Automation Glossary • Fault Tree Analysis (FTA)

What Is Fault Tree Analysis (FTA)?

Merobix Engineering • • 6 min read

Fault tree analysis starts from the outcome you never want to see and works backward to find every way it could happen. Instead of building up from components, it begins with a single undesired top event - a fire, a vessel overpressure, a total loss of a safety function - and traces downward through logic gates to the combinations of failures that could cause it. This guide explains how a fault tree is structured, what its AND and OR gates mean, and why it is the deductive complement to bottom-up FMEA.

Back to Blog

Fault Tree Analysis (FTA) in one line: Fault tree analysis (FTA) is a top-down, deductive reliability method that begins with a defined undesired top event and works downward through Boolean logic gates - primarily AND and OR - to identify the combinations of lower-level faults that can cause it. The result reveals the root causes and minimal cut sets, the smallest sets of failures that together produce the top event, and can be used to calculate the probability of that event.

Top-Down Logic and the Gates

A fault tree is built downward from a single top event, which is the specific undesired outcome under investigation - it must be defined precisely, because the whole tree is an exploration of how that one outcome arises. Below the top event, the analysis asks what immediate faults could cause it, and connects them with logic gates that capture how those faults combine. The tree grows downward, each level decomposing a fault into its own contributing faults, until it reaches basic events that need no further breakdown.

The two fundamental gates encode the logic of causation. An OR gate means the output fault occurs if any one of its input faults occurs - the inputs are independent ways to reach the same result, so any single one is sufficient. An AND gate means the output fault occurs only if all its input faults occur together - the inputs must coincide, which is how the tree represents protective redundancy, since a redundant system fails only when both the primary and its backup fail at once.

This gate structure is what gives FTA its analytical power. An AND gate high in the tree tells you that several things must go wrong simultaneously for the top event to happen, which usually indicates a robust design; a top event reachable through a chain of OR gates from a single basic fault indicates a vulnerability, because one failure alone is enough. Reading the tree's gates is therefore a direct way to see where a system is protected and where it is exposed.

Minimal Cut Sets and Probability

Once a fault tree is built, its most useful output is the set of minimal cut sets. A cut set is any combination of basic events that, if they all occur, causes the top event; a minimal cut set is one from which you cannot remove any event without breaking its ability to cause the top event. The minimal cut sets are essentially the complete list of the distinct ways the undesired event can happen, expressed as the smallest sufficient combinations of failures.

The size of the minimal cut sets is immediately informative. A minimal cut set of one - a single basic event that alone causes the top event - is a single point of failure and usually the first thing to design out. Larger cut sets require more failures to coincide and so represent more resilient paths. Ranking the cut sets by size and by the likelihood of their events points directly at the weakest links in the system.

When failure probabilities are available for the basic events, the fault tree can be quantified, propagating those probabilities up through the gates to estimate the probability of the top event itself. OR gates roughly add the contributing probabilities while AND gates multiply them, which is why AND-gated redundancy drives the top-event probability down so sharply. This quantitative capability is why FTA is a mainstay of formal safety and risk assessments, where a numerical likelihood of a hazardous event is required rather than just a qualitative picture.

FTA Versus FMEA and Its Role Alongside SCADA

Fault tree analysis and FMEA approach reliability from opposite directions and are often used together. FMEA is bottom-up and inductive: it starts at the component level and asks what happens if this part fails, cataloging effects upward. FTA is top-down and deductive: it starts from an undesired outcome and asks what could cause it, tracing downward. FMEA excels at exhaustively cataloging single-point failures, while FTA excels at capturing how combinations of failures - which FMEA handles poorly - together produce a specific hazard.

Because FTA can represent AND-gated combinations, it is the natural tool for analyzing systems built around redundancy and layered protection, which is exactly what safety instrumented systems and other protective functions in oil and gas rely on. It answers the question that matters for those systems: what would it take for all the protections to fail at once, and how likely is that. This makes FTA a standard part of the risk assessments behind safety integrity level decisions.

The link to field monitoring is that a fault tree names precisely which basic events lead to a hazardous top event, and many of those basic events are conditions a SCADA platform can watch. If a fault tree shows that a particular pressure exceedance combined with a failed relief path leads to the top event, monitoring that pressure and the health of the relief path gives early sight of two of the tree's basic events. Merobix historizes and alarms on such field conditions, so the individual faults a fault tree identifies as contributing to a serious event can be observed as they develop rather than discovered only after the combination has occurred.

Frequently Asked Questions

What is the difference between fault tree analysis and FMEA?

FTA is top-down and deductive - it starts from an undesired top event and traces downward through logic gates to the combinations of faults that cause it. FMEA is bottom-up and inductive - it starts at the component level and works upward through the effects of each failure. FTA captures combinations of failures well, while FMEA excels at cataloging single-point failures, so the two are often used together.

What is a minimal cut set in fault tree analysis?

A minimal cut set is the smallest combination of basic events that, occurring together, causes the top event - one from which no event can be removed without breaking its ability to cause that event. The minimal cut sets are the distinct ways the undesired event can happen. A cut set of size one is a single point of failure and usually the highest priority to eliminate.

What do the AND and OR gates mean in a fault tree?

An OR gate means the output fault occurs if any one of its inputs occurs, so any single input is sufficient - this represents independent ways to reach the same failure. An AND gate means the output occurs only if all inputs occur together, which represents redundancy, since a protected function fails only when the primary and its backup both fail at the same time.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
EPA Subpart W (GHG Reporting)  •  Methane Slip  •  Flare Combustion Efficiency  •  Destruction and Removal Efficiency (DRE)  •  Continuous Parametric Monitoring (CPMS)  •  Opacity Monitoring  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →