On board, the question is never whether to do preventive maintenance, but on what, how often, and for what reason. A plan that treats the starting air compressor and the forepeak bilge pump with the same intensity wastes the time of a crew that has none to spare. Conversely, letting the steering gear drift towards failure means accepting a risk at sea that cannot be recovered.
Reliability centered maintenance, or RCM, supplies the judgement that most vessel maintenance plans lack. It is an engineering method that forces every task to be justified by the real consequences of a failure, item by item and failure mode by failure mode. Its principle is selective: it applies only to equipment whose failure carries serious consequences for safety, the environment or the operation of the ship.
This article applies the seven questions of the method to shipboard equipment, and covers three points that industrial handbooks leave out: the collision with regulatory requirements, the hidden failures of standby arrangements, and the fleet effect across sister vessels.
Why RCM means something different at sea
A plant ashore can stop a line and have a part delivered the same day. A ship on passage has neither. Three constraints change the equation. Isolation: onboard spares are finite, and the failure of a single item can immobilise the vessel far from any workshop. Redundancy: two or more generator sets, two sea water pumps, two steering control systems — this is exactly what RCM knows how to exploit, provided it is measured honestly. Manpower: the engine team is sized to run the plant, not to absorb a preventive plan written without judgement.
RCM answers all three. It frees up time where redundancy makes a failure acceptable, and reinvests it in the items whose failure is unforgiving. This is the logic of our guide to building a preventive maintenance plan in four steps, taken one step further: where the PMS organises tasks, RCM decides which of them deserve to exist at all.
The seven RCM questions applied to shipboard equipment
The method requires seven questions to be answered in order before any task is proposed. Maintenance is only discussed once it is established what the item must do and what it costs when it stops doing it.
Questions 1 and 2: function and functional failure
What must the item do, in its operating context? The answer has to be quantified. "Cooling" means nothing. "Keeping the main engine fresh water inlet temperature within the maker's range, at full load and at maximum sea water temperature" is a workable function. Context is part of the definition: the same pump does not have the same function on a vessel on ocean passage and on a unit waiting at anchor.
In what ways does the item stop performing that function? Functional failure is rarely binary. A sea water pump may be stopped altogether, or deliver below the flow needed at full load while remaining adequate at reduced load. Two states, two distinct sets of consequences.
Questions 3 to 5: modes, effects and consequences
What are the failure modes? The actual physical causes, not general categories. For a starting air compressor: fouled or broken valves, worn piston rings, scaled intercooler, defective pressure safety device. For a deck winch: brake wear, internal leakage in the hydraulic motor, fluid contamination. Each mode is analysed separately because each calls for a different countermeasure.
What happens when it occurs? Here the observable effects are described, the ones the engine team will actually see: rising temperature, pressure drop, alarm on the panel, noise, vibration, traces of leakage. This description is what later determines whether a failure is detectable, and by what means.
Why does this failure matter? This alone justifies spending crew time. The same mechanical failure does not carry the same severity depending on whether it affects a redundant item or a single one, a safety system or a domestic service. This is where the difference lies between a reasoned vessel maintenance plan and a catalogue of inherited tasks.
Questions 6 and 7: proactive tasks and default actions
What can be done to prevent or detect the failure? RCM keeps a task only if it is technically effective against the failure mode in question and economically defensible. Three families exist: the scheduled restoration or replacement task (overhaul at a fixed interval, in running hours or calendar time), the on-condition task (measuring a parameter that announces degradation: gearbox oil analysis, vibration readings on a generator set, per-cylinder exhaust temperature monitoring), and the failure-finding task, reserved for hidden failures and covered further down. Moving from scheduled to on-condition work is often the first gain of an RCM study, which is the subject of our article on moving from corrective to condition based maintenance.
And if no proactive task is worthwhile? The method accepts three outcomes: run to failure, where the consequences are acceptable and the repair is within the ship's means; redesign, where the failure is unacceptable and no monitoring makes it predictable; or a change in the way the plant is operated, by altering operating parameters or imposing a documented emergency procedure. The third route is common at sea, where an installation cannot be redrawn but the shipboard operating procedures expected under chapter 7 of the ISM Code can be developed.
