15.1 Multi-System Failure Scenarios
Key Takeaways
- Multi-system failures combine power, PRS, thruster, and control degradations so residual capability after the design WCF can disappear even when each fault alone looks survivable
- Priority order under stress is protect people and external work first, declare ASOG status, contain the plant (open bus / restore generation), fix bad references before they drive-off, and use IJS or manual only with a clear plan
- A consequence analysis alarm is an operational trigger, not a decorative HMI colour — it links residual WCF capability to graded ASOG action
- Drive-off from overweight or faulty PRS requires rapid deselection or mode change; drift-off from blackout or thruster loss needs recovery and weather-aware escape, not thruster commands that do not exist
- Inside the 500 m zone, blackout or major degradation is a worksite emergency: communicate, protect divers/gangway/load, and move to a safe condition on the agreed escape path
Why single-system chapters are not enough
Earlier chapters treat power, position references, thrusters, FMEA/WCF, consequence analysis, and ASOG/CAM as separate topics. On the bridge — and on Phase A MCQs and Phase C simulator runs — failures stack. A generator trip during diving is manageable if residual thrusters, open bus, and three healthy PRS families remain. The same trip becomes a crisis if the plant is closed-bus, one DGNSS is already rejected, a thruster is deselected for maintenance, and consequence analysis is yellow. Integrated operations means linking those facts into one decision tree instead of treating each alarm as an isolated riddle.
This section walks multi-system scenarios with priority actions. Memorise the sequence before the details: protect people and external work → declare ASOG status and communicate → secure residual plant → stop bad references from driving thrusters → recover position only when power and sensors support it.
The operator decision tree (exam-stable skeleton)
| Priority | Question | Typical tools / actions |
|---|---|---|
| 1. People & task | Are divers, gangway users, crane load, or ROV at immediate risk? | Notify dive/crane/ROV control; start time-to-terminate recovery if ASOG red or trending red |
| 2. Status colour | What does the active ASOG say for this plant/environment state? | Green continue / advisory notify-modify / red suspend-abort |
| 3. Power partition | Open or closed bus? Generators online both sides? Spinning reserve? | Start standby gens; open ties if unproven closed bus is cascading; follow blackout recovery if dead |
| 4. Thrusters | Which thrusters still produce force on residual power? | Confirm enables; do not command dead thrusters; reallocate if needed |
| 5. References | Is a bad PRS driving position? Enough independent families? | Deselect/reject bad PRS; restore voting; prevent drive-off |
| 6. Control mode | Auto DP still safe, or need IJS / manual / escape? | Independent Joystick (IJS) as trained backup when auto is untrusted; escape path if required |
| 7. Residual proof | Does consequence analysis still say post-WCF hold is possible? | If no → red path for critical work even if position looks fine now |
[!IMPORTANT] Exam trap: “Position is still holding, so ignore the yellow/red ASOG and consequence alarm.” Holding now is not the same as surviving the next design failure or stopping a drive-off already in progress. Class 2/3 thinking is residual-capability thinking.
Scenario 1 — Lose one DGNSS while a closed-bus generator trips
Setup: Construction vessel in closed bus near a structure (not yet full CAM open-bus philosophy). Two DGNSS, one taut wire, one laser. One generator trips; PMS redistributes load. Simultaneously DGNSS-A is rejected for multipath. Position still looks smooth on the remaining mix.
What is really happening:
| Layer | Degradation |
|---|---|
| Power | Spinning reserve falls; on closed bus, a second electrical event can black all thrusters |
| PRS | One absolute family lost; voting thinner; higher weight on remaining DGNSS/laser/taut wire |
| WCF picture | Effective worst residual may already be worse than open-bus design WCF |
| Consequence analysis | May go advisory/yellow as reserve and thruster margin shrink |
Correct priority actions:
- Notify Master / client / worksite per ASOG advisory — do not “watch quietly.”
- Start standby generation immediately; restore spinning reserve.
- Treat closed bus as elevated risk: if company CAM for this proximity requires open bus, open the bus-tie when safe (or abort critical phase until plant matches CAM).
- Confirm PRS: enable alternate absolute if available; do not overweight the remaining DGNSS; verify laser/taut wire health.
- Re-check consequence analysis and residual thruster set; if red for proximity work → suspend critical activity, open footprint / move clear on escape heading.
- Log the event; do not restart critical work until plant and references meet CAM floors.
Wrong actions: closing more common-mode links to “share reserve”; raising bad DGNSS weight to “smooth the plot”; continuing critical work because the footprint is still small for thirty seconds.
Scenario 2 — Drive-off from bad PRS weight
Setup: Dive support vessel in Auto DP, CAM, open bus. Three PRS enabled. A relative laser locks onto a wrong target (or jumps after vessel/target move). Operator or auto-weighting gives the laser high weight. Thrusters drive hard toward the false position — drive-off toward or away from the worksite.
Recognition cues: thrusters working hard; position error growing on other references; model/current estimates odd; laser alone “happy.”
Correct priority actions:
- Stop the wrong command path — deselect/reject the faulty PRS immediately; if auto is still fighting, drop to a trained IJS or backup mode per company procedure so thrusters no longer chase the bad fix.
