14.3 Comparison, Failure Reversion and Sensor Interfacing
Key Takeaways
- Both ECAM and EICAS use the same safety colour language: red for warning or exceedance requiring immediate action, amber for caution requiring awareness or timely action, and green for a normal in-limit parameter.
- If the upper display unit fails, primary engine indication and warning/alerting information is typically transferred automatically to the remaining display (Airbus E/WD transfer; Boeing compact format).
- FADEC/EEC channels supply the majority of engine operating parameters as validated digital data, while independent sensors such as fire loops, some oil-quantity sensors and vibration transducers feed the indicating and warning path separately.
- Associated BITE in the indicating and warning computers records and isolates LRU faults for centralised maintenance readout; in-flight crew-alert pages remain operational displays, not the maintenance manual.
14.3 Comparison, Failure Reversion and Sensor Interfacing
Sections 14.1 and 14.2 treated Airbus ECAM and Boeing EICAS as separate general arrangements. For preparation under the broad current 5.15 heading, put the two historically listed systems on one page: same job, different packaging, shared colour language, display reversion, sensor and FADEC inputs, and associated BITE. Knowledge remains level 1 for all categories. The comparison below is classroom typical-teaching, not a type-course differences list and not a claim that every Airbus or Boeing aeroplane matches the table in every LRU name.
Side-by-Side General Arrangement
Both systems exist because modern turbofan aeroplanes produce more engine and system data than a row of electro-mechanical gauges can show honestly, and because a central warning caption panel cannot explain which pump, valve or channel has failed. Both therefore display primary engine parameters permanently, rank crew alerts by urgency, keep redundant computers and two stacked display units, inhibit selected amber messages in take-off and landing windows, and record faults in BITE. They differ in how computers are specialised and in whether the alerting display itself writes procedural action lines.
| Topic | Typical Airbus ECAM | Typical Boeing EICAS |
|---|---|---|
| Full name | Electronic Centralised Aircraft Monitoring | Engine Indicating and Crew Alerting System |
| Permanent engine window | Upper E/WD | Upper primary EICAS |
| Systems window | Lower SD synoptic pages + STS | Lower secondary engines, STATUS, synoptics on later types |
| Alert computers | Dual FWC (messages, aurals, flight-phase inhibit) | Dual EICAS computers (indication and alerting together) |
| Synoptic data | Dual SDAC into DMC | Acquired inside the EICAS computers (and later display systems) |
| Image generation | DMC 1/2/3 shared with EFIS | EICAS computers drive the two DUs directly |
| Procedure presentation | E/WD may show colour-coded action lines (type-course content) | Messages are titles; electronic checklists, if fitted, are a separate system |
| Display-unit failure | E/WD image transfers to the lower DU; system pages move toward an ND | Remaining DU shows compact primary-plus-selected-secondary format |
| Amber declutter | CLR / RCL on the ECP | CANCEL / RECALL |
The examination point is not to memorise every box part number. It is to recognise that losing one display must not lose N1/EPR, EGT and the warning list, that amber can be parked during critical phases, and that green never means failed.
Colour Coding: Red, Amber, Green
Colour is a safety code. It is shared, with only local extras, across ECAM, EICAS and the rest of the electronic instrument system.
| Colour | Meaning on engine and alert displays | Typical use |
|---|---|---|
| Red | Warning or exceedance requiring immediate action | Warning messages, red-line exceedance of N1/EPR/EGT, fire indications, MASTER WARN |
| Amber | Caution requiring awareness or timely action | Caution messages, caution-range parameters, MASTER CAUT, EICAS indented advisories (still amber) |
| Green | Normal, in-limit parameter or completed normal indication | Normal engine readouts, ECAM memos, healthy synoptic flow |
| White | Labels, scales, status (EICAS), secondary titles | Not a warning colour |
| Cyan / blue | Actions still to be done, or communication as fitted | Must not be read as a red warning |
| Magenta | Particular limitations or pointers as fitted | Type-specific; not the basic warning colour |
Rules that survive both manufacturers: red beats amber beats green; a red warning is never a memo and a green memo is never a failure. An exceedance is colour on the gauge as well as a possible message — if EGT is red, the parameter has crossed a limit even before the crew reads a title. Advisory is not a fourth safety colour on EICAS; it is still amber, distinguished by indent and by the absence of master-caution lights. On ECAM, advisory is typically a pulsing parameter rather than a new colour. White status is not less red; it is a different class: non-time-critical information on a status page. Colour is part of the indicating system, not decoration; unapproved filters or a DU driven beyond its luminance specification destroy the code.
Display and Computer Reversion
Reversion is the planned degraded mode. Module 5 wants the automatic essential picture, not the full DMC-switch catalogue from a type course.
Display-unit failure. On ECAM, if the upper DU fails, the E/WD (primary engines plus messages) is automatically transferred to the lower DU. System synoptics then have to be recovered on an EFIS ND via an ECAM/ND transfer switch. If the lower DU fails, the E/WD remains on the upper unit and system pages are recovered the same way. The crew keeps engines and alerts; they lose convenient synoptics until they transfer. On EICAS, if either DU fails, the remaining unit presents a compact format that retains primary engine parameters and the highest-priority alert messages, with selected secondary parameters condensed onto the same screen. Again the essential picture survives.
