AUS-EC1-L3.3

Automation, control and alarm management

This lesson covers the principles and failure modes of PID control loops, the practical discipline of alarm flood and inhibition management, and the testing obligations for blackout-recovery automation aboard vessels with periodically unattended machinery spaces.

Entry & progression

In an unattended machinery space, the alarm system is your watchkeeper. A chief who does not know exactly what it will and will not tell him has delegated the watch to something he does not understand.

Periodically unattended machinery space operation is the normal condition on most modern vessels, including large yachts. The space is monitored rather than manned. A duty engineer is on call, a bridge alarm repeats machinery faults to the watch officer, and an engineer's-call system escalates if the duty engineer does not answer. MO72 recognises this: service on call in periodically unattended machinery spaces can count as qualifying watchkeeping time.

Control loops, briefly

Most shipboard control is proportional-integral-derivative. Proportional action responds to the size of the error, integral action removes the residual offset over time, and derivative action responds to the rate of change. When a loop hunts - oscillates about setpoint - it is usually over-gained, or the sensor is noisy. When a loop takes forever to settle after a large disturbance, suspect integral windup: the integral term saturated while the actuator sat at its limit, and must now unwind before anything happens. Cascade loops - a slow master trimming a fast slave, as in fuel temperature control - reject disturbances far better than a single loop, but they fail in more interesting ways.

WARNING — Sensors lie, and control systems believe them A control system acting on a failed sensor will drive the plant confidently into the very fault it exists to prevent. Cross-check a critical reading against a second, independent indication before you act on it. The gauge that agrees with the alarm is worth more than the alarm.

Alarm management - the failure nobody plans for

The most dangerous condition of an alarm system is not silence. It is flood. When a single fault cascades two hundred alarms into a panel, the one alarm that mattered is invisible. And the day-to-day version is worse: standing alarms that nobody can clear get inhibited, inhibited alarms get forgotten, and six months later the plant is running with its most important protection switched off and nobody aboard remembers doing it.

  1. Keep an inhibited and suppressed alarm register. Every inhibition written down, with the reason, the person, and a date to restore.
  2. Review it - at least monthly, with the first engineer, and at every handover.
  3. Nothing is inhibited to make the panel quiet. An alarm that is always on is either a real fault or a badly set point. Fix one or the other.
  4. Rationalise the setpoints. An alarm that gives no time to act is not an alarm; it is a notification of failure.
  5. Test the safety trips and shutdowns on a schedule, and record it. A shutdown that has never been proved is a hope.

The automation you must be able to prove

Blackout recovery: emergency generator start, standby generator auto-start and synchronisation, sequential restart of essential consumers, preferential trip or load shedding of non-essential loads. These schemes are elaborate, they are rarely used, and they are exactly the ones that fail when finally called upon. Test them when you can afford to fail - alongside, in daylight, with the department awake - not at 0300 off a lee shore.

Practice questions

5 questions
recallcore

recall · core

In a PID loop, persistent oscillation about setpoint most commonly indicates: (a) Excessive proportional gain, or a noisy sensor (b) Insufficient integral action (c) A failed derivative term (d) A saturated actuator

recallcore

recall · core

The most dangerous condition of a machinery alarm system is: (a) A single unacknowledged alarm (b) Alarm flood - the alarm that mattered lost among hundreds - and the chronic inhibiting of standing alarms that follows (c) An alarm with a conservatively set setpoint (d) A duplicated alarm on the bridge repeat

recallcore

recall · core

An alarm that is permanently standing should be: (a) Inhibited so the panel is quiet (b) Ignored by the watch (c) Treated as either a real fault to be fixed or a badly set point to be corrected (d) Deleted from the alarm list

recallcore

recall · core

Blackout recovery and standby machinery auto-start schemes should be tested: (a) Only during class survey (b) Never, because testing risks a blackout (c) Only after a real blackout has occurred (d) On a schedule, in conditions where a failure is affordable - alongside, in daylight, with the department awake

recallcore

recall · core

A control system acting on a failed sensor will typically: (a) Fail safe and shut the plant down (b) Drive the plant into the very fault it is intended to prevent (c) Raise a sensor-failure alarm in all cases (d) Revert automatically to manual control

AI-drafted catalogue content pending SME review. Sea service and course requirements change; verify with AMSA before relying on this for a career decision.

School