Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Risk Management Framework”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Risk-Informed Safety Assurance and Probabilistic Assessment of Mission-Critical Software-Intensive Systems

This report validates and documents the detailed features and practical application of the framework for software intensive digital systems risk assessment and risk-informed safety assurance presented in the NASA PRA Procedures Guide for Managers and Practitioner. This framework, called herein the "Context-based Software Risk Model" (CSRM), enables the assessment of the contribution of software and software-intensive digital systems to overall system risk, in a manner which is entirely compatible and integrated with the format of a "standard" Probabilistic Risk Assessment (PRA), as currently documented and applied for NASA missions and applications. The CSRM also provides a risk-informed path and criteria for conducting organized and systematic digital system and software testing so that, within this risk-informed paradigm, the achievement of a quantitatively defined level of safety and mission success assurance may be targeted and demonstrated. The framework is based on the concept of context-dependent software risk scenarios and on the modeling of such scenarios via the use of traditional PRA techniques - i.e., event trees and fault trees - in combination with more advanced modeling devices such as the Dynamic Flowgraph Methodology (DFM) or other dynamic logic-modeling representations. The scenarios can be synthesized and quantified in a conditional logic and probabilistic formulation. The application of the CSRM method documented in this report refers to the MiniAERCam system designed and developed by the NASA Johnson Space Center.

Guarro, Sergio B.↗

Shooting the Moon

This story is about an unlikely NASA mission to the Moon. It was unlikely because it was started with far too little time and too-little money to complete. It was unlikely because it was able to take chances to accept risk of failure. It was unlikely because it was searching for the unthinkable: water-ice on the moon... Figure 1-1: LCROSS Mission. The mission of the Lunar CRater Observation and Sensing Satellite (LCROSS) was to investigate the possibility of water ice in craters on the Moon s poles. This is certainly an interesting scientific topic in itself, but I intend to focus on the compelling experience of managing the LCROSS Project in the context of this storied Agency. Perhaps most interesting are the implications this story has for managing any development effort, lunar or not, and working a balance to achieve success. NASA is by design a risk-taking agency within the US Government. It could be argued that NASA s purpose in the aerospace community is to take on the really big challenges that either the corporate world can t afford, are not yet profitable endeavors, or are just too risky for private corporations to entertain. However, expectations of the Agency have evolved. A combination of grim human tragedies and some very public cost and schedule overruns have challenged the public s and Congress s tolerance for risk-taking within the Agency. NASA, which is supposed to be in the business of taking risks to do bold, difficult things, has become less and less able to do so within its cost framework. Yet effectively replacing prudent risk management with attempts to "risk-eliminate" is completely unaffordable. So where does risk-taking fit within the Agency, or within private/corporate organizations for that matter? Where astronauts play there is clearly concern about risk. When an organization puts humans in harm s way, it is understandably going to take extra effort to assure nobody gets hurt. Doing so, of course, costs money - a lot of money to pay for labor and hardware which is attempting to assure nothing will go wrong. Sophisticated designs, with doubly- or triply-redundant systems, extensive testing to verify those systems, and numerous engineering test units built to learn and evolve a hardware design, all drive the cost and time required to implement. Human spaceflight is an expensive business because of the exceptional system complexity and levels of assurance required for human space travel. What about missions that do not involve human spaceflight? What about missions whose potential failure will not take a human life, whose costs are small and whose urgency and importance are limited by design? A portfolio consisting of this type of mission can be designed to be risk tolerant, not requiring large expenditures to guarantee against failure. With the money saved, the number of missions that can be executed within the portfolio grows, or the total cost of the portfolio can be reduced. The NASA LCROSS mission is a pathfinder example of a low-cost, quick turn-around mission which struck a balance on mission risk, while accomplishing big objectives, like defining how we understand the Moon.

Andrews, Daniel R.↗

Modeling interconnections of safety and financial performance of nuclear power plants, part 3: Spatiotemporal probabilistic physics-of-failure analysis and its connection to safety and financial performance

