569
1 INTRODUCTION
Ship machinery maintenance directly affects safety,
environmental protection, reliability, availability,
regulatory compliance and the commercial
performance of a vessel. Marine machinery operates
under variable loads, environmental exposure, limited
repair opportunities and demanding voyage
schedules. Maintenance decisions must therefore
account not only for equipment age or scheduled
intervals, but also for the consequences of failure,
current technical condition, available redundancy,
operational requirements and the feasibility of
intervention. Maintenance practice has consequently
developed from predominantly corrective and time-
based approaches towards reliability-centred,
condition-based, predictive and risk-based strategies
intended to improve deterioration detection,
intervention timing and the allocation of maintenance
resources [18, 19, 21].
A Risk-based Method for Selecting Ship Machinery
Maintenance Strategies
O. Acomi¹, B. Belev
1
, M. Chervinskyi
2
& N. Acomi
3
1
Nikola Vaptsarov Naval Academy, Varna, Bulgaria
2
TEAM4Excellence Research Center, Constanta, Romania
3
Constanta Maritime University, Constanta, Romania
ABSTRACT: Ship machinery maintenance must balance safety, reliability, availability, regulatory compliance and
cost under operational constraints and frequently incomplete data. Conventional approaches based on fixed
maintenance intervals, corrective intervention or isolated condition monitoring remain necessary, but they do not
provide a consistent basis for selecting among alternative maintenance strategies when failure likelihood,
consequence severity, equipment condition, uncertainty, feasibility and cost interact. This paper proposes an
integrated risk-based method for selecting maintenance strategies at machinery, component and failure-mode
level. Failure-mode analysis, reliability and conditional probability assessment, condition evidence, consequence
assessment, risk classification and uncertainty treatment provide structured inputs to a Maintenance Decision
Engine. Candidate strategies - including corrective, time-based preventive, condition-based, predictive, risk-
based, opportunity and deferred maintenance -are first screened against statutory, classification, manufacturer,
safety and technical constraints. Only admissible alternatives proceed to multi-criteria ranking using the
Technique for Order Preference by Similarity to Ideal Solution. The ranking considers expected risk reduction,
technical suitability, reliability and availability contribution, implementation feasibility, expected total cost, and
evidence confidence. Ranking margins and sensitivity analysis are used to assess robustness, while post-ranking
engineering review confirms, modifies or overrides the numerical recommendation according to condition, risk
urgency, redundancy and operational feasibility. The selected strategy is then converted into a traceable
maintenance action and recorded through the planned or computerised maintenance management system. The
principal contribution is the integration of established engineering methods within a constrained, transparent
and auditable maintenance decision process.
http://www.transnav.eu
the International Journal
on Marine Navigation
and Safety of Sea Transportation
Volume 20
Number 3
September 2026
DOI: 10.12716/1001.20.03.05
570
Condition monitoring provides important evidence
of actual machinery state through methods such as
vibration analysis, lubricating-oil analysis,
thermography, ultrasonic testing, performance
monitoring and process-parameter trending. These
techniques can identify developing degradation before
functional failure and can support more appropriate
maintenance timing than fixed intervals alone [13].
Planned maintenance systems and computerised
maintenance management systems, referred to
collectively in this paper as PMS/CMMS, also improve
the recording of running hours, work orders, defects,
spare-parts consumption, inspection findings and
completed maintenance. Their value, however,
depends on data quality, consistent reporting and the
extent to which recorded information is subsequently
used in technical decision-making [22, 23].
The availability of additional data does not in itself
determine which maintenance strategy should be
selected. Possession of condition-monitoring
equipment, machinery-performance records and a
functioning PMS/CMMS does not guarantee a
transparent procedure for choosing between
corrective, preventive, condition-based, predictive or
risk-based intervention. Condition information must
be interpreted in relation to a defined failure mode,
decision interval, deterioration mechanism and
consequence of failure. Similarly, a calculated
probability of failure has limited decision value unless
it is considered together with redundancy, operational
context, cost, compliance requirements and the
practical opportunity to perform the work. Data-
driven maintenance therefore depends not only on
analytical capability, but also on reliable data,
competent interpretation, organisational processes and
clear action rules [5, 20].
Several established engineering methods can
support individual parts of this problem. Failure Mode
and Effects Analysis and Failure Mode, Effects and
Criticality Analysis provide a structured basis for
defining functions, failure modes, causes, effects and
existing controls. Fault-tree analysis can represent
causal pathways, while reliability analysis and the
Weibull distribution can estimate survival and failure
probability where suitable operating and failure
records are available. Condition-monitoring evidence
can modify the assessment of current failure
likelihood, and consequence analysis can determine
the potential effects on safety, environment, asset
condition, availability, cost and compliance. Risk
matrices, Monte Carlo simulation, Bayesian methods
and other probabilistic approaches can further assist
where uncertainty or conditional dependence must be
considered [6, 17].
These methods nevertheless tend to address
separate stages of the maintenance problem. Failure
analysis identifies potential failure modes, reliability
analysis estimates how failure behaviour changes with
time, and condition monitoring indicates whether
degradation is developing. Risk assessment establishes
priority, while cost and feasibility analysis determine
whether a proposed intervention can be implemented.
None of these outputs independently establishes
which maintenance strategy is both technically
admissible and preferable under the complete set of
safety, operational, economic and regulatory
constraints. A further decision layer is therefore
required to convert the outputs of established analyses
into a defensible strategy and a practical maintenance
action.
A significant issue is the treatment of mandatory
constraints. A strategy that conflicts with a statutory
requirement, classification condition, manufacturer
instruction, company procedure or immediate safety
requirement cannot be considered acceptable merely
because it has lower cost or greater operational
convenience. Such constraints should be applied before
alternatives are compared numerically. Otherwise, an
inadmissible strategy could remain within the decision
matrix and compensate for poor technical or regulatory
performance through favourable scores against less
important criteria. Maintenance-strategy selection
should therefore distinguish between the admissibility
of an alternative and its relative performance after
admissibility has been established.
Multi-criteria decision-making provides a suitable
basis for comparing the remaining alternatives because
maintenance strategies must be evaluated against
several competing criteria. The Technique for Order
Preference by Similarity to Ideal Solution, or TOPSIS,
enables alternatives to be ranked according to their
proximity to an ideal performance profile and their
distance from a least-desirable profile. It can
accommodate benefit and cost criteria expressed in
different units and produces a transparent preference
index for each alternative [4, 8]. TOPSIS has also been
used in marine and offshore maintenance-strategy
selection, supporting its relevance to decisions
involving technical, operational and economic criteria
[3, 16]. However, a numerical ranking alone should not
be treated as a final engineering decision. The result
remains sensitive to criterion definitions, scores,
weights, evidence quality and the operating
assumptions used in the assessment.
This paper therefore proposes an integrated risk-
based method for selecting ship-machinery
maintenance strategies. The method is applied at
component or failure-mode level and is centred on a
Maintenance Decision Engine. Engineering analyses
provide structured inputs describing the failure mode,
current condition, likelihood, consequence, risk,
uncertainty, cost and feasibility. The engine first
removes strategies that are legally, technically or
operationally inadmissible. It then ranks the
admissible alternatives using TOPSIS and evaluates
the stability of the ranking through ranking-margin
and sensitivity analysis. A post-ranking engineering
review subsequently considers mandatory
requirements, condition development, risk urgency,
redundancy, operational continuity and
implementation feasibility before the preferred
strategy is converted into a specific maintenance
action.
The contribution of the proposed method is not the
isolated use of FMEA/FMECA, Weibull analysis, risk
matrices, condition monitoring or TOPSIS, all of which
are established techniques. Its contribution lies in
combining these methods within a controlled and
traceable decision process. Engineering evidence and
risk assessment first establish the technical basis of the
decision. Candidate maintenance strategies are then
screened against mandatory requirements before the
admissible alternatives are compared using multi-
571
criteria ranking. The robustness of the ranking is
subsequently examined, after which engineering
review and, where necessary, override determine the
final maintenance action. The selected action and its
outcome are then recorded through PMS/CMMS
feedback.
This structure distinguishes the reasons for
excluding a strategy from the assessment of how
admissible strategies perform and from the subsequent
decision on implementation. It also ensures that a
numerical ranking cannot supersede statutory,
classification, manufacturer or safety requirements.
2 INTEGRATED RISK-BASED MAINTENANCE
DECISION MODEL
2.1 Framework Architecture, Scope and Inputs
The proposed model converts established engineering
analyses into a structured process for selecting ship-
machinery maintenance strategies. It is applied at
machinery-system, component or failure-mode level,
where the assessment boundary, available evidence,
operating context and decision interval can be defined.
Maintenance decisions are based on the combined
influence of failure likelihood, consequence severity,
current condition, operational feasibility, cost and
mandatory requirements. FMEA/FMECA provides the
failure-mode structure, reliability analysis estimates
failure likelihood where suitable data are available,
