Renata Radziszewska
Safety Assessment Engineer · Certification & Airworthiness
Warsaw, Poland
Safety Assessment Engineer applying ARP4761 methodology to aircraft and propulsion system safety analyses. Authors FHA, PSSA, and SSA documents for major aircraft systems — propulsion, fuel, hydraulic, flight control — and performs the fault tree analysis (FTA) and failure mode and effects analyses (FMEA) that underpin the safety substantiation. Experienced in coordinating safety analysis with system designers to ensure architecture drives safety requirements downstream.
Expertise
- Functional Hazard Assessment (FHA)
- Preliminary System Safety Assessment (PSSA)
- System Safety Assessment (SSA)
- Fault Tree Analysis (FTA)
- ARP4761 safety assessment methodology
Technologies
Work History
2025-01
AI-assisted FTA review tool — collaborated with AI team on a prototype LLM tool that reviews FTA logic for common errors (missing gates, cut set coverage, unmitigated single-point failures). Provided labeled FTA review examples as training data.
Challenge: LLM FTA review missed subtle single-point failures in nested fault trees — it correctly identified obvious unmitigated failures but failed to trace common cause failures through three levels of fault tree hierarchy. Required defining explicit traversal depth requirements in the tool specification.
Learned: AI FTA review tools must be tested specifically for multi-level fault tree traversal. Single-level pattern matching is insufficient for real fault trees — common cause failures and shared basic events must be tracked across the full tree depth to catch all single-point failure vulnerabilities.
2024-05
Flight control system SSA — integrated FTA results from PSSA with component-level failure data from suppliers to compute failure condition probabilities. Verified compliance with all Catastrophic (<10^-9/fh) and Hazardous (<10^-7/fh) probability requirements.
Challenge: One Catastrophic condition ('Loss of Pitch Control') had a computed probability of 2.4×10^-9/fh — non-compliant against the 10^-9 requirement. Required architecture redesign to add a third independent pitch control path, increasing system weight by 14 kg.
Learned: SSA compliance checks must be iterative throughout FCS architecture development, not a single late-stage computation. Discovering a non-compliant Catastrophic failure condition probability late in design when supplier FMEA data is available forces last-minute architecture changes — much more expensive than early PSSA-guided architecture selection.
2023-10
Fuel system PSSA — fault tree analysis for 8 Catastrophic fuel system failure conditions including fuel exhaustion, fuel tank explosion, and ETOPS fuel planning failure. Derived system-level safety requirements for fuel quantity sensing redundancy.
Challenge: The fuel exhaustion fault tree had a common cause event (flight crew error in fuel planning) that was difficult to quantify — crew error rates are poorly characterized for ETOPS operations. Required using the AMC 25.1309 conservative crew error rate and formally documenting the uncertainty.
Learned: Human error probability in safety FTA must use published, conservative reference values from AMC/AC unless specific human factors study data is available. Using internal estimates without regulatory backing will be rejected by DER during SSA review.
2023-03
Functional Hazard Assessment for the propulsion system — identified and classified 47 propulsion failure conditions from catastrophic to no-safety-effect. Established probability requirements for each Major, Hazardous, and Catastrophic condition per CS-25.1309.
Challenge: Classifying the severity of 'Loss of Thrust Asymmetry Protection' was contentious — operations and flight dynamics engineers disagreed on whether this was Hazardous (10^-7) or Major (10^-5) depending on the flight phase and aircraft configuration. Required a dedicated cross-functional review to reach consensus on the classification rationale.
Learned: FHA severity classification for failure conditions that span multiple flight phases requires explicit phase-by-phase assessment. A failure that is Major during cruise may be Catastrophic during approach — the FHA must document the worst-case phase classification and the rationale for it.