What is Redundancy, Really?
In engineering, redundancy is the practice of duplicating critical components to increase a system's reliability. Think of it like the spare tyre in your car's boot—you hope you never need it, but it's there in case you do. On an aircraft, this concept
is applied to nearly every essential system, but on a far more sophisticated level. Modern airliners are built with multiple layers of backup. This means that for a catastrophic failure to occur, it’s not just one part that needs to fail, but its independent backup, and often a third or even fourth backup system as well. The goal is to ensure that no single failure can jeopardise the safety of the aircraft.
The Multi-Engine Safety Net
The most visible example of redundancy is an aircraft’s engines. While it may look like a plane needs all its engines to fly, that's not the case. Commercial twin-engine jets are designed and certified to fly safely on just one engine. This capability is governed by a set of rules known as ETOPS (Extended-range Twin-engine Operations Performance Standards). An ETOPS rating specifies how long, in minutes, a plane can safely fly with a single engine to the nearest suitable airport. Modern aircraft like the Airbus A350 and Boeing 787 have ETOPS ratings of 370 and 330 minutes, respectively, allowing them to fly direct routes over vast oceans and remote areas, far from the nearest runway, with an incredible safety margin.
More Than Just Engines
Redundancy extends far beyond the engines. Aircraft rely on hydraulic systems to move flight controls like the rudder, elevators, and flaps. Instead of one hydraulic system, large commercial jets have multiple—typically three—independent systems. These systems are often powered by different sources, such as different engines or electric pumps, so the failure of one engine doesn't knock out all hydraulic power. Similarly, the electrical systems that power everything from cockpit instruments to navigation and communication equipment are also duplicated. Aircraft have multiple generators and batteries, ensuring that if one power source fails, another is ready to take over instantly.
Fly-by-Wire: Digital Backups
In older aircraft, pilots moved flight controls using a series of physical cables and pulleys. Most modern airliners, starting with the Airbus A320, use a 'fly-by-wire' system. Here, the pilot's inputs are converted into electronic signals processed by flight control computers. These computers then command actuators to move the control surfaces. To ensure reliability, these systems are highly redundant, often using three (triplex) or four (quadruplex) independent computers running in parallel. If one computer produces an erroneous result or fails, the others can outvote it and take over seamlessly, ensuring the pilot's commands are executed correctly. This digital redundancy not only adds a layer of safety but also allows for flight envelope protections that prevent the aircraft from entering an unsafe state.
When Redundancy Is Put to the Test
Aviation history is filled with incidents where redundancy was the hero. In 2010, Qantas Flight 32, an Airbus A380, suffered an uncontained engine failure that damaged hydraulic and electrical systems. Despite a cascade of failures, the aircraft's remaining redundant systems allowed the crew to land safely. Another famous example is US Airways Flight 1549, the 'Miracle on the Hudson'. After losing both engines to a bird strike, the pilots still had control of the flight surfaces thanks to backup power, which allowed them to successfully ditch the plane in the Hudson River. These incidents, while dramatic, are powerful demonstrations of a safety philosophy that anticipates failure and builds resilience right into the aircraft's design.
