condition monitoring describes the current technical
state, and consequence assessment establishes
criticality and risk. These outputs are supplied to the
Maintenance Decision Engine, which screens
candidate strategies, compares the admissible
alternatives and supports selection of an
implementable maintenance action. The method
therefore combines the principles of risk-based and
reliability-centred maintenance with uncertainty
treatment, operational constraints and PMS/CMMS
feedback.
The framework comprises four connected layers.
The evidence and constraint layer consolidates
equipment, maintenance, operating, condition, cost
and mandatory-requirement data and records their
quality. The engineering-analysis layer converts these
inputs into failure-mode, likelihood, condition,
consequence and risk assessments. The Maintenance
Decision Engine removes inadmissible strategies and
compares the remaining alternatives against risk
reduction, technical suitability, reliability and
availability, implementation feasibility, expected cost
and evidence confidence. The implementation and
feedback layer translates the selected strategy into an
action, priority, timing and temporary controls, while
PMS/CMMS outcomes update subsequent
assessments. Figure 1 presents the complete
framework.
The central position of the Decision Engine
distinguishes the proposed framework from a
sequential collection of maintenance tools. The
surrounding analytical methods provide evidence and
constraints, while the Decision Engine performs the
formal comparison and selection.
2.1.1 Scope, boundaries and assumptions of the model
The model supports operational-phase
maintenance decisions at machinery-system,
component or failure-mode level. The assessment unit
comprises a defined function, item, failure mode,
operating context and decision interval. This boundary
must be detailed enough to connect maintenance
history, condition evidence, likelihood, consequence,
redundancy and available actions to a specific decision
while remaining practical for PMS/CMMS use.
The method is suitable where deterioration, failure
history or condition evidence can be observed and
technically feasible maintenance responses identified.
It operates within the PMS/CMMS, Safety
Management System, statutory obligations,
classification requirements, manufacturer instructions
and company procedures, which remain mandatory
constraints. Any deferral or modification of a
prescribed task remains subject to the applicable
technical and organisational approval process.
Figure 1 Architecture of the Integrated Risk-Based Maintenance Decision-Support Framework. Source: author, informed by
[10, 13–15, 18, 21].
572
The method assumes that the assessment boundary
and failure mode can be defined, that relevant
engineering evidence is available, and that the possible
consequences can be assessed in relation to safety,
environment, asset damage, operational availability,
cost, compliance or commercial effect. Evidence can be
quantitative or qualitative and includes running hours,
maintenance and defect history, inspection findings,
condition-monitoring results, failure records and
documented engineering judgement. A practical
decision interval must also be specified, such as the
period until the next port call, inspection, running-
hour threshold, maintenance opportunity or dry-
docking. Likelihood, risk and the resulting
maintenance response are interpreted in relation to this
interval.
The method concerns operational maintenance
decision-making and does not address ship design,
construction, major conversion, disposal or recycling.
It is not a complete accident-causation model, although
risk and consequence reasoning are used to identify
maintenance priorities and required controls.
2.1.2 Model inputs, data requirements and equipment
selection
The model uses quantitative and qualitative
maintenance, operational and condition evidence.
Quantitative inputs include running hours, failure
dates, maintenance intervals, repair duration, cost,
downtime and condition-monitoring measurements.
Qualitative inputs include inspection comments, defect
descriptions, crew observations, survey findings,
manufacturer recommendations and engineering
judgement. These inputs support definition of the
assessment boundary and failure mode, estimation of
likelihood and consequence, risk classification,
maintenance-strategy comparison, feasibility
assessment and subsequent PMS/CMMS feedback. The
selected equipment item or failure mode should have a
clearly defined function, a technically meaningful
failure mechanism and potential safety,
environmental, operational, compliance, asset or
commercial consequences. Sufficient maintenance,
failure or condition evidence should be available to
support the assessment, and a practical decision
interval and feasible maintenance responses must be
identifiable. The result should also be capable of being
recorded, implemented and reviewed through the
PMS/CMMS.
Table 1 summarises the required data, their typical
sources and their role in the model.
Before assessment, records are screened for
completeness, consistency and relevance. Where the
available data do not support quantitative reliability
analysis, likelihood classes, manufacturer or fleet
evidence, conservative assumptions and documented
engineering judgement are used. Isolated condition
measurements are interpreted qualitatively unless
supported by a reliable trend, while incomplete cost
data are used for relative rather than falsely precise
comparison.
Table 1 Data requirements for the proposed maintenance
strategy model
Data
category
Typical source
Use in the
model
Equipment
identification
PMS/CMMS,
manuals,
drawings,
equipment
register
Defines the
assessment
boundary
Maintenance
history
PMS/CMMS,
work orders,
maintenance
reports
Supports
maintenance
history review
and interval
assessment
Running
data
PMS/CMMS,
engine logs,
automation
system,
logbooks
Supports
likelihood and
Weibull
assessment
Failure and
defect data
Defect reports,
corrective work
orders, incident
reports, chief
engineer reports
Supports
failure-mode
definition and
probability
assessment
Condition
evidence
Condition-
monitoring
systems,
inspection
reports, survey
reports,
laboratory
reports
Supports
condition
interpretation
and likelihood
adjustment
Consequence
information
Risk assessment,
incident records,
class/SMS
requirements,
technical
judgement
Supports
consequence
and criticality
assessment
Cost and
feasibility
data
Purchasing
records,
superintendent
reports,
quotation
records, voyage
plan, dock plan
Supports cost,
downtime and
feasibility
assessment
Compliance
requirements
SMS, class rules,
manuals,
circulars,
company
procedures
Defines
mandatory
constraints and
escalation
requirements
Feedback
data
PMS/CMMS,
close-out
reports,
superintendent
review
Supports
model
updating and
organisational
learning
Source: author.
2.1.3 Equipment breakdown and failure-mode definition
Before likelihood and consequence are assessed,
machinery is decomposed to the lowest level that
supports a specific and traceable maintenance decision.
The hierarchy can include system, subsystem,
component, itemised part and failure mode and should
follow the existing PMS/CMMS structure where
practical.
Each item is defined by its required function and
operating conditions. A failure mode describes the
573
specific manner in which the function is lost or
degraded and must be distinguished from both
symptoms and causes. For example, high temperature
is a symptom, reduced cooling capacity is a failure
mode, and fouling or pump degradation are possible
causes.
Failure modes are identified from vessel records,
manuals, condition reports, survey findings, crew
observations and comparable engineering evidence.
For each mode, the assessment records its causes, local,
system and vessel-level effects, and existing
preventive, detective or mitigating controls.
The resulting failure-mode register contains
equipment identification, function, failure mode,
causes, effects, controls, evidence source and
confidence, decision interval and feasible responses. It
follows FMEA/FMECA logic to structure the evidence,
while criticality is determined subsequently through
consequence and risk assessment.
2.2 Reliability, Uncertainty and Risk Assessment
The model uses a tiered approach to likelihood
assessment. Where sufficient failure and survival data
are available, reliability analysis is applied, with the
Weibull distribution used to estimate reliability and
failure probability. Where the available records do not
support quantitative estimation, condition evidence,
maintenance history and engineering judgement are
used to assign a semi-quantitative likelihood class.
Likelihood is assessed over a defined decision
interval expressed in running hours, calendar time,
voyage duration or the period until the next port,
inspection or maintenance opportunity. The selected
time basis should reflect the relevant failure
mechanism: running hours are generally appropriate
for use-dependent deterioration, while calendar time is
more suitable for age-dependent processes. Where
both are relevant, both should be considered and the
more conservative interpretation applied.
Reliability is the probability that an item will
perform its required function for a specified period
under stated conditions. For a non-repaired item or a
component considered between maintenance
interventions, reliability at time t can be expressed as:
( ) ( )
R t P T t=
(1)
where R(t) is the reliability at time t, and T is the time
to failure.
Reliability estimates are conditional on the
operating profile, maintenance history, component
age, environmental conditions, data quality and
similarity of the supporting dataset. The calculated
value should therefore be recorded together with its
evidence source and confidence level.
The probability of failure by time t is the
complement of reliability. It is expressed as:
( ) ( )
F t 1 R t=−
(2)
where F(t) is the cumulative probability of failure by
time t.
For maintenance planning, the most useful
probability is often the probability that the item will fail
during the next interval, given that it has survived until
the present time. This is expressed as:
( )
( )
( )
f
R t Δt
P t, Δt 1
Rt
+
=−
(3)
where Pf(t,Δt) is the probability of failure during the
interval from t to t + Δt, R(t) is the reliability at the
current running time or age, and R(t + Δt) is the
reliability at the end of the decision interval.
This formulation connects reliability analysis with
practical maintenance timing because the relevant
question is whether the component can continue
operating through the selected interval rather than
whether it will eventually fail. The interval should
therefore correspond directly to the maintenance
decision being considered.
The Weibull distribution is selected as the main
quantitative reliability model because it is widely used
in lifetime reliability and maintenance engineering. It
is flexible and can represent different failure
behaviours, including early failures, random failures
and wear-out failures.
For the proposed model, the two-parameter
Weibull reliability function is expressed as:
( )
β
t
R t exp
η



