Empirical record

Evidence

The strongest real-world cases tested against the canonical definition, and the cases that look like Silent Expiry and are not. This page exists so that the concept can be checked against the record rather than accepted on its wording.

Every case here was reconstructed from a primary source — an accident investigation report, a regulatory document, a published standard — and tested adversarially: the working assumption was that the case does not qualify, and each of the three conditions had to be established against that assumption. Of nine candidates examined, seven were rejected. The rejections are as much a part of the evidence as the survivors, and they are set out in full below.

Two things this page does not claim. It does not claim that the cases below are the only ones, or that the search was exhaustive: five domains were examined, not every domain, and the open questions are stated at the end. And it does not claim that any case reaches the top grade. No case in the record is graded A.

How cases are graded §

Classification used throughout this page
ClassMeaning
ACanonical. All three conditions directly supported by documentary evidence.
BStrong. The mechanism clearly fits; one condition rests partly on inference.
CAnalogue. The mechanism resembles Silent Expiry; at least one condition cannot be established.
DExclusion. The case resembles Silent Expiry superficially and fails a defining condition.

Both incident cases below are graded B, and both for the same reason: they fail to reach A on condition 1. Investigation reports record what a control's parameter is; they rarely record when it was set or on what evidence. That is a limitation of the source literature, not of the condition, and the correct response is to grade the case B — not to relax the definition. Positive evidence that a control was inadequate from inception defeats condition 1 at any grade.

Strongest cases §

Three. Two are incidents with primary investigation reports; the third is structural — the mechanism as a standards family states it, with no accident attached.

Challenger 605 flap drive shaft — aviation maintenance §

Control. Maintenance task 275000-202: a detailed inspection of the flap flexible drive shafts every 2400 flight hours.

Premise. Stated numerically in the manufacturer's maintenance schedule: task intervals are based on an average utilization of 500 flight hours and 300 flight cycles in 12 calendar months. At that rate the task is a corrosion control that comes round about every 4.8 years.

What changed. The fleet was flying 275 flight hours a year; the occurrence aircraft averaged 283 across its life. The interval quietly became an 8.5-year one. The degradation mechanism — moisture ingress, then corrosion — runs on calendar time, not flight hours. The flight-hour count was a proxy for calendar time, and the proxy relationship is what died.

Why it fits. Six years and eight months after manufacture the shaft sheared in flight. The component had never been inspected, because the inspection was not yet due and was not required to have been; the aircraft was maintained in accordance with the regulations and approved procedures throughout. The premise was recorded — in a footnote to the schedule — and the compliance check asked only one question: has the aircraft reached 2400 hours? It never asked whether the aircraft was flying 500 hours a year. Nothing broke, nothing alarmed, and the investigating authority states the causal chain in those terms in its own findings.

Three-condition check
1 · A reason existedThe premise is stated numerically. That 500 flight hours a year was representative when the interval was set is inferred, not documented — the reason this case is B and not A.
2 · SeparatedThe premise was written down and still sat outside the check. The manufacturer separately tracked true fleet utilization, in a customer-service programme that does not set intervals.
3 · MuteThe compliance check returned not due — correct, and carrying no information about elapsed calendar time. Four service difficulty reports in 34 years, against 484 shafts sold in four, with no attribution of series, defect or time in service.
ConsequenceFlap failure in flight; zero-flap landing; tail strike and structural damage. No fatalities.
VerdictClass B — strong. Weakest condition: 1.

Source: Transportation Safety Board of Canada, report A20W0016 (2021) — References. A separate strand of the same occurrence — a manufacturing defect that punctured the shaft casing — is an ordinary latent defect and is not Silent Expiry. A third strand, the manufacturer's decision to apply a moisture-ingress improvement to one fleet and not the other, fails condition 3: that hazard was identified in 2007.

Air Midwest 5481 average-weight programme — air transport §

Control. An approved average-weight weight-and-balance programme: standard weights per adult passenger and per checked bag, used to compute every load manifest.