Here, this paper is a byproduct of a line of research by the authors to analyze interrelationships of safety and financial performance of nuclear power plants (NPPs). The result of this line of research is summarized in three parts: Part 1 covers a categorical review of relevant literature and the theoretical bases that support the methodological developments in Part 2. Part 2 introduces an Integrated Enterprise Risk Management (I-ERM) methodological framework to quantify the interconnections of safety and financial performance with a focus on operation and maintenance (O&M) of NPPs. Part 2 has also demonstrated the applicability and values of the I-ERM methodology through an NPP case study. This paper is Part 3, where detailed development and implementation of one of the I-ERM modules, i.e., probabilistic physics-of-failure (PPoF) analysis, and its connection with safety and financial performance is reported. In this article, the physical failure modeling for hardware components is advanced by incorporating finite element analysis (FEA) into PPoF analysis and coupling the FEA-based PPoF with the maintenance performance through a renewal process model. This article covers two scientific contributions: (i) first-of-its-kind incorporation of FEA into the PPoF model of thermal fatigue for NPP components; and (ii) advancing the interface between the PPoF analysis and the renewal process model in order to deal with spatiotemporal FEA outputs and to efficiently estimate the physical transition rates even when the PPoF outputs are dominated by success data. Through the incorporation of FEA, the resolution of the PPoF analysis is enhanced as spatiotemporal conditions such as stress and temperature can be considered explicitly instead of relying on simplified assumptions or analytical models with reduced spatiotemporal dimensions. To demonstrate an application of the FEA-based PPoF analysis and its coupling with maintenance through the renewal process model, a case study is conducted using excess letdown elbow piping in the chemical and volume control system of a Pressurized Water Reactor.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Economic Risk-Informed Maintenance Planning and Asset Management (Final Report)

The proposed work will provide a holistic framework for cost-minimizing risk-informed maintenance planning, including inspection, in light water reactors (LWRs). Specifically, we develop a two-tier framework that (a) coarsely minimizes the total maintenance cost during the remaining normal operating cycle of the plant prior to the next scheduled outage (long-term), subject to safety requirements, and (b) uses the outputs of the first model to develop a secondary optimization model to finely schedule maintenance activities to maximize the financial impact of these activities in the next week (short-term).

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Cyber-Physical Risks for Advanced Reactors

Cybersecurity for industrial control systems is an important consideration that advance reactor designers will need to consider. How cyber risk is managed is the subject of on-going research and debate in the nuclear industry. This report seeks to identify potential cyber risks for advance reactors. Identified risks are divided into absorbed risk and licensee managed risk to clearly show how cyber risks for advance reactors can potentially be transferred. Absorbed risks are risks that originate external to the licensee but may unknowingly propagate into the plant. Insights include (1) the need for unification of safety, physical security, and cybersecurity risk assessment frameworks to ensure optimal coordination of risk, (2) a quantitative risk assessment methodology in conjunction with qualitative assessments may be useful in efficiently and sufficiently managing cyber risks, and (3) cyber risk management techniques should align with a risked informed regulatory framework for advance reactors.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Distributed Solar in Tamil Nadu

With India’s ambitious renewable energy targets and decreasing rooftop solar prices, customer adoption of rooftop solar on Tamil Nadu’s distribution network is set to increase in the coming years. With that comes the challenge of how to assess the impact of these emerging distributed energy resources. In an effort to help with such an assessment, NREL has created a holistic analysis framework for Tamil Nadu Generation and Distribution Company (TANGEDCO). The Emerging technologies Management and Risk evaluation on distribution Grids Evolution (EMeRGE) analysis framework and tool will help TANGEDCO and other distribution companies (DISCOMs) in India analyze new interconnection applications and evaluate the system risk impact over time with new emerging DERs.

Children's Investment Fund Foundation↗

A Framework to Assess Advanced Reactor Spent Fuel Management Facility Deployment

Previous planning and prioritization for LWR SNF management investigated the risks and uncertainties of deploying facilities such as consolidated interim storage [1, 2, 3, 4]. As part of that work, activities and milestones were collected into success precedence diagrams that charted a path to achieving facility deployment [1]. In that framework, activities are any research, development, design, or decision required to achieve an intermediate goal; milestones are activity endpoints and mark the completion of deliverables. Milestones can be thought of as achievements required to reach the final goal of facility deployment; activities are the means by which milestones are accomplished. In planning, activities and milestones are compiled into comprehensive flow charts that visualize the steps necessary for deployment. This framework has been used to quantify risks, timelines, and costs of deploying SNF management facilities.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Recommended Practices for Managing Induced Seismicity Risk Associated with Geologic Carbon Storage