=−




(4)
where β is the shape parameter, and η is the scale
parameter or characteristic life.
The corresponding cumulative probability of
failure is:
( )
β
t
F t 1 exp
η



= − −




(5)
The conditional probability of failure during the
next decision interval can therefore be written as:
( )
ββ
f
t Δt t
P t, Δt 1 exp
ηη


+


= − − −




(6)
The Weibull hazard rate provides an additional
indication of the failure tendency over time:
( )
β 1
βt
h t
ηη
−

=


(7)
where h(t) is the instantaneous failure rate at time t.
The mean time to failure for the two-parameter
Weibull distribution is:
1
MTTF ηΓ 1
β

=+


(8)
where Γ is the gamma function.
574
The shape parameter β describes the failure
tendency. Values below 1 indicate a decreasing failure
rate associated with early-life or installation-related
failures; values close to 1 indicate an approximately
constant failure rate; and values above 1 indicate
increasing failure tendency associated with ageing,
wear, fatigue, corrosion, fouling or similar
deterioration. The scale parameter η represents the
characteristic life, at which the cumulative failure
probability of the two-parameter Weibull distribution
is approximately 63.2%.
Weibull parameters are application-specific and
should be interpreted in relation to load, operating
profile, environmental exposure, maintenance quality
and other relevant conditions. Where vessel-specific
records are insufficient, fleet data, manufacturer
information, published evidence or documented
engineering judgement can provide provisional inputs,
provided that the source and uncertainty are recorded.
Quantitative estimation requires operating time,
failure or replacement dates, component age, repair
history and censored observations representing items
that have survived for a known period without failure.
Where sufficient failure and survival data exist,
Weibull parameters can be estimated through
maximum likelihood estimation, probability plotting
or suitable reliability software. Estimates based on
small samples should be treated as provisional,
supported by sensitivity analysis and reported
together with the underlying data basis and confidence
level.
Condition evidence—including vibration,
lubricating-oil analysis, thermography, process
parameters, inspection findings and manufacturer
recommendations—can indicate that actual equipment
condition is better or worse than expected from age or
running hours alone. This evidence is therefore used to
support or modify the reliability-based estimate. A
worsening and well-supported trend can justify a
higher likelihood class, while stable repeated
measurements can support retaining or, where
technically justified, reducing the assigned class. Every
modification should be supported by a recorded
engineering justification.
Where failure history is insufficient for defensible
quantitative analysis, likelihood is assigned using the
semi-quantitative scale in Table 2. The classification
should consider running hours, maintenance and
defect history, condition evidence, manufacturer
guidance, fleet experience and documented
engineering judgement. The probability bands are
indicative thresholds for the selected decision interval
and can be mapped to an existing company-approved
likelihood scale.
The scale does not replace an approved SMS or
company risk-assessment procedure. Where an
existing likelihood classification is already used, it can
be mapped to the proposed model. The assigned class
must correspond to the defined decision interval
because the same component can have different
likelihood levels over the period to the next port call,
scheduled maintenance or dry-docking.
Table 2 Proposed likelihood classes for the model
Likelihood
class
Description
Indicative
probability
within the
decision
interval
Typical evidence
1 – Very
Low
Failure is credible
but unlikely
within the
decision interval
< 1%
No defects, stable
condition trend,
recent maintenance,
low running hours
2 - Low
Failure is possible
but not expected
within the
decision interval
1-5%
Minor concerns,
stable or slowly
changing condition,
adequate controls
3 -
Moderate
Failure may occur
within the
decision interval
5-15%
Moderate running
hours, recurring
minor defects,
uncertain condition
evidence
4 - High
Failure is a
realistic concern
within the
decision interval
15-30%
Deteriorating trend,
repeated defects,
overdue
maintenance, reduced
confidence
5 - Very
high
Failure is
expected unless
action is taken
> 30%
Severe degradation,
alarms, repeated
failure, clear defect,
ineffective controls
Source: author.
2.2.1 Uncertainty treatment
Maintenance decisions frequently rely on
incomplete records, limited failure histories, uncertain
condition evidence and changing operating
circumstances. Relevant uncertainty concerns data
quality, reliability parameters, condition
measurements, consequence judgement, cost,
feasibility, operating context and model assumptions.
These uncertainties are addressed through screening,
confidence classification, ranges or probability
distributions, scenario analysis, sensitivity testing and
conservative engineering judgement.
Evidence is classified as having high, medium or
low confidence. High-confidence records support
quantitative reliability analysis; medium-confidence
evidence requires interpretation and sensitivity testing;
and low-confidence evidence supports semi-
quantitative likelihood classes, conservative
assumptions or scenario analysis rather than
unsupported statistical precision.
Where uncertain inputs can be represented by
defensible ranges or probability distributions, Monte
Carlo simulation produces distributions of failure
probability, risk or expected cost rather than a single
point estimate [24, 25]. Where distributions cannot be
justified, normal, adverse and conservative scenarios
are used.
Sensitivity analysis identifies the assumptions that
most strongly influence the recommendation. A result
that remains stable under plausible variations is
regarded as robust, whereas a materially changing
result requires additional evidence, revised
assumptions or a more conservative decision. The
essential requirement is that uncertainty is explicitly
recorded and treated in proportion to the available
evidence.
575
2.2.2 Consequence and criticality assessment
Consequence is assessed separately from likelihood
to avoid double counting and preserve the
transparency of the risk calculation. The likelihood
module estimates whether the failure mode can occur
within the selected decision interval, while the
consequence assessment determines the severity of the
resulting effects. A low-probability failure can
therefore require urgent attention where its credible
consequences are severe, while a more frequent failure
can remain manageable where effects are limited and
effective controls are available.
Consequence is assessed across seven categories:
safety, environmental impact, asset damage,
operational availability, financial cost, class or
statutory compliance, and commercial or reputational
effect. The assessment considers both local component
effects and wider system- or vessel-level effects,
including loss of function, reduced redundancy, delay,
off-hire, pollution exposure and compliance
consequences.
Redundancy and existing barriers can reduce
consequence only where their availability,
independence and suitability for the relevant operating
condition are verified. Standby equipment should not
be assumed effective where it is unavailable, defective,
overloaded or exposed to the same common-cause
failure. Consequence should also reflect the operating
context, including manoeuvring, restricted waters,
cargo operations, high load, reduced redundancy,
remote operation and the time until external support or
repair is available. The assessment therefore uses the
same decision interval and operational assumptions as
the likelihood module.
Table 3 defines a five-level consequence scale in
which 1 represents very low consequence and 5
represents very high consequence. The scale supports
consistent classification and subsequent combination
with the likelihood result.
For each failure mode, the analyst should assign a
score to each consequence category. The model then
uses the maximum credible consequence score as the
primary consequence score:
( )
,1 ,2 ,
max , , ,
i i i i m
C c c c=
(9)
where Ci is the consequence score for failure mode i, ci,k
is the score assigned to consequence category k, and m
is the number of consequence categories considered.
The maximum credible consequence is used
because it prevents severe safety, environmental or
compliance effects from being diluted by lower scores
in other categories. A failure mode is therefore not
treated as having low criticality merely because its
direct repair cost or local equipment damage is limited.
Where a company already uses an approved
weighted consequence method, the weighted score is
calculated as:
,
11
,1
mm
w
i k i k k
kk
C w c w
==
==

