11.2 Worst Case Failure
Key Takeaways
- Worst Case Failure (WCF) is the single failure (or defined design failure set) that causes the greatest reduction in DP position-keeping capability
- WCF residual capability is the basis for post-failure capability plots and for planning whether work can continue after the design failure
- WCF is configuration-dependent: on open bus it is often loss of one bus/thruster group, not necessarily total plant blackout
- Closed bus without proven protection can make plant-wide blackout the effective worst case — worse than the open-bus design WCF
- Exam trap: WCF is not “every thruster and every generator fail at once from unrelated causes”; it is the design single-failure worst residual
Defining Worst Case Failure for DP
Worst Case Failure (WCF) is the single failure (or the defined design failure used in class/FMEA, including certain Class 3 compartment losses) that produces the greatest reduction in the vessel’s ability to generate the thruster forces needed for station-keeping. After that failure, the remaining plant is the residual system. Residual capability — not intact capability — is what critical operations must still respect if a failure occurs mid-task.
If you remember one sentence: WCF is the design failure that hurts DP capability the most while still being a single (or defined design) event — not a free-for-all multi-fault disaster movie.
Why WCF exists as a concept
Class 2/3 philosophy does not require infinite thrusters after every imaginable accident. It requires that after the worst design single failure, enough thrust and power remain to hold in the analysed environment (within the vessel’s post-failure envelope). WCF focuses engineering and operations on that residual envelope:
| Concept | Intact plant | After WCF |
|---|---|---|
| Thrusters available | Full enabled set | Residual set only |
| Power available | Full partitioned plant | Surviving section(s)/sources |
| Capability plot | Intact plot | Post-WCF / residual plot |
| Weather acceptance | Larger envelope | Reduced envelope |
| Operational meaning | Entry/planning baseline | “Can we still hold if the design failure hits now?” |
Capability plots, ASOG weather limits for critical work, and online consequence analysis all lean on a clear WCF definition. If nobody knows the WCF, “we are Class 2” is an empty slogan.
WCF is not always whole-plant blackout
A common exam and bridge error is: “Worst case is always total blackout of everything.” That is only true if the plant and configuration make total loss the worst single event. On a well-partitioned open-bus Class 2 vessel, the design WCF is frequently:
- loss of one main bus section (short circuit, section blackout, or associated generator group),
- with loss of all thrusters fed only from that section,
- while the other section’s generators and thrusters continue.
In that configuration, whole-plant blackout is not the design single failure — it would require common-mode or multi-section events beyond the open-bus design case (or a closed common bus without adequate protection).
| Configuration | Typical design WCF picture | Residual idea |
|---|---|---|
| Open bus, balanced thrusters | Loss of one bus/thruster group | Opposite group remains |
| Closed bus, unproven protection | Single electrical fault may black whole plant | Residual thrusters may be zero |
| Closed bus, FMEA-proven protection | Fault cleared/isolated per analysis | Residual per addendum |
| Class 3 compartment fire/flood case | Loss of everything in one compartment | Redundant compartment remains |
[!IMPORTANT] Exam trap: “WCF always means blackout of the whole plant.” Only if configuration and failure physics make that the worst single design event. On open bus, WCF is often loss of one side, and residual thrusters should still exist.
What “greatest reduction in capability” means
Not every single failure is the WCF. Losing one small tunnel thruster may be a single failure but not the worst. WCF is the single failure (among those analysed) that leaves the smallest residual station-keeping capacity — typically the failure that removes the largest thruster group or the most critical power partition.
Engineers compare residual force envelopes after each candidate failure. The worst residual (still meeting class single-failure rules if the design is sound) becomes the WCF used for:
- Post-failure capability plots (wind/wave/current limits after WCF),
- Operational planning (can the residual plant hold this weather if failure occurs?),
- Consequence analysis software (online check against residual model),
- ASOG / CAM setup (plant must be configured so the residual set is real and available).
| Failure example | Likely severity |
|---|---|
| One of four similar thrusters trips | Moderate — not always WCF |
| Entire bus section and its thrusters lost (open bus) | Often the WCF candidate |
| Single gyro fails with 3-gyro voting | Low thruster impact if voting healthy |
| Common-mode black of both sections | Catastrophic — may exceed intended design WCF if config wrong |
Configuration changes the WCF
WCF is not a fixed sticker independent of how you run the ship today.