The geologic storage of carbon dioxide (CO 2 ) is one method to help reduce or eliminate atmospheric CO 2 emissions. The sequestered CO 2 is originally captured from the atmosphere or from a stationary industrial source and subsequently injected into a deep subsurface porous rock formation. To facilitate the successful deployment of field scale carbon storage projects, the U.S. Department of Energy (DOE) is developing tools and protocols for defensible, science-based frameworks to quantify and mitigate risks associated with the long-term storage of CO 2 . This protocol specifically addresses the risk of induced seismicity due to injection in a geologic carbon storage (GCS) site. This integrated and risk-based protocol is a product of the U.S. DOE Fossil Energy’s National Risk Assessment Partnership (NRAP), a multi-year collaborative research effort of Los Alamos National Laboratory (LANL), Lawrence Berkeley National Laboratory (LBNL), Lawrence Livermore National Laboratory (LLNL), National Energy Technology Laboratory (NETL), and Pacific Northwest National Laboratory (PNNL). These recommended practices describe a set of 7 steps to evaluate, manage, communicate, and mitigate the risk of induced seismicity at GCS sites. The base methodology of the recommended practices follows a framework similar to the Protocol for Addressing Induced Seismicity Associated with Enhanced Geothermal Systems (Majer et al., 2012), developed for the Geothermal Technology Office of the U.S. DOE. These recommended practices present a framework to systematically assess the induced seismicity risk and quantify the associated uncertainties. These recommendations are based on current research and are sufficiently general to allow for modification and application to a variety of different types of sites. The substance of the recommended practices contained herein includes both technical and non-technical issues, and covers all operational stages of the GCS project lifecycle. They start at the preliminary risk assessment phase, continue through site assessment and characterization, include best practice communication and seismic monitoring plan methodologies, discuss the evaluation and mitigation of seismic hazard and risk, and closes with an exploration of operational management plans, which conclude when the induced seismicity risk abates back to background level. The focus of these recommendations is on actively managing the risks associated with induced seismicity by developing an actionable risk management plan that starts at the project proposal stage and continues through site closure through an iterative assessment and improvement process. The audience of this document is expected to include all interested stakeholders (e.g., operators, project developers, regulators, and the general public) and is expressly written to be accessible to this broad range of partners. This document is intended to disseminate knowledge gained through recent advances in the science of induced seismicity hazard and risk assessments, to provide updates based on recent experience gained by similar corollary injection-induced seismicity cases, and most importantly to establish a uniform framework to carry out a successful induced seismicity risk management plan for carbon storage projects in the future. These recommendations do not directly address any domestic or international regulations or standards. A complementary NRAP report makes recommendations for the assessment and management of environmental subsurface risks associated with unwanted fluid migration at GCS sites (Thomas et al., 2021) and should be referred to in order to address those additional GCS site risks.

54 ENVIRONMENTAL SCIENCES↗

Recommended Practices for Managing Induced Seismicity Risk Associated with Geologic Carbon Storage

The geologic storage of carbon dioxide (CO 2 ) is one method to help reduce or eliminate atmospheric CO 2 emissions. The sequestered CO 2 is originally captured from the atmosphere or from a stationary industrial source and subsequently injected into a deep subsurface porous rock formation. To facilitate the successful deployment of field scale carbon storage projects, the U.S. Department of Energy (DOE) is developing tools and protocols for defensible, science-based frameworks to quantify and mitigate risks associated with the long-term storage of CO 2 . This protocol specifically addresses the risk of induced seismicity due to injection in a geologic carbon storage (GCS) site. This integrated and risk-based protocol is a product of the U.S. DOE Fossil Energy’s National Risk Assessment Partnership (NRAP), a multi-year collaborative research effort of Los Alamos National Laboratory (LANL), Lawrence Berkeley National Laboratory (LBNL), Lawrence Livermore National Laboratory (LLNL), National Energy Technology Laboratory (NETL), and Pacific Northwest National Laboratory (PNNL). These recommended practices describe a set of 7 steps to evaluate, manage, communicate, and mitigate the risk of induced seismicity at GCS sites. The base methodology of the recommended practices follows a framework similar to the $\textit{Protocol for Addressing Induced Seismicity Associated with Enhanced Geothermal Systems}$ (Majer et al., 2012), developed for the Geothermal Technology Office of the U.S. DOE. These recommended practices present a framework to systematically assess the induced seismicity risk and quantify the associated uncertainties. These recommendations are based on current research and are sufficiently general to allow for modification and application to a variety of different types of sites. The substance of the recommended practices contained herein includes both technical and non-technical issues, and covers all operational stages of the GCS project lifecycle. They start at the preliminary risk assessment phase, continue through site assessment and characterization, include best practice communication and seismic monitoring plan methodologies, discuss the evaluation and mitigation of seismic hazard and risk, and closes with an exploration of operational management plans, which conclude when the induced seismicity risk abates back to background level. The focus of these recommendations is on actively managing the risks associated with induced seismicity by developing an actionable risk management plan that starts at the project proposal stage and continues through site closure through an iterative assessment and improvement process. The audience of this document is expected to include all interested stakeholders (e.g., operators, project developers, regulators, and the general public) and is expressly written to be accessible to this broad range of partners. This document is intended to disseminate knowledge gained through recent advances in the science of induced seismicity hazard and risk assessments, to provide updates based on recent experience gained by similar corollary injection-induced seismicity cases, and most importantly to establish a uniform framework to carry out a successful induced seismicity risk management plan for carbon storage projects in the future. These recommendations do not directly address any domestic or international regulations or standards. A complementary NRAP report makes recommendations for the assessment and management of environmental subsurface risks associated with unwanted fluid migration at GCS sites (Thomas et al., 2021) and should be referred to in order to address those additional GCS site risks

