Occupational Safety, Health, and Environmental (OSHE) Blog

What is Functional Hazard Assessment (FHA)?

A process safety consultant explains what a functional hazard assessment classifies, what each severity class commits you to, and how FHA differs from HAZOP

288
What is Functional Hazard Assessment (FHA)?

Functional hazard assessment answers a different question from the risk assessments most safety practitioners run. A HAZOP or a job hazard analysis asks whether the thing that has been designed is safe enough. An FHA asks how safe the thing needs to be, before anyone has decided what it will be made of. It is a top-down, qualitative examination of what a system is supposed to do, run early, to work out which functional failures would be catastrophic and therefore how much integrity the eventual design has to carry.

That inversion is the whole point, and it is why FHA outputs are targets rather than findings. This guide covers the aviation form the technique is named after, its equivalents in rail, process, automotive and machinery, and the 2023–24 standards changes that pulled ground crew safety into scope.

Key takeaways

Six points carry most of what a practitioner needs from this technique:

  • An FHA identifies failure conditions at the function level and classifies them by severity. Each class carries a probability target that the design must then be shown to meet.
  • In civil aviation the governing guidance is SAE ARP4761A, issued 20 December 2023 alongside ARP4754B, with FAA AC 25.1309-1B (30 August 2024) and EASA AMC 25.1309 setting the acceptable means of compliance.
  • The FAA classifies failure conditions as no safety effect, minor, major, hazardous or catastrophic, with catastrophic requiring an average probability on the order of 1 × 10⁻⁹ per flight hour or less.
  • AC 25.1309-1B now requires risk to ground crew — handling, maintenance and servicing personnel near the aircraft — to be assessed, which puts an airworthiness technique directly into occupational safety territory.
  • The same logic runs under other names elsewhere: EN 50126 in rail, hazard and risk analysis under IEC 61511 in process plants, and HARA under ISO 26262 in automotive.
  • FHA is not HAZOP. HAZOP works bottom-up from deviations in a designed process; FHA works top-down from functions before the design exists.

What functional hazard assessment actually is

An FHA examines functions, not equipment. Before a designer has chosen a hydraulic actuator or a programmable controller, the system is still only a list of things it must accomplish. Hold attitude. Maintain cabin pressure. Isolate the reactor. Hold the train at a stop signal. The assessment takes each of those functions and asks what happens if it is lost, if it operates when it should not, or if it operates incorrectly — and how bad that would be for the people exposed.

The FAA's own description in AC 25.1309-1B is worth reading closely. It describes an FHA as a systematic, comprehensive examination of aeroplane and system functions. The conditions it looks for are those arising from malfunctions, or from a failure to function as intended. And it stresses that the assessment deals with the operational vulnerabilities of systems, not with a detailed analysis of how they are built. The assessment should also account for normal system responses to unusual and abnormal external factors, which is where weather, icing and turbulence enter.

Why the analysis starts with functions

Starting from functions rather than parts buys two things. It lets safety work begin before there is any hardware to analyse, which is the only point at which the answer can still change the architecture cheaply. And it catches failure conditions that no component-level analysis will find, because the hazard lives in the combination rather than in any single item.

Choosing the level of abstraction is the difficult part of the whole technique, and it is where most weak FHAs are decided. Define functions too broadly and the assessment produces four rows and tells you nothing. Define them too narrowly and you have written an FMEA with the wrong cover sheet, hundreds of pages long, with the aircraft-level picture buried.

What the assessment produces

The output is not a list of recommendations. It is a set of commitments that the rest of the programme has to satisfy, and they get carried forward into requirements documents rather than an action tracker.

