Study for the advanced DP level by mastering five distinctions and applying them under time pressure: (1) drift-off is lost thrust, drive-off is wrong thrust; (2) equipment class is fixed by design, activity mode is chosen per task from the DP activity plan; (3) two agreeing references of the same type prove less than one independent reference; (4) an FMEA documents design intent, consequence analysis governs the live task; (5) still holding position does not mean the vessel still meets the task's required mode. Practise the decision loop - signature, independence, consequence, decision, log - on linked-failure drills until each step is automatic.
Drift-off and drive-off: opposite failure motions need opposite responses
Drift-off is a loss of thrust: the vessel gives way to environmental force and moves off station comparatively slowly. Drive-off is unwanted thrust: the vessel powers away at full output. They demand different immediate actions.
In a drift-off, a major power or thruster failure removes holding force, and the vessel accelerates downwind or down-current. Because of the vessel's mass, it keeps travelling a meaningful distance even after the environment's push is resisted again. Your response is to stop or limit the task, bring remaining thrusters to bear deliberately, and apply the abort criteria in the DP activity plan rather than chasing position aggressively with a weakened plant.
In a drive-off, the plant is usually intact but actively harmful: a control or feedback fault drives thrusters at full output in the wrong direction. This is the fastest excursion and the one where seconds matter most, so the priority is cutting or reducing erroneous thrust quickly, for example through the DP system's thrust-reduction or abort functions. Recognising which motion you are watching, from the speed profile and the alarm pattern, is the first decision of any excursion.
| Feature | Drift-off | Drive-off |
|---|---|---|
| Underlying cause | Power or thrust lost; holding force insufficient | Erroneous position command or feedback; thrust applied wrongly |
| Typical speed profile | Gradual acceleration, longer stopping distance | Rapid excursion at high thrust |
| Operator priority | Protect the task, redistribute remaining thrust, follow abort criteria | Reduce erroneous thrust output immediately |
| Why the distinction matters | Plant is damaged, so recovery is a capability problem | Plant is healthy but dangerous, so recovery is a control problem |
Equipment class is designed in; activity mode is chosen for the task
DP equipment class describes the redundancy built into the vessel. DP activity mode is the operational standard a specific task requires. A strongly redundant vessel can still lawfully operate in a lower activity mode when task risk allows.
Under the IMO guidelines for DP vessels, equipment Class 1 means a single fault may cause loss of position. Class 2 means redundancy is provided so that no single fault causes loss of position. Class 3 extends that to any single fault, including fire or flooding in any one compartment. Class is fixed by design and demonstrated through analysis and trials; an operator cannot change it at sea.
Activity mode is a live operational choice documented in the DP activity plan. Consequence analysis compares the worst-case single failure with the current operation and shows the resulting safe operating envelope. A Class 2 vessel may perform a low-consequence transfer in a Class 1 activity mode, but it cannot legitimately perform a task whose plan requires Class 3 mode. The mode decision flows from the plan and the consequence result, never from how stable the vessel happens to feel at that moment.
Position references: why two agreeing sources are not proof of truth
A DP controller needs references with different failure modes. Agreement between two references of the same type can conceal common-mode error, so independence and quality indicators matter more than simple vote counting.
Common references include DGNSS, hydroacoustic systems, taut wire, and laser or radar-based systems, each vulnerable to different conditions: signal interference for satellite systems, acoustic conditions for subsea systems, weather and surface clutter for optical and radar types. The operator's job is to watch reference quality, disagreement trends, and error indicators continuously, and to ask whether the sources in use can fail in the same way at the same time.
That question became urgent industry-wide when IMCA published guidance on GNSS jamming and spoofing and their operational impacts on DP, and when the Nautical Institute highlighted jamming detection for seafarers. Interference can make same-type references drift together, which is exactly the situation vote counting handles badly.
Run this worked case: a DP 2 survey vessel holds over a site with two DGNSS receivers and one hydroacoustic reference. Over several minutes both DGNSS positions drift about eight metres east while the acoustic reference stays on the target.
- Plausible mistake: the operator sees two references agreeing against one, concludes the acoustic system is faulty, and deselects it.
- Better decision: treat identical simultaneous drift of two same-type references as a common-mode signature, possibly interference or spoofing. Keep the independent acoustic reference in the solution, cross-check with a fixed visual or radar range, brief the master, and review the DP activity plan.
- Why it matters: the controller follows the selected references. Deselecting the one healthy independent input hands the vessel to the compromised source.