58 GEOSCIENCES↗

Data Centers and Digital Assurance Workshop 3 – Mitigations for Digital Assurance Risks

The third session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort, held on November 18, 2025, focused on developing mitigation strategies for digital assurance risks identified in previous workshops. Hosted by Idaho National Laboratory (INL) and ScottMadden, the session emphasized the application of Cyber-Informed Engineering (CIE) to data center infrastructure, particularly at the utility–data center interface. Participants revisited and ranked key digital assurance risks, including architecture and interface weaknesses, governance gaps, and AI-enabled threats. The workshop introduced the 12 principles of CIE, advocating for consequence-focused design, engineered controls, and secure information architecture to proactively reduce cyber-physical vulnerabilities. These principles were applied to critical data center systems such as power distribution, UPS, cooling, SCADA/BMS, and grid-forming batteries. The session also addressed governance challenges at the interconnection boundary, highlighting the need for clear roles in telemetry sharing, firmware management, and trip settings. Special attention was given to emerging risks from behind-the-meter (BTM) generation, including reverse-power flow and the integration of small modular reactors (SMRs), which shift data centers from large loads to complex generation nodes. Participants explored how interconnection agreements can serve as enforceable instruments for digital assurance, and reviewed gaps in current standards such as NERC CIP, IEC 62443, and IEEE 1547. The workshop concluded with pathways to standardization, including model agreement language, state-level programs, and expanded NERC guidance. INL also presented tools and frameworks for secure procurement and supplier risk management, reinforcing the need for integrated engineering and policy solutions to secure the evolving data center–grid ecosystem. Session 3 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Advancing process-based flood frequency analysis for assessing flood hazard and population flood exposure

Recent studies have showcased the use of process-based hydrological models with Stochastic Storm Transposition (SST) techniques to conduct Flood Frequency Analysis (FFA). This framework, referred hereby FFA-SST, has proved to be a robust strategy to estimate peak flows of specific annual exceedance probability (e.g., 100-year peak flow) that can reflect natural and anthropogenic disturbances, including changes in land use and meteorological patterns. With the objective of advancing the FFA-SST framework, this study presents for the first time the use of an Integrated Surface-Subsurface Hydrological Model (ISSHM) to conduct FFA-SST by extending the analysis from peak flow responses to flood extent, enabling a unique view and analysis of flood hazard and population flood exposure at the basin scale. As a proof-of-concept, we used the ISSHM, Advanced Terrestrial Simulator (Amanzi-ATS) model, and the SST model, RainyDay, to conduct FFA-SST by simulating the flood response to 5,000 annual synthetic storm events in a 2,227 $km^2$ Southeast Texas watershed. We demonstrate that ATS, without site-specific calibration, provides a robust process-based representation of peak flows, flood extent, streamflow, evapotranspiration, soil moisture content, and water storage changes. Our results and analyses, covering frequency curves up to a 500-year return period for peak flows, basin inundation fractions, and the number of people exposed to flooding, offer a unique perspective to analyze flood impacts across spatial scales. Overall, this study provides critical insights for flood risk management by extending the FFA-SST framework to include both flood hazard and population flood exposure analyses at the basin scale. Such an approach will empower stakeholders and disaster emergency agencies with a more comprehensive understanding of flood impacts across the entire basin domain, facilitating informed decision-making for flood risk assessment and management.

58 GEOSCIENCES↗

Design Status and Experimental Strategy for Initial Molten Salt Irradiation Experiments in HFIR

The development and deployment of molten salt reactor (MSR) technologies require experimental capabilities that can evaluate molten fuel salt behavior and structural material performance under representative irradiation conditions. Although modeling and separate effects testing provide important insight, there remains a critical lack of in-pile data that capture the coupled effects of neutron irradiation, temperature, salt chemistry, and time. Informed by lessons learned from historical MSR programs and recent international irradiation efforts, this report presents a structured approach to addressing existing gaps in molten salt irradiation testing using the High Flux Isotope Reactor (HFIR). A phased irradiation strategy is presented that incrementally increases experimental complexity while managing cost, risk, and facility constraints. The framework progresses from passive, nonfueled static capsule experiments to fueled, instrumented, and ultimately circulating molten salt systems, providing a pathway for materials screening, mechanistic understanding, and qualification-relevant testing. The report defines a near-term Phase 1 passive capsule concept, associated irradiation conditions, and a conceptual post-irradiation examination strategy. Ongoing modeling, out-of-pile testing, and safety analysis activities are described to support continued capability maturation and to enable future phases of molten salt irradiation testing in support of MSR technology deployment.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Responsibly Harnessing the Power of AI

