14.2 Checklists, Alarms & Time to Terminate
Key Takeaways
- Location and setup checklists verify power, thrusters, PRS, sensors, mode, ASOG, and worksite readiness before critical DP work starts
- Alarm prioritisation separates critical (immediate threat to position, power, or life) from advisory (degraded margin requiring attention)
- Time to terminate (TTT) is the remaining time needed to safely stop the external activity and move the vessel to a safer condition
- Blackout TTT thinking asks how long residual drift or recovery allows before the worksite becomes unsafe after power loss
- Exam TTT items are conceptual — compare recovery duration to residual margin; they are not heavy formula papers
Checklists turn CAM/ASOG theory into a start gate
You can know Class 2 philosophy perfectly and still enter critical DP work with the wrong bus state, a thruster deselected, or a single PRS family online. Location and setup checklists exist to stop that. They are the operational bridge between planning (capability, ASOG, CAM/TAM) and the moment thrusters take the load near a hazard.
Induction and Simulator assessments reward candidates who treat checklists as verification, not as a tick-box race.
Location / setup checklists before DP
Exact company forms differ. Exam-stable families of checks before entering or continuing critical DP include:
| Checklist family | Typical verification |
|---|---|
| Location / field | Charted hazards, 500 m / safety zones, escape routes, concurrent vessel traffic, water depth for taut wire/acoustics |
| Power | Generators online per mode; bus-tie open/closed as planned; PMS healthy; spinning reserve; blackout recovery readiness |
| Thrusters | Required thrusters available, deployed (if retractable), enabled for DP; no unexpected inhibits |
| PRS | Independent references selected; targets/responders confirmed; voting healthy; known blind sectors |
| Sensors | Gyros, MRUs, wind sensors available and consistent |
| DP control | Correct mode path; setpoints; gains/footprint settings appropriate; consequence analysis reviewed |
| ASOG / documentation | Correct activity ASOG active; colour status green for entry; defects logged |
| Worksite | Dive/crane/ROV ready; communications tested; SIMOPS agreed |
| People | Competent DPO (and second person if required) on the desk; Master/ECR informed |
| Checklist mistake | What it causes |
|---|---|
| Skipping power/bus rows | “CAM” label with closed bus and weak residual |
| Enabling only one PRS family | Common-mode position error risk |
| Ignoring thruster out of service | Residual after WCF weaker than plots |
| Using yesterday’s standby ASOG | Wrong abort criteria for today’s dive |
| No escape route brief | Panic heading into the hazard when aborting |
[!IMPORTANT] A completed checklist is a snapshot. If the plant changes after the tick, re-verify. Checklists do not freeze the universe green forever.
Alarm prioritisation: critical vs advisory
DP bridges can generate many alarms. Safe operators prioritise:
| Priority band | Meaning | Typical DPO response |
|---|---|---|
| Critical | Immediate threat to position-keeping, power integrity, thruster control, or people/worksite safety | Stop non-essential tasks; stabilise position/plant; follow emergency/ASOG red path; communicate worksite stop if required |
| Advisory / caution | Degraded margin, early warning, single-channel fault with residual still OK | Investigate root cause; notify as ASOG yellow requires; restore redundancy; prepare contingency |
| Informational | Status change, completed sequence, low operational impact | Note/log; do not let it mask higher alarms |
Examples of critical-leaning alarms (context-dependent, but exam-recognisable):
- loss of multiple PRS / voting collapse toward single-reference control,
- thruster emergency stop or unexpected full thrust (drive-off suspicion),
- bus section blackout / generator cascade under critical load,
- DP process station failure without healthy changeover,
- consequence analysis residual inadequate during critical work,
- position excursion beyond agreed limits near a structure.
Examples of advisory-leaning alarms:
- one of three gyros disagreed and rejected,
- single generator high temperature with reserve still online,
- one laser target quality drop while two other PRS families remain healthy,
- weather approaching but still inside yellow band with actions defined.
Rules of prioritisation under stress:
- Position and power first — is the vessel about to move dangerously, or is residual power collapsing?
- Do not bury critical alarms under silent-acknowledge spam.
- One root cause may spawn many secondary alarms — find the initiating failure.
- Link alarms to ASOG rows — many “yellow/red” decisions are alarm-driven.
- Never disable critical alarms to keep the screen quiet during client visits.
| Bad habit | Better habit |
|---|---|
| Acknowledge all without reading | Read, rank, act on highest risk first |
| Chase a minor sensor while thruster force is wrong | Fix drive-off / force anomaly first |
| Assume green position means ignore power alarms | Power residual is part of position safety |
| Hide recurring advisory | Treat recurrence as degradation trend |
Time to terminate (TTT) — the core idea
Time to terminate (TTT) is the time required to safely conclude the external critical activity and place people, equipment, and the vessel in a safer condition. It is not merely “how long until we hit the platform if we drift now,” though drift/drive timing informs how much TTT margin you still have.
