15.1 Multi-System Failure Scenarios

Key Takeaways

  • Multi-system failures combine power, PRS, thruster, and control degradations so residual capability after the design WCF can disappear even when each fault alone looks survivable
  • Priority order under stress is protect people and external work first, declare ASOG status, contain the plant (open bus / restore generation), fix bad references before they drive-off, and use IJS or manual only with a clear plan
  • A consequence analysis alarm is an operational trigger, not a decorative HMI colour — it links residual WCF capability to graded ASOG action
  • Drive-off from overweight or faulty PRS requires rapid deselection or mode change; drift-off from blackout or thruster loss needs recovery and weather-aware escape, not thruster commands that do not exist
  • Inside the 500 m zone, blackout or major degradation is a worksite emergency: communicate, protect divers/gangway/load, and move to a safe condition on the agreed escape path
Last updated: July 2026

Why single-system chapters are not enough

Earlier chapters treat power, position references, thrusters, FMEA/WCF, consequence analysis, and ASOG/CAM as separate topics. On the bridge — and on Phase A MCQs and Phase C simulator runs — failures stack. A generator trip during diving is manageable if residual thrusters, open bus, and three healthy PRS families remain. The same trip becomes a crisis if the plant is closed-bus, one DGNSS is already rejected, a thruster is deselected for maintenance, and consequence analysis is yellow. Integrated operations means linking those facts into one decision tree instead of treating each alarm as an isolated riddle.

This section walks multi-system scenarios with priority actions. Memorise the sequence before the details: protect people and external work → declare ASOG status and communicate → secure residual plant → stop bad references from driving thrusters → recover position only when power and sensors support it.

The operator decision tree (exam-stable skeleton)

PriorityQuestionTypical tools / actions
1. People & taskAre divers, gangway users, crane load, or ROV at immediate risk?Notify dive/crane/ROV control; start time-to-terminate recovery if ASOG red or trending red
2. Status colourWhat does the active ASOG say for this plant/environment state?Green continue / advisory notify-modify / red suspend-abort
3. Power partitionOpen or closed bus? Generators online both sides? Spinning reserve?Start standby gens; open ties if unproven closed bus is cascading; follow blackout recovery if dead
4. ThrustersWhich thrusters still produce force on residual power?Confirm enables; do not command dead thrusters; reallocate if needed
5. ReferencesIs a bad PRS driving position? Enough independent families?Deselect/reject bad PRS; restore voting; prevent drive-off
6. Control modeAuto DP still safe, or need IJS / manual / escape?Independent Joystick (IJS) as trained backup when auto is untrusted; escape path if required
7. Residual proofDoes consequence analysis still say post-WCF hold is possible?If no → red path for critical work even if position looks fine now

[!IMPORTANT] Exam trap: “Position is still holding, so ignore the yellow/red ASOG and consequence alarm.” Holding now is not the same as surviving the next design failure or stopping a drive-off already in progress. Class 2/3 thinking is residual-capability thinking.

Scenario 1 — Lose one DGNSS while a closed-bus generator trips

Setup: Construction vessel in closed bus near a structure (not yet full CAM open-bus philosophy). Two DGNSS, one taut wire, one laser. One generator trips; PMS redistributes load. Simultaneously DGNSS-A is rejected for multipath. Position still looks smooth on the remaining mix.

What is really happening:

LayerDegradation
PowerSpinning reserve falls; on closed bus, a second electrical event can black all thrusters
PRSOne absolute family lost; voting thinner; higher weight on remaining DGNSS/laser/taut wire
WCF pictureEffective worst residual may already be worse than open-bus design WCF
Consequence analysisMay go advisory/yellow as reserve and thruster margin shrink

Correct priority actions:

  1. Notify Master / client / worksite per ASOG advisory — do not “watch quietly.”
  2. Start standby generation immediately; restore spinning reserve.
  3. Treat closed bus as elevated risk: if company CAM for this proximity requires open bus, open the bus-tie when safe (or abort critical phase until plant matches CAM).
  4. Confirm PRS: enable alternate absolute if available; do not overweight the remaining DGNSS; verify laser/taut wire health.
  5. Re-check consequence analysis and residual thruster set; if red for proximity work → suspend critical activity, open footprint / move clear on escape heading.
  6. Log the event; do not restart critical work until plant and references meet CAM floors.

Wrong actions: closing more common-mode links to “share reserve”; raising bad DGNSS weight to “smooth the plot”; continuing critical work because the footprint is still small for thirty seconds.

Scenario 2 — Drive-off from bad PRS weight

Setup: Dive support vessel in Auto DP, CAM, open bus. Three PRS enabled. A relative laser locks onto a wrong target (or jumps after vessel/target move). Operator or auto-weighting gives the laser high weight. Thrusters drive hard toward the false position — drive-off toward or away from the worksite.

Recognition cues: thrusters working hard; position error growing on other references; model/current estimates odd; laser alone “happy.”

