Approach DPM revision by tracing every maintenance decision back to the redundancy group it touches, the capability that remains if that group is lost mid-task, and the document that authorizes the timing. Two worked scenarios, a class-versus-decision table, and a scored paper drill build that reasoning chain.
Why a maintenance task that looks routine can be a single fault in DP terms
DP maintenance decisions are judged against single-fault logic: the work itself can disable redundancy, create cross-connections, or start the very compartment event the design assumes is survivable. Study the fault a task can create, not just the component it services.
Start from the concept of a redundancy group: a collection of equipment whose total loss does not cause loss of position, because the design tolerates any fault confined within one group. Maintenance interacts with this logic because work can bridge groups — a temporary power supply shared across trains, switchboards tied together for the job, a fire door wedged open, or a monitoring loop inhibited. Each of those extends the reach of a single fault beyond the group it was meant to stay inside.
Build the habit of reading what the task procedure actually requires before judging it. Compare two written work orders for the same component: one isolates strictly inside its own group, while the other needs a cross-tie or a shared temporary supply. The second work order changes the vessel's fault tolerance for the duration of the job. Trace that change — from task to group to consequence — rather than judging the component's condition alone; that trace is the reasoning skill this subject turns on.
Telling DP equipment Class 2 and Class 3 apart when planning work
Class 2 assumes no single fault, including loss of any active compartment, causes loss of position; Class 3 additionally assumes a compartment can be lost to fire or flooding. The class defines which maintenance methods the design can absorb.
The equipment classes come from the IMO guidelines for DP systems, which the industry's training and assurance framework builds on. Class 3 adds physical separation on top of Class 2 redundancy: machinery spaces divided by A-class divisions, cabling for redundant services routed apart, and two independent control stations. Those design features are also your diagnostic clue in scenarios — when a question describes two physically separated engine rooms with duplicated control stations, you can justify Class 3 from the design rather than from a stated label.
Worked scenario: a Class 3 construction-support vessel holds position and a technician proposes servicing a switchboard in one machinery room by tying both main boards together through the emergency switchboard for a stable supply. The mistake is approving it because the redundant room is untouched — the cross-tie lets a fault in the worked-on room propagate into the surviving train, and any boundary opened for the work erases the compartment-loss assumption Class 3 rests on. The better decision refuses the tie, keeps isolation inside the single group, and reschedules. It matters because Class 3 station keeping treats the compartment as expendable; the work method quietly revoked that.
| DP equipment class | Single-fault assumption | Design implication | Maintenance decision it drives |
|---|---|---|---|
| Class 1 | Loss of position may follow a single fault | No redundancy required | Critical work normally waits for non-DP periods |
| Class 2 | No single active fault or active compartment loss causes loss of position | Redundant components without physical separation | Work on one train is acceptable if it cannot reach the other train |
| Class 3 | Loss of any single compartment to fire or flood is survivable | Physical separation, segregated cabling, two control stations | Work must not breach separation: no open boundaries, cross-ties, or shared temporary supplies |
How position reference degradation and GNSS jamming should change maintenance timing
Position reference systems degrade before they fail: DGNSS can be jammed or spoofed, acoustics lose signal in poor water conditions, and taut wire drifts with vessel motion. Reported interference should push reference-system maintenance toward windows of maximum remaining redundancy.
Know the systems and their characteristic degradation. DGNSS suffers multipath and is vulnerable to jamming and spoofing — IMCA has published DP-specific guidance on GNSS jamming and spoofing plus a safety flash with a good-practice example, and the Nautical Institute's Navigator addresses jamming detection for seafarers. Hydroacoustic references lose signal through water-column conditions, thruster noise, and weakening transponder batteries; taut wire output drifts with angle sensor error. Each degradation mode suggests a different maintenance indicator to watch.
Worked scenario: a Class 2 vessel holds over a subsea manifold with DGNSS plus two acoustic references, and the electronics room schedules a DGNSS antenna swap. An hour earlier, a neighbouring vessel reported GPS jamming. The mistake is proceeding because the acoustics look healthy — a degraded DGNSS solution can mislead before it alarms, and an antenna swap can momentarily drop the reference feed. The better decision treats the jamming report as a live input, verifies the acoustic references against each other and the vessel's turn behaviour first, and defers the swap until the vessel can tolerate losing a reference cleanly.
Choosing between preventive, corrective and condition-based maintenance on DP systems
Preventive maintenance follows time or running hours; corrective responds to failure; condition-based responds to measured indicators such as vibration, oil analysis, or thermography. On DP-critical equipment, the choice also determines how much warning you get before capability degrades.
Apply each approach with DP examples in mind. Preventive work buys predictability — gyro overhauls at fixed intervals, UPS battery testing on schedule. Condition-based work buys warning time — oil analysis on thruster gearboxes, thermographic surveys of switchboards, insulation resistance trending. Corrective work buys neither: the component has already failed, so a redundancy group is unavailable until the repair completes. The trade-off to internalize is warning versus exposure, because DP capability depends on the worst group's state, not the average.
