Concept

Hidden failures, inspection & PFD

Not every failure announces itself. On redundant and protective equipment, a unit can fail silently and sit there failed — degrading your redundancy — until a proof test or an actual demand reveals it. Modelling that is the difference between an optimistic availability number and a realistic one.

The short answer

A revealed failure is detected the instant it happens — an alarm trips, output is lost — so repair starts immediately. A hidden (dormant, unrevealed) failure is silent: the system keeps running on its healthy units, nobody knows, and no repair starts. It is discovered only by a periodic inspection / proof test — or, in a redundant group, by a demand when the redundancy is finally needed.

Hidden failures are the dominant risk for standby and protective systems, and the reason proof-test intervals are a primary design lever. Ignore them and you over-state availability; model them and you see how silently redundancy erodes between tests.

Revealed vs hidden failures

The default assumption in most quick studies is that every failure is self-announcing. That is fine for the running, load-bearing equipment whose loss you would notice at once. It is wrong for anything whose job is to sit and wait: a standby pump, a backup generator, a trip relay, a relief valve. Those fail dormant — the failure has no outward symptom until you call on the item.

Why redundancy makes it matter

Consider two pumps in 1-of-2 redundancy. If pump A fails hidden, the system stays up on pump B — and nobody knows A is dead. Your “redundant” system is now a single pump, one failure from an outage, with no warning. The hidden failure has silently eroded the redundancy.

This is why a hidden failure with no redundancy is actually less dangerous to model — losing the only unit is noticed immediately (the function is lost). It is precisely the redundant and protective cases where “hidden” changes the answer.

Inspection & proof tests

A hidden failure stays undetected until a periodic inspection (proof test) at interval τ finds it and starts the repair. Because the failure can happen any time between two tests, the average time spent failed-but-undetected is about τ/2. Shorter test intervals mean less undetected time — at the cost of more testing.

Inspection is distinct from preventive maintenance: PM restores/renews equipment on a schedule; inspection detects hidden failures and initiates the normal repair. You can have either, both, or neither.

Demand-based revelation

A hidden failure is also revealed the moment the redundancy is actually called upon. In the 1-of-2 example, when pump B fails the group can no longer deliver — that demand exposes A’s hidden failure, and both are now repaired. So a hidden failure surfaces at whichever comes first: the next proof test, or a demand that exhausts the redundancy. Modelling both is what makes the availability of a redundant, infrequently-tested system realistic.

PFD and the τ/2 rule

The standard figure for a hidden, periodically-tested item is its average probability of being failed-undetected — the PFDavg of IEC 61508. For a single item with failure rate λ and test interval τ it is approximately λτ/2 (plus the repair contribution once revealed). Equivalently, the item behaves as an alternating-renewal process whose mean down time gains τ/2 — the mean undetected dwell — on top of the repair time.

QuantityMeaning
Mean time undetectedAverage time a hidden failure sits unnoticed before a proof test reveals it (≈ τ/2 for an exponential failure).
PFDavgTime-average probability the item is sitting failed-undetected — the headline safety/availability figure.

How Ramly models it

Mark a component type — or an individual failure mode — as a hidden failure. Add an inspection plan(per component, or per subsystem block) to reveal it on a proof-test interval. The results report each hidden item’s mean time undetected and PFDavg.

  • Monte Carlo plays it out exactly: hidden failures stay silent, redundancy degrades, and they’re revealed by inspection or on demand when the redundant group is exhausted.
  • Analytical integrates the RBD structure function over the proof-test interval for the exact PFDavg and the PFD(t) curve — including k-of-n voting (1oo2, 2oo3) and a common-cause term — with the result mapped to a SIL band. (For the operating redundancy case, where a hidden failure is found on demand rather than only by test, use Monte Carlo.)
Not sure which solver to use? See Monte Carlo vs Analytical.

Model a hidden failure

Mark a redundant component as hidden, add an inspection plan, and watch the availability — and the PFD — respond to the test interval.