Computer failure. On ECAM, one FWC still supplies warnings, one SDAC still supplies synoptics, and a remaining DMC can be selected onto the ECAM DUs if DMC 3 fails. Loss of both FWCs is the serious case: engine parameters may still be formatted by the DMC/FADEC path, but automatic warning generation is lost. Loss of both SDACs hurts synoptics more than the E/WD message field. On EICAS, the surviving computer drives both displays. Loss of both EICAS computers removes the electronic engine/alert picture and forces standby instruments if they exist.
Invalid source / disagree. When dual sensors or dual FADEC channels disagree, the display typically flags the parameter amber, blanks a digital readout, or offers a source-select switch. The system prefers no number over a wrong number. That is a sensor-reversion idea, not a DU compact mode.
[!WARNING] Do not reset computers in flight as a first reflex. Recycle procedures, if they exist, are type-course and often inhibited in critical phases. The Module 5 diagnosis is: identify whether the lost function is a DU, a DMC/EICAS computer, an FWC versus SDAC path, or a sensor/FADEC input — then use the approved maintenance test on the ground.
Sensor and FADEC Interfacing
The displays do not invent N1. They present values that other systems have already measured and, in most cases, already validated.
FADEC / EEC path. Each engine has dual-channel digital control. The channels measure rotor speeds, EGT (or TGT) thermocouples, fuel metering, variable-geometry positions and similar parameters, compare channels, and output a validated digital data stream (commonly ARINC 429 words with sign/status) to ECAM DMCs or EICAS computers. Thrust limits used as gauge bugs are often computed in the same control computers. If a channel is invalid, the remaining channel continues to run the engine and the indicating system should follow the valid source or flag a disagree. A frozen FADEC output must not be allowed to look like a healthy green N1 without a validity-bit check — that is why SSM/status bits matter even at familiarisation level.
Independent sensors. Not every engine-related alert comes through FADEC. Typical independent inputs include fire and overheat loops (a control-computer freeze must not remove the fire warning), oil quantity on many types (a tank probe rather than a FADEC torque-motor), vibration transducers processed by a dedicated monitor, thrust-reverser locked/unlocked discretes, and filter-bypass switches. Those signals enter the FWC or EICAS alert logic on their own wiring or buses. The indicating system is an interface concentrator: digital engine data on one path, discrete safety loops on another, airframe synoptic data on a third (SDAC or equivalent). Cross-comparison, debounce and validity windows sit in the warning computers so that a single open-circuit probe does not both shut down an engine picture and hide a fire.
Analogue versus digital. Older installations still digitise analogue tachometer and thermocouple voltages at a data concentrator. Newer ones keep the analogue world inside the FADEC and send only digital words. Either way, the display LRU is not the primary measuring instrument. Calibrating a DU does not calibrate the N1 probe.
BITE Relation to Crew Alerting
BITE is associated with both ECAM and EICAS because the same computers that format gauges also test themselves, their displays, and often their input buses. Power-up BITE runs when the box is energised. Continuous BITE watches in flight. Initiated BITE is a ground maintenance action.
The relation to crew alerting is a classification, not an identity. Operational warnings and cautions (red and amber on the E/WD or primary EICAS) are for the current flight. Status items (ECAM STS page, EICAS STATUS) are real but not time-critical. BITE-only items may never appear in front of the crew; they wait in the central maintenance computer or centralised fault-display system. Clearing an ECAM caution or using CANCEL on an EICAS advisory does not empty BITE memory. Exceedances remain recorded. LRU fault isolation (which FWC, which DU, which EEC channel, which fire loop) is read from maintenance pages. Using the crew-alert list as if it were a fault-isolation manual misses dormant faults and misleads the next crew when a cancelled amber returns after RECALL.
[!NOTE] Chapter boundary. This section only ties BITE to indicating and warning. Central maintenance computers, fault classes and initiated-test philosophy are developed with the other representative systems studied under Module 5.15. A Part-66 candidate should know that the BITE menu exists, that it is not the E/WD, and that sensor/FADEC validity is one of the things BITE watches.
When a report says ECAM blank or EICAS compact, translate it into the shared model: which display died, which computer path died, which sensor was invalid, and did inhibit hide an amber? A red fire warning should still be treated as a fire-loop problem, not a FADEC N1 problem, because fire is independently interfaced. A green engine picture with no messages means the indicating path believes the engines are in limit — confirm with an independent standby indication if the report is that it looked too good. That is an appropriate familiarisation boundary for ECAM and EICAS before the type course begins.
Which colour-coding statement is common teaching for both ECAM and EICAS engine and alert displays?
If the upper ECAM or EICAS display unit fails, what reversion is typically provided?
How do FADEC/EEC computers and independent sensors typically interface with ECAM or EICAS?
What is the relationship between ECAM/EICAS crew alerting and BITE in typical electronic aircraft systems?