Correct priority actions:

  1. Stop the wrong command path — deselect/reject the faulty PRS immediately; if auto is still fighting, drop to a trained IJS or backup mode per company procedure so thrusters no longer chase the bad fix.
  2. Protect divers — alert dive control; if excursion risk is high, begin emergency recovery / ASOG red path without waiting for a perfect diagnosis speech.
  3. Rebuild a trustworthy sensor set — re-enable independent families (DGNSS, acoustics, taut wire) that still vote cleanly; never re-admit the suspect laser until verified.
  4. Only return to Auto DP when references, power, and thrusters are coherent and ASOG is no longer red.
  5. Debrief: common-mode and weighting discipline prevent recurrence.
Drive-off clueDrift-off clue
Thrusters producing force the wrong wayThrusters dead or powerless (e.g. blackout)
Often PRS / sensor / model faultOften power / thruster / fuel loss
First fix: kill bad input / change modeFirst fix: restore power and thrust, manage weather drift

Confusing drive-off with drift-off is a classic Induction trap: you cannot “drive against” a blackout, and you must not leave Auto DP chasing a poisoned reference during a drive-off.

Scenario 3 — Blackout during 500 m zone operations

Setup: Vessel inside the 500 m zone of an installation on approach or station-keeping. Full main blackout — thrusters stop; DP UPS keeps computers and critical sensors alive briefly. Wind and current set the vessel toward the platform.

Correct priority actions:

  1. Declare emergency — bridge team, engine room, installation as required; this is not a private DPO problem.
  2. Blackout recovery with engineers: restore generation first (not thruster thrashing on a dead bus); follow vessel blackout checklist; avoid simultaneous thruster inrush that re-trips the plant.
  3. Manage drift — know set and drift, escape corridor, and whether anchors/tugs/other means exist; if thrusters remain dead, do not pretend Auto DP is working.
  4. External work — no critical simultaneous ops; if a gangway, hose, or ROV is connected, execute emergency disconnect procedures.
  5. When power returns: carefully re-enable thrusters, verify PRS, only then Auto DP; leave or hold clear until plant is proven stable — do not immediately resume close approach on a fragile recovery.
  6. ASOG after blackout in the zone is effectively red until residual capability and configuration are restored.

Scenario 4 — Section loss + thruster fail + consequence analysis alarm

Setup: Open-bus Class 2 vessel in CAM dive. Section A blacks (design WCF). One residual thruster on Section B also fails or is force-limited. Online consequence analysis alarms: post-failure residual cannot hold present weather.

Correct reading: even though open-bus design expected residual thrusters after WCF, two degradations (section + thruster) plus weather put you outside the safety case for diving. The consequence alarm is the mathematical voice of that fact.

Actions: ASOG red — terminate dive (time to terminate already in mind), recover divers, move to safe condition, restore thruster/power, re-run residual check before any return. Do not argue that “we are still Class 2 on paper.” Class notation does not override live residual inadequacy.

Scenario 5 — CAM label without CAM plant (configuration lie)

Setup: Placard says CAM. Bus closed without proven protection; one side single-generator; only GNSS online; thruster deselected. Weather rising; advisory consequence analysis.

Teaching point: multi-system “failure” can be pre-existing configuration debt. The first single fault may produce a plant-wide or common-mode loss the FMEA never accepted for this activity. Correct action is to stop calling it CAM, restore true CAM (open bus or proven closed, generators, thrusters, independent PRS) or downgrade/abort the activity under ASOG — before the fault arrives.

Linking CAM, ASOG red, IJS, and consequence analysis

ToolRole in multi-fault response
CAMThe plant state you should have entered before critical work so residual after WCF is real
ASOGColour-coded actions when plant/environment leaves green
Consequence analysisLive check that post-WCF hold still exists in present weather/load
IJSTrained backup control when Auto DP commands cannot be trusted (e.g. drive-off)
WCF knowledgeTells you which thrusters/power should remain after design failure

Use them together: CAM reduces the chance of Scenario 5; consequence analysis detects Scenario 4 early; ASOG forces Scenario 3/4 red paths; IJS is a surgical tool in Scenario 2 — not a substitute for power recovery in blackout.

Exam and simulator habits

  1. State the failure type aloud: drive-off vs drift-off vs partial power vs full blackout.
  2. Name the ASOG colour and the external work action in the same breath.
  3. Check bus, gens, thrusters, PRS as a set, not one screen only.
  4. Treat consequence alarms as operational, not optional.
  5. Prefer early terminate when time-to-terminate is long (dive recovery, gangway, heavy lift set-down).

Bottom line: multi-system scenarios punish single-topic thinking. Integrate power, PRS, thrusters, CAM configuration, ASOG colours, IJS, and consequence analysis into a fixed priority order: people and task first, residual plant and truthful references second, re-entry to critical work only when the residual safety case is real again.

Test Your Knowledge

During critical DP work a vessel suffers a drive-off because a relative laser is highly weighted after locking onto a wrong target. What is the best first priority among the following?

A
B
C
D
Test Your Knowledge

A Class 2 vessel in open bus loses one bus section (design WCF) and then also loses a residual thruster on the healthy side; consequence analysis alarms that post-failure capability is inadequate in present weather during diving. What should the DPO conclude?

A
B
C
D
Test Your Knowledge

While on closed bus near a structure, one generator trips and one DGNSS is rejected. Which integrated response best matches good practice?

A
B
C
D
Test Your Knowledge

How does a full main blackout inside the 500 m zone differ from a drive-off in the DPO’s first technical focus?

A
B
C
D