Premise. That the carrier's passengers and bags match the standard averages, which were built for what the guidance called a conventional airline passenger group.

What changed. The body-weight figures were inherited essentially unchanged across four revisions of the guidance between 1965 and 1995. A survey conducted after the accident found the true average adult weight some twenty pounds above the assumed figure, with carry-on and checked bags also understated. Every operator surveyed adjusted its weights afterwards.

Why it fits. The accident aircraft was outside its centre-of-gravity limits while its paperwork said it was inside them — and it got there because the crew followed the approved programme correctly. This is the same mechanism in a different class of control: a parameter rather than an interval, which is the first evidence that the state is not particular to maintenance scheduling.

Three-condition check
1 · A reason existedThe averages reflected a real population when first derived. The original derivation and date are not in the report — inferred, so B.
2 · SeparatedThe guidance recorded its basis as a qualitative caveat with no data and no date. The programme was approved without the required check that it applied to this carrier, and the carrier had never surveyed.
3 · MuteEvery manifest returned within limits. A ramp agent's report of two unusually heavy bags dead-ended: there was no tag for them and no field on the form, so the crew was not required to account for them. Foreign survey evidence from three countries never reached the guidance.
ConsequenceLoss of pitch control on take-off; 21 fatalities. The weight assumptions were named among the contributing factors.
VerdictClass B — strong. Weakest condition: 1.

Source: National Transportation Safety Board, report AAR-04/01 (2004) — References. A separate strand, a maintenance rigging error, was the primary probable cause; it is an execution failure and is not Silent Expiry. The remedy adopted afterwards is worth noting: the standard weights were re-based on national health-survey data and tied to a recurring revalidation — the premise was attached to a verification loop.

Useful-lifetime expiry of a reliability claim — functional safety §

Control. A safety function carrying an integrity claim — a SIL or Performance Level — established by a reliability calculation.

Premise. A constant failure rate, valid only within the component's assumed useful lifetime, commonly twenty years.

What changed. The component passes its useful lifetime. Nothing else changes at all.

Why it fits. The device still actuates. It passes its proof test. Its certificate is valid and the integrity claim in the safety requirements specification is unchanged. But proof testing verifies function, not the validity of the reliability model behind the claim — so a device beyond its useful life that still trips will pass every test while the integrity level it is credited with is no longer supported. This is the mechanism stripped of narrative: no accident, no organization, nobody to blame, and a verification that is structurally incapable of interrogating its own premise.

Three-condition check
1 · A reason existedThe constant-failure-rate assumption is valid within the useful lifetime, and is stated as such by the standard.
2 · SeparatedThe premise is in the standard. The proof test consults the device, not the model.
3 · MutePassing a proof test carries no information about whether the reliability model still holds. There is nothing for the test to find.
VerdictClass B — strong, structural rather than incident-based.

This case is also the clearest evidence against treating Silent Expiry as a discovery: a standards family named and mitigated this structure decades ago. It is recorded here because it is the purest instance of the mechanism, not because it is novel. The provision has not been verified against the standard text, which is not publicly available; the description rests on secondary technical guidance and is marked accordingly.

Analogues §

Cases where the mechanism is visible but at least one condition cannot be established from the available record. They are not evidence for the concept; they are candidates that a better source could settle either way.

Warehouse sprinkler protection against a changed commodity — fire protection. Class C. A sprinkler system designed and maintained for one commodity classification, in a building whose stored product had changed underneath it — in the wider case, an industry-wide change in aerosol propellant chemistry that left the word on the carton the same while the hazard behind it changed. The system operated; it was overwhelmed. What cannot be established from the accessible record is whether the commodity premise was recorded anywhere the inspection regime consulted, or whether any signal about it had reached that regime. Condition 2 is unproven, and the primary investigation report could not be obtained.

