14.1 Watchkeeping & Handover
Key Takeaways
- DP watchkeeping is continuous active monitoring of PRS health, power, thrusters, environment, position/heading, and ASOG colour status — not passive screen-watching
- Never leave the DP desk unattended during critical operations; if you must step away, hand control to a competent relief first
- Structured handover covers plant status, faults, setpoints, weather/current, activity phase, ASOG status, and the escape plan
- Fatigue degrades alarm recognition and decision quality; companies may require two-person DP ops for high-consequence work
- Exam scenarios punish silent desk abandonment, incomplete handovers, and ignoring yellow/red ASOG rows during the watch
Watchkeeping is the human half of station-keeping
Dynamic Positioning thrusters and computers can hold a vessel only while the operator keeps the plant, references, and operational limits honest. DP watchkeeping means continuous, active supervision of the DP system and the surrounding operation — not sitting near a green screen while reading email. On the NI Induction MCQ and Simulator path, many “operator judgment” failures are really watchkeeping failures: the plant told the truth; nobody was looking, or the relief was briefed too late.
If earlier chapters taught you what the systems do, this section teaches how you stay present so those systems remain safe for the task.
What continuous monitoring actually covers
A competent DPO on watch scans a priority loop, not a random dart of the eyes. Typical continuous items include:
| Watch item | What “healthy” looks like | Why it matters |
|---|---|---|
| Position & heading | Within footprint/watch circle; heading holds setpoint | Detects excursion before the worksite does |
| PRS health | Required independent references enabled, voting stable, low rejection | Prevents drive-off on bad sensors |
| Power plant | Generators online per CAM/TAM; spinning reserve; bus state matches plan | Residual capability after failure depends on this |
| Thrusters | Enabled set correct; no unexplained force bias or trip | Allocation errors grow footprint or yaw |
| Environment | Wind, wave, current, thruster wash trends | Weather can push ASOG yellow/red while equipment still looks green |
| Sensors | Gyro / MRU / wind voting or comparison healthy | Sensor faults can steer thrusters wrongly |
| ASOG colour status | Green or managed advisory with actions in progress | Status is the operational stop/go language |
| Consequence analysis | Residual after WCF still adequate for the activity | Class 2/3 critical work depends on residual awareness |
| Worksite interface | Dive/crane/ROV phase known; communications open | External activity drives time to terminate |
| Alarms & trends | Acknowledged correctly; root cause pursued | Unacknowledged alarm cascades hide real failures |
Continuous does not mean staring at one pixel. It means a repeatable scan (often every few minutes, denser in critical phases) plus immediate attention when any item degrades.
[!IMPORTANT] Exam trap: “Once Auto DP is selected and green, the DPO can leave the console for an hour because the computer is in control.” Wrong. Automation runs the loop; the operator owns the operation. Critical DP work requires a competent person at the DP desk.
Never leave the DP desk unattended during critical ops
“Unattended” is an exam and incident-investigation keyword. During critical activities — diving, close proximity, heavy-lift critical phases, other CAM-type work — the DP desk must not be empty. If the on-watch DPO must leave (toilet, medical, emergency elsewhere), they must hand over to a competent, briefed relief before walking away.
| Situation | Acceptable? | Correct practice |
|---|---|---|
| Divers in water, DPO steps aft for coffee without relief | No | Call relief; complete mini-handover; only then leave |
| Open-water TAM standby, two DPOs on bridge, one leaves after full handover | Yes if company manning allows continuous cover | Named person remains at desk with current status |
| Critical lift, DPO “just” goes to ECR for five minutes | No unless another competent DPO is already on the desk | Use radio/phone from the desk or relieve properly |
| Simulator exercise with instructor temporarily pausing the run | Training-specific | Follow centre rules; do not generalise pause to real ops |
Companies define manning tables; the exam principle is stable: critical DP = continuous competent presence at the DP control station.
Structured handover — the content that must transfer
Handover is not “it’s green, see you.” A structured DP handover transfers enough state that the incoming operator can continue without rediscovering the plant under pressure. Core content:
- Activity phase — what is happening now (dive bell run, ROV close approach, standby, lift critical window, 500 m entry).
- DP mode and setpoints — Auto/joystick/mixed; position and heading setpoints; any intentional offsets.
- Plant configuration — open/closed bus; generators online; thrusters enabled/deselected; CAM or TAM label with truth check.
- PRS and sensors — which references are selected; known degraded targets; gyro/MRU/wind status.
- Faults, inhibits, and work orders — anything not normal: thruster out of service, PRS noisy, PMS inhibit, temporary jumper notes.
- ASOG colour status and open actions — current band; who was notified; what restoration is in progress.
- Weather and current — present values, trend, forecast window relevance.
- Worksite communications — last agreement with dive control / crane / client; pending movements.
- Escape plan / contingency — preferred exit heading, sea room, emergency abort path, time-sensitive recoveries underway.