Input to an FHAOutput from an FHA
Function list at the chosen levelNamed failure conditions, with identifiers
Operational and environmental envelopeEffect on the system, operators and exposed people
Operating phases or modesSeverity classification per condition
Service experience from similar systemsProbability target implied by each classification
Regulatory or contractual safety criteriaDerived safety requirements and integrity levels

The practical items an FHA report has to contain before it is any use downstream are:

  • A function description precise enough that two engineers would classify the same failure the same way
  • Failure conditions covering loss, unintended operation and incorrect operation of each function
  • The operational phase in which each condition is assessed, because severity is phase-dependent
  • The severity classification with the reasoning, not just the letter
  • The safety objective — the probability or integrity target that the classification imposes
  • The assumptions made about operator detection and response, flagged so they can be verified later

Where FHA sits in the safety assessment chain

FHA is the first analysis in a sequence, and its value depends entirely on what happens after it. On its own it produces a classified list. The sequence turns that list into evidence that a design meets the targets the list set.

Under ARP4761A the chain runs from an aircraft-level FHA down to system-level FHAs. Those feed preliminary assessments, which test whether a proposed architecture can meet the objectives. Final assessments then demonstrate that the built design does meet them. The revision that took effect in December 2023 formalised the aircraft-level half of this, which had been common practice for years without being written down.

StageWhat it asksWhen
Aircraft/system-level FHA (AFHA)Which whole-vehicle functions matter, and how badlyConcept, before architecture
System FHA (SFHA)The same question inside each systemAs architecture emerges
Preliminary assessment (PSSA/PASA)Can this architecture meet the objectives?During design
Safety assessment (SSA/ASA)Does the built design meet them?Before certification
Supporting analyses (FTA, FMEA, CCA)How do failures combine and propagate?Throughout

The chain matters to an occupational safety reader for one reason: every assumption the FHA made about how people detect and respond to a failure becomes an operating constraint once the asset is in service. AC 25.1309-1B is explicit on this point. Where an analysis credits crew or maintenance action, the applicant must verify three things: that the indication is actually provided, that it will in fact be recognised, and that the required action has a reasonable expectation of being accomplished in time.

The handovers where FHA assumptions most often get lost are:

  • Design to commissioning — the classification assumed an alarm that ended up shared with three others
  • Commissioning to operations — a proof-test interval that nobody scheduled
  • Operations to maintenance — a latent failure whose detection depends on a check that drifted
  • Original build to modification — a change that quietly invalidated the function definition
Infographic showing the five-stage safety assessment chain for aircraft design, from functional hazard assessment through in-service operations, with system diagrams and failure analysis examples at each step.

The five severity classes and what each one commits you to

This is the part people underestimate. Classifying a failure condition is not a labelling exercise. It sets a numerical target that the design has to be shown to achieve. Moving a condition up one class typically demands two orders of magnitude more reliability.

The FAA sets out the relationship in Table 4-1 of AC 25.1309-1B. Failure conditions with no safety effect carry no probability requirement. Minor conditions may be probable. Major conditions must be no more frequent than remote. Hazardous conditions must be no more frequent than extremely remote. Catastrophic conditions must be extremely improbable.

ClassificationEffect on the aircraftAllowable qualitative probabilityAverage probability per flight hour
No safety effectNo effect on operational capability or safetyNo requirementNo requirement
MinorSlight reduction in safety margins or capabilityProbable~10⁻³ or less, greater than ~10⁻⁵
MajorSignificant reduction in safety margins or capabilityRemote~10⁻⁵ or less, greater than ~10⁻⁷
HazardousLarge reduction in capability; serious or fatal injury to a small number of people other than the flight crewExtremely remote~10⁻⁷ or less, greater than ~10⁻⁹
CatastrophicMultiple fatalities, normally with hull lossExtremely improbable~10⁻⁹ or less

Source: FAA AC 25.1309-1B, Table 4-1 (30 August 2024). Ranges are stated "on the order of" and are guidelines for quantitative analysis, not pass marks on their own.

Two details in that table repay attention. The FAA defines multiple fatalities, for the purpose of a safety assessment, as two or more — a lower bar than most people assume when they hear "catastrophic". And the hazardous row is the one that carries an explicit reference to people who are not the flight crew, which is the thread that runs into the ground-crew changes discussed further down.

⚖️ Jurisdiction note: The FAA and EASA are harmonised on the class names and on the 10⁻⁹ figure, but their wording on the "probable" band is not identical. AC 25.1309-1B brackets probable between roughly 10⁻³ and 10⁻⁵. EASA's AMC 25.1309 describes probable failure conditions as those with an average probability per flight hour greater than the order of 1 × 10⁻⁵, without stating an upper bound. Check which authority's text your project is assessed against before quoting a range.

Three rules govern how the table is used in practice:

  • Depth of analysis follows the class. Hazardous and catastrophic conditions need a detailed safety analysis; a minor condition may be settled by a design and installation appraisal
  • A quantitative figure alone is not a compliance case. The FAA treats the numbers as guidelines supporting engineering judgement, not as a pass mark
  • No single failure may be catastrophic. That requirement stands independently of any probability calculation
Risk assessment matrix displaying the relationship between hazard severity and probability, showing acceptable, probable, remote, and unacceptable risk regions with contour lines indicating risk levels from 10^-2 to 10^-10.

How an FHA is run: the six decisions that matter

Every guide to FHA lists the same steps. The steps are not where assessments go wrong. They go wrong at a handful of judgement calls that the step list does not surface, and those are worth naming separately.

Deciding the level of abstraction

Set the function list at the level where a reader outside the design team could still tell what the system is for. "Provide braking" is usually too coarse to classify. "Energise solenoid SV-104" is a component, not a function. Something like "decelerate the vehicle on command from the driver" sits at the level where failure conditions become classifiable.

Deciding the operational phase

Severity is not a property of the failure; it is a property of the failure in a phase. Losing thrust reverse matters on a wet runway and does not matter at cruise. In process plants the equivalent is start-up, normal running, shutdown and abnormal operation — and start-up is where most of the interesting classifications live, because that is when protective systems are most often overridden.

Deciding how much credit to give the operator

An FHA that classifies a condition as major because "the operator will notice and intervene" has made a testable claim about a human being. AC 25.1309-1B requires that claim to be verified rather than assumed. Reviewing brownfield packages for Worley, the recurring question I ask about any control credited in an assessment is whether anyone has watched a real operator do it, at night, on the fourth day of a turnaround. If nobody has, the classification is a hypothesis.

The remaining three decisions concern scope and consistency, and they are the ones an assessor will probe first:

  1. What is inside the system boundary — interfaces are where multi-system failure conditions hide, and an FHA that stops at the boundary will miss them
  2. Whether combinations were considered — the FAA notes that conditions individually classified as minor or major can be hazardous or catastrophic when they occur together at aircraft level
  3. Who classified, and against what criteria — a severity matrix agreed after the classifications are written is not a criterion, it is a justification
Flowchart showing six critical decision points in Functional Hazard Analysis, progressing from phase selection through operator verification, boundary definition, combination checks, and criteria agreement to achieve valid FHA assessment.

FHA outside aviation: rail, process, automotive and machinery

The technique is not aviation property. Every functional safety regime built on IEC 61508 runs a version of it, and the confusion practitioners meet is mostly vocabulary rather than method. Each sector kept its own name, its own integrity scale and its own severity criteria, while the underlying move — classify the function, derive the target — stayed the same.

SectorGoverning standardWhat the analysis is calledIntegrity measure
Civil aviationSAE ARP4761A / ARP4754B; CS/14 CFR 25.1309Functional hazard assessment (AFHA, SFHA)Development assurance level (FDAL/IDAL)
RailEN 50126-1:2017 and EN 50126-2:2017Functional hazard analysis / hazard identificationSafety integrity level, tolerable hazard rate
Process industriesIEC 61511 (from IEC 61508)Hazard and risk analysis (H&RA)Safety integrity level for each SIF
AutomotiveISO 26262-3Hazard analysis and risk assessment (HARA)Automotive safety integrity level (ASIL)
MachineryIEC 62061; ISO 13849-1Safety function risk assessmentSIL or performance level

Rail — EN 50126

The rail RAMS standard was substantially revised in 2017, splitting into a generic lifecycle process in Part 1 and a systems approach to safety in Part 2. Functional analysis feeds hazard identification, hazards go into a hazard log, and safety requirements are apportioned down to functions and then to suppliers. The hazard log is the artefact that distinguishes rail practice: it is a live document, not a report issued once.

Process industries — IEC 61511

In a refinery or a gas plant, the equivalent step is the hazard and risk analysis that opens the functional safety lifecycle. IEC 61511-1 is the process sector implementation of IEC 61508:2010; the current text is the 2016 second edition consolidated with Amendment 1 (2017) as Edition 2.1. The analysis identifies the scenarios, decides which need instrumented protection, defines each safety instrumented function, and assigns it a SIL. Most operators reach that answer through a HAZOP followed by LOPA or a risk graph.

Working on upstream barrier assurance for Santos across the Cooper Basin and the Gladstone interfaces, the gap I found most often was not in the SIL calculation. It was that the assumptions underneath it — proof-test intervals, bypass discipline, the independence of two supposedly separate layers — had never been checked in the field after commissioning. In the United States the same discipline is a legal requirement rather than a good practice, under the process hazard analysis element of 29 CFR 1910.119.

Automotive — ISO 26262

ISO 26262-3 covers the concept phase. Its hazard analysis and risk assessment produces an ASIL from three factors rather than one: severity, probability of exposure to the operational situation, and controllability by the driver. That third factor has no aviation equivalent. It is why a road-vehicle hazard analysis cannot be lifted straight into another sector. The 2018 edition remains current — ISO reviewed and confirmed it in 2024 — but work on a third edition began in late 2023 and a new work item has since been registered, so check the current status before citing it in a programme plan.

The differences that actually trip people up when they move between these regimes are:

  • Severity criteria are not transferable. Aviation classifies against occupant and crew outcomes; rail against passengers and the public; process against people, environment and asset
  • Exposure is treated differently. Automotive scores it explicitly; aviation folds it into flight phase; process handles it through demand rate
  • Controllability is an automotive concept. Crediting it outside ISO 26262 needs a separate, verified argument
  • The integrity scales do not map onto one another. SIL 2 is not ASIL B and neither is DAL C, and any table that equates them is a rough guide at best
A diagram showing five industry vocabularies using the same functional safety technique: Aviation, Rail, Machinery, Process, and Automotive, each with their respective standards and SIL/PL classifications centered around classifying functions and deriving targets.

FHA, HAZOP and Fault Hazard Analysis: three things that get confused

Three separate confusions circulate around this acronym, and all three cause real problems in tender documents and scopes of work. Untangling them takes a paragraph each.

The abbreviation collides. FHA also stands for Fault Hazard Analysis, an inductive technique derived from FMEA that reasons from specific component failures outward to their system effects. That is the opposite direction of travel from functional hazard assessment, which is deductive and top-down. Two different methods, one abbreviation, and a scope of work that says only "FHA" has not specified anything.

HAZOP is not an alternative to FHA. A hazard and operability study, standardised as IEC 61882, examines a designed process node by node. Guide words are applied to parameters such as flow, pressure and temperature to find deviations from design intent. It needs a design to examine. An FHA runs before that design exists. In a well-run project both happen, in that order, and the FHA tells the HAZOP team which functions carry the severe consequences.

Neither is a workplace risk assessment. A functional hazard assessment says nothing about manual handling, working at height or the ladder someone will use to reach the instrument. It addresses hazards arising from the malfunctioning behaviour of the system. Occupational risk assessment addresses hazards arising from the work. A plant can hold an impeccable set of SIL determinations and still injure a fitter.

