Safety Features

An AND gate is indicative of a safety feature, because two or more conditions must simultaneously be satisfied. In the example, these safety features are the timer and the fuse. Notice that the removal of the timer and the fuse, the safety features, would remove the AND gates.

AND gates also require a sequential operation of the events. The fuse must fail prior to the motor, and the timer must fail prior to the switch; otherwise, the consequences will be unrelated to the tree output.

An INHIBIT gate is similarly an indication of some safeguard, as there is only a conditional connection between the events. The undesirable event cannot occur, unless a certain condition is satisfied, as well as the input being present.

Thus a safe system will have a considerable number of AND gates and INHIBIT gates in its fault tree. A system with safety features in each branch would be demonstrably safe.