FOM-10.17 Fleet Operations Manual
FOM
Critical Equipment
Doc No.: FOM 10.17
Revision: 01
Date: 15 Oct 2024
Issued by: DPA
Approved by: MD

1. APPLICATION

This document applies to all employees and contracted personnel in the company and fully managed vessels.

2. PURPOSE

To provide clear instructions for the identification, testing and planned maintenance of critical equipment.

3. INTRODUCTION

As per the ISM code, critical equipment, alarms and systems are those of which the sudden operational failure may result in hazardous situations.

ISM Code Paragraph 10.3 states: “The Company should identify equipment and technical systems the sudden operational failure of which may result in hazardous situations. The safety management system should provide for specific measures aimed at promoting the reliability of such equipment or systems. These measures should include the regular testing of stand-by arrangements and equipment or technical systems that are not in continuous use.”

It is essential that procedures are in place for the identification of critical equipment and measures are in place to promote the reliability of equipment identified as critical.

The Company has identified Critical Equipment based on risk assessment described in section 5.

Note:
The list of company identified critical equipment is located in E38 form.

Critical equipment shall be marked for clear identification using Poster 036.

Caution:
Any maintenance on critical equipment shall be in accordance with section 11. E30 – Critical Equipment Maintenance Concurrence Request, HSSEQ-34 -Lock out Tag out shall be completed if any alarm system requires deactivation to facilitate maintenance.

Note:
A dedicated crew member shall conduct fire watch and patrol for the area affected due to deactivation. Records shall be maintained in deck log book and engine log book with details including location, start and stop time of deactivation of fire detection system, signatures of officer and engineer of watch.

4. DEFINITIONS

The following definitions apply for the purposes of this procedure:

Critical Equipment: All Critical Equipment, Systems and Alarms shall be referred to as Critical Equipment.

Hazardous Situation – A situation where harm to personnel or the environment is likely to occur immediately or within a few minutes.

Likelihood – Likelihood of occurrence of adverse effects if potential hazards realize.

Severity – Severity of consequence of adverse effects if potential hazards realize.

Risk – Severity X Likelihood.

Essential Equipment – Any equipment which is intended to mitigate serious potential hazards or is required by class, owner, company policy or other authority.

Critical Equipment – Any essential equipment for which sudden failure or loss of its functionality may result in a hazardous situation. (Will failure or loss of its functionality harm somebody or harm the environment immediately or within a few minutes?).

High Reliability – No major shortcomings in reliability of the equipment and redundancy is available (i.e. back up or alternative equipment is available).

Medium Reliability – Equipment is operational with no major shortcomings in reliability but redundancy is not available.

Low Reliability – Equipment is operational but not dependable and redundancy is not available.

High Risk Equipment – Any equipment with risk level I or II as per the table ‘Reliability and Risk’ contained in E38.

Inoperative – Critical equipment is not able to be used due to planned maintenance or unplanned maintenance as result of breakdown. This does not include routine tests and inspections where equipment is not taken out of service.

5. RISK BASED IDENTIFICATION OF CRITICAL EQUIPMENT

Risk assessment and hazard-identification method is used to facilitate the identification of critical equipment as measures to promote their reliability and to document this process.

Note:
Vessels are required to use E38 to identify any such equipment not listed in section 3 which may be categorized as critical equipment depending on type of vessel, cargo, or area of trade when deemed necessary.

All technical shipboard systems are listed in appropriate functional categories “Technical Ship Systems” (Column A).

For each item, the following questions are consecutively reviewed and answered taking into account the definitions listed in section 4.