FMEA, assurance trials, capability plots and consequence analysis do different jobs
The FMEA proves the design intent; periodic DP assurance trials re-prove the systems; capability plots show environmental limits with the full plant; consequence analysis compares the worst-case single failure with the live task.
A failure mode and effects analysis identifies single failure points and verifies that redundancy behaves as designed, producing statements such as: loss of any one generator must not cause loss of position. Its value to a working operator is knowing the documented worst-case failure for your specific vessel, including which recovery actions are automatic and which are manual. Re-read it before a new operation rather than assuming all DP vessels behave alike.
Do not conflate the related tools. A capability plot shows where the vessel can hold station with its complete plant in given wind and current; it answers whether you can survive the present environment. Consequence analysis predicts the effect of losing the largest remaining contributor while on task, often displayed as an operating radius; it answers whether you can survive the next failure. Assurance or annual trials periodically re-prove the systems against the FMEA, and their results belong in the vessel's DP documentation, not in an operator's memory.
Loss of redundancy mid-task: a worked decision on a Class 2 vessel
A single failure that leaves the vessel unable to meet the task's required activity mode ends that mode, even if position is still being held perfectly. The DP activity plan and the consequence result drive continue, step down, or abort.
The principle is that a vessel can hold position and still be unsafe for the task, because redundancy exists to survive the next failure, not the last one. After a failure, the consequence analysis result, not the calm picture on the screen, determines whether the assigned activity mode is still met. This is why the plan defines modes per task phase in advance: it removes the temptation to renegotiate safety margins during a busy watch.
Second worked case: a Class 2 vessel conducts a subsea task whose DP activity plan assigns DP Class 2 activity mode, with the plant split. A main generator trips during the critical phase, and consequence analysis shows the remaining plant can no longer meet the required mode.
- Plausible mistake: the operator keeps working because position is stable and the console looks calm, deferring any decision until the task finishes.
- Better decision: run the consequence analysis, confirm the required mode is no longer met, brief the master, and either step the task down to a mode the remaining plant supports or abort and secure the operation. Log the event and report it under the vessel's procedures and applicable industry DP reporting schemes.
- Why it matters: continuing silently converts a designed-for failure into unmitigated exposure to the next one.
Power plant choices: split bus, closed bus and blackout recovery
Bus configuration trades electrical flexibility against fault propagation. Closed-bus operation shares generators and load but can spread a severe fault across the plant; splitting protects but reduces post-failure thruster availability.
With a closed bus, all main generators run synchronised and the full thruster set is available, which simplifies power management. The cost is that a severe electrical fault can propagate and trip the whole board. Whether closed-bus operation is permitted for a given vessel and task is determined by the vessel's studies and FMEA, so the operator's answer comes from the ship's own documentation rather than from general preference.
With a split bus, a fault in one section leaves the other running, but thrusters supplied by the faulted section are lost and the DP system must redistribute thrust, changing capability immediately. Know the blackout picture too: the emergency generator supplies essential services, not station keeping, and uninterruptible power supplies protect control and operator stations for a limited time. For each vessel, list which recovery actions are automatic and which need manual initiation, and rehearse the manual ones.
A two-failure drill you can write, run and score yourself on
Build a paper drill with two linked failures and rehearse the response aloud, step by step. Score yourself against the rubric below, using concrete observations rather than feelings to judge your readiness.
The exercise: sketch a fictional Class 2 vessel on a DP Class 2 activity. Inject failure one, a slow common-mode drift on two same-type position references; five minutes later inject failure two, a main generator trip during the critical task phase. Write out, in order, the alarm responses, the reference-handling decision, the consequence-analysis call, the continue or step-down or abort decision, and every log entry you would make.
Run it in a DP simulator you have legitimate authorised access to, or as a tabletop walk-through against your written script. Expected observations: you recognise the common-mode signature within your routine reference agreement check, keep one independent input, state the required activity mode and the consequence result explicitly before deciding, and produce a log a third party could reconstruct the event from. Score each rubric item from 0 to 2; these are learning milestones only, not predictions of any assessment outcome.
- Named both failure signatures and their different responses without prompting.
- Treated agreeing references of the same type with suspicion and kept one independent source.
- Quoted the required activity mode and the consequence-analysis outcome before deciding.
- Wrote a log entry sufficient for a reviewer to reconstruct the sequence.
- Adaptable preparation sequence: week one, failure motions plus class and mode definitions in your own words; week two, one page per reference system on vulnerabilities; week three, power architecture, capability plots and consequence analysis for a vessel type you know; week four, two linked-failure drills, log writing and an after-action review against this rubric.
References and further reading
Use these references to explore the concepts and check the latest information from the relevant organizations.
