11.2 Worst Case Failure

Key Takeaways

  • Worst Case Failure (WCF) is the single failure (or defined design failure set) that causes the greatest reduction in DP position-keeping capability
  • WCF residual capability is the basis for post-failure capability plots and for planning whether work can continue after the design failure
  • WCF is configuration-dependent: on open bus it is often loss of one bus/thruster group, not necessarily total plant blackout
  • Closed bus without proven protection can make plant-wide blackout the effective worst case — worse than the open-bus design WCF
  • Exam trap: WCF is not “every thruster and every generator fail at once from unrelated causes”; it is the design single-failure worst residual
Last updated: July 2026

Defining Worst Case Failure for DP

Worst Case Failure (WCF) is the single failure (or the defined design failure used in class/FMEA, including certain Class 3 compartment losses) that produces the greatest reduction in the vessel’s ability to generate the thruster forces needed for station-keeping. After that failure, the remaining plant is the residual system. Residual capability — not intact capability — is what critical operations must still respect if a failure occurs mid-task.

If you remember one sentence: WCF is the design failure that hurts DP capability the most while still being a single (or defined design) event — not a free-for-all multi-fault disaster movie.

Why WCF exists as a concept

Class 2/3 philosophy does not require infinite thrusters after every imaginable accident. It requires that after the worst design single failure, enough thrust and power remain to hold in the analysed environment (within the vessel’s post-failure envelope). WCF focuses engineering and operations on that residual envelope:

ConceptIntact plantAfter WCF
Thrusters availableFull enabled setResidual set only
Power availableFull partitioned plantSurviving section(s)/sources
Capability plotIntact plotPost-WCF / residual plot
Weather acceptanceLarger envelopeReduced envelope
Operational meaningEntry/planning baseline“Can we still hold if the design failure hits now?”

Capability plots, ASOG weather limits for critical work, and online consequence analysis all lean on a clear WCF definition. If nobody knows the WCF, “we are Class 2” is an empty slogan.

WCF is not always whole-plant blackout

A common exam and bridge error is: “Worst case is always total blackout of everything.” That is only true if the plant and configuration make total loss the worst single event. On a well-partitioned open-bus Class 2 vessel, the design WCF is frequently:

  • loss of one main bus section (short circuit, section blackout, or associated generator group),
  • with loss of all thrusters fed only from that section,
  • while the other section’s generators and thrusters continue.

In that configuration, whole-plant blackout is not the design single failure — it would require common-mode or multi-section events beyond the open-bus design case (or a closed common bus without adequate protection).

ConfigurationTypical design WCF pictureResidual idea
Open bus, balanced thrustersLoss of one bus/thruster groupOpposite group remains
Closed bus, unproven protectionSingle electrical fault may black whole plantResidual thrusters may be zero
Closed bus, FMEA-proven protectionFault cleared/isolated per analysisResidual per addendum
Class 3 compartment fire/flood caseLoss of everything in one compartmentRedundant compartment remains

[!IMPORTANT] Exam trap: “WCF always means blackout of the whole plant.” Only if configuration and failure physics make that the worst single design event. On open bus, WCF is often loss of one side, and residual thrusters should still exist.

What “greatest reduction in capability” means

Not every single failure is the WCF. Losing one small tunnel thruster may be a single failure but not the worst. WCF is the single failure (among those analysed) that leaves the smallest residual station-keeping capacity — typically the failure that removes the largest thruster group or the most critical power partition.

Engineers compare residual force envelopes after each candidate failure. The worst residual (still meeting class single-failure rules if the design is sound) becomes the WCF used for:

  1. Post-failure capability plots (wind/wave/current limits after WCF),
  2. Operational planning (can the residual plant hold this weather if failure occurs?),
  3. Consequence analysis software (online check against residual model),
  4. ASOG / CAM setup (plant must be configured so the residual set is real and available).
Failure exampleLikely severity
One of four similar thrusters tripsModerate — not always WCF
Entire bus section and its thrusters lost (open bus)Often the WCF candidate
Single gyro fails with 3-gyro votingLow thruster impact if voting healthy
Common-mode black of both sectionsCatastrophic — may exceed intended design WCF if config wrong

Configuration changes the WCF

WCF is not a fixed sticker independent of how you run the ship today.