  1. The potential hazardous situations if the system is not operational? (ref. definition “Hazardous Situation) (Column B – list down potential hazardous situations)
  2. The Severity if this potential hazardous situation occurs? (Column C) (Risk Matrix: Severity from 1 to 6 – select from drop down list)
  3. The Likelihood of this potential hazardous situation occurring? (Column D) (Risk Matrix: Likelihood from 1 to 6 – select from drop down list)
  4. Risk category is automatically determined based on risk matrix with ratings either being I, II, III. (Column E)
  5. Is this system Essential? (Column F – select “Yes” or “No”)
  6. Will the sudden loss of system functionality result in a potentially hazardous situation? (Column G – select “Yes” or “No”)
  7. The system is automatically identified as “Critical” if Column F and Column G are both “Yes”. If either one is “No”, the system is not “Critical”. This is based on the logic flowchart chart indicated in Figure 1 below. (Column H)
  8. What is required for system reliability for this system? Policy is no unacceptable risk and therefore, all system identified as being ”Critical”, must have “High” Required Availability”. (Reliability and Risk Matrix) (Column I – select either “High”, “Medium” or “Low”).
  9. Vessel specific Data
  10. Is the listed system, alarm or equipment applicable to your vessel? (Column J – select “Yes” or “No”)
  11. What is the “Current Available Reliability” of your system alarm or equipment? (Reliability and Risk Matrix) (Column M – select either “High”, “Medium” or “Low”)
  12. Due to “no unacceptable risk” policy, if “Current Available System Reliability” is less than the “Required Availability”, an automatic notification, “Action Required to Improve Onboard Reliability”, will be displayed. See definition and Reliability and Risk Matrix. (Column N)
  13. If action is required to be taken to improve onboard reliability, outline actions to reduce risk to acceptable levels and / or increase reliability where applicable including achievable target dates and responsible personnel to implement and follow-up. (Column O)
  14. Outline follow-up results of actions taken to reduce risk to acceptable levels and / or increase reliability where applicable including achievable target dates. (Column P)

Figure 1: Simplified flow chart for Risk based Assessment

6. ESSENTIAL EQUIPMENT AND CRITICAL EQUIPMENT

Although it is recognized that each on-board equipment has a measure of importance in the operation of a ship, it is also necessary to ensure that equipment identified as ‘critical’ actually meets the requirements of the definition above in section 4.

Essential equipment can be considered as very important but to a lesser extent when compared with items identified as ‘critical’.

Critical equipment must be given the highest priority in terms of planned maintenance, regular testing and reporting requirements.

A limited list of critical equipment helps to ensure that the most important items are given the highest priority.

A list of critical equipment in an easy to understand format must be included in the ship’s planned maintenance system.

7. RELIABILITY AND REDUNDANCY

Key issues to consider in the identification of critical equipment are reliability and redundancy.

One of the most important equipment reliability design techniques is redundancy. This means that if one part of a system fails, there is an alternate success path, such as a backup system. For example, the Mast lights may use two light bulbs. If one bulb fails, the mast light still operates using the other bulb.

Redundancy significantly increases system reliability, and is often the only viable means of doing so.

Essential equipment which has no redundancy or backup systems may be identified as critical on one ship but the same piece of equipment on another ship may be identified as essential but not critical due to the increased reliability of the equipment provided by system redundancy in the form of one or more backup systems.

Therefore, redundancy can be considered as a measure to promote the reliability of equipment identified as critical.

8. RELIABILITY AND RISK

Having identified the lists of critical and essential equipment it is important to ensure that the risks associated with the use of such equipment are maintained at an acceptable level.

By comparing the required reliability of any equipment with the actual or available reliability of the equipment it can be determined if the equipment is low, medium or high risk.

Note:
Equipment identified as high risk must be subject to additional control measures such as more frequent inspection and testing or a more stringent planned maintenance regime in order lower the risks involved to an acceptable level.

The Reliability and Risk Matrix below, which is also included in E38, provides a short cut between reliability and risk.

Figure 3: Reliability and Risk Matrix

Figure 4: Risk Matrix

9. INSPECTION AND TESTING OF CRITICAL EQUIPMENT

When critical equipment has been identified, it is essential to establish safeguards to ensure functional reliability or the use of back-up arrangements in case of sudden operational failure.

These specific measures must include the regular inspection and testing of stand-by equipment or technical systems that are not in continuous use.

Such inspections and tests should include:

Note:
The required frequency and records of the inspections and tests of critical equipment must be maintained within the ship’s planned maintenance system.

10. CRITICAL EQUIPMENT SPARES

When the critical equipment list for each ship has been identified it is important to assess the requirement of minimum spare parts for each piece of equipment. Any identified minimum spares, if applicable, should be included within the ship’s planned maintenance system.

Certain minimum critical spares for such company identified critical equipment are identified in E38A ‘Risk based identification of critical equipment’, under the sheet ‘critical spares’. In addition to these, minimum spares, and the optimal level of spare parts for each equipment should be determined taking the following factors into consideration:

In case it is identified after a comprehensive review, that a critical equipment may not need a minimum spares stock level to be maintained, the criticality should be managed with thorough implementation of the various other control measures outlined in this document FOM 10.17 ‘Critical Equipment’. Thus, the equipment should be inspected, tested and maintained, and failure management procedures applied; in accordance with the guidelines in the other sections of this document, to ensure equipment availability and reliability.