Near-misses and exclusions §

Seven of the nine candidates examined were rejected. Most failed on condition 3 — a signal attributable to the premise's failure had in fact reached someone able to change the control, and was rationalised, deferred or answered falsely. Those are failures of response. The concept covers what was never asked, not what was asked and answered badly.

Cases that resemble Silent Expiry and are excluded
CaseFailsWhy
Grenfell TowerCondition 3The nearest miss in the record. A coroner's letter after an earlier fire told the fire service to anticipate fire behaving inconsistently with the compartmentation principle; a later letter about external fire spread reached the building's managers; and weeks before the fire an assessor answered that the cladding complied, on assurances the inquiry found had never been obtained. A warning received and mishandled. Absent that exchange this would be a strong case, which is precisely why it must be excluded.
Alaska Airlines 261Condition 3, change managementEvery extension of the inspection interval was a decided, approved change, and the investigation found one of them unsupported by adequate technical data. The wear-rate premise then failed through an execution failure of the companion lubrication task. An inspector asked the premise question aloud at the last check and was overruled.
Fukushima DaiichiCondition 3The operator's own engineers computed tsunami heights far above the design basis and the results reached management, who deferred. The signal was received.
BP Texas CityCompliance, condition 3The siting control was not complied with, so the case fails before any condition is reached; prior warnings had also been received.
Nimrod MR2Condition 1The safety case was defective at creation. There was no true premise to expire.
Winter Storm UriCondition 1Most freeze-related outages occurred at temperatures above the stated design premise. The equipment failed within its premise; the premise did not cease to be true.
Knight CapitalCompliance, executionThe deployment control was not carried out on one of the servers. An execution failure, excluded at the first clause of the definition.
Oroville Dam spillwayConditions 1 and 3Poor foundation conditions were documented in the original geology reports and not addressed in the design, so no premise existed to expire. Anomalous drain flows observed at first use were later deemed normal — a received signal, normalised.
Aloha Airlines 243Conditions 2 and 3The premise was recorded exactly where verification could see it — the fail-safe rationale in the structural classification, and a service bulletin that had explicitly defined the disbonding and cracking sequence years earlier. The operator was found to have had sufficient information.
Chalk's Ocean Airways 101Conditions 1 and 3No fatigue analysis had ever been performed, so there was no premise. The damage announced itself for years: a crack stop-drilled three times, the same leak written up repeatedly, and a matching crack found in a sister aircraft months before.
MSC NapoliCondition 1, materialityDeclared container weights were never shown to have been reliable, and the investigation found the discrepancy insufficient to have caused the hull failure. The root cause was a design shortfall.

Two of these were dropped for a different reason and are recorded for completeness: a vessel rupture in which an inspection had already identified the wall thickness approaching its limit, and a tank collapse in which the governing inspection standard's requirements were not met. Both are failures of response or of execution.

What this page does and does not establish §

It establishes that the phenomenon occurs. In one case the investigating authority sets out the mechanism as its own finding as to cause; in another an aircraft was outside its limits while its paperwork said otherwise, because the crew followed an approved programme correctly. And it establishes that the definition discriminates: seven of nine candidates were rejected, for five distinct documented reasons. A concept that refuses Grenfell, Fukushima and Alaska 261 is doing work.

It does not establish more than that. Five domains were examined, not twenty-one. Both incident cases are graded B rather than A. Both are aviation, and both involve a control whose parameter stood proxy for the variable that actually drove the hazard — a useful search heuristic, and a caution: the demonstrated range is narrower than the claimed range. The standing of the evidence, stated plainly, is supported with limitations. The relationship to existing concepts is set out under References, and no claim of novelty is made there or here.

How a case is read out of an investigation report — the control, its premise, the routing of the signals, and the point at which a report can no longer support the reading — is the subject of Level 4 of the Articles library.

This page carries the cases. The canonical definition carries the concept, and nothing here forms part of it. Where a case and the definition disagree, the definition is what gets revised — and the wording of Rev3 was changed because the strongest case on this page did not fit it.