Skip to content

Arc Skills / Safety

Perform a functional hazard assessment

This task examines what an aircraft or system function can do wrong in its operational context. Arc Skills produces a functional hazard assessment excerpt with separate conditions, effects and assumptions for safety review.

Use this skill

Use Arc Skills to perform an FHA for the named function and operating phases. Start from loss, misleading output, untimely behavior and inadvertent activation before considering component causes.

Inputs:
- Function list and phase definitions.
- Crew alerts, procedures and operating assumptions.
- Project-approved severity criteria and source revision.

Return failure-condition rows with effects, compensating action, evidence gap and follow-on analysis. Propose severity only where the supplied criteria and operational facts support it; do not infer FDAL or item levels.

Set up the toolkit · Read the skill instructions

What you provide and what you get

Inputs and outputs
What you haveHow it is usedWhat you get
Functions and phasesDefines assessment unitFailure-condition list
Crew/alert contextTests whether effects differ by responseAssumption record
Severity criteriaSupports controlled classification when availableDecision request

Blank and misleading cabin-pressure indications diverge

Illustrative engineering example.

A synthetic aircraft function displays cabin pressure during climb. A blank screen is obvious to the crew, while a plausible but wrong pressure value may delay recognition. Alert timing and crew procedure are not supplied.

Function-centered FHA excerpt
Failure conditionPossible operational effectCompensation evidenceOpen assessment
Display blank during climbCrew loses direct pressure indicationBlank state is visibly apparentCheck independent alert and crew procedure
Plausible wrong pressure during climbCrew may trust inaccurate value and delay responseNo mismatch alert or detection time suppliedAssess alert latency and operational effect
Display updates lateCrew sees stale trend near phase changeSampling/latency requirement absentDefine acceptable timing from system need

All three conditions come from one function, but they have different recognition and response paths. Treating “display failure” as one row would hide the difference between obvious loss and misleading information.

The table does not classify severity because the controlled category definitions, alert design and crew response evidence are absent. It also does not translate any later severity into FDAL, IDAL or software level. The safety authority can use these rows to request operational analysis and confirm which conditions need deeper system assessment.

Examine failure behavior in each phase

  1. State the function from the operator or aircraft perspective and fix the phase.
  2. Separate no output, wrong plausible output, late output and inadvertent output.
  3. Record effect, exposure, alerts and crew compensation as evidence or assumptions.
  4. Apply the project severity scheme only after the relevant operational facts are available.

Questions about this task

Why separate blank from misleading indication?

A blank display may be recognized quickly, while plausible wrong information can be acted on. Their consequences depend on alerts and procedures.

Can this FHA assign software level?

No. The FHA describes function failure conditions; development-assurance allocation is a later, distinct controlled decision.

Sources and further reading

  • FAA AC 25.1309-1A: Official system-safety guidance describing functional hazard assessment as a preliminary, function-centered analysis.
  • FAA AC 20-174: Official recognition of ARP4754A as an acceptable civil-aircraft development process.