Connect the choice to redundancy state. Starting planned work while one group has already failed stacks degradations: the vessel is then one fault from losing position by design. A useful discipline in scenarios is to classify the vessel's current state first — healthy, one group under maintenance, or one group failed — before adding any new task. The identical task can be reasonable in the first state and indefensible in the third, and stating that dependence explicitly is what makes the answer complete.
| Approach | Trigger | DP application example | Key limitation |
|---|---|---|---|
| Preventive | Calendar interval or running hours | Gyro overhaul at fixed intervals | Opens a redundancy group regardless of condition |
| Corrective | Reported failure or defect | Repairing a failed UPS module | Leaves a group unavailable until complete |
| Condition-based | Measured indicator against a limit | Thermographic survey of a switchboard | Needs reliable sensors and sound interpretation |
What the FMEA actually constrains when you touch a DP system
An FMEA is a component-level analysis of how a DP system behaves under each fault; proving trials validate it and annual trials reconfirm it. Maintenance and modifications must not invalidate the assumptions the FMEA states.
Define the pieces precisely. The FMEA report describes failure behaviour at component level; proving trials demonstrate that the analysed behaviour matches reality; annual DP trials reconfirm it over time. The related concept of worst-case failure design intent sets the minimum capability the vessel must retain for its intended DP activity. Maintenance enters this picture through assumptions: a like-for-like part swap preserves them, while a different component model, new firmware, or a temporary bypass changes failure modes the analysis took as given.
Apply it as a checklist. Before any modification, ask whether it changes isolation points, alarm behaviour, automatic changeover logic, or anything else the FMEA described. If yes, the change needs assessment — and possibly trials — before the vessel resumes the activity that relied on the original analysis. In paper scenarios, treat the phrases 'temporary bypass' and 'non-identical replacement' as triggers for exactly this line of questioning: what assumption changed, who assessed it, and what evidence now supports the DP capability claim.
Documentation habits that make maintenance decisions defensible
A defensible maintenance decision records the equipment class and DP activity mode, the redundancy group affected, the capability that remains, the guideline invoked, and the evidence — such as a trial result — supporting the timing.
Name the documents that carry these decisions: the DP operations manual, activity-specific operating guidelines (ASOG) or their drilling equivalents with green, amber, and red parameter bands, defect and deficiency reports, and trials records. IMCA's DP station keeping reporting scheme illustrates the wider point — offshore documentation is written for readers beyond the vessel, feeding industry learning. A record that only the writer could interpret serves nobody in that chain.
Train the writing directly. Draft a two-line deferral note naming the class, the affected group, the remaining capability, the authorization relied on, and the trigger for review. Then compare it against a vague version — 'deferred for safety reasons' — and notice what is missing: nothing in the vague version could be challenged, checked, or lifted on a shift change. The specific version is what makes a timing justification complete, because it names the basis a reader would need.
A scored paper drill and an adaptable DPM study sequence
Rehearse with a paper drill: take a simplified vessel, three maintenance tasks, and score yourself on class identification, redundancy-group tracing, capability consequences, and defensible timing. Then follow a sequence from definitions through drills to documentation.
Set up the drill on paper: sketch a simplified two-room Class 3 vessel with its power generation, thrusters, references, and control stations, then write three plausible maintenance tasks against it — one preventive, one corrective, one condition-based. For each task, work the full chain: which redundancy group it touches, what capability remains if that group is lost mid-task, whether it should run during the current DP activity, and which document authorizes the decision. Score yourself against the rubric below and repeat the drill with a different vessel type each time.
Shape the sequence to your timeline. Week one, rebuild definitions and redraw the Class 3 layout from memory, including cabling routing and control stations. Week two, map the three maintenance approaches to a component list with one example each. Week three, run the drill three times across drilling, IMR, and dive-support profiles. Week four, rehearse the documentation language and read IMCA safety flashes and the Navigator's GNSS jamming piece for how interference reports actually read. Scale the weeks to your available time, and remember that administrative details such as scheduling and eligibility belong to the credential issuer — check the Nautical Institute site directly for those.
- Class identification: state the vessel's equipment class and the compartment event it assumes, justified from design features rather than a stated label.
- Group trace: name the redundancy group each task touches and score one point per correct group, plus one per consequence expressed in capability terms rather than equipment terms.
- Timing decision: decide run or defer, and cite the document relied on — a decision without a stated basis scores zero.
- Documentation: write the approval or deferral note in under 100 words; the target is a note a relief colleague could act on without asking a question.
- Milestone: completing a three-task drill in roughly 15 minutes with consistent scoring across all four lines indicates the reasoning is settling in — a learning milestone, not a pass prediction.
References and further reading
Use these references to explore the concepts and check the latest information from the relevant organizations.
