Low-level outlet (LLO) gates play a vital role in the safe operation of impounding reservoirs. Although they may remain unused for extended periods, they must perform reliably whenever called upon, whether to manage reservoir levels during extreme weather events, to draw the reservoir down following a seismic event, to facilitate maintenance activities or to respond to emergency operating conditions. Failure to operate as intended can have significant consequences for public safety, downstream infrastructure and the long-term integrity of the dam itself.
Designing these critical systems therefore requires more than robust and thorough engineering. Due to the critical and complex nature of these systems, the design should follow a structured approach that identifies potential hazards, quantifies operational risk and establishes, on the evidence, whether the proposed design will achieve an appropriate level of reliability throughout its service life.
KGAL Consulting Engineers Ltd was commissioned by BC Hydro to carry out a reliability study of a proposed new low-level outlet gate installation at one of its dams. This study was undertaken while the design was still developing, so that its findings could inform engineering decisions rather than simply verify them once the design was complete.
By combining established risk assessment techniques with close collaboration between the client, designers and operational staff, the process enabled hazards to be identified early, design options to be evaluated objectively and system reliability to be quantified while the design remained open to change.
The result is a structured, evidence-based methodology that documents the reliability of a proposed design, identifies the components that dominate the residual risk, and gives the design team a basis on which to target further improvement, if required. Crucially, its purpose is to offer pragmatic and practical design advice, rather than simply to demonstrate compliance with a notional quantitative target.
A structured safety lifecycle
A safety lifecycle approach provides a systematic framework for reducing risk by integrating safety considerations throughout the design process, rather than treating them as a final verification exercise. The principles are set out in IEC 61508, Functional Safety of Electrical, Electronic and Programmable Electronic Safety Systems, and are widely applied within high-hazard industries such as oil and gas, chemical processing and power generation. They translate readily to critical hydraulic infrastructure, where dependable operation on demand is essential. The study described here was not undertaken as a formal assessment against the standard, but the sequence it followed reflects the same logic.
At its core, the methodology follows a logical sequence:
- Define the target range for probability of failure on demand for the system.
- Identify the hazards, and the functions required to prevent them.
- Assess the reliability required of the systems performing those functions.
- Quantify the proposed design against those targets.
- Establish which elements dominate the residual risk, and direct design effort accordingly.
Rather than applying these principles as isolated engineering exercises, KGAL incorporated them into a phased methodology developed for the LLO gate project. Each phase built upon the findings of the previous stage, ensuring that safety, reliability and operational performance remained integral to every engineering decision.
Defining the functional requirements
The process began with a detailed review of the documentation defining the operational requirements for the proposed low-level outlet gates. This material set out the intended gate configuration, operating philosophy and performance requirements under both routine and emergency operating conditions, together with the functional scenarios the gates would be expected to perform throughout their operational life.
KGAL undertook a comprehensive technical review, providing early feedback on design assumptions, operational requirements and areas requiring clarification before detailed engineering commenced. Establishing a clear understanding of the functional requirements at the outset ensured that subsequent assessments rested on an engineering understanding shared by the client, designers and operational stakeholders.
Identifying hazards while the design remains open
With the functional requirements established, the project team undertook a series of formal Hazard and Operability (HAZOP) workshops..
The workshop brought together specialists from BC Hydro’s engineering, operations, and dam safety teams alongside the gate designers and KGAL’s reliability engineers. Using a structured approach, the team systematically challenged each operating scenario to identify credible hazards, equipment failures, operational deviations and human factors that could compromise safe operation of the gates.
Rather than focusing solely on the equipment, the assessment considered the complete operational system, including mechanical, hydraulic, electrical, electronic and control elements, together with the interaction of operators and maintenance personnel. For every identified hazard, the team evaluated the potential causes, consequences, existing safeguards and opportunities for further risk reduction. Where existing protection measures were considered insufficient, actions were identified to eliminate or mitigate the risk through improved design.
This collaborative exercise established the hazard register that guided every subsequent stage of the assessment.
Informing the developing design
It is worth being clear about the starting point. This was not a blank sheet: a preliminary gate arrangement had already been developed when the reliability study commenced. What the HAZOP findings changed was the direction in which that arrangement subsequently developed.