- Protect divers — alert dive control; if excursion risk is high, begin emergency recovery / ASOG red path without waiting for a perfect diagnosis speech.
- Rebuild a trustworthy sensor set — re-enable independent families (DGNSS, acoustics, taut wire) that still vote cleanly; never re-admit the suspect laser until verified.
- Only return to Auto DP when references, power, and thrusters are coherent and ASOG is no longer red.
- Debrief: common-mode and weighting discipline prevent recurrence.
| Drive-off clue | Drift-off clue |
|---|---|
| Thrusters producing force the wrong way | Thrusters dead or powerless (e.g. blackout) |
| Often PRS / sensor / model fault | Often power / thruster / fuel loss |
| First fix: kill bad input / change mode | First fix: restore power and thrust, manage weather drift |
Confusing drive-off with drift-off is a classic Induction trap: you cannot “drive against” a blackout, and you must not leave Auto DP chasing a poisoned reference during a drive-off.
Scenario 3 — Blackout during 500 m zone operations
Setup: Vessel inside the 500 m zone of an installation on approach or station-keeping. Full main blackout — thrusters stop; DP UPS keeps computers and critical sensors alive briefly. Wind and current set the vessel toward the platform.
Correct priority actions:
- Declare emergency — bridge team, engine room, installation as required; this is not a private DPO problem.
- Blackout recovery with engineers: restore generation first (not thruster thrashing on a dead bus); follow vessel blackout checklist; avoid simultaneous thruster inrush that re-trips the plant.
- Manage drift — know set and drift, escape corridor, and whether anchors/tugs/other means exist; if thrusters remain dead, do not pretend Auto DP is working.
- External work — no critical simultaneous ops; if a gangway, hose, or ROV is connected, execute emergency disconnect procedures.
- When power returns: carefully re-enable thrusters, verify PRS, only then Auto DP; leave or hold clear until plant is proven stable — do not immediately resume close approach on a fragile recovery.
- ASOG after blackout in the zone is effectively red until residual capability and configuration are restored.
Scenario 4 — Section loss + thruster fail + consequence analysis alarm
Setup: Open-bus Class 2 vessel in CAM dive. Section A blacks (design WCF). One residual thruster on Section B also fails or is force-limited. Online consequence analysis alarms: post-failure residual cannot hold present weather.
Correct reading: even though open-bus design expected residual thrusters after WCF, two degradations (section + thruster) plus weather put you outside the safety case for diving. The consequence alarm is the mathematical voice of that fact.
Actions: ASOG red — terminate dive (time to terminate already in mind), recover divers, move to safe condition, restore thruster/power, re-run residual check before any return. Do not argue that “we are still Class 2 on paper.” Class notation does not override live residual inadequacy.
Scenario 5 — CAM label without CAM plant (configuration lie)
Setup: Placard says CAM. Bus closed without proven protection; one side single-generator; only GNSS online; thruster deselected. Weather rising; advisory consequence analysis.
Teaching point: multi-system “failure” can be pre-existing configuration debt. The first single fault may produce a plant-wide or common-mode loss the FMEA never accepted for this activity. Correct action is to stop calling it CAM, restore true CAM (open bus or proven closed, generators, thrusters, independent PRS) or downgrade/abort the activity under ASOG — before the fault arrives.
Linking CAM, ASOG red, IJS, and consequence analysis
| Tool | Role in multi-fault response |
|---|---|
| CAM | The plant state you should have entered before critical work so residual after WCF is real |
| ASOG | Colour-coded actions when plant/environment leaves green |
| Consequence analysis | Live check that post-WCF hold still exists in present weather/load |
| IJS | Trained backup control when Auto DP commands cannot be trusted (e.g. drive-off) |
| WCF knowledge | Tells you which thrusters/power should remain after design failure |
Use them together: CAM reduces the chance of Scenario 5; consequence analysis detects Scenario 4 early; ASOG forces Scenario 3/4 red paths; IJS is a surgical tool in Scenario 2 — not a substitute for power recovery in blackout.
Exam and simulator habits
- State the failure type aloud: drive-off vs drift-off vs partial power vs full blackout.
- Name the ASOG colour and the external work action in the same breath.
- Check bus, gens, thrusters, PRS as a set, not one screen only.
- Treat consequence alarms as operational, not optional.
- Prefer early terminate when time-to-terminate is long (dive recovery, gangway, heavy lift set-down).
Bottom line: multi-system scenarios punish single-topic thinking. Integrate power, PRS, thrusters, CAM configuration, ASOG colours, IJS, and consequence analysis into a fixed priority order: people and task first, residual plant and truthful references second, re-entry to critical work only when the residual safety case is real again.
During critical DP work a vessel suffers a drive-off because a relative laser is highly weighted after locking onto a wrong target. What is the best first priority among the following?
A Class 2 vessel in open bus loses one bus section (design WCF) and then also loses a residual thruster on the healthy side; consequence analysis alarms that post-failure capability is inadequate in present weather during diving. What should the DPO conclude?
While on closed bus near a structure, one generator trips and one DGNSS is rejected. Which integrated response best matches good practice?
How does a full main blackout inside the 500 m zone differ from a drive-off in the DPO’s first technical focus?