Fault Tree Analysis

Fault tree analysis software, built for aircraft certification

Construct, quantify and trace fault trees for every failure condition, and keep them connected to the FHA, FMEA and requirements they depend on.

Fault Tree Analysis (FTA) is the quantitative backbone of an aircraft safety assessment. For each failure condition identified in the Functional Hazard Assessment, you build a top-down logic model of how component, system and environmental failures combine to cause it, then quantify the probability and compare it against the certification target for that severity.

Safety Lab Aero gives you a full FTA environment that does not stop at drawing the tree. Every tree links to its failure condition, carries the certification-basis target, and stays connected to the FMEA evidence, component library and requirements underneath it.

Build the tree

Quantify it rigorously

Safety Lab Aero computes the top-event probability directly, not just a minimal-cut-set upper-bound approximation. That matters whenever a basic event repeats across cutsets or when common-cause coupling is present: the cases where the simple upper bound quietly over- or under-states the result.

Set basic-event data the way your evidence actually exists

A basic event can take its rate from a direct failure rate, an MTBF, a fixed probability, a component-library entry (with environment, quality and temperature factors applied), or a Markov model for repairable, multi-state items. Repeated logical events are treated as one physical event so the quantification does not double-count them.

Allocate DAL top-down

Development Assurance Levels flow from the failure-condition severity down through the tree, honoring gate logic, with support for the ARP 4754B allocation options on AND gates. See ARP 4754B & DAL allocation for how that fits the development-assurance flow.

Frequently asked questions

What is fault tree analysis?

Fault tree analysis (FTA) is a top-down method that starts from an undesired event, such as a failure condition from the functional hazard assessment, and works out which combinations of lower-level failures can cause it. The logic is drawn as gates (AND, OR and others) over basic events. Once the tree is built, it is quantified with failure rates and exposure times to give the probability of the top event, which is then compared against the certification target for that failure condition.

What is a basic event in a fault tree?

A basic event is a leaf of the tree: a failure that is not broken down any further, such as the failure of a component, a human action, or an environmental condition. Each basic event carries a failure rate (or a fixed probability) and an exposure time, and those numbers, combined through the gates above it, produce the probability of the top event. In Safety Lab Aero, basic-event rates can come from piece-part FMEA rows or the component library.

What is a dynamic fault tree?

A dynamic fault tree adds gates whose outcome depends on the order or timing of failures, not just on which failures occur. The common dynamic gates are PAND (priority AND, where inputs must fail in sequence), SPARE (a spare takes over when the primary fails), and FDEP (a trigger event forces its dependent events to fail). Static gates cannot express these behaviors, so dynamic trees are quantified by simulation rather than by cut sets. Safety Lab Aero supports PAND, SPARE and FDEP with a Monte Carlo simulator.

Does Safety Lab Aero compute exact top-event probability or just the cut-set upper bound?

It computes the top-event probability directly and shows the minimal-cut-set upper bound alongside it for reference. The direct result is what you need when basic events repeat across cutsets or when common-cause coupling is present, where the upper bound is no longer a good approximation.

Can it handle dynamic fault trees?

Yes. PAND, SPARE and FDEP gates are supported, with a Monte Carlo simulator that samples failure times and honors time-ordered semantics for dynamic behavior.

Does the fault tree connect to FMEA and requirements?

Yes. Piece-part FMEA modes feed basic-event rates, the component library sources failure data, and safety requirements derive from the tree: all kept in one connected model so a change in one place flags what it affects elsewhere.

See it on your own analysis

Safety Lab Aero keeps functions, hazards, fault trees, FMEA, common-cause, requirements and verification in one connected model, from FHA to a certification-ready evidence package.

Start free trial