U Flies / The System Around It

Redundancy is the design philosophy, not a spare part

The interesting question is never whether a component can fail, but what has already been arranged for when it does.

Engineers building anything that carries people begin from an unflattering assumption: every part will eventually fail, every sensor will eventually lie, and every system will eventually be asked to work on a day when something else is already broken. The response is not to hunt for components that never fail, because there are none. It is to arrange matters so that no single failure is decisive. Critical systems are duplicated, often several times over, and frequently built to different designs and driven by different power sources, so that a common cause cannot take them all at once.

The pattern repeats at every scale. Instruments are cross checked against independent instruments. Control paths have alternative routes. Power has multiple sources, including ones that need nothing but the aircraft moving through the air. Aircraft that fly long distances over water or wilderness are certified, routed and equipped on the explicit assumption that they may have to continue and land with less than everything working. The whole architecture is designed backwards from failure rather than forwards from success, which is a strange way to think and a very effective one.

Maintenance follows the same logic. Components are inspected and replaced on schedules set by hours and cycles rather than by whether anyone has noticed a problem, and items that are permitted to be unserviceable are governed by published lists that specify what may be deferred, for how long, and under what conditions. It is bureaucratic in the most literal sense, and that is the point. The aim is a system whose safety does not depend on anyone being lucky, attentive or heroic on any particular day.