11. MAINTENANCE OF CRITICAL EQUIPMENT

The work flow for maintenance of critical equipment is as follows:

Planned maintenance Unplanned maintenance (breakdown)
For non-critical equipment For non-critical equipment
HSSEQ-18 Risk assessment for non-routine job or Daily Work Safety Notice HSSEQ-26 for routine job Deficiency created in Technical Deficiency list (TDL- DSM or E24)
PMS to be updated after job completion Risk assessment HSSEQ18
DSM PMS to be updated after job completion
Technical Deficiency list (TD- E24L) to be updated after job completion
E48 specification to be created in case job deferred “For Docking” in TDL
For critical equipment For critical equipment
Risk assessment HSSEQ-18 Deficiency created in Technical Deficiency list (TDL- DSM or E24)
E30 - Critical Equipment Maintenance Permit, Part A to be filled up by ship staff for jobs identified as critical on PMS and send to office along with Risk assessment HSSEQ-18 for comments and concurrence Risk assessment HSSEQ18
E30- Part B to be filled up by Vessel Manager / FGM and Marine Superintendent / Marine Manager for office concurrence* E30-Critical Equipment Maintenance Permit, Part A to be filled up by ship staff for jobs identified as critical on PMS and send to office along with Risk assessment HSSEQ-18 for comments and concurrence
DSM PMS to be updated after job completion E30- Part B to be filled up by Vessel Manager / Tec Director and Marine Superintendent / Marine Manager for office concurrence*
E30 to be filed into File together with correspondence with Office DSM PMS to be updated after job completion
Technical Deficiency list (TD- E24L) to be updated after job completion
E30 to be filed into File together with correspondence with Office
*Concurrence to be provided by (E30 signed by) Tech director in case the maintenance is unplanned or is being carried out within port limits.

Prior to starting any maintenance:

After a permit time has expired and before continuing with the intended maintenance

In case the maintenance has been suspended and prior to resumption of the work

This is not applicable to maintenance carried out when the vessel is in a shipyard or during dry-docking.

The risk assessment must include as a minimum:

12. ADDITIONAL SAFETY PROCEDURES

If the agreed shutdown period for critical equipment or systems is exceeded, any extension or alternative actions must be reviewed by shore management.

A further risk assessment is to be undertaken if circumstances such as environmental conditions, crew fatigue or operational parameters change.

The maintenance of critical equipment must be assigned to appropriately qualified personnel as per section 13.

13. CRITICAL MAINTENANCE ON MAIN ENGINE & AUXILIARY ENGINES

Main Engine and Auxiliary Engines are not categorised as critical equipment, however for main engine and auxiliary engines (on those vessels having only 2 AEs installed or operational), when carrying out maintenance under following circumstances, critical equipment maintenance procedures outlined in section 11 of this document (FOM 10.17 Critical Equipment) should be followed:

E30 (office concurrence) with risk assessment should be carried out for not only the vessels installed with 2 AEs, but also for the vessels where only 2 AEs are functional (i.e. also on the vessel where one out of 3 AEs is out of operation, and the maintenance is required on one of the two available AEs).

14. FAILURE OF CRITICAL EQUIPMENT

Shore management must be informed whenever there is a complete failure in any critical equipment.

This means breakdown resulting in situation where emergency contingency measures need to be implemented regardless of duration of breakdown.

Master is required to notify by phone and email to Vessel Manager at earliest with corrective action plan for rectification.

Any consequent maintenance shall be classified as unplanned and is subject to procedures as per section 11.

Risk Assessment (HSSEQ-18) should be prepared to identify all relevant hazards arising from the defect on the critical equipment, and the control measures required to be exercised for safe operations on board. Risk Assessment should be attached to the respective technical defect in the ‘Technical Deficiency List’ E24 of the vessel.

15. ASSIGNMENT OF RESPONSIBILITIES FOR CRITICAL EQUIPMENT

The Master or Chief Engineer are responsible for ensuring that only appropriately qualified and experienced personnel are assigned to operate or perform planned or unplanned maintenance, testing, inspection, repair or the amending of parameters such as alarm set points of critical equipment.

Maintenance, repair or amending parameters such as alarm set points must always be completed under the direct supervision of the Master, Chief Officer, Chief Engineer or Second Engineer. (TMSA Element 4A, Stage 3.4).

16. REVIEW OF CRITICAL EQUIPMENT

The list of critical equipment for each ship must be reviewed annually or whenever deemed necessary by shore management based on the outcome of ship inspections, audits, fleet statistics, accident, incident and near miss investigation and root cause analysis.