What is Fault Tree Analysis?
Fault tree analysis (FTA) is a systematic risk analysis technique used to identify and visualize potential failures within a system, focusing on their root causes and the events that could lead to undesired outcomes, such as system malfunctions or safety hazards. FTAs are widely used in high-risk industries—such as aerospace, healthcare, and engineering—to enhance safety, improve reliability, and inform decisions.

The Basic Idea
Imagine that your car headlights fail to turn on automatically when it gets dark. To properly fix the issue and be on your way, you must first identify the cause of failure. There are two common reasons: either the electrical system or the physical bulbs are failing. To determine what is causing either the electrical system or bulbs to fail, you can conduct a fault tree analysis.
The purpose of a fault tree analysis is to systematically and logically break down a problem into its possible causes, helping to identify the root cause and prevent similar failures in the future. In a fault tree analysis, the fault is described as the top-level or top event. Next, intermediate events are identified—in this case, electrical system failure or auto part failure. Since either of these intermediate events would lead to the top event, they are represented through an “OR” logic gate, which shows that either event is sufficient to lead to the top-level event. Next, you would map out the basic events that could lead to these two intermediate events, such as a faulty sensor or bulb.1

Conducting an FTA has helped you to outline the logical relationships between events, providing you with a visual diagram to find the root cause of the problem. Now that you’ve identified the basic events, you can further investigate the source of the failure by testing the sensors or examining the light bulbs for physical damage.
Fault tree analyses allow us to understand the relationships between events in a complex system and tackle problems methodically, exploring each event to ultimately determine the root cause of the issue.2 FTAs are primarily used in industries with complex systems—such as the automotive and aviation industries, energy and power generation, or manufacturing—where safety, reliability, and risk management are critical.
“The fundamental concept of a Fault Tree Analysis is the translation of the failure behavior of a physical system into a visual diagram and logic model... A very simple set of rules and symbols provides the mechanism for analyzing very complex systems, and complex relationships between hardware, software, and humans.”
— Clifton Ericson II, an expert in system and software safety and reliability and author of multiple books on fault tree analysis.4
Key Terms
Top (Level) Event: The issue or error that requires an investigation. Top-level events only have inputs.5
Intermediate Events: Events that could lead to the top-level event, caused by one or more basic events. Intermediate events have both outputs (the top event) and inputs (basic events).5
Basic Events: The root cause(s) that led to the problem that is being diagnosed.6
Underdeveloped Event(s): A cause or event that requires further investigation because of insufficient information.6
Logic Gate: Symbols in a fault tree analysis that represent how intermediate events connect to an outcome. The two most common types of logic gates are the “AND” gate (each of the events has to happen for the problem to occur) and the “OR” gate (any of the events occurring will lead to the issue).2
Probability of Failure: Conducting quantitative analysis to determine the probability of a basic event failing to understand its likelihood of contributing to the top event.7
Root Cause Analysis: A broader methodology that aims to solve problems by finding the underlying cause rather than solely addressing the symptoms. Fault tree analysis is a specific technique of root cause analysis.
History
As nations across the globe began to develop nuclear weapons, the U.S. Air Force developed the Minuteman Intercontinental Ballistic Missile (ICBM) System as part of its strategic deterrent forces.8 The missile is land-based, “ready-to-go,” and can carry nuclear warheads over long distances. The ICBM System required the U.S. Air Force to store highly dangerous missiles to deploy in the event of an attack by another nation, which meant that if anything went awry, there was a lot at stake.
In 1961, Harold Watson and Allison Bothwell Mearns from Bell Labs, a pioneering research and development company, designed a system in collaboration with the U.S. Air Force to analyze and prevent system failures for the Minuteman missile system.9 This was one of the first recorded instances of fault tree analysis. Watson and Mearns developed a methodology for evaluating events and their risk of failure to fine-tune the Minuteman project and make it more reliable.
Dave Haasl, who worked for Boeing, recognized the value of fault tree analysis and adopted it for safety evaluation in developing commercial aircraft in 1963. In 1965, Boeing hosted the first System Safety Conference, where multiple companies presented their papers on the value of fault tree analysis. After this conference, the method was adopted worldwide in the aerospace industry.3
In the 1970s, the nuclear power industry saw the impact of fault tree analysis on the aerospace industry and began using it to design nuclear power plants, leading to further advancement and the creation of fault tree software codes.3
People
Harold Watson
A systems engineer for Bell Labs who was asked to evaluate the Minuteman Intercontinental Ballistic Missile Launch Control System under contract with the U.S. Air Force Ballistic Systems Division. Watson developed a top-down approach to evaluate potential faults, ensuring safety and proper deployment.10
Allison Bothwell Mearns
An electrical engineer for the U.S. Air Force and then Bell Labs, Mearns collaborated with Watson to develop the fault tree analysis for the Minuteman ICBM System. During his time at Bell Labs, Mearns also created and owned the patent for prepaid telephone calling cards.11
David “Dave” Haasl
A system safety engineer at Boeing who worked on safety processes and methodologies for complex systems. Haasl recognized the value of fault tree analysis, originally developed for the Minuteman Missile System, and applied it to developing commercial aircraft.3 After leaving Boeing in 1964, Haasl worked as a consultant for fault tree analysis, helping notable clients such as NASA, the National Transportation Safety Board, and the U.S. Army.12
behavior change 101
Start your behavior change journey at the right place
Impacts
Fault tree analysis (FTA) allows us to gain a deeper understanding of complex systems by identifying and mapping out the interdependencies and failure pathways that lead to a top event. This systematic approach not only uncovers potential risks but also helps identify the root causes of issues, enabling organizations to address them before they escalate.
Maps Complex Dependencies
Fault tree analysis is useful for creating a visual and logical representation of a complex system in which multiple processes could lead to a given outcome. Through a visual depiction of a complicated system, fault tree analysis makes it easier for us to understand how various processes interact and, therefore, what measures need to be put in place to prevent failure.2
Additionally, logic gates help to show that these processes are often interdependent, and issues frequently arise due to a combination of factors, similar to the Swiss cheese model. By mapping out the paths that lead to an event and collecting probability data, system engineers can identify where faults may occur and which are most probable so that precautionary steps can be taken before problems arise.13

Addresses Root Causes of Long-term Impacts
When problem-solving, we tend to treat symptoms—the top event—rather than address the underlying issue. For example, if a pipe is leaking, your instinct may first be to cover the crack to stop the leak. However, this is a superficial “band-aid” solution that will likely lead to a repeat issue. A fault tree analysis, on the other hand, would help you identify different failures that could have led to the leak—such as corrosion or incorrect installation—and allow you to address the problem at its root.
By mapping out all of the basic and intermediate events, a fault tree analysis surpasses the quick fix and explores the various factors that may have contributed to the failure, helping organizations find solutions that will have positive long-term impacts.14
Mitigates Risk Proactively
Although we discuss fault tree analysis with respect to finding the cause of a top event, it is often conducted before issues occur by identifying what faults could potentially lead to an undesirable outcome. This allows organizations to manage risk effectively and allocate resources toward ensuring that basic events operate as they should.2
This is especially important for safety in high-stakes industries like nuclear energy and healthcare. If the Minuteman System had failed, that would have led to a nuclear weapon being deployed incorrectly, risking the lives of hundreds and thousands of people.
Controversies
While fault tree analysis is a valuable tool for understanding and mapping out potential risks that lead to failure, that does not mean it’s a fail-proof method. It can be difficult—not to mention costly—to accurately identify every potential risk, and the method tends to place too much focus on a singular top event.
Relies on Expertise of Analysts
To know what factors contribute to a top event, a systems analyst needs to have an expert understanding of the system. Fault tree analysis is conducted on complex systems, and it’s not a sure bet that analysts will be able to accurately identify all the potential failure risks or the probability of them occurring.2 However, computational advancements have led to improved analysis.9
Even if a company has the appropriate personnel and tools available to conduct an accurate fault tree analysis, for complex systems, this can be quite timely and expensive—all to discover faults that may not occur. If the top event is an issue that would not be too damaging or costly, a fault tree analysis may not be the most appropriate risk management tool, which is why the method is primarily used in high-stakes industries.
Assumes Binary of Failure or Success
The theory behind fault tree analysis relies on the premise that a system (and all of its events) will either perform successfully or fail. This is a binary assumption that doesn’t allow for the possibility that some events may not perform optimally but could still lead to a path of success.15
While this perspective allows us to create a manageable model for a complex system, real-world events do not usually fit so neatly into the categories of success or failure. That means that the risk assessment may be inaccurate and possibly overestimate the likelihood of failure.
Explores Singular Issues
Although a fault tree analysis explores multiple interdependent causes behind an issue, it can only explore one top event at a time.16 In a complex system, there are usually many potential unwanted outcomes. Focusing on a single top event can cause a company to focus all its resources on preventing one issue while ignoring other potential issues, at least temporarily.
For example, an aviation company may be trying to prevent the top event of an airplane crash. While this may be the most important failure to avoid, there are other potential issues that a company needs to be aware of to be successful. Perhaps the engineering of the safest aircraft is a design that would lead to decreased capacity or comfort—not catastrophic issues, but they could cause an airline to be unsuccessful as a profitable company. This highlights the challenge of balancing safety with other operational and business considerations. Before putting a change identified in an FTA into effect, organizations should investigate how it will impact other aspects of business.
Case Studies
Applying Fault Tree Analysis to Prevent Surgical Mistakes
Although rare, wrong-site surgery (WSS)—when a surgery is performed on the wrong person or wrong organ, limb, side, or vertebral level—affects hundreds of patients each year.17 This clearly adversely impacts the patient but also has negative consequences for the hospital, with time and resources wasted.
Since WSS is a rare occurrence, finding ways to prevent it is difficult when only looking at a single hospital or even multiple hospitals. Instead, a system-level fault tree analysis that explores the process for scheduling a patient operation and analyzes where errors may occur can help to diminish the number of wrong-site surgeries.
Researchers from the Center for Healthcare Studies in Chicago completed a fault tree analysis to understand how individual faults in the scheduling of a patient operation contribute to the top event of wrong-site surgery. They gathered data through a literature review of articles that discussed the occurrence of WSS and analyzed what potential basic and intermediate events occur within three process categories: prior to the day of surgery, pre-operative day of surgery, and intra-operative day of surgery.
After analyzing potential faults, the researchers determined the probability of each fault occurring and discovered the three events that are most likely to contribute to a WSS: transcription errors in documents prior to the day of surgery, failure of intraoperative verifications, and omitting steps on the day of surgery verification.
While prevailing assumptions about wrong-site surgery suggested that WSS occurs because of a high case volume, the fault tree analysis revealed that it is more likely due to a lack of reliability within the scheduling system and provided insight into which areas should be focused on to avoid future incidents.
Fault Tree Analysis for Railroad Crossing System Safety
Deutsche Bahn AG, the national railway company in Germany, developed a new railroad crossing system that used radio communication and software computations instead of physical sensors and signals.18 The radio-based system was created to reduce costs and increase flexibility, but before being implemented, Deutsche Bahn had to ensure that it was a safe approach.
The company conducted a fault tree analysis, exploring what events could lead to a collision. They identified that the top event (collision) could occur for two reasons: either because the train passes the crossing while barrier arms are not lowered, even though no signal has been sent to the train to continue (in this case, this indicates an error in the train’s system or a misjudgment by a conductor), or that the train does receive a signal when it shouldn’t as the barriers are not lowered, and proceeds.

Deutsche Bahn AG explored what errors in the radio communication and software computation system could lead to one of these two intermediate events occurring, which in turn would likely lead to the top event. This allowed them to highlight potential causes and implement new safety measures for the radio railroad crossing system to make it more reliable prior to launch.