Think of TTT as a clock that starts when you decide to stop (or when conditions force a stop):
| TTT component | Examples |
|---|---|
| Worksite recovery | Recover divers, land a load, disconnect hose, clear ROV from structure |
| Communication & decision | Notify dive control / crane / Master; get confirmation |
| Vessel manoeuvre to safe condition | Move clear of 500 m zone, open sea room, change heading to escape route |
| Stabilisation | Re-establish comfortable footprint away from hazard |
If divers need 35 minutes to recover safely, you cannot wait until weather or residual capability is already beyond limits and then start recovery. You must start termination early enough that recovery finishes while residual safety still exists.
| Concept | Question it answers |
|---|---|
| ASOG limit | When is status no longer acceptable for the activity? |
| TTT | How long does a controlled stop take once we decide? |
| Margin | How long before we hit the ASOG red / residual cliff? |
| Decision | Start terminate when margin ≤ TTT (plus safety buffer) |
Exam language: “Weather is rising; recovery takes 40 minutes; limits will be exceeded in 25 minutes if the trend continues — when do you start recovery?” Correct conceptual answer: now / immediately, not after the limit is crossed.
Drift-off, drive-off, and blackout TTT thinking
TTT interacts with failure scenarios you studied under drive-off / drift-off and blackout recovery:
| Scenario | Position behaviour | TTT relevance |
|---|---|---|
| Drift-off | Loss of thrust/power → environmental forces move vessel | Estimate whether remaining sea room / time allows safe worksite recovery before contact |
| Drive-off | Uncommanded thruster force moves vessel | May force immediate emergency stop of thrusters/mode change — TTT for people may be shortened by emergency protocols |
| Blackout | Power loss; thrusters stop until recovery | Blackout TTT thinking: how long can the activity remain safe while black, and how long until power/thrusters restore versus when people must already be clear |
Blackout TTT is conceptual on the exam:
- If blackout recovery typically needs several minutes and divers need much longer underwater recovery, diving is planned on residual capability and early abort, not on hoping blackout never happens mid-dive without margin.
- If the vessel is already at ASOG red plant status, do not start a long recovery activity that assumes perfect power.
- After blackout, priorities are safety of people, blackout recovery procedure, and avoiding structure — not finishing commercial task steps.
You are not expected to integrate differential equations of drift. You are expected to reason:
- How long does safe termination take?
- How fast are conditions or failures eating the remaining margin?
- Is residual capability after WCF still enough for that duration?
- If not → terminate earlier or do not start the critical phase.
Worked conceptual TTT examples
Example 1 — Rising weather. Wind still green but trend will reach abort limit in ~20 minutes. Divers need ~30 minutes to recover. Start controlled recovery now (or sooner). Waiting for the red weather number guarantees recovery finishes outside safe limits.
Example 2 — Advisory generator loss. Spinning reserve enters ASOG yellow. ROV can be recovered in 8 minutes; structure is 80 m away in light current. Notify worksite, start standby gen, consider early ROV recovery if residual after next failure would be inadequate — do not ignore yellow because position still looks pretty.
Example 3 — Blackout during close approach. Blackout occurs inside the 500 m zone. Immediate actions follow blackout/emergency procedures; worksite stops external critical tasks as planned. TTT for “finish the survey line” is zero — commercial completion is abandoned.
Example 4 — Checklist prevents TTT crisis. Pre-entry checklist catches taut wire not deployed and only GNSS online. Approach delayed. Better to spend ten minutes on the checklist than invent a TTT plan after common-mode GNSS failure mid-approach.
Linking checklists, alarms, and TTT in one loop
Pre-job: location/setup checklist → CAM/TAM true → ASOG active
│
Watch: prioritise alarms → map to ASOG colour → reassess residual
│
If margin shrinking: compare remaining safe time vs TTT
│
├─ Margin > TTT + buffer → notify, restore, continue if ASOG allows
└─ Margin ≤ TTT + buffer → start terminate / abort path now
Exam traps for checklists, alarms, and TTT
| Trap | Correct framing |
|---|---|
| Checklists are optional if experienced | Checklists are required verification, not ego tests |
| All alarms are equal | Prioritise critical threats to position/power/life |
| TTT starts when you hit the structure | TTT is the controlled stop duration you must finish before limits are gone |
| TTT is only a complex formula exam | NI-style items are conceptual margin vs recovery time |
| Blackout TTT means keep diving until UPS dies | Blackout forces emergency priorities, not task completion |
| Green position cancels yellow power alarms | Power residual is part of future position safety |
Operator habits
- Run the right checklist for this location and activity — not last voyage’s standby list.
- Rank alarms: position/power/critical first.
- Know the worksite’s realistic TTT before the critical phase starts.
- Start termination when remaining margin ≤ TTT plus buffer, not after red is already true.
- After any critical alarm or blackout, drop commercial goals and run emergency/ASOG logic.
Bottom line: Setup checklists prove the plant and references match the job before DP critical work. Alarms must be prioritised — critical threats first, advisories managed, never silenced for convenience. Time to terminate is how long a safe stop takes; compare it to remaining weather/plant margin, including blackout/drift thinking, using conceptual judgment rather than heavy maths.
What is the main purpose of location and setup checklists before critical DP work?
How should a DPO prioritise a cascade of DP alarms during critical work?
Time to terminate (TTT) is best defined as:
Divers need about 30 minutes to recover safely. Weather trend analysis shows ASOG abort limits will be reached in about 15 minutes if the rise continues. What is the correct conceptual decision?