\/engenharia-do-proprietario\/\">Owner\u2019s Engineering<\/a>, or under <a href=\"\/servicos\/contratacao-integrada\/servicos-continuados-de-engenharia-consultiva\/\">Ongoing Engineering Consulting Services<\/a>. The differentiator is converting the analysis into a traceable decision and following whether the recommended actions actually changed the risk.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Data, Assumptions, and Tree Validation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A quantitative FTA needs to record the origin and applicability of its data. Internal history, manufacturer data, reliability databases, tests, and statistical analyses can be used, but no source eliminates the need to verify operating regime, population, and time unit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Assumptions such as independence, mission time, initial state, repair policy, protection coverage, and resource availability need to remain visible. Without them, the calculated number is not reproducible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Technical review should verify whether the top event remains correctly defined, whether the boundary is coherent, whether repeated events have been treated as the same event, whether common causes are represented, and whether the cut sets make physical sense. Design, configuration, or operational changes can invalidate an old tree even when its mathematical logic remains correct.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Common errors include assuming independence without justification, mixing failure rate with probability, ignoring maintenance conditions, decomposing irrelevant events, and accepting software numerical output without engineering review.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">FTA is complete when its logic and assumptions make it possible to answer the original question and guide a decision. The objective is not to produce the largest possible tree, but to reveal in a traceable way <strong>how the top event can occur, which paths dominate risk, and which changes actually alter that result<\/strong>.<\/p>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Technical references<\/summary>\n<p class=\"wp-block-paragraph\">[1] IEC. <a href=\"https:\/\/webstore.iec.ch\/en\/publication\/4311\">IEC 61025:2006 \u2014 Fault tree analysis (FTA)<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[2] IEC. <a href=\"https:\/\/webstore.iec.ch\/en\/publication\/59809\">IEC 31010:2019 \u2014 Risk management \u2014 Risk assessment techniques<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[3] ABNT. <a href=\"https:\/\/www.abntcatalogo.com.br\/\">ABNT NBR 5462:1994 \u2014 Reliability and maintainability \u2014 Terminology<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[4] ISO. <a href=\"https:\/\/www.iso.org\/standard\/83053.html\">ISO 55000:2024 \u2014 Asset management \u2014 Vocabulary, overview and principles<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[5] ISO. <a href=\"https:\/\/www.iso.org\/standard\/83054.html\">ISO 55001:2024 \u2014 Asset management \u2014 Asset management system \u2014 Requirements<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[6] ISO. <a href=\"https:\/\/www.iso.org\/standard\/63578.html\">ISO 21505:2017 \u2014 Project, programme and portfolio management \u2014 Guidance on governance<\/a>.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Frequently asked questions<\/summary>\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-o-que-fta-7bfd412e\"><strong class=\"schema-faq-question\">What is FTA?<\/strong> <p class=\"schema-faq-answer\">FTA, or Fault Tree Analysis, is a deductive technique that starts from an undesired top event and logically decomposes the combinations of events capable of producing it.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-qual-a-diferen-a-entre-fta-e-fmea-7488bd94\"><strong class=\"schema-faq-question\">What is the difference between FTA and FMEA?<\/strong> <p class=\"schema-faq-answer\">FTA is top-down: it starts from an undesired event and searches for its causal combinations. FMEA is bottom-up: it starts from failure modes and analyzes their effects.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-o-que-significa-uma-porta-and-na-fta-3f8315d0\"><strong class=\"schema-faq-question\">What does an AND gate mean in FTA?<\/strong> <p class=\"schema-faq-answer\">An AND gate indicates that all inputs must occur to produce the output. For independent events, the joint probability can be calculated as the product of the probabilities.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-o-que-significa-uma-porta-or-na-fta-a4e62ec9\"><strong class=\"schema-faq-question\">What does an OR gate mean in FTA?<\/strong> <p class=\"schema-faq-answer\">An OR gate indicates that any one input is sufficient to produce the output. The union probability must account for overlap between events.