(10)
where Ci
w
is the weighted consequence score and wk is
the weighting assigned to consequence category k.
Table 3 Consequence categories and scoring criteria for the
proposed model
Consequenc
e category
1 - Very
low
2 - Low
3 -
Moderate
4 - High
5 - Very
high
Safety
No
injury or
material
exposure
First aid or
minor
unsafe
condition
Medical
treatment
or lost-
time
injury
potential
Serious
injury or
multiple-
person
exposure
Fatality or
multiple
serious-
injury
potential
Environme
ntal
No
release
Small
contained
leak
Reportabl
e minor
release
requiring
shipboar
d
response
Significant
pollution
requiring
external
response
Major
pollution or
severe
environmen
tal damage
Asset
damage
No
damage
or minor
adjustme
nt
Minor
repair by
ship staff
Planned
repair or
service
attendanc
e
Major
system or
consequent
ial damage
Catastrophi
c
machinery
or major-
system loss
Operational
availability
No
operatio
nal effect
Minor
manageable
delay
Reduced
redundan
cy or
restricted
operation
Off-hire,
deviation
or repair at
next port
Vessel unfit
to proceed
or loss of
essential
function
Financial
cost
Negligibl
e routine
cost
Low
normal-
budget
repair cost
Moderate
repair,
service or
downtim
e cost
High
emergency
, logistics
or off-hire
cost
Major
claim,
salvage or
extended
off-hire
exposure
Class,
statutory
and
compliance
No effect
Minor
documentat
ion issue
Deficienc
y
requiring
planned
correctio
n
Condition
of class,
PSC
deficiency
or critical-
equipment
non-
conformity
Detention,
loss of class
or major
statutory
non-
compliance
Commercial
and
reputational
No effect
Minor
administrati
ve or
customer
inconvenien
ce
Voyage
delay or
service
disruptio
n
Significant
charter,
cargo,
customer
or
reputation
effect
Major
contractual,
reputationa
l or market-
access
consequenc
e
Source: author.
The model therefore applies the maximum credible
consequence unless an approved weighted method is
already established within the company’s risk-
management system. A failure mode is classified as
critical where any category receives a high or very high
score, where the affected equipment is designated as
critical under the SMS, where class or statutory
compliance is involved, or where failure can lead to
loss of an essential ship function.
2.2.3 Risk estimation and classification
Risk is estimated by combining the likelihood of
failure within the decision interval with the
corresponding consequence assessment. This
preserves the distinction between how likely a failure
is and how severe its effects would be. A frequent but
low-consequence failure is generally addressed
through monitoring or planned intervention, whereas
a low-probability failure with severe safety,
576
environmental, compliance or essential-function
consequences is subject to escalation or immediate
control.
When a numerical probability of failure is available,
the risk value for failure mode i can be expressed as:
i i i
R P C=
(11)
where Ri is the numerical risk value for failure mode i,
Pi is the probability of failure within the selected
decision interval, and Ci is the consequence value or
consequence score.
Where consequence is expressed monetarily, the
result represents an expected failure consequence.
Where a consequence score is used, the result is a
relative risk value intended for transparent
comparison rather than a precise monetary estimate.
Where likelihood is expressed as a class rather than
as a numerical probability, the semi-quantitative risk
score is calculated as:
i i i
RS L C=
(12)
where RSi is the semi-quantitative risk score for failure
mode i, Li is the likelihood class, and Ci is the
consequence score.
This formulation supports applications where
available failure and operating records do not justify a
numerical probability estimate. The likelihood and
consequence scores must follow the defined scales and
remain supported by recorded evidence and
engineering judgement.
The risk category is assigned from the likelihood-
consequence matrix:
( )
,
i i i
RC f L C=
(13)
where RCi is the risk category for failure mode i and
f(Li,Ci) represents the mapping defined in the risk
matrix.
The proposed model uses a 5x5 likelihood-
consequence matrix presented in Table 4. The
likelihood scale follows Table 2, while the consequence
scale follows Table 3. The product of the two values
gives a risk score between 1 and 25.
Table 4 Proposed likelihood-consequence risk matrix
Likelihood class
/ Consequence
score
1 - Very
low
2 - Low
3 -
Moderate
4 - High
5 - Very
high
5 - Very high
5
Moderate
10 High
15 Very
high
20 Very
high
25 Very
high
4 - High
4 Low
8
Moderate
12 High
16 Very
high
20 Very
high
3 - Moderate
3 Low
6
Moderate
9
Moderate
12 High
15 Very
high
2 - Low
2 Low
4 Low
6
Moderate
8
Moderate
10 High
1 - Very low
1 Low
2 Low
3 Low
4 Low
5
Moderate
Source: author.
The matrix provides a consistent classification for
the proposed model but does not replace an approved
SMS, class or statutory risk-assessment procedure.
Where an established company matrix exists, the
likelihood and consequence outputs can be mapped to
that matrix before maintenance-strategy selection.
The resulting score is grouped into low, moderate,
high and very high risk categories, as shown in Table
5. These categories identify the required attention,
urgency and escalation level but do not independently
select the final maintenance strategy or action. That
selection is performed by the Maintenance Decision
Engine.
Table 5. Risk bands and indicative maintenance response levels
Risk
score
band
Risk
category
Meaning in the
proposed model
Indicative maintenance
response
1-4
Low
Risk is controlled by
existing maintenance
and monitoring
arrangements.
Continue normal PMS/CMMS
task, maintain routine
monitoring and review at next
planned interval.
5-9
Moderate
Risk is acceptable
only with active
monitoring or
planned follow-up.
Increase monitoring, inspect
at next suitable opportunity,
review PMS interval or
prepare spare parts.
10-14
High
Risk requires
planned corrective
action or
management review
within the decision
interval.
Plan repair, replacement or
overhaul; escalate to
superintendent where
operational or compliance
effect is material.
15-25
Very high
Risk is not
acceptable without
prompt action,
additional control or
formal escalation.
Take urgent action, restrict
operation, repair at earliest
opportunity, stop or isolate
equipment where required,
and escalate to shore
management, class or
manufacturer where relevant.
Source: author.
A numerical likelihood–consequence product is
insufficient where failure can affect safety,
environmental protection, statutory or class
compliance, or an essential ship function. A low
likelihood must not suppress a severe credible
consequence. The model therefore applies the
following high-consequence review trigger:
4 criticality review required
i
C 
(14)
The trigger is model-specific and corresponds to
consequence scores of 4 and 5, representing high and
very high consequence. It ensures that severe safety,
environmental, compliance or essential-function
effects receive explicit engineering review even where
their calculated likelihood is low. Where an approved
company or class-related procedure defines an
equivalent threshold, that procedure can be mapped to
the model.
High-consequence, low-probability failure modes
are therefore assessed conservatively. The reviewer
should consider the maximum credible consequence,
verified redundancy, existing barriers, common-cause
exposure and the operating context before accepting
continued operation or deferral.
Uncertainty results should also inform the assigned
risk category. Where Monte Carlo simulation or
sensitivity analysis is used, the assessment should
consider the range of outcomes and the probability of
exceeding a risk threshold rather than relying only on
a mean value. A risk category that changes materially
under plausible assumptions indicates a sensitive
577
result and should prompt additional evidence,
inspection or conservative treatment. Where
quantitative analysis is not justified, the failure mode
should be assessed under normal, adverse and
conservative scenarios, and the selected response
should remain acceptable under the plausible higher-
risk condition.
2.3 Maintenance Decision Engine
The preceding modules convert reliability, condition,
consequence, uncertainty and operational evidence
into a classified risk position. This establishes the
significance and urgency of the assessed failure mode
but does not independently determine which
maintenance strategy is most appropriate.
The Maintenance Decision Engine provides the
formal strategy-selection stage of the framework. It
first removes alternatives that are legally, technically or
operationally inadmissible, then compares the
remaining strategies through multi-criteria ranking.
The preliminary recommendation is subsequently
subjected to engineering review and converted into a
specific action, priority, timing and control
arrangement. The method therefore distinguishes
strategy admissibility, comparative performance and
practical implementation, preserving the reason for
each exclusion, ranking and final decision.
2.3.1 Candidate maintenance strategies
The Decision Engine evaluates alternative
maintenance strategies at failure-mode level. For each
assessed failure mode i, the initial set of candidate
strategies is defined as:
1 2 3 4 5 6 7
, , , , , ,
i i i i i i i i
A A A A A A A A=
(15)
where Ai1 to Ai7 represent corrective maintenance, time-
based preventive maintenance, condition-based
maintenance, predictive maintenance, risk-based
maintenance, opportunity maintenance and deferred
maintenance, respectively.
The initial set includes corrective, time-based
preventive, condition-based, predictive, risk-based,
opportunity and deferred maintenance. Corrective
maintenance permits continued operation until a
recognised defect or functional failure requires action
and is principally suitable for low-criticality,
adequately redundant items. Time-based preventive
maintenance applies a predetermined calendar or
running-hour interval, while condition-based
maintenance initiates action from observed
deterioration. Predictive maintenance estimates future
condition, remaining useful life or failure probability
from historical and current evidence. Risk-based
maintenance determines priority from the combined
likelihood and consequence of failure. Opportunity
maintenance schedules technically appropriate work
during a suitable operational, port, shutdown or dry-
docking window. Deferred maintenance postpones
action to a defined point subject to temporary controls,
acceptance criteria and a review date.
Inclusion in the initial set does not establish
technical suitability or permission to use the strategy.
Alternatives that conflict with mandatory
requirements or lack the conditions necessary for
effective implementation are removed during
admissibility screening. Strategies can also be
combined; for example, risk assessment establishes
priority, condition monitoring determines the
intervention point, and opportunity maintenance
defines the execution window.
2.3.2 Strategy admissibility and mandatory engineering
constraints
Before the candidate strategies are compared
mathematically, the Decision Engine determines
whether each strategy is admissible for the assessed
failure mode. Admissibility is treated as a mandatory
engineering constraint rather than as an ordinary
weighted criterion. A strategy that is legally non-
compliant, technically ineffective or operationally
unsafe cannot compensate for that deficiency through
lower cost or greater convenience.
1, if strategy is admissible for failure mode ,
0, if strategy is inadmissible for failure mode .
ij
ji
g
ji
=
(16)
Only strategies for which gij=1 proceed to the multi-
criteria comparison. Every exclusion must be
supported by a recorded technical, regulatory or
operational justification.
The admissible strategy set for failure mode i is
defined as:
adm
1
i ij i ij
A A A g= =∣
(17)
Mandatory statutory, class, SMS, manufacturer and
company requirements are assessed before numerical
ranking. Where a requirement prescribes or
necessitates a specific response, that response takes
precedence regardless of cost, convenience or
calculated likelihood. This applies particularly to
critical equipment, protection systems, statutory
deficiencies, class conditions, manufacturer limits and
immediate safety concerns.
A mandatory response therefore bypasses the
ranking procedure rather than being retained as an
alternative with a low score. The Decision Engine
records the applicable requirement, the resulting
override and the authority responsible for the decision.
After the admissibility stage, the Decision Engine
compares the remaining maintenance strategies
against a common set of decision criteria. For failure
mode i, the comparison is represented by a decision
matrix:
i jk
mn
x

