Professional Documents
Culture Documents
Faith Chandler
Office of Safety & Mission Assurance
2004 MAPLD/Mishaps Seminar 1 Chandler
Agenda
Payload Canister
2004 MAPLD/Mishaps Seminar 4 Helios Chandler
Purpose of NASA Mishap Investigation
Navigation
• Identify the type of failure. Equipment Failure
Root Cause(s)
• One of multiple factors (events, conditions or organizational factors)
that contributed to or created the proximate cause and subsequent
undesired outcome and, if eliminated, or modified would have
prevented the undesired outcome. Typically multiple root causes
contribute to an undesired outcome.
Organizational factors
• Any operational or management structural entity that exerts control
over the system at any stage in its life cycle, including but not
limited to the system’s concept development, design, fabrication,
test, maintenance, operation, and disposal.
Gather data.
Identify facts surrounding the undesired outcome.
• When did the undesired outcome occur?
• Where did it occur?
• What conditions were present prior to its occurrence?
• What controls or barriers could have prevented its occurrence
but did not?
• What are all the potential causes?
• What actions can prevent recurrence?
• What amelioration occurred? Did it prevent further damage or
injury?
Condition
Exceeded- Undesired
Event Event Failed Barrier Event Outcome
Or Control
Condition
Exceeded- Undesired
Exceeded-
Outcome
Event Event Failed Barrier Event Failed
Or Control Amelioration
Lost High
Speed Data
Satellite Tech. Used Stream
Thrusters Oriented Satellite Failed to
Wrong Method (Mission
Powered Up Space Craft Deploy Antenna To Correct
Failure)
Poor
Line of
Sight
Meteoroid Logic Control Power Supply Arming Relay Firing Relay Sabotage
Impacted Satellite Failed Failed Failed Failed
X Satellite
Power Up
Thrusters Oriented
Space Craft
Poor
Line of Sight
Satellite Failed
To Deploy Antenna
Technician Used Wrong
Method to Correct
Meteoroid Logic Control Power Supply Arming Relay Firing Relay Sabotage
Impacted Satellite Failed Failed Failed Failed
Meteoroid Logic Control Power Supply Arming Relay Firing Relay Sabotage
Impacted Satellite Failed Failed Failed Failed
• Be sure to keep your questions focused on the original issue. For example
“Why was the condition present?”; “Why did the event occur?”; “Why was
the barrier exceeded?” or “Why did the barrier fail?”
Undesired Outcome
WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY
Event #1 Event #1 Event #1 Condition Failed Failed Failed
Condition Condition Event #2 Event #2 Event #2
Occurred Occurred Occurred Existed or Exceeded Exceeded Exceeded
Existed or Existed or Occurred Occurred Occurred Barrier or Barrier or Barrier or
Changed Changed Changed Control Control Control
Undesired Outcome
WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY
WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY
Undesired Outcome
WHY
X
WHY WHY WHY WHY WHY WHY WHY WHY
X
WHY
X
WHY WHY
X
Condition Condition Condition Event #2 Event #2 Event #2 Failed Failed Failed
Event #1 Event #1 Event #1 Existed or Existed or Existed or Occurred Occurred Occurred Exceeded Exceeded Exceeded
Occurred Occurred Occurred Changed Changed Changed Barrier or Barrier or Barrier or
Control Control Control
XX
WHY WHY WHY WHY WHY
XWHY WHY WHY WHY
XX
WHY WHY WHY WHY WHY WHY WHY
XX
WHY WHY WHY
Undesired Outcome
WHY
WHY WHY WHY WHY WHY WHY WHY WHY WHY ROOT CAUSES
2004 MAPLD/Mishaps Seminar 26 Chandler
Root Cause Analysis- Steps
Some people choose to leave contributing factors on the tree to show
all factors that influenced the event.
Contributing factor: An event or condition that may have contributed to
the occurrence of an undesired outcome but, if eliminated or modified,
would not by itself have prevented the occurrence.
If this is done, illustrate them differently (e.g., dotted line boxes and arrows) so
that it is clear that they are not causes.
Undesired Outcome
Contributing
WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY WHY
WHY Factors
WHY WHY WHY
WHY WHY WHY WHY WHY WHY WHY
Power Supply
Failed
Battery Dead
Tells What Failed
Tells Types of Failures
Installed Beyond Shelf
Improperly Limit
Proximate Cause(s) The event(s) that occurred, including any condition(s) that existed immediately before the undesired
outcome, directly resulted in its occurrence and, if eliminated or modified, would have prevented the
undesired outcome. Also known as the direct cause(s).
Root Cause(s) One of multiple factors (events, conditions or organizational factors) that contributed to or created the
proximate cause and subsequent undesired outcome and, if eliminated, or modified would have
prevented the undesired outcome. Typically multiple root causes contribute to an undesired outcome.
Root Cause Analysis (RCA) A structured evaluation method that identifies the root causes for an undesired outcome and the
actions adequate to prevent recurrence. Root cause analysis should continue until organizational
factors have been identified, or until data are exhausted.
Event A real-time occurrence describing one discrete action, typically an error, failure, or malfunction.
Examples: pipe broke, power lost, lightning struck, person opened valve, etc…
Condition Any as-found state, whether or not resulting from an event, that may have safety, health, quality,
security, operational, or environmental implications.
Organizational Factors Any operational or management structural entity that exerts control over the system at any stage in its
life cycle, including but not limited to the system’s concept development, design, fabrication, test,
maintenance, operation, and disposal.
Examples: resource management (budget, staff, training); policy (content, implementation, verification);
and management decisions.
Contributing Factor An event or condition that may have contributed to the occurrence of an undesired outcome but, if
eliminated or modified, would not by itself have prevented the occurrence.
Barrier A physical device or an administrative control used to reduce risk of the undesired outcome to an
acceptable level. Barriers can provide physical intervention (e.g., a guardrail) or procedural separation
in time and space (e.g., lock-out-tag-out procedure).
2004 MAPLD/Mishaps Seminar 33 Chandler
NASA Mishap Classification Levels
Classification Level Property Damage Injury
Type A Total direct cost of mission failure and property damage is $1,000,000 or more, Occupational injury and/or illness that resulted in:
or A fatality,
Crewed aircraft hull loss has occurred, or
or A permanent total disability,
Occurrence of an unexpected aircraft departure from controlled flight (except or
high performance jet/test aircraft such as F-15, F-16, F/A-18, T-38, and T-34, The hospitalization for inpatient care of 3 or more people
when engaged in flight test activities). within 30 workdays of the mishap.
Type B Total direct cost of mission failure and property damage of at least $250,000 but Occupational injury and/or illness has resulted in
less than $1,000,000. permanent partial disability.
or
The hospitalization for inpatient care of 1-2 people within
30 workdays of the mishap.
Type C Total direct cost of mission failure and property damage of at least $25,000 but Nonfatal occupational injury or illness that caused any
less than $250,000. workdays away from work, restricted duty, or transfer to
another job beyond the workday or shift on which it
occurred.
Type D Total direct cost of mission failure and property damage of at least $1,000 but Any nonfatal OSHA recordable occupational injury and/or
less than $25,000. illness that does not meet the definition of a Type C
mishap.
Close Call Total direct cost of mission failure and property damage is less than $1,000 Minor injury requiring first aid which possesses the
or potential to cause a mishap
An occurrence or condition of employee concern in which there is no property or
damage but possesses the potential to cause a mishap. An occurrence or condition with no injury but possesses
the potential to cause a mishap.