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-o-que-minimal-cut-set-5d07fd65\"><strong class=\"schema-faq-question\">What is a minimal cut set?<\/strong> <p class=\"schema-faq-answer\">It is a minimal set of basic events whose joint occurrence is sufficient to produce the top event. If any event is removed, that combination is no longer sufficient.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-fta-precisa-ser-quantitativa-af45d910\"><strong class=\"schema-faq-question\">Does FTA need to be quantitative?<\/strong> <p class=\"schema-faq-answer\">No. Qualitative analysis can already reveal single points of failure, dependencies, common causes, and critical paths. Quantification should be used when data and assumptions are appropriate.<\/p><\/div><\/div>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Related technical materials<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Related engineering services<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"\/servicos\/operacao\/engenharia-de-confiabilidade-e-disponibilidade\/\">Reliability and Availability Engineering<\/a><\/li><li><a href=\"\/servicos\/servicos-transversais\/gerenciamento-de-riscos-de-engenharia\/\">Engineering Risk Management<\/a><\/li><li><a href=\"\/servicos\/planejamento\/revisao-validacao-tecnica-projetos-design-review\/\">Design Review in Engineering Projects<\/a><\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Related technical content<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"\/conteudo\/artigos-tecnicos\/fmea-engenharia-modos-efeitos-causas-falha\/\">FMEA in Engineering: How to Analyze Failure Modes, Effects, and Causes<\/a><\/li><li><a href=\"\/conteudo\/artigos-tecnicos\/analise-causa-raiz-rca-metodologia-tecnicas-falhas-engenharia\/\">Root Cause Analysis \u2014 RCA<\/a><\/li><li><a href=\"\/conteudo\/artigos-tecnicos\/analise-ram-reliability-availability-maintainability-engenharia\/\">RAM Analysis: Reliability, Availability, and Maintainability<\/a><\/li><li><a href=\"\/conteudo\/artigos-tecnicos\/reliability-by-design-projetar-sistemas-confiabilidade-manutenibilidade\/\">Reliability by Design: How to Design Systems for Reliability and Maintainability<\/a><\/li><li><a href=\"\/conteudo\/artigos-tecnicos\/analise-criticidade-ativos-criterios-matriz-priorizacao\/\">Asset Criticality Analysis<\/a><\/li><li><a href=\"\/conteudo\/artigos-tecnicos\/engenharia-confiabilidade-metodos-indicadores-aplicacoes\/\">Reliability Engineering: Methods, Metrics, and Applications<\/a><\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Guides and references<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"\/conteudo\/guias-tecnicos\/gestao-de-engenharia-processos-governanca-projetos-desempenho\/\">Engineering Management: Processes, Governance, Projects, and Performance<\/a><\/li><li><a href=\"\/conteudo\/whitepapers\/data-center-resiliente-framework-avaliacao-modernizacao-aceite\/\">Resilient Data Center: Assessment, Design, Modernization, and Acceptance<\/a><\/li><\/ul>\n<\/details>\n","protected":false},"excerpt":{"rendered":"<p>Fault Tree Analysis applied to engineering: top event, AND\/OR gates, minimal cut sets, common-cause failures, probabilities, and reliability decisions.<\/p>\n","protected":false},"author":1,"featured_media":78884,"parent":0,"template":"","meta":{"_a3a_global_related_solutions":[],"_a3a_global_related_services":[],"_a3a_global_related_materials":[],"_a3a_post_lang":"en-us","_a3a_translation_group_id":"be2018a2-d859-480b-a74d-a000c16e4e34","_a3a_i18n_canonical_slug":"fault-tree-analysis-fta-method-logic-gates-calculation-application","_a3a_prod_post_id":"","_a3a_lang_url_en-us":"","_a3a_lang_url_es-es":""},"categories":[],"segments":[],"mercados":[],"etapas":[],"class_list":["post-81035","articles","type-articles","status-publish","has-post-thumbnail","hentry"],"_links":{"self":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/81035","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles"}],"about":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/types\/articles"}],"author":[{"embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/81035\/revisions"}],"predecessor-version":[{"id":81036,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/81035\/revisions\/81036"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/media\/78884"}],"wp:attachment":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/media?parent=81035"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/categories?post=81035"},{"taxonomy":"segments","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/segments?post=81035"},{"taxonomy":"mercados","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/mercados?post=81035"},{"taxonomy":"etapas","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/etapas?post=81035"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}