Lesson previewBuild Recovery Before the Failure1 section shown
Preview lesson
Build Recovery Before the Failure
What you will learn
Distinguish duplicated equipment from genuinely independent navigation capability and prepare a recovery state that remains usable after a common-cause failure.
A second screen is not automatically a backup. Recovery depends on what the alternative shares with the primary system, whether it is current and ready, and whether the crew can use it when the failure occurs.
Start with functions, not gadgets. The passage needs some way to preserve time, position evidence, direction, movement, hazards, communications and a reconstructable record. For each function, identify the display, sensor, data path, power source, physical location, chart or publication, and person needed to keep it working. Two plotters can fail together when they share one GNSS antenna, data bus, battery bank, charging path, chart account, mounting position or water exposure.
The RYA describes an alternative means of fixing position and navigating to safety that should ideally continue independently if the primary system fails. MCA guidance for vessels within its scope likewise stresses cross-checking, reversionary sensors, separate power and a backup used to the same extent as the primary. The exact lawful carriage arrangement varies by vessel, operation and jurisdiction, so this lesson does not declare one universal paper or electronic solution for every yacht.
Readiness is an operational state. Relevant charts and publications must cover the route and be current for their intended use; the alternative must be charged or supplied, accessible, protected and configured; the last trusted position and passage plan must be transferable; and more than one person should know the takeover sequence. The workbench below compares constructed failures by symptom, shared dependency, trusted evidence and next action. It is a revision decision aid, not a vessel design approval or navigation system.
Recovery board
Trace the failure before trusting the replacement
Select a constructed failure. The board keeps immediate control, shared dependencies, trusted evidence and the next verification action visible together.
Dark display
The main chart display goes dark while other DC equipment still appears powered.
- 1Protect
- 2Time and freeze
- 3Classify
- 4Cross-check
- 5Recover
- 6Handover
- Immediate control
- Keep lookout and vessel control separate from diagnosis; reduce exposure and workload as the real situation requires
- Shared dependency
- Display circuit, connector, local water exposure, network and the primary charting position
- Trusted evidence
- Last independently supported position, time, compass, log, lookout, depth and maintained route record
- Recovery check
- Test the planned alternative with the failed display and disputed feed excluded
Supported result
The symptom is contained as a display-path failure until evidence supports a wider or narrower diagnosis.
Safety boundary
A dark screen does not prove GNSS failure, total power loss or that an unopened spare is ready.
Worked example
A yacht carries a fixed plotter and a tablet. Both use the same Wi-Fi GNSS feed, charge from the same 12-volt socket and are kept at the exposed navigation position.
- 1List the apparent duplication: two displays and two software interfaces.
- 2Trace the common dependencies: one position source, one charging path and one water-exposure location.
- 3Ask what remains if that GNSS feed is false, the socket is dead or the position is flooded.
- 4Add and rehearse alternatives that address the intended failures rather than merely adding another screen.
Sense check: If one event can remove both displays or feed both the same false position, the arrangement has duplication but not independence for that event.
| Capability | Shared dependency to expose | Readiness evidence |
|---|---|---|
| Position | Constellation, antenna, receiver, network and datum | Independent check demonstrated and last trusted fix transferable |
| Chart and route | Device, account, update, power and physical location | Relevant current material opened and route available |
| Direction | Heading sensor, compass, variation and power | Independent compass and error record usable |
| Time | GNSS-derived clocks, battery and correction record | Independent time source checked and rate known where used |
| Communication | Main bus, antenna, position feed and handset | Fallback path, position wording and power state rehearsed |
Build a dependency register
For every navigation and communication function, trace sensor, data, power, location, source material and trained operator.
1. Function
Name the capability that must continue, not just the installed product.
2. Dependency
Mark every shared feed, connector, bus, battery, antenna, mount, chart source and person.
3. Proof
Record the latest isolated test and the exact takeover action.
Sense check: A backup claim is incomplete until it names the failure it covers and the dependency that makes it independent for that failure.
Common mistake or limitation
- Counting screens while ignoring a shared sensor, network, power supply, chart source or exposed location.
- Calling stored equipment ready without current route coverage, configuration, charge, access and crew familiarisation.
- Turning commercial-vessel backup rules into one universal pleasure-yacht carriage statement.
Recap
- Plan functions and dependencies before choosing backup equipment.
- Independence is specific to a failure; two devices can share the same false data or lost power.
- A useful alternative is current, accessible, protected, tested and understood by the crew.
Optional quick check
Section 1 of 1