Artificial Intelligence (AI) based applications are on the cusp of offering the public and private sectors tools of tremendous potential that will likely transform the world in much the same way that previous technological revolutions have. To harness these tools, a vast and rapidly increasing assortment of ethical AI guidelines and principles are being developed to manage the myriad of risks these tools pose. Documents, frameworks, standards, and regulations have been developed by private industry, research institutions, governments and nongovernmental organizations, international standards bodies and more. This work details representative approaches to ethically developing, managing, and operating current AI technologies. The various approaches are analyzed for commonality, divergence, and implementation strategy to help develop approaches for managing AI tools in the nuclear landscape. This work will support the creation of a common vocabulary and a deeper understanding of the ethical/ responsible AI landscape and advance the considerations required for structured frameworks in the international safeguards domain.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Risk-Informed Operations and Maintenance Decision Making Using Deep Reinforcement Learning

A challenge for operating nuclear power plants is the significant cost of operations and maintenance, at times consuming up to 66% of annual operating costs. This project aims to build a framework for a risk-informed asset-management tool that integrates inspections, repairs, spare-part inventory, supply chain, and business choices to lower overall O&M costs. Our approach uses a combination of data-driven modeling and deep reinforcement learning to create and implement optimal maintenance policies for the existing nuclear fleet, as well as new advanced reactors. The creation of an asset management tool that uses these advanced methods will give operators new capabilities to help reduce the burden of O&M spending in nuclear power plants.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

The Cybersecurity Value-at-Risk Framework: Informing Cybersecurity Decisions

The Cybersecurity Value-at-Risk Framework is a tool that can be used by hydropower plant manager to make more educated cybersecurity investments. Users can take a self guided assessment allowing the tools to generate risk, impact and cybersecurity scores and be given risk-based recommendations to enhance decision-making.

CVF↗

Testing a Run-Time Assurance Framework Coupled with Integrated Risk Mitigation Capabilities for Autonomous Urban UAS Flights

The In-Time Aviation Safety Management System (IASMS) Concept of Operations (ConOps) envisions new capabilities to monitor, assess, and mitigate flight safety risks. Systems will be tailored to mission type, vehicle/equipage type, operational environment, and safety risk tolerance. Within an IASMS framework, several capabilities may be implemented spanning three operational phases (pre-flight, in-flight, and post-flight/off-line); and consisting of lower level functions and information services which may reside onboard the aircraft, on third-party server(s), and/or on ground/operator station(s). Each capability will be designed to produce and disseminate safety-relevant information; perform detection, diagnosis, and prediction of unsafe situations; and/or execute mitigation actions when hazardous events warrant such changes. This paper focuses on recent testing of airborne capabilities that demonstrate inflight aspects of the overarching concept for autonomous unmanned aircraft systems (UAS) operations in urban environments. A flight test architecture is described that applies run-time assurance principles (e.g., executes independent of the unassured autopilot), real-time risk assessment, and a technique to execute contingencies if necessary either automatically or via pilot intervention. Several tests using small UAS were conducted to verify the assured in-flight risk mitigation capability. The paper draws significantly from a larger NASA technical report and recent prior conference papers, providing additional details. Data is analyzed for two representative flights to illustrate the performance for various sequential and simultaneous hazards used during testing. During each automated flight, several hazards are encountered at various points along the flight path. At each point, the hazard is mitigated by the system, with the vehicle then continuing to subsequent points. The paper concludes with lessons-learned regarding relevant aspects of the overarching IASMS concept and how it may be updated and further advanced in the future.

population activity↗

International Cybersecurity: Capabilities and Overview [Slides]

Innovations in clean energy technology are beginning to transform electric grids around the world. It is more important than ever to understand and improve the resiliency and security of the grid against natural and human disruptions as our energy systems become more distributed, intelligent, and interconnected. Through its advanced cybersecurity technical assistance portfolio, experts at the National Renewable Energy Laboratory (NREL) work with international governments to support secure and resilient deployment of renewable energy assets and address grid interconnection challenges. Cybersecurity technical assistance is tailored to the needs of our international partners.

24 POWER TRANSMISSION AND DISTRIBUTION↗