10.1 The consequence of a failure mode on the
operation, function, or status of an equipment or a system is called
a 'failure effect'. Failure effects on a specific sub-system or equipment
under consideration are called “local failure effects". The
evaluation of local failure effects will help to determine the effectiveness
of any redundant equipment or corrective action at that system level.
In certain instances, there may not be a local effect beyond the failure
mode itself.
10.2 The impact of an equipment or sub-system
failure on the system output (system function) is called an "end effect".
End effects shall be evaluated and their severity classified in accordance
with the following categories:
-
.1 catastrophic;
-
.2 hazardous;
-
.3 major; and
-
.4 minor.
The definitions of these four categories of failure effects
are given in 2.3 of annex 3 of this
Code.
10.3 If the end effect of a failure is classified
as hazardous or catastrophic, back-up equipment is usually required
to prevent or minimize such effect. For hazardous failure effects
corrective operational procedures may be accepted.