Functional hazard assessmentHAZOPFault Hazard Analysis
DirectionTop-down, deductiveStructured guide-word reviewBottom-up, inductive
Needs a design first?NoYesYes
Starts fromFunctionsNodes and parametersComponent failure modes
Typical outputClassified failure conditions and targetsDeviations, causes, safeguards, actionsFailure effects and criticality
ReferenceSAE ARP4761A; EN 50126IEC 61882FMEA-derived practice

Three questions settle which technique a piece of work actually needs:

  • Does a design exist yet? If not, only the functional assessment can run
  • Is the deliverable a target or a finding? Targets come from FHA; findings come from HAZOP
  • Is the concern the system malfunctioning, or the work being done? The second is occupational risk assessment, and neither of the others covers it
Infographic comparing three hazard analysis methods: Functional Hazard Assessment using top-down function-to-effects analysis, HAZOP using across-the-node process interrogation, and Fault Hazard Analysis using bottom-up component-to-effects analysis, with examples and workflow diagrams.

What changed in 2023–24, and why occupational safety should care

Anyone citing the 1996 edition of ARP4761 or the 1988 advisory circular is working from superseded material. Both were replaced inside eighteen months of each other, and the replacements matter beyond the certification office.

ARP4761A was issued on 20 December 2023 together with ARP4754B, with EUROCAE ED-135 as its European counterpart. The revision split the single FHA into aircraft-level and system-level assessments. It added preliminary aircraft safety assessment and aircraft safety assessment processes at the vehicle level. It recognised model-based safety analysis and cascading effects analysis as formal methods, and took the FDAL/IDAL assignment guidance across from ARP4754. Its scope also widened beyond large aeroplanes to smaller aircraft, rotorcraft, engines and propellers.

AC 25.1309-1B followed on 30 August 2024, cancelling AC 25.1309-1A, which had stood since June 1988. Alongside heavier treatment of latent failures, it carries the change that should interest anyone running an operational HSE function.

Ground crew are now explicitly in scope

The advisory circular states that where relevant, applicants should account for risks to persons other than aeroplane occupants, such as ground crew, when assessing system failure conditions. It defines ground crew as aircraft handling, maintenance or servicing personnel operating in or near the aircraft while it is in a ground operating condition. It then names the threats it has in mind: electric shock to mechanics, atmospheric threats to mechanics, and unwanted door or thrust reverser movement.

I spent two years as an airside safety advisor at Sydney Airport, and the apron is where that clause lands. The people exposed to an unwanted door or reverser movement are dispatchers, loaders, refuellers and engineers, most of them employed by someone other than the aircraft operator. Nothing in an airside induction tells them that a design assessment somewhere assigned a probability target to the thing that could crush them. The gap I watched most often on stands was not a missing rule but a missing line of sight: nobody on the ramp had ever seen the assumptions that were made on their behalf.

The practical questions this opens up for a ground operations HSE team are:

  • Which system failure conditions were classified with ramp personnel as the exposed population? Ask the operator's engineering function, not the handling agent
  • What operator or maintainer action was credited in reaching those classifications, and does it appear anywhere in the ground handling procedures
  • Which of those actions are trained and assessed, rather than assumed
  • Where the design assumed an exclusion zone, whether that zone is marked, enforced and survivable during a peak bank
Timeline showing evolution of aerospace safety documentation from 1988 to 2024, displaying four standards documents progressing from restrained to current specification AC 25.1309-1B, with key dates and certification milestones.

Where functional hazard assessments fail in practice

The failures are consistent across sectors, and none of them are analytical. They are all failures of maintenance, in the sense that the assessment stopped being true and nobody noticed.

The first is the frozen FHA. Both ARP4761A and AC 25.1309-1B treat the assessment as iterative, to be updated as the design develops. In practice the document gets issued, the design changes twice, and the classification is never revisited. Auditing brownfield packages for Worley across Perth, Kuala Lumpur and Abu Dhabi, the modification that invalidated an earlier assessment was almost never the large one — the large ones attracted a management of change review. It was the small tie-in that changed what a function actually did.