Rather than progressing independently, the gate designers worked closely with BC Hydro and KGAL through an iterative process in which identified hazards continually informed design decisions. This enabled potential risks to be engineered out wherever possible through design simplification, improved redundancy, enhanced operational controls and more resilient system architecture, including the provision of multiple independent drive paths, so that no single loss of power or control would leave the gates inoperable.
By the conclusion of this phase, the design provided sufficient detail to define the principal mechanical equipment, lifting arrangements, electrical infrastructure and control philosophy.
Assessing failure modes
Once the design had matured, KGAL facilitated a comprehensive Failure Modes and Effects Analysis (FMEA). Where the HAZOP identified potential hazards, the FMEA examined how individual components could fail and what effect those failures would have on the performance of the LLO gate system as a whole. Each major subsystem, including the mechanical drive train, power supplies, electrical controls and instrumentation, was systematically analysed to identify potential failure modes, likely causes and resulting operational consequences. The assessment also identified the protection layers that would either prevent failures from occurring or mitigate their consequences should they arise.
Beyond identifying weaknesses, the FMEA built a detailed understanding of system behaviour under fault conditions and highlighted opportunities to improve resilience. The resulting data formed the basis for the quantitative reliability assessment undertaken during the next phase.
Quantifying system reliability
With the potential failure modes identified, all significant failures were carried forward into a Fault Tree Analysis (FTA) to quantify the reliability of the proposed design.
Fault Tree Analysis is a top-down analytical technique that models how individual component failures, together with operator actions and system interactions, can combine to produce an undesired event, in this case, the gates failing to open sufficiently to pass the required discharge on demand. Using established reliability data together with the findings of the FMEA, the analysis calculated the Probability of Failure on Demand (PFD) for the complete system. Human factors, including operator action, remote control centre operation and access arrangements, were included within the scope of the assessment alongside the equipment itself.
The calculated PFD, and the fault trees more generally, were used to evaluate the overall reliability of the system and allowed the team to evaluate where improvements might be possible.

From result to recommendation
The assessment did not, at first pass, demonstrate that the proposed design would meet its target. The calculated probability of failure on demand fell short by more than an order of magnitude.
This is where a purely pass-or-fail reading of the result would have been unhelpful. Rather than treating the shortfall as a verdict on the design, the fault tree model was used diagnostically, ranking the individual contributors to the overall PFD so that design effort could be directed at the small number of items dominating the outcome.
A series of sensitivity studies was then undertaken to establish the magnitude of the biasing influence exerted by particular subsystems. These identified the mechanical drive train as the dominant contributor to the calculated figure, because it is a single point of failure. The distinction matters considerably in practice: without it, a design team can expend substantial effort on improvements that barely move the overall reliability figure, while the item actually governing the result goes unaddressed.
The recommendations arising from the study are therefore focused on the top contributing items, those changes most likely to deliver a material improvement in overall reliability. Design development against those recommendations is continuing, and the reliability model provides the means to test each proposed change objectively before it is adopted.
Scope and limitations
Any quantified reliability assessment rests on a defined scope, and it is worth stating this one plainly.
The analysis addressed random hardware failures and therefore assumes constant failure rates. Failures arising from equipment deterioration and wear-out are not modelled; these are assumed to be managed through maintenance and through refurbishment or replacement of equipment across the installation’s life. The assessment to date has addressed the scenario in which the outlet fails to pass sufficient water on demand during a large flood. The converse scenario, failure to stop the flow of water on demand, is to be addressed in a subsequent phase of the study. Other potential failure modes exist but were judged less critical and were not carried forward.
None of this undermines the value of the exercise. It does, however, make the point that a reliability figure is a statement about a defined set of failure mechanisms, and is only as meaningful as the scope behind it is explicit.
Conclusions
The methodology applied by KGAL demonstrates how functional safety thinking can be brought to bear on the design of critical hydraulic infrastructure. By integrating hazard identification, failure modes analysis and quantified reliability assessment throughout the design process, safety considerations become an integral part of engineering decision-making rather than a final compliance exercise.
Although developed for a specific low-level outlet gate project, the methodology has broader application across dams, flood defence infrastructure, navigation structures and other hydraulic steel systems where dependable operation on demand is essential.
As owners and operators continue to modernise ageing infrastructure while meeting increasingly demanding safety and resilience requirements, structured, risk-based design methodologies will become an increasingly important part of engineering best practice.
Authored by Paul Jones, CEng MIET, Associate Director, KGAL Consulting Engineers Ltd. https://www.kgalglobal.com/