Classifying failure consequences on board
RCM sorts consequences into categories, because each calls for a different decision logic. Here is the maritime version of that classification.
| Consequence category | What is being avoided | Typical shipboard item | Decision logic |
|---|---|---|---|
| Personnel safety | Injury to, or endangerment of, crew or passengers | Steering gear, deck winches and hydraulics, compressor pressure safety devices | A task must be found; failing that, the design or the operating method changes. |
| Environment | Discharge to sea, oil pollution | Bilge water separator, bunkering lines, fuel transfer pumps | Same requirement as safety: the status quo is not acceptable. |
| Operations | Delay, deviation, off-hire, loss of manoeuvrability | Main engine, bow thruster, generator sets | Economic judgement: cost of the task against cost of unavailability. |
| Direct cost only | Repair and spares, with no effect on the voyage | Redundant service pump, domestic auxiliary | Failure acceptable if the repair is within the ship's means. |
| Hidden failure | A standby item unavailable without anyone knowing | Emergency generator, emergency fire pump, emergency steering control | Periodic testing to reveal the true state of the arrangement. |
The table says something simple: on the first two rows, the economic argument does not apply. The cost of a task is not weighed against the cost of a pollution incident or an injury. An effective task is sought, and failing that, something else changes.
Criticality and the decision matrix
Failure mode, effects and criticality analysis — FMECA — turns this reasoning into priorities. It combines three dimensions: the frequency of the failure mode, the severity of its consequences, and detectability, meaning the ability to see degradation coming before it becomes a failure.
Detectability deserves particular attention at sea. An instrumented and alarmed shaft bearing does not have the same detectability as a bearing checked by hand once a watch: two identical items may call for two different strategies depending on their instrumentation, and the analysis must record this.
Criticality matrix applied to shipboard equipment
| Severity of consequence | Rare failure | Occasional failure | Frequent failure |
|---|---|---|---|
| Safety or environment Steering gear, bilge water separator, standby arrangements |
Scheduled task or periodic test | On-condition, instrumented monitoring | Reinforced on-condition, review of design or operating method |
| Major operational impact Main engine, generator sets, bow thruster |
Scheduled at maker's interval | On-condition: oil analysis, vibration, exhaust temperatures | On-condition plus root cause treatment |
| Limited operational impact Redundant air compressor, standby cooling pump |
Accepted run to failure | Light periodic inspection | Reduced scheduled task |
| Cost only Non-essential auxiliaries, domestic services |
Accepted run to failure | Accepted run to failure | Periodic inspection or replacement on wear |
The matrix is not an automatic answer: it exists to make a decision visible and to have it endorsed by the chief engineer and the technical department ashore. A cell filled in without written justification in the analysis is worth nothing.
The point industrial methods ignore: RCM collides with regulation
This is where a direct transposition of an industrial RCM study fails at sea. The analysis may perfectly well conclude, on sound technical grounds, that a redundant item can run to failure: limited consequence, repair within the ship's means, no economically justifiable proactive task. That reasoning is correct in a factory. It becomes inapplicable as soon as the equipment is subject to a mandated interval.
Liferafts, extinguishers, the emergency fire pump, survival craft and their launching arrangements are governed by intervals that are not negotiable. No criticality analysis authorises extending them, and the conclusion "run to failure" simply does not exist for these items.
The output of an RCM analysis must therefore be reconciled with mandated tasks before it enters the maintenance plan. In practice this means one more step in the process:
- First establish the base of tasks with mandated intervals, with their origin, and freeze it.
- Run the RCM analysis on the critical items, without self-censorship.
- Compare the two lists item by item.
- Where RCM proposes a shorter interval than the requirement, keep the RCM interval.
- Where it proposes a longer interval, or no task at all, keep the requirement: regulation always wins.
One thing is worth keeping even when the requirement prevails: the technical justification produced by the analysis. It explains what the task actually prevents, and turns an imposed obligation into a task the crew understands. It is also what makes the plan defensible in an audit, as we set out in our article on the ISM Code and vessel maintenance compliance.
Hidden failures and chapter 10.3 of the ISM Code
RCM treats one category of failure separately: the kind that does not announce itself when it occurs, the hidden failure. A standby item that does not run can be out of service for weeks without anyone noticing. Nothing stops, no alarm sounds. The failure only appears at the moment the standby is needed, which is the worst possible moment.
Shipboard examples are numerous: emergency generator, emergency fire pump, emergency steering control, remote emergency stops, alarms never exercised in normal operation. For all of these, RCM prescribes a specific task, the failure-finding task: the arrangement is deliberately put into service at a defined interval, not to maintain it, but to reveal whether it is still capable of working.
This is precisely what chapter 10.3 of the ISM Code addresses, requiring identification of equipment and technical systems whose sudden operational failure may result in hazardous situations, and requiring regular testing of standby arrangements and equipment not in continuous use. The RCM failure-finding task and the chapter 10.3 requirement are the same thing, expressed in two languages.