=

X
(18)
where:
m is the number of admissible maintenance strategies;
n is the number of decision criteria;
xjk is the performance score of maintenance strategy j
against criterion k.
The decision matrix contains only admissible
strategies. An excluded alternative is removed entirely
rather than retained with a low score, preventing legal,
safety or technical inadmissibility from being offset by
favourable cost or convenience. The remaining
578
strategies are assessed against six criteria: expected risk
reduction, technical suitability, reliability and
availability contribution, implementation feasibility,
expected total cost, and evidence confidence and
traceability. These criteria translate the preceding
reliability, condition, risk and feasibility outputs into
the common comparison structure defined in Table 6.
Table 6. Decision criteria for maintenance-strategy
comparison
Criterion
Definition
Direction
Expected risk
reduction
Degree to which the strategy reduces
failure likelihood, consequence
exposure or both during the decision
interval.
Benefit
Technical suitability
Compatibility of the strategy with the
failure mechanism, degradation
behaviour, detectability and available
maintenance method.
Benefit
Reliability and
availability
contribution
Expected effect on functional
reliability, equipment availability,
redundancy and continuity of
essential operations.
Benefit
Implementation
feasibility
Practical ability to apply the strategy
considering access, competence,
spares, service support, operating
condition and maintenance
opportunity.
Benefit
Expected total cost
Direct maintenance cost together with
expected downtime, off-hire, service,
spare-parts and residual failure-cost
exposure.
Cost
Evidence
confidence and
traceability
Extent to which the strategy is
supported by reliable condition data,
failure history, technical
documentation and auditable decision
evidence.
Benefit
Source: author, developed from the integrated risk, reliability,
condition, cost and feasibility modules of the proposed framework
and informed by marine maintenance-strategy selection research [7,
18].
Risk reduction, technical suitability, reliability and
availability, implementation feasibility, and evidence
confidence are benefit criteria, for which higher values
are preferable. Expected total cost is a cost criterion, for
which lower values are preferable. Quantitative values
should be used where defensible; otherwise, the
ordinal scale in Table 7 can be applied.
Table 7. Ordinal scoring scale for Decision Engine criteria
Score
Benefit-criterion interpretation
Expected-total-cost
interpretation
1
Very poor or unsupported
performance
Very low expected total
cost
2
Poor performance
Low expected total cost
3
Moderate performance
Moderate expected total
cost
4
Good performance
High expected total cost
5
Very good or strongly supported
performance
Very high expected total
cost
Source: author.
Ordinal scores must be supported by identifiable
reliability results, condition evidence, risk
classifications, technical requirements, maintenance
history, feasibility constraints or cost estimates. Where
the evidence does not justify a distinction between
adjacent scores, the more conservative value should be
selected and the uncertainty recorded.
Because the decision criteria can contain monetary
values, operating hours and ordinal assessments, they
are normalised before weighting.
For each criterion k, the normalised value is
calculated as:
2
1
jk
jk
m
jk
j
x
r
x
=
=
(19)
where rjk is the normalised performance of strategy j
against criterion k.
Vector normalisation converts the criteria into
dimensionless values while preserving their relative
differences. Benefit and cost directions are
subsequently reflected in the ideal-solution calculation.
Criterion weights represent the relative importance
of each factor in the strategy comparison. The weighted
normalised value is:
jk k jk
v w r=
(20)
where:
vjk is the weighted normalised value;
wk is the weight assigned to criterion k;
rjk is the normalised criterion value.
The weights are subject to:
1
1, 0
n
kk
k
ww
=
=
(21)
The criterion-weight vector is written as:
( )
12
w , , ,
n
w w w=
(22)
The weights wk are established through
documented expert elicitation, company policy or
another structured weighting procedure. Their
influence on the ranking is examined through
sensitivity analysis.
Risk reduction and technical suitability should
normally receive the greatest emphasis because the
method seeks a technically defensible response rather
than the lowest-cost alternative. The selected weights
must be documented and tested through sensitivity
analysis, and no weighting arrangement can
compensate for unacceptable risk or technical
incompatibility.
2.3.3 TOPSIS strategy-ranking procedure
TOPSIS is used because it can compare a limited set
of admissible strategies against benefit and cost criteria
expressed through different units or ordinal scales. The
method ranks alternatives according to their proximity
to a positive ideal solution and distance from a
negative ideal solution, producing a transparent
preference index [4, 8]. Its computational simplicity
and suitability for sensitivity analysis are appropriate
for the proposed Decision Engine, and previous marine
and offshore studies have applied TOPSIS to
maintenance-strategy selection [3, 16]. The ranking is
performed only after admissibility screening and
remains subject to engineering review.
After the criterion values have been normalised and
weighted, the Decision Engine applies TOPSIS [8] to
determine the ideal and least-desirable performance
579
profiles. The ideal profile represents the most desirable
observed performance for each criterion among the
admissible strategies, while the least-desirable profile
represents the least favourable observed performance.
The positive ideal solution is defined as:
max ,
,
min ,
jk
j
P P P
kk
jk
j
v k B
A v v
v k C
==
(23)
The negative ideal solution is defined as:
min ,
,
max ,
jk
j
N N N
kk
jk
j
v k B
A v v
v k C
==
(24)
The criterion sets used in the ideal-solution
definitions are:
is a benefit criterion ,
is a cost criterion
B k k
C k k
=
=
∣
∣
(25)
For benefit criteria, the positive ideal is the highest
weighted normalised value and the negative ideal is
the lowest; this relationship is reversed for expected
total cost. A strategy is therefore favoured only where
it performs satisfactorily against the technical and risk-
related criteria as well as cost.
The separation of each strategy from the positive
ideal solution is calculated as:
( )
2
1
n
PP
j jk k
k
S v v
=
=−
(26)
The separation from the negative ideal solution is
calculated as:
( )
2
1
n
NN
j jk k
k
S v v
=
=−
(27)
The preferred strategy should be close to the
positive ideal profile and distant from the least-
desirable profile.
The relative preference index for strategy j is
calculated as:
, 0 1
N
j
jj
PN
jj
S
CC
SS
=
+
(28)
The preference index ranges from zero to one, with
larger values indicating stronger relative performance.
The admissible strategies are ranked in descending
order of the preference index:
adm
pref
arg max
ij i
ij
A
AC
=
(29)
The highest-ranked admissible strategy becomes
the preliminary recommendation. It is not the final
