4.1.1 The limits of safe operation, special handling
procedures and any operational restrictions should be examined and
developed as a result of full-scale trials conducted by simulating
possible equipment failures.
4.1.2 The failures to be examined should be those
leading to major or more severe effects as determined from the evaluation
of the SSA in accordance with part C of these Interim Guidelines.
4.1.3 Failures to be examined should be agreed
between the craft manufacturer and the Administration and each single
failure should be examined in a progressive manner.
4.1.4 The failures to be examined should be single
failure events unless a single failure has an immediate and inevitable
secondary effect.
4.1.5 If the manufacturer or Administration believes
that a simulation of any failure or malfunction could endanger the
craft or personnel, the effects of that failure or malfunction may
be deduced by calculation and/or analysis in accordance with part
C of these Interim Guidelines. In the event, the Administration may
require that systems or procedures be introduced or changed to reduce
the risk to a tolerable level or may impose operational limits to
achieve the same result.