The second is the orphaned assumption. Every credited operator action, proof-test interval and exclusion zone is a promise the assessment made to the regulator on the operations team's behalf. When I compared day and night findings on airside leadership walks, the pattern was consistent. The controls documented in daylight and the controls present at 03:00 were not the same set, and no analysis anywhere accounted for the difference.

The third is severity drift. Classifications get softened during design because the target is expensive, and the softening is recorded as an engineering judgement with no new evidence behind it. On the steel side, reviewing machine safety on the hot mill and coating lines at BlueScope, I saw the same pattern in performance-level determinations. The required level fell — not because the hazard changed, but because meeting it was inconvenient.

The checks worth running on any FHA handed to you, in the order I would run them:

  1. Compare the function list against the current design description. If they disagree, the classifications are stale
  2. Extract every credited human action into a single list. Then find each one in an operating or maintenance procedure
  3. Find any classification that was downgraded and ask what evidence supported the change
  4. Check the exposed populations named. If contractors, maintainers or ground personnel are absent, ask why
  5. Ask when it was last reissued and against which design revision
Comparison infographic showing differences between stale assessment with outdated design and red X marks versus live assessment with current design and green checkmarks, highlighting procedure references and risk management improvements.

Frequently asked questions

These are the questions that come up most often when a team meets the technique for the first time.

Is FHA qualitative or quantitative?

The identification and classification of failure conditions is qualitative — it relies on engineering judgement about effects. The probability targets that the classifications imply are quantitative. So the assessment itself is qualitative, but it hands a numerical obligation to the analyses that follow it.

What is the difference between FHA and FMEA?

FHA is top-down and starts from functions before a design exists. FMEA is bottom-up and starts from the failure modes of specific components in a design that already exists. They answer different questions and are usually both required, with the FHA setting the targets that the FMEA helps demonstrate.

Who should be in an FHA team?

At minimum, systems engineers who own the functions, a safety engineer who owns the method, and someone with operational experience of the equipment class. Severity classification is a competent-person judgement with certification consequences, so it should not be delegated to a single analyst working alone.

When should an FHA be updated?

Whenever functions change, whenever new failure conditions are identified, and whenever a design change alters what a function does or how it is implemented. A modification that looks small can still change a function's definition, which is the most common reason an assessment quietly goes stale.

Does FHA apply outside aviation?

Yes, under other names. Rail runs functional hazard analysis under EN 50126, process plants run hazard and risk analysis under IEC 61511, automotive runs HARA under ISO 26262, and machinery runs safety function risk assessment under IEC 62061. The vocabulary and the integrity scales differ; the logic does not.

Is an FHA the same as a risk assessment?

No. A workplace risk assessment addresses hazards arising from the work being done — manual handling, access, energy isolation. An FHA addresses hazards arising from a system malfunctioning. A site needs both, and neither substitutes for the other.

About the author

Ethan Hughes is an Australian Occupational Health, Safety and Environment (OHSE) major hazard and process safety assurance consultant with 17 years of continuous field experience across 14 countries. His work centres on verifying that critical controls and process safety barriers still function at night, with contractors, and under production pressure. That includes upstream barrier health and SIMOPS assurance for Santos across the Cooper Basin and Gladstone interfaces, and airside safety at Sydney Airport, where design assumptions meet the ramp. He currently leads Hughes Major Hazard Assurance in Melbourne, after senior roles with BHP, CSL, Santos, BlueScope Steel, Worley, DHL, Newmont, Merck, Sydney Airport, Lendlease, Origin Energy and Transurban.

Credentials include ISO 45001 Lead Auditor, ISO 14001 Internal Auditor, NEBOSH International General Certificate, ICAM incident investigation, HAZOP facilitator awareness and major hazard facility / process safety management awareness.

Sources and further reading

Ethan HughesE
WRITTEN BY

Ethan Hughes is an environmental scientist passionate about sustainable workplace practices. With a background in environmental impact assessment and waste management, Ethan helps businesses reduce their ecological footprint without compromising safety standards. His OSHE Blog articles blend eco-conscious strategies with real-world safety solutions.

Related posts