That equivalence has a practical consequence. An owner who conducts an RCM analysis produces, at no extra effort, the critical equipment list and the testing programme that chapter 10 of the ISM Code expects. Conversely, an owner who builds a serious ISM 10.3 list has already done half the work of identifying hidden failures. Both approaches pursue the same objective: proving that a standby arrangement is available before it is needed.
These tests must still leave a trace. A test carried out but not recorded does not exist for an auditor, and the evaluation required under chapter 12 of the ISM Code bears precisely on the owner's ability to demonstrate that the system works. That is the role of the maintenance module: to carry the test task, its interval, its result and the person who performed it.
The fleet effect: what makes RCM affordable
The standard objection to RCM is its cost: a serious analysis consumes expert hours from the chief engineer, the superintendent, sometimes the maker. On a single vessel, the investment is hard to defend.
Across a fleet of sister vessels the equation changes. Main engine, generator sets, steering gear and sea water systems are identical from one unit to the next. The analysis carried out once — functions, failure modes, consequences, selected tasks — applies to the whole series, and its unit cost is divided by the number of ships. This is what puts RCM within reach of a mid-sized owner, where it would remain a luxury on a single vessel.
Sharing the work carries one strict condition: the equipment hierarchy and coding must be common across the fleet. If the same sea water system is described over three levels on one vessel and five on its sistership, if the same pump carries two different tags, the analysis does not transpose and the benefit disappears.
Common coding is therefore a prerequisite, not a by-product. It is built in the equipment register, before the first analysis is launched. Once in place, it produces three effects:
- Maintenance strategies can be compared from one vessel to another, and divergences become visible.
- Failure history aggregates across the whole series, giving frequencies based on a meaningful volume of observations rather than on the recollection of one ship.
- Spares are shared, since critical items carry the same nomenclature throughout the fleet.
This last effect is often what pays for the exercise. Managing the work at series level is the province of the fleet view.
The role of the CMMS in the process
An RCM analysis is only as good as the data feeding it. Without reliable history, frequencies are impressions and severities are recollections.
Upstream: supplying the facts
Work order history is the raw material of the analysis. How many times has this failure mode occurred across the series? What was the actual downtime, the spares consumed, the degraded operating mode during the repair? These answers are read from the reports entered on board, provided the entries distinguish failure modes from one another. A history in which everything is filed as "pump repair" is of no use.
Downstream: carrying the decision
The chosen strategy then has to become real tasks, with their interval, their trigger — calendar, running hour counter, measured condition — and their method statement. The CMMS carries the traceability that allows a decision to be revisited: if a failure mode recurs despite the task, the task was not effective against that mode and the analysis must be revised. RCM is not a one-off exercise: it lives on fleet feedback, within the wider framework described in our complete guide to maritime CMMS.
The seven questions at a glance
| Question | What it establishes | Example: sea water cooling pump |
|---|---|---|
| 1. Function | What the item must do, quantified in its operating context | Cool the main engine at full load, at maximum sea water temperature |
| 2. Functional failure | The states in which the function is no longer delivered | Insufficient flow at full load, or complete stoppage |
| 3. Failure modes | The actual physical causes, analysed separately | Seal wear, bearing degradation, impeller erosion, strainer blockage |
| 4. Effects | What the engine team actually observes | Rising fresh water temperature, alarm, vibration, leakage at the gland |
| 5. Consequences | Safety, environment, operations or cost alone | Forced speed reduction, engine damage if monitoring fails |
| 6. Proactive tasks | The task effective against the mode and economically defensible | Vibration readings, seal inspection, strainer cleaning according to trading area |
| 7. Default actions | Accepted run to failure, redesign or change of operating method | Accepted run to failure on the standby pump, subject to periodic testing |
Conclusion
RCM is not a method to be applied everywhere, and that is its strength. It decides where to concentrate effort, on the basis of the real consequences of a failure rather than habit. Applied to shipboard equipment, it produces a plan that is shorter, better justified and easier for a crew to keep to.
Three conditions separate an analysis that stays in a binder from one that changes the plan. Reconciliation with mandated tasks: regulation always wins, and the analysis then serves to explain the task rather than remove it. Serious treatment of hidden failures, which maps exactly onto the requirement to test standby arrangements under chapter 10.3 of the ISM Code. And scale: a hierarchy and coding shared across sister vessels turn a one-off expert investment into an asset reusable across the whole series.
To discuss putting this into practice across your fleet, get in touch with the Smart Sailors team.

