Systems — availability of a redundant supply
Availability of a redundant essential supply, as a reliability block diagram with the arithmetic attached to the blocks. Typed FlowScript for reliability engineering. Keywords: FMEA, failure mode, RPN, reliability.
Make it your own.
// Availability of a redundant essential supply, as a reliability block
// diagram with the arithmetic attached to the blocks.
//
// The system is the essential electrical supply to an eight-theatre suite:
// grid and standby generator in parallel, a pair of UPS modules in
// parallel behind them, and a single distribution board in series with
// everything. Each item's availability is MTBF / (MTBF + MTTR); parallel
// legs combine as 1 - (1-A1)(1-A2); series items multiply.
//
// The generator carries a second number that a pure availability model
// misses: it is only useful if it starts. Start-on-demand reliability is
// folded into its effective availability, which is why the standby leg is
// worth less than its MTBF suggests. The board, with no redundancy at all,
// then dominates the answer — as a single point of failure always does.
availability_model theatre_supply {
title: "Essential supply to theatres 1-8"
scope: "From the 11 kV intake to the theatre isolated-power panels; the IPS transformers themselves are out of scope"
configuration: "(Grid | standby generator) -> (UPS A | UPS B) -> distribution board"
operating_hours: 8760 h
basis: "MTBF from the trust's CMMS 2021-2025; MTTR from contractor attendance records"
requirement: "HTM 06-01: no single failure to interrupt supply to an occupied theatre"
}
supply_item grid_supply {
of: theatre_supply
label: "Grid intake, 11 kV, dual feeder"
mtbf: 4380 h
mttr: 3.5 h
availability: = mtbf / (mtbf + mttr)
unavailability: = 1 - availability
}
supply_item standby_generator {
of: theatre_supply
label: "1.6 MVA standby generator, 15 s start"
mtbf: 8760 h
mttr: 12 h
running_availability: = mtbf / (mtbf + mttr)
start_reliability: 0.995 source "42 monthly black-start tests, 2021-2025"
// A generator that is available but does not start is not available.
availability: = running_availability * start_reliability
unavailability: = 1 - availability
}
supply_item ups_a {
of: theatre_supply
label: "UPS module A, 200 kVA, 20 min autonomy"
mtbf: 26280 h
mttr: 6 h
availability: = mtbf / (mtbf + mttr)
unavailability: = 1 - availability
}
supply_item ups_b {
of: theatre_supply
label: "UPS module B, 200 kVA, 20 min autonomy"
mtbf: 26280 h
mttr: 6 h
availability: = mtbf / (mtbf + mttr)
unavailability: = 1 - availability
}
supply_item distribution_board {
of: theatre_supply
label: "Essential distribution board — no redundancy"
mtbf: 43800 h
mttr: 4 h
availability: = mtbf / (mtbf + mttr)
unavailability: = 1 - availability
}
availability_result theatre_supply_result {
of: theatre_supply
source_leg: = 1 - grid_supply.unavailability * standby_generator.unavailability
ups_leg: = 1 - ups_a.unavailability * ups_b.unavailability
system: = source_leg * ups_leg * distribution_board.availability
unavailability: = 1 - system
nines: = 0 - log10(unavailability)
downtime_per_year: = unavailability * theatre_supply.operating_hours
downtime_minutes_per_year: = unavailability * 525600[min]
// Where the downtime actually comes from: the unredundant board.
board_share: = pct(distribution_board.unavailability, unavailability)
source_share: = pct(1 - source_leg, unavailability)
ups_share: = pct(1 - ups_leg, unavailability)
}
// What a second board would buy, which is the only question the model was
// commissioned to answer.
availability_option second_board {
of: theatre_supply_result
label: "Second distribution board with automatic changeover"
board_pair: = 1 - distribution_board.unavailability * distribution_board.unavailability
system: = theatre_supply_result.source_leg * theatre_supply_result.ups_leg * board_pair
downtime_minutes_per_year: = (1 - system) * 525600[min]
minutes_saved: = theatre_supply_result.downtime_minutes_per_year - downtime_minutes_per_year
capital_cost: 148000
currency: "GBP"
cost_per_minute_saved: = capital_cost / (minutes_saved * 15)
verdict: "A second board removes nineteen twentieths of the expected downtime, because the board is where nearly all of it is. Costed over a fifteen-year life that is about GBP 206 per theatre-minute recovered, which is the cheapest minute of availability on the estate."
}
figure supply_rbd {
title: "Reliability block diagram — theatre essential supply"
width: 900
height: 400
background: "transparent"
}
label_2d {
text: "Source (parallel)"
x: 215
y: 42
anchor: middle
size: 12
weight: bold
color: "#334155"
}
label_2d {
text: "UPS (parallel)"
x: 475
y: 42
anchor: middle
size: 12
weight: bold
color: "#334155"
}
label_2d {
text: "Distribution (series)"
x: 735
y: 42
anchor: middle
size: 12
weight: bold
color: "#334155"
}
shape rbd_grid {
kind: rect
x: 120
y: 62
w: 190
h: 80
r: 6
fill: "#dbeafe"
stroke: "#1d4ed8"
strokeWidth: 1.4
label: "Grid intake"
}
shape rbd_generator {
kind: rect
x: 120
y: 202
w: 190
h: 80
r: 6
fill: "#dbeafe"
stroke: "#1d4ed8"
strokeWidth: 1.4
label: "Standby generator"
}
shape rbd_ups_a {
kind: rect
x: 390
y: 62
w: 170
h: 80
r: 6
fill: "#dcfce7"
stroke: "#15803d"
strokeWidth: 1.4
label: "UPS A"
}
shape rbd_ups_b {
kind: rect
x: 390
y: 202
w: 170
h: 80
r: 6
fill: "#dcfce7"
stroke: "#15803d"
strokeWidth: 1.4
label: "UPS B"
}
shape rbd_board {
kind: rect
x: 640
y: 132
w: 190
h: 80
r: 6
fill: "#fee2e2"
stroke: "#b91c1c"
strokeWidth: 1.6
label: "Distribution board"
}
arrow_2d {
x1: 40
y1: 172
x2: 112
y2: 172
color: "#64748b"
head: none
}
arrow_2d {
x1: 112
y1: 102
x2: 112
y2: 242
color: "#64748b"
head: none
}
arrow_2d {
x1: 112
y1: 102
x2: 118
y2: 102
color: "#64748b"
}
arrow_2d {
x1: 112
y1: 242
x2: 118
y2: 242
color: "#64748b"
}
arrow_2d {
x1: 310
y1: 102
x2: 388
y2: 102
color: "#64748b"
}
arrow_2d {
x1: 310
y1: 242
x2: 388
y2: 242
color: "#64748b"
}
arrow_2d {
x1: 560
y1: 102
x2: 638
y2: 162
color: "#64748b"
}
arrow_2d {
x1: 560
y1: 242
x2: 638
y2: 182
color: "#64748b"
}
arrow_2d {
x1: 830
y1: 172
x2: 886
y2: 172
color: "#64748b"
label: "Theatres"
}
annotation {
target: rbd_board
text: "Single point of failure — most of the expected downtime is here"
offsetX: -40
offsetY: 96
style: footnote
}
note availability_language {
text: "Availability answers how much of the year the supply is there. It says nothing about when: four nines spread as one minute a month reads very differently in an operating theatre from four nines spent in one 53-minute outage. The mitigation for the second is the UPS autonomy, not the availability figure."
anchor: theatre_supply_result
}
view rbd: figure(supply_rbd)