maintenance decision until ranking robustness,
engineering compatibility and implementation
conditions have been reviewed.
2.3.4 Ranking robustness, confidence and engineering
review
The TOPSIS ranking is treated as a decision aid
because criterion scores and weights often reflect
incomplete data, uncertain condition trends, estimated
costs and professional judgement. Its robustness must
therefore be examined before implementation.
The first robustness indicator is the ranking margin
between the first- and second-ranked strategies:
( ) ( )
1 , 2 ,
i
ii
C C C = −
(30)
where C(1) and C(2) are the highest and second-highest
preference indices, respectively.
A large margin indicates clear separation between
the leading strategies, while a small margin indicates
similar overall performance and greater sensitivity.
The margin is interpreted together with data
confidence and weight sensitivity rather than against a
universal acceptance threshold.
Sensitivity analysis varies the criterion weights
under plausible scenarios, including greater emphasis
on risk and technical suitability, reliability and
availability, cost and feasibility, or evidence
confidence. A recommendation is considered robust
where the same strategy remains preferred or where
changes in ranking do not materially alter the required
maintenance response. Repeated changes under small
weight variations indicate a sensitive result.
A sensitive ranking does not invalidate the method
but indicates that the available evidence does not
clearly distinguish between the leading alternatives.
The available engineering responses include
requesting additional condition evidence, refining cost
or feasibility assumptions, verifying redundancy,
revising the scores or weights, selecting a combined
strategy, or retaining the more conservative admissible
option.
The final engineering review should confirm that
the recommended strategy is compatible with the
identified failure mechanism, risk category, condition
trend, redundancy arrangement, statutory and class
requirements, operational circumstances and available
implementation opportunity. The review should also
identify whether the preferred strategy represents the
principal maintenance orientation or whether it should
be combined with a supporting strategy.
The Decision Engine record should identify the
admissible and excluded strategies, exclusion reasons,
supporting evidence, scores, weights, preference
indices, sensitivity results, ranking confidence, selected
strategy, engineering-review conclusion and required
implementation conditions. This record links the
analytical evidence to the subsequent implementation
assessment.
Following TOPSIS ranking, the preliminary
strategy is reviewed against five implementation
conditions. Mandatory statutory, class, SMS or
manufacturer requirements can override the ranking.
Condition evidence must support the proposed
intervention or prompt further inspection and
increased urgency. The selected action must provide
sufficient control of the classified risk, and continued
operation or deferral requires verified and
580
independent redundancy. Where immediate
implementation is not feasible, temporary controls and
the earliest safe execution opportunity must be
defined. The decision, controls and subsequent
outcome are recorded in the PMS/CMMS. Figure 2
summarises this post-ranking engineering logic.
Escalation is required where the assessed failure
mode affects safety, pollution prevention, class or
statutory compliance, essential functions, redundancy,
repeated failure or an uncertain technical diagnosis.
The appropriate shipboard, shore-management, class,
flag, manufacturer or specialist authority should be
involved according to the required competence and
approval level. A mandatory or engineering override
supersedes the TOPSIS result where a prescribed
response applies or where the leading strategy does not
provide adequate risk control. The reason, authority,
supporting evidence and approved action must be
recorded so that any difference between the calculated
recommendation and the final decision remains
traceable.
2.3.5 Cost, downtime and operational feasibility
assessment
The multi-criteria comparison incorporates
expected total cost and implementation feasibility, but
its criterion scores do not constitute a complete work-
planning estimate. A subsequent implementation
check therefore considers direct and residual failure
costs, downtime, required resources, operating
restrictions and the earliest safe maintenance
opportunity. This assessment applies only to
technically admissible actions; safety, environmental,
class, statutory, SMS and manufacturer requirements
remain controlling constraints.
Where sufficient information is available,
alternative maintenance actions are compared using
expected cost. For a maintenance action (a), expected
cost can be expressed as:
( ) ( ) ( )
a f f d
EC a C P a C C a= + +
(31)
where EC(a) is the expected cost of action a, Ca is the
direct action cost, Pf(a) is the probability of failure
under or after action a, Cf is the consequence cost of
failure, and Cd(a) is the downtime, off-hire or
operational cost associated with the action.
Equation (31) combines the direct action cost,
residual failure exposure and downtime or operational
cost associated with each alternative. It allows
monitoring, inspection, planned intervention and
urgent repair to be compared without assuming that
the option with the lowest immediate cost is preferable.
Where monetary inputs are uncertain, ranges or
scenarios should be used and the underlying
assumptions recorded.
A technically preferred action is not always
immediately feasible because of unavailable spare
parts, specialist or class attendance, unsafe access, the
vessel’s operating status or an insufficient port
window. In such cases, the model identifies the earliest
safe execution opportunity and defines time-limited
temporary controls, such as increased monitoring,
reduced load, operating restrictions, use of verified
standby capacity or preparatory inspection. The
PMS/CMMS record should state why immediate
implementation is not possible, who approved the
interim arrangement and when the permanent action
will be completed. Operational feasibility must not be
used to normalise unacceptable risk.
Figure 2 Maintenance-action selection logic following maintenance-strategy ranking. Source: author, adapted from [1, 2, 9–11,
21].
581
The implementation check confirms whether the
selected action should be executed immediately,
performed at the earliest safe opportunity, supported
by temporary controls or formally escalated. Among
the technically feasible and compliant implementation
alternatives associated with the confirmed
maintenance strategy, the preferred action is the option
with the lowest expected cost that reduces residual risk
to the accepted level:
( )
*
f
aA
a arg min EC a
=
(32)
where a* is the preferred feasible action and Af is the set
of actions that are technically feasible and compliant
with mandatory safety, class, statutory, SMS and
operational constraints.
The feasible action set is defined as:
( )
acc
is technically feasible,
, complies with mandatory constraints
f
a A a
A
R a R a