  • Open bus: design WCF usually section/group loss; residual thrusters on the healthy side.
  • Closed bus: a single fault may become whole-plant blackout — effective WCF worse than open-bus design unless protection is proven.
  • Thrusters deselected “to save fuel”: residual after a real section loss may be less than the FMEA assumed because you already removed part of the “surviving” set.
  • Generators offline on one side: open-bus residual power may be inadequate even if thrusters are present.
  • Retractable thruster stowed: residual set assumed in trials may not be available.
Operator actionEffect on real residual after failure
Open bus, both sides powered, all residual thrusters enabledMatches typical FMEA residual
Closed bus critical work without proofResidual may be zero thrusters
Half residual thrusters deselectedResidual weaker than plots
One side with no spinning generationResidual power collapses

CAM exists largely so that the plant you are running is the plant whose WCF residual was analysed.

WCF as the basis for capability and planning

Intact capability plots answer: “With everything healthy, what weather can we hold?” Post-WCF plots answer: “After the design failure, what weather can we still hold?” Critical activity planning should be governed by the more restrictive residual picture when the consequence of failure is high (diving, close proximity, heavy lift over a live asset).

Practical planning questions:

  • If WCF happens now, do we still stay outside the structure / keep the gangway / protect divers?
  • Is present weather inside the post-WCF plot, not only the intact plot?
  • Is heading still optimal for residual thrusters after WCF?
  • Does ASOG already force stop-work if residual would be inadequate?
Plot typeUse
Intact capabilityBest-case envelope; entry screening
Post-WCF capabilityEnvelope after design failure; critical-work limit
Footprint / real weatherWhat you are actually experiencing

Exam traps: WCF vs multiple simultaneous independent failures

Assessments love this confusion:

Wrong ideaRight idea
WCF = thrusters + gens + PRS all die from unrelated causes at onceWCF = one design failure (or defined design set) with greatest capability loss
Class 2 must survive any three independent faultsClass 2 is single-failure tolerance (plus design rules), not infinite multi-fault
If residual thrusters remain, it cannot be WCFWCF can still leave residual — that residual is the design outcome
Blackout is always WCF on open busOpen-bus WCF is often one section, not both
WCF is only an engineer termDPO uses WCF for plots, consequence analysis, CAM

Also distinguish:

  • Design WCF (FMEA/class) — what residual is supposed to remain.
  • Effective operational worst case — what you actually get if you run closed bus, inhibit protection, or deselect residual thrusters. The second can be worse than the design WCF; that is operator/configuration failure, not a rewrite of the definition.

Worked WCF scenario

A dive support vessel runs open bus, two sections, two thrusters per section. FMEA WCF is black of Section A: both Section A thrusters stop; Section B thrusters and generators remain. Post-WCF plots show hold capability in present weather with a small margin. Online consequence analysis is green. The engineer proposes closing the bus-tie to save fuel during the dive. The DPO refuses: closed bus can turn a single short into loss of all four thrusters, which is beyond the design WCF residual the dive was planned against. Later, in open water TAM standby with no divers, closed bus may be accepted with clear abort criteria — because the consequence of a worse effective failure is tolerable, not because the physics changed.

Operator checklist around WCF

  1. Know the documented WCF for the operating mode (open/proven closed).
  2. Know which thrusters and power remain after it.
  3. Compare present weather and heading to post-WCF capability, not only intact.
  4. Keep CAM configuration so residual assets are real (enabled, powered, deployed).
  5. Treat configuration changes that worsen effective residual as stop-work triggers until reassessed.

Bottom line: WCF is the single (or defined design) failure that most reduces DP capability; residual plant after WCF drives capability plots and planning; on open bus it is often one bus/thruster group rather than total blackout; and multi-simultaneous independent failures are not the definition of WCF on the exam.

Test Your Knowledge

What does Worst Case Failure (WCF) mean in DP Class 2/3 practice?

A
B
C
D
Test Your Knowledge

On a Class 2 vessel running open bus with thrusters split across two independent sections, what is most often the design WCF picture?

A
B
C
D
Test Your Knowledge

Why is post-WCF capability used for critical operational planning?

A
B
C
D
Test Your Knowledge

Which statement is an exam trap rather than a correct WCF principle?

A
B
C
D