- Questions and confirmation — relief repeats critical points; both agree the desk is transferred.
| Handover element | Weak example | Strong example |
|---|---|---|
| Status | “All good” | “ASOG green; open bus; three gensets online; laser + DGNSS + taut wire voting” |
| Faults | “Something with thruster 3 earlier” | “Thruster 3 deselected for seal leak; residual matches CAM if Section B holds” |
| Weather | “Fine” | “Wind 18 kn rising; heading 245° weather-optimal; yellow band at 25 kn” |
| Phase | “Working” | “Divers at 40 m; time to terminate ~35 min; no concurrent crane over the moonpool” |
| Escape | Omitted | “Abort clears to SE; Master briefed; client channel 8” |
Incomplete handovers are a classic root cause when the new DPO “didn’t know thruster 3 was already out” and then loses another thruster into residual-capability failure.
Scan discipline during the watch
Good watchkeepers combine routine scanning with event-driven focus:
- After any alarm: identify source → check position/heading → check residual plant → check ASOG row → communicate.
- After any plant change (generator start/stop, thruster select, PRS enable): re-verify configuration matches CAM/TAM and ASOG green criteria.
- After worksite phase change: re-brief time to terminate and escape plan.
- Before and after meal reliefs or short absences of other bridge team members: confirm DP cover is still continuous.
Do not silence recurring alarms without diagnosis. Repeated “nuisance” alarms are often early PRS degradation or power instability. Simulator examiners watch whether candidates chase root cause or simply acknowledge forever.
Fatigue and two-person operations
Fatigue slows reaction to alarm cascades, shrinks attention tunnel width, and increases risk of accepting commercial pressure (“just five more minutes”). Company SMS, flag, and client requirements increasingly address hours of rest for DPOs the same way they do for navigational officers. Exam-stable ideas:
| Fatigue risk | Operational mitigation |
|---|---|
| Long critical watches | Rotate DPOs; planned reliefs |
| Night + high alarm load | Two-person DP where required; higher scan frequency |
| Back-to-back approaches | Delay non-essential work; do not stack fatigue with proximity risk |
| “Hero culture” staying on past limit | Master/SMS enforcement of rest rules |
Two-person DP operations (two competent persons involved in DP watchkeeping — exact titles vary by company: dual DPO, DPO + assistant, senior + junior) are often required or strongly preferred for:
- diving support,
- close-proximity / 500 m work,
- complex SIMOPS,
- high-traffic or high-alarm periods,
- trainee supervision under a certified DPO.
Two-person ops are not a substitute for competence of the person actually at the desk. They provide cross-check, communication bandwidth, and fatigue resilience. Exam stem: “critical dive, only one uncertified trainee at the desk while the DPO sleeps” → fail.
Worked watchkeeping scenarios
Scenario A — Silent walk-away. During ROV work near a jacket, the DPO leaves for the mess without relief. A laser target is masked; position drifts toward structure. Correct exam judgment: desk abandoned during critical work — primary human-factor failure — regardless of how “green” the last glance looked.
Scenario B — Strong handover. Outgoing DPO uses a written/prompt card: open bus CAM, thruster 2 deselected, ASOG advisory on rising wind, divers recovering (TTT 25 min), escape SE. Incoming DPO repeats back, checks thruster enables and PRS live, accepts the watch. When wind hits yellow, they already know recovery is underway.
Scenario C — Fatigue decision. After 14 hours including two approaches, the client wants a third close pass. Company rest rules and Master judgment delay the pass until a rested DPO is on the desk. Schedule pressure does not cancel watchkeeping fitness.
Scenario D — Incomplete status. Relief is told “position is fine” but not that consequence analysis is advisory and one bus has a generator inhibited. The new DPO continues critical work until a single failure would lose residual. The root error was handover content, not only the later trip.
Exam traps for watchkeeping and handover
| Trap | Correct framing |
|---|---|
| Auto DP = unattended desk OK | Critical ops need continuous competent presence |
| Handover = “green, bye” | Structured transfer of plant, PRS, ASOG, phase, escape |
| Fatigue is personal weakness only | Fatigue is a managed operational risk |
| Two-person ops replace training | Two-person ops support competence; they do not create it |
| ASOG is only for planning meetings | ASOG status is live watch content every scan cycle |
| Escape plan is Master-only secret | Escape plan must be known to the on-watch DPO |
Operator habits that pass exams and protect the worksite
- Keep a mental (or written) scan loop: position → PRS → power → thrusters → weather → ASOG → worksite.
- Treat the DP desk as a critical control station — leave only after proper relief.
- Use a handover checklist every time, including short reliefs during critical phases.
- State ASOG colour and open actions out loud at handover.
- Escalate early when fatigue or alarm load exceeds one person’s bandwidth.
- Never hide defects to “keep the watch looking green.”
Bottom line: DP watchkeeping is continuous monitoring of PRS, power, thrusters, environment, and ASOG status by a present, competent operator. Do not leave the desk unattended during critical operations. Hand over with full status, faults, setpoints, weather, activity phase, and escape plan. Manage fatigue and use two-person operations when consequence and company rules demand it.
During saturation diving under a platform, the on-watch DPO needs to leave the DP desk. What is the correct practice?
Which set of items best describes a structured DP handover?
Why do companies sometimes require two-person DP operations during high-consequence work?
Which behaviour is a classic DP watchkeeping failure on exams and in incidents?