=



∣
(33)
Here, A is the complete set of candidate
maintenance actions, R(a) is the residual risk associated
with action a, and Racc is the accepted risk level.
Mandatory constraints include applicable safety, class,
statutory, Safety Management System, manufacturer
and operational requirements.
Neither the cheapest nor the most conservative
option is automatically preferred. The selected action
must provide adequate risk control, remain technically
appropriate and be capable of implementation within
the relevant decision interval.
2.3.6 PMS/CMMS feedback and model updating
The PMS/CMMS supplies the equipment hierarchy,
running hours, maintenance and defect history,
inspection findings and condition evidence used by the
model and retains the approved decision [12, 13, 22,
23]. The record identifies the assessed item and failure
mode, assumptions, risk and admissibility results,
selected strategy, engineering review, temporary
controls, responsibility and review date.
After implementation, actual findings, condition
improvement, recurrence, delays and modifications
are recorded to update failure history, maintenance
intervals, condition thresholds, cost assumptions and
reliability estimates. Repeated findings also support
fleet-level review of maintenance tasks, spare-parts
selection, operating practices, monitoring, training and
supplier arrangements, subject to applicable safety,
class, statutory, manufacturer and company
requirements.
3 DISCUSSION
The proposed model is transferable as a decision-
support architecture rather than as a fixed numerical
template. Its principal elements—the definition of
equipment functions and failure modes, assessment of
likelihood and consequence, treatment of uncertainty,
screening of candidate strategies, multi-criteria
ranking, engineering review and PMS/CMMS
feedback—can be applied to different vessels,
machinery systems and operating contexts. The
numerical inputs, however, must reflect the
characteristics of the particular application. Equipment
boundaries, failure modes, decision intervals,
consequence scores, criterion weights, redundancy
assumptions, cost estimates and admissibility
constraints therefore require vessel- and system-
specific calibration.
This requirement should be regarded as normal
engineering adaptation rather than as a fundamental
limitation. The same machinery component can have
different criticality depending on vessel type,
operating profile, available redundancy, trading area,
maintenance history and repair opportunity. A failure
that is manageable on a vessel with verified standby
capacity and frequent port access can require a more
conservative response where redundancy is limited or
external assistance is not readily available. The method
preserves a consistent decision structure while
allowing these differences to be represented through
application-specific evidence and constraints.
The maturity of the maintenance-management
system and the quality of the available data both
influence confidence in the resulting recommendation.
PMS/CMMS records can contain incomplete running
hours, inconsistent equipment names, unclear defect
descriptions and insufficient distinction between
preventive replacement and functional failure. Such
limitations affect failure-mode definition, Weibull
estimation, likelihood classification and the confidence
assigned to the Decision Engine output. Quantitative
reliability analysis should therefore be used only
where failure and survival data are sufficiently
complete and comparable. Where this condition is not
met, semi-quantitative likelihood classes, conservative
assumptions and scenario analysis provide a more
defensible basis than unsupported numerical
precision. Uncertainty should be explicitly recorded
and considered in accordance with established risk-
management principles [10, 14].
Condition-monitoring evidence also requires
careful interpretation. Vibration, oil analysis,
thermography and process-parameter trends can
identify deterioration, but their significance depends
on measurement quality, operating load, baseline
definition, alarm thresholds and diagnostic
competence. A single abnormal measurement does not
necessarily demonstrate an imminent failure, while
apparently stable values do not guarantee that all
relevant degradation mechanisms are detectable.
Condition evidence is therefore used as one input to
likelihood assessment and strategy admissibility rather
than as an independent maintenance decision.
The risk matrix provides a practical means of
combining likelihood and consequence, but it remains
semi-quantitative. Broad risk categories can conceal
differences between failure modes and are influenced
by judgement, company risk tolerance and operating
context. The maximum credible consequence rule and
the high-consequence review trigger reduce the
possibility that severe safety, environmental or
compliance effects are obscured by a low likelihood
score. Nevertheless, failure modes close to a decision
threshold, subject to substantial uncertainty or capable
of affecting essential functions require engineering
review beyond the numerical matrix.
582
The TOPSIS ranking is similarly dependent on the
selected criteria, scores and weights. Its value lies in
making those assumptions explicit and applying them
consistently across admissible strategies, not in
removing professional judgement. A narrow ranking
margin indicates that the leading alternatives are
closely matched, while repeated changes under
plausible weight variations show that no strategy is
clearly dominant. In such circumstances, the method
supports additional inspection, revised scoring, a
combined maintenance strategy or selection of the
more conservative admissible option. Sensitivity
analysis and post-ranking engineering review are
therefore integral safeguards rather than optional
additions.
Finally, the proposed model remains a decision-
support method and not an autonomous maintenance
authority. Its effectiveness depends on competent
personnel, reliable reporting, clear responsibilities and
proper execution of the selected action. Operational
constraints such as voyage schedule, safe access, spare-
parts availability and specialist attendance sometimes
delay implementation, but they should not be used to
normalise unacceptable risk. Where immediate
intervention is not feasible, temporary controls,
responsibility, approval, escalation conditions and a
defined review date must be recorded. This is
consistent with the treatment of maintenance as a
continuing shipboard and shore-management
responsibility under the ISM framework and
associated IACS maintenance guidance [9, 11].
4 CONCLUSIONS
This paper proposes an integrated risk-based method
for selecting ship-machinery maintenance strategies at
component and failure-mode level. The method
combines FMEA/FMECA, reliability and conditional