Related TDL Content
How to Run Scenario Planning Drills: A Cybersecurity Risk Management Solution
Fault tree analysis helps companies identify potential failures before an issue arises and understand what factors may contribute to it. Essentially, this provides a roadmap for quickly addressing an issue if it occurs. In this article, our writers, Lindsey Turk, Dan Pilat, and Research Director Dr. Brooke Struck, explore the benefits of preparation through scenario planning drills when it comes to cybersecurity attacks with Cybersecurity Leader Michael Coden.
The Peltzman Effect
Fault tree analysis helps organizations implement safety measures in high-stakes industries where safety is of the utmost importance. However, according to the Peltzman Effect, when safety measures are implemented, people actually tend to increase their risky behavior as they do not perceive as much risk. In this reference guide, we explore why this occurs and how implementing too many safety measures may backfire.
Sources
- Zhao, Z. (2023). Vehicle fault diagnosis using FTA and FMEA method. Applied and Computational Engineering, 6(1), 159–164. https://doi.org/10.54254/2755-2721/6/20230758
- IBM. (n.d.). Fault tree analysis. Retrieved January 6, 2025, from https://www.ibm.com/think/topics/fault-tree-analysis
- Ericson, C. A. (1999). Fault tree analysis: A history. Proceedings of the 17th International System Safety Conference. Retrieved from https://ftaassociates.com/wp-content/uploads/2018/12/C.-Ericson-Fault-Tree-Analysis-A-History-Proceedings-of-the-17th-International-System-Safety-Conference-1999.pdf
- Ericson, C. A. (n.d.). Clif Ericson biography. Retrieved January 6, 2025, from http://clifericson.com/ClifEricsonBio.html
- Fiix Software. (n.d.). Fault tree analysis. Retrieved January 6, 2025, from https://fiixsoftware.com/glossary/fault-tree-analysis/
- Mister Simplify. (2019, April 9). Fault tree analysis explained with examples - Simplest explanation ever [Video]. YouTube. https://www.youtube.com/watch?v=dKtIG0UXS6Y
- Zoidii. (n.d.). Fault tree analysis. Retrieved January 6, 2025, from https://zoidii.com/glossary-post/fault-tree-analysis
- U.S. Air Force. (n.d.). LGM-30G Minuteman III. U.S. Air Force. Retrieved January 6, 2025, from https://www.af.mil/About-Us/Fact-Sheets/Display/Article/104466/lgm-30g-minuteman-iii/
- Kumar, B. (2024, April 6). Let’s learn fault tree analysis (FTA). LinkedIn. https://www.linkedin.com/pulse/lets-learn-fault-tree-analysis-fta-balwinder-kumar-gn3lc/
- Chethana, A. (2016, October 23). Fault tree analysis seminar report. SlideShare. https://www.slideshare.net/slideshow/fault-tree-analysis-semiar-report/67542161
- Dignity Memorial. (n.d.). Allison Mearns. Dignity Memorial. Retrieved January 6, 2025, from https://www.dignitymemorial.com/obituaries/newton-nj/allison-mearns-11385154
- The World Link. (2015, March 10). David Haasl. The World Link. https://theworldlink.com/news/local/obituaries/david-haasl/article_0995c8dc-83f2-5e71-9e55-dfaae6316b39.html
- SafetyCulture. (2024, May 14). Fault tree analysis. SafetyCulture. https://safetyculture.com/topics/fault-tree-analysis/
- Eisner, C. (2022, October 31). Fault tree analysis. MaintainX. https://www.getmaintainx.com/learning-center/fault-tree-analysis
- Fussell, J. B. (1975). A review of fault tree analysis with emphasis on limitations. IFAC Proceedings Volumes, 8(1), 552–557.
- Hessing, T. (n.d.). Fault tree analysis. Six Sigma Study Guide. Retrieved January 6, 2025, from https://sixsigmastudyguide.com/fault-tree-analysis/
- Abecassis, Z. A., McElroy, L. M., Patel, R. M., Khorzad, R., Carroll, C. IV, & Mehrotra, S. (2014). Applying fault tree analysis to the prevention of wrong site surgery. Journal of Surgical Research, 193(1), 88–94. https://doi.org/10.1016/j.jss.2014.08.062



















