Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the the-events-calendar domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/storm/sites/dev-imca-int-com-1/public/wp-includes/functions.php on line 6114

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the woocommerce-eu-vat-number domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/storm/sites/dev-imca-int-com-1/public/wp-includes/functions.php on line 6114
Power management system dynamic positioning (DP) incident - DEV imca
Skip to content

Power management system dynamic positioning (DP) incident

We have received the following information from a member regarding a power management system (PMS) fault which led to a DP station keeping incident on one of its vessels. This safety flash outlines the incident, the learnings from the incident and the member’s recommendations.

Operational Status

At the time of the incident, the member’s vessel was engaged in routine saturation diving operations and two divers were deployed working inside a subsea jacket within the 500 m zone. The weather conditions were moderate with a wind speed of 30 knots.

The vessel was operating in DP Class 2 with two 2 stern azimuth thrusters and two bow thrusters running with all enabled in the DP system. Three diesel generators were running with the bus tie closed and the other generator was on standby.

The reference systems in use at the time were a DGPS, the port and starboard tautwires and a hydroacoustic reference system.

The Incident

At 1000 hours, due to the increasing weather conditions, a decision was made to start another bow thruster and at 1007 hours the engineers operated the breaker to start the thruster. However, it failed to start and within 10 seconds the two stern azimuth thrusters indicated ‘not ready’ and stopped. The power management system was checked which confirmed that the two stern azimuth thrusters were not in operation. The vessel started to move ahead under the influence of the wind and seas that were from astern.

The Red Abandon Dive Alarm was activated and the divers commenced returning to the bell. The vessel Master, upon hearing the alarm, went to the bridge. The dynamic positioning operator (DPO) changed to DP manual control of the vessel. By this time, the vessel was down wind from her intended position some 15 metres off the platform.

One of the stern azimuth thrusters started and the DPO was able to gain some control by using full thrust astern and selecting yaw to control heading. The other stern azimuth thruster attempted to start causing both stern azimuth thrusters to stop. One stern azimuth thruster again started and the engineers were instructed to leave the situation as it was but the power management again tried to start the other stern azimuth thruster leading to both units again stopping.

The port and starboard tautwires and bow beacon were deployed ahead of the vessel so that the above movements did not make them out of limits at any time therefore they were always available as references.

This sequence of events covered approximately six minutes and resulted in the vessel being a maximum of 40 metres from her intended location before being driven back some 10 metres towards the divers. At approximately 1016 hours the situation was stabilised. The divers were recovered to the bell and the bell was recovered to surface.

Conclusions as to the Cause

The incident is considered to have been caused by a failure of the timer in the bow thruster when starting it which lead to an overcurrent on the bus bar, which, due to the proximity of the control cables of the control system board to the bus bar, caused a partial failure in one of three cards on the control system board.

Two of these control system cards initiated the start/stop sequence for the vessel’s thrusters. It was expected that if a failure occurred on a card the system would fail safe and maintain the status quo, i.e. if thrusters were operating they would continue to operate and the fault in the card would be indicated to the operator.

The situation was further exacerbated by the fact that the control system cards were not sufficiently segregated and that the damaged card contained the control functions for both stern azimuth thrusters which were shut down as a result of this incident.

The DP FMEA for the vessel was reviewed as part of the investigation and it was found that it did not identify the above single point failure. Neither had this fact been identified internally or during annual DP trials and audits which the vessel had undergone since the FMEA was first written. The FMEA has been regularly reviewed since first being produced and the document was on its fifth revision.

Until the incident, it had been considered that a failure of this type was not possible on board the vessel.

Recommendations

As a result of the incident and the findings of the investigation, the company involved has identified a number of recommendations which are set out below:

  1. The control system cards should be reconfigured to bring about a suitable segregation of critical consumers (thrusters and transformers) to remove the single card failure mode affecting systems on both sides of the switchboard.
  2. An independent review of the reconfiguration should be undertaken to ensure that the modification is valid and will not bring about other failures that lead to undesired events.
  3. Protection systems should be installed on the control boards such that the supply to the input channels (from field devices) is galvanically isolated from that used within the board’s processing package. The protection system should be demonstrated prior to acceptance.
  4. The segregation of the data input cables from diesel generator protection units to the control systems cards should be increased to protect the cards from the possibility of an induced current or voltage.
  5. An FMEA should be carried out on the reconfigured vessel management system (power management/integrated control systems) and a trials protocol developed to test and validate the FMEA findings.
  6. A review of other vessels in the fleet vessel management systems should be undertaken to ensure that similar failure mechanisms are not present.

IMCA Safety Flashes summarise key safety matters and incidents, allowing lessons to be more easily learnt for the benefit of all. The effectiveness of the IMCA Safety Flash system depends on Members sharing information and so avoiding repeat incidents. Please consider adding safetyreports@imca-int.com to your internal distribution list for safety alerts or manually submitting information on incidents you consider may be relevant. All information is anonymised or sanitised, as appropriate.

IMCA’s store terms and conditions (https://www.imca-int.com/legal-notices/terms/) apply to all downloads from IMCA’s website, including this document.

IMCA makes every effort to ensure the accuracy and reliability of the data contained in the documents it publishes, but IMCA shall not be liable for any guidance and/or recommendation and/or statement herein contained. The information contained in this document does not fulfil or replace any individual’s or Member's legal, regulatory or other duties or obligations in respect of their operations. Individuals and Members remain solely responsible for the safe, lawful and proper conduct of their operations.