- Open bus: design WCF usually section/group loss; residual thrusters on the healthy side.
- Closed bus: a single fault may become whole-plant blackout — effective WCF worse than open-bus design unless protection is proven.
- Thrusters deselected “to save fuel”: residual after a real section loss may be less than the FMEA assumed because you already removed part of the “surviving” set.
- Generators offline on one side: open-bus residual power may be inadequate even if thrusters are present.
- Retractable thruster stowed: residual set assumed in trials may not be available.
| Operator action | Effect on real residual after failure |
|---|---|
| Open bus, both sides powered, all residual thrusters enabled | Matches typical FMEA residual |
| Closed bus critical work without proof | Residual may be zero thrusters |
| Half residual thrusters deselected | Residual weaker than plots |
| One side with no spinning generation | Residual power collapses |
CAM exists largely so that the plant you are running is the plant whose WCF residual was analysed.
WCF as the basis for capability and planning
Intact capability plots answer: “With everything healthy, what weather can we hold?” Post-WCF plots answer: “After the design failure, what weather can we still hold?” Critical activity planning should be governed by the more restrictive residual picture when the consequence of failure is high (diving, close proximity, heavy lift over a live asset).
Practical planning questions:
- If WCF happens now, do we still stay outside the structure / keep the gangway / protect divers?
- Is present weather inside the post-WCF plot, not only the intact plot?
- Is heading still optimal for residual thrusters after WCF?
- Does ASOG already force stop-work if residual would be inadequate?
| Plot type | Use |
|---|---|
| Intact capability | Best-case envelope; entry screening |
| Post-WCF capability | Envelope after design failure; critical-work limit |
| Footprint / real weather | What you are actually experiencing |
Exam traps: WCF vs multiple simultaneous independent failures
Assessments love this confusion:
| Wrong idea | Right idea |
|---|---|
| WCF = thrusters + gens + PRS all die from unrelated causes at once | WCF = one design failure (or defined design set) with greatest capability loss |
| Class 2 must survive any three independent faults | Class 2 is single-failure tolerance (plus design rules), not infinite multi-fault |
| If residual thrusters remain, it cannot be WCF | WCF can still leave residual — that residual is the design outcome |
| Blackout is always WCF on open bus | Open-bus WCF is often one section, not both |
| WCF is only an engineer term | DPO uses WCF for plots, consequence analysis, CAM |
Also distinguish:
- Design WCF (FMEA/class) — what residual is supposed to remain.
- Effective operational worst case — what you actually get if you run closed bus, inhibit protection, or deselect residual thrusters. The second can be worse than the design WCF; that is operator/configuration failure, not a rewrite of the definition.
Worked WCF scenario
A dive support vessel runs open bus, two sections, two thrusters per section. FMEA WCF is black of Section A: both Section A thrusters stop; Section B thrusters and generators remain. Post-WCF plots show hold capability in present weather with a small margin. Online consequence analysis is green. The engineer proposes closing the bus-tie to save fuel during the dive. The DPO refuses: closed bus can turn a single short into loss of all four thrusters, which is beyond the design WCF residual the dive was planned against. Later, in open water TAM standby with no divers, closed bus may be accepted with clear abort criteria — because the consequence of a worse effective failure is tolerable, not because the physics changed.
Operator checklist around WCF
- Know the documented WCF for the operating mode (open/proven closed).
- Know which thrusters and power remain after it.
- Compare present weather and heading to post-WCF capability, not only intact.
- Keep CAM configuration so residual assets are real (enabled, powered, deployed).
- Treat configuration changes that worsen effective residual as stop-work triggers until reassessed.
Bottom line: WCF is the single (or defined design) failure that most reduces DP capability; residual plant after WCF drives capability plots and planning; on open bus it is often one bus/thruster group rather than total blackout; and multi-simultaneous independent failures are not the definition of WCF on the exam.
What does Worst Case Failure (WCF) mean in DP Class 2/3 practice?
On a Class 2 vessel running open bus with thrusters split across two independent sections, what is most often the design WCF picture?
Why is post-WCF capability used for critical operational planning?
Which statement is an exam trap rather than a correct WCF principle?