probability analysis, condition evidence, consequence
assessment, risk classification, uncertainty treatment
and multi-criteria decision-making within a single
decision-support framework. Its central feature is the
Maintenance Decision Engine, which separates
mandatory admissibility from comparative ranking.
Statutory, class, manufacturer, Safety Management
System and safety requirements are therefore applied
as controlling constraints rather than treated as
ordinary weighted criteria.
The admissible alternatives are evaluated using
TOPSIS against expected risk reduction, technical
suitability, contribution to reliability and availability,
implementation feasibility, expected total cost and
evidence confidence. Ranking margins and sensitivity
analysis indicate whether the numerical preference is
robust. The ranking remains preliminary until
engineering review confirms compatibility with the
failure mechanism, condition trend, risk urgency,
redundancy arrangement and operational
circumstances. This prevents a mathematically
favourable option from overriding mandatory
requirements or providing insufficient risk control.
The selected strategy is converted into an
implementable maintenance action that defines timing,
responsibility, temporary controls and escalation
where required. Recording the decision and its
outcome through the PMS/CMMS provides
traceability and supports later revision of failure
history, maintenance intervals, condition thresholds,
cost assumptions and reliability estimates. The method
is intended for vessel- and system-specific calibration
rather than use as a fixed universal template. Its
effectiveness depends on the quality of maintenance
records, condition evidence, failure data and
professional judgement. The paper therefore
establishes the formal methodology and its decision
safeguards, while practical application and empirical
validation remain subjects for vessel-specific studies.
REFERENCES
[1] ABS, 2018a. Guidance Notes on Failure Mode and Effects
Analysis (FMEA) for Classification. Houston, TX:
American Bureau of Shipping.
[2] ABS, 2018b. Guidance Notes on Reliability-Centered
Maintenance. Houston, TX: American Bureau of
Shipping.
[3] Asuquo, M.P., Wang, J., Zhang, L. and Phylip-Jones, G.,
2019. Application of a multiple attribute group decision
making (MAGDM) model for selecting appropriate
maintenance strategy for marine and offshore machinery
operations. Ocean Engineering, 179, pp.246–260.
doi:10.1016/j.oceaneng.2019.02.065.
[4] Behzadian, M., Khanmohammadi Otaghsara, S., Yazdani,
M. and Ignatius, J., 2012. A state-of-the-art survey of
TOPSIS applications. Expert Systems with Applications,
39(17), pp.13051–13069. doi:10.1016/j.eswa.2012.05.056.
[5] Cheliotis, M., Lazakis, I. and Theotokatos, G., 2020.
Machine learning and data-driven fault detection for ship
systems operations. Ocean Engineering, 216, 107968.
doi:10.1016/j.oceaneng.2020.107968.
[6] Daya, A.A. and Lazakis, I., 2024. Systems reliability and
data driven analysis for marine machinery maintenance
planning and decision making. Machines, 12(5), 294.
doi:10.3390/machines12050294.
[7] Emovon, I., 2016. Multi-criteria Decision Making Support
Tools for Maintenance of Marine Machinery Systems.
PhD thesis. Newcastle University. Available through
Newcastle University eTheses, handle 10443/3280.
[8] Hwang, C.-L. and Yoon, K., 1981. Multiple Attribute
Decision Making: Methods and Applications: A State-of-
the-Art Survey. Lecture Notes in Economics and
Mathematical Systems, Vol. 186. Berlin and Heidelberg:
Springer-Verlag. doi:10.1007/978-3-642-48318-9.
[9] IACS, 2018. Recommendation No. 74: A Guide to
Managing Maintenance in Accordance with the
Requirements of the ISM Code. Rev. 2, August 2018.
London: International Association of Classification
Societies.
[10] IEC, 2019. IEC 31010:2019 Risk Management — Risk
Assessment Techniques. Geneva: International
Electrotechnical Commission.
[11] IMO, 2018. International Safety Management Code (ISM
Code) and Guidelines on Implementation of the ISM
Code. London: International Maritime Organization.
[12] ISO, 2003. ISO 13374-1:2003 Condition Monitoring and
Diagnostics of Machines — Data Processing,
Communication and Presentation — Part 1: General
Guidelines. Geneva: International Organization for
Standardization.
[13] ISO, 2018a. ISO 17359:2018 Condition Monitoring and
Diagnostics of Machines — General Guidelines. Geneva:
International Organization for Standardization.
[14] ISO, 2018b. ISO 31000:2018 Risk Management —
Guidelines. Geneva: International Organization for
Standardization.
[15] Jardine, A.K.S., Lin, D. and Banjevic, D., 2006. A review
on machinery diagnostics and prognostics implementing
583
condition-based maintenance. Mechanical Systems and
Signal Processing, 20(7), pp.1483–1510.
doi:10.1016/j.ymssp.2005.09.012.
[16] Karatuğ, Ç., Arslanoğlu, Y. and Guedes Soares, C., 2022.
Determination of a maintenance strategy for machinery
systems of autonomous ships. Ocean Engineering, 266,
113013. doi:10.1016/j.oceaneng.2022.113013.
[17] Khan, F.I., Sadiq, R. and Haddara, M.M., 2004. Risk-
based inspection and maintenance (RBIM): Multi-
attribute decision-making with aggregative risk analysis.
Process Safety and Environmental Protection, 82(6),
pp.398–411. doi:10.1205/psep.82.6.398.53209.
[18] Lazakis, I. and Ölçer, A.I., 2016. Selection of the best
maintenance approach in the maritime industry under
fuzzy multiple attributive group decision-making
environment. Proceedings of the Institution of
Mechanical Engineers, Part M: Journal of Engineering for
the Maritime Environment, 230(2), pp.297–309.
doi:10.1177/1475090215569819.
[19] Lazakis, I., Turan, O., Aksu, S. and Incecik, A., 2010.
Increasing ship operational reliability through the
implementation of a holistic maintenance management
strategy. Ships and Offshore Structures, 5(4), pp.337–357.
doi:10.1080/17445302.2010.480899.
[20] Lloyd’s Register, NYK Line and MTI, 2024. Data-Driven
Condition Based Maintenance. London and Tokyo:
Lloyd’s Register, NYK Line and Monohakobi Technology
Institute.
[21] Moubray, J., 1997. Reliability-Centred Maintenance. 2nd
ed. Oxford: Butterworth-Heinemann.
[22] Rødseth, Ø.J., Steinebach, C. and Mo, B., 2007. The use of
technical condition indices in ship maintenance planning
and the monitoring of the ship’s safety condition. In:
Proceedings of the International Symposium on Maritime
Safety, Security and Environmental Protection, Athens,
Greece, 20–21 September 2007.
[23] Thoben, K.-D., Homburg, N. and Gerriets, A., 2008.
MarLife: Development of a life cycle management system
for the maritime industry. In: Ship Repair Technology
Symposium, Newcastle-upon-Tyne, 1–2 September 2008,
pp.98–105.
[24] Vose, D., 2008. Risk Analysis: A Quantitative Guide. 3rd
ed. Chichester: Wiley.
[25] Zio, E., 2013. The Monte Carlo Simulation Method for
System Reliability and Risk Analysis. London: Springer.