What a False Alarm Costs a Master at Sea

Seventeen minutes, in the one case with timestamps. On Commodore Clipper a real fire read as a detector fault: 11 silences, 7 resets, then the system died.
Seventeen minutes, in the one case where someone wrote down the seconds. The cost of a false alarm is not the bridge attention it consumes — it is the next alarm, the real one, arriving into a crew that has already decided the system is wrong. On Commodore Clipper in June 2010 that cost was measured: a genuine vehicle-deck fire alarmed at 02:42:36 and was not believed until 02:59:20.
That matters commercially because false-positive rate is the one detection specification buyers can compare on a datasheet, and it is quoted as a percentage nobody experiences. What a master experiences is a count, per voyage, and a judgment about whether the box on the bridge is worth getting out of a chair for. This post is about the arithmetic behind that judgment, and what the alert standards already say about it.
What disbelief cost on a real ship
It cost the whole early-warning margin, on a system that was working correctly. The MAIB's report into the fire on Commodore Clipper (24/2011) records the sequence to the second. Sensor D24 alarmed on the bridge and in the engine control room at 02:42:36; sensors either side followed within 30 seconds. The duty engineer had smelled no smoke, suspected a faulty component, and silenced the alarm six more times over the next three minutes before resetting it at 02:45:42. It reactivated. The second officer silenced it at 02:46:20 and reset it too. At 02:49:12 the fire detection system ceased to function — 6 minutes 54 seconds after the first alarm, having recorded 16 sensors, 81 activations, 11 silences and 7 resets. Fire was confirmed at 02:59:20, by the chief engineer smelling smoke when he opened his cabin door.
Two details make this the decisive case rather than an anecdote. First, MAIB notes the system had no particular history of spurious alarms — this was not a crew worn down by months of nuisance activations, which is the usual alarm-fatigue story. It was a single misreading by two competent officers. Second, every independent check available to them came back negative: the engineer decks below smelled nothing, the officer of the watch looked at the CCTV and saw haze he read as a picture fault, and the lookout's portable VHF returned eight unreadable calls. The instrument was right and every human verification route was wrong. That is the shape of the problem — not laziness, but an alarm that could not tell anyone why it was alarming.
The percentage no one on a bridge experiences
A false-positive rate is a per-cell, per-interval probability, and a ship experiences its product with the whole grid. Take 0.5% — a number that reads as tolerable in a specification. Across 1,200 sensor cells over a 14-day voyage it is about six false alarms, one every 56 hours, and no master will keep responding to the sixth at full pace. Process-industry alarm management has been explicit about the ceiling for decades: EEMUA 191 treats more than ten new alarms in a ten-minute window as the start of an alarm flood, and industry practice targets roughly five or fewer alarms per operator per hour in normal operation. The Clipper deck produced 81 activations in 6 minutes 54 seconds — on the order of a hundred in ten minutes, an order of magnitude past the flood threshold, and presented as 81 identical events rather than one developing fire.
So the engineering target is not 'low', it is 'below the threshold at which a crew starts making its own judgments'. That is several orders of magnitude tighter than a marketing percentage, and it is where most of the effort in a detection layer actually goes. But the Clipper case shows the target alone is not sufficient: a system with a clean false-alarm history still lost seventeen minutes, because a low rate does not give an officer a reason to believe any particular alarm.
What the alert standards already require — and where fire detection sits
IMO wrote the answer for navigation equipment in the same year as the Clipper fire, and fire detection was not in scope. Resolution MSC.302(87), adopted 17 May 2010, sets performance standards for Bridge Alert Management after IMO 'recognized scenarios where inadequate alert management could lead to human error'. Its stated philosophy is to 'avoid unnecessary distraction of the bridge team by redundant and superfluous audible and visual alarm announcements' and to 'reduce the cognitive load on the operator'. The mechanics are worth reading as a design spec by anyone building a detection HMI:
- Four priorities, not one: emergency alarm, alarm, warning, caution — distinguished by colour, symbol and sound pattern (an alarm is three short signals every 7–10 seconds; a warning two every 15 seconds to 5 minutes), so priority is audible before it is assessed.
- Silencing is bounded and temporary by design: alerts within the officer of the watch's responsibility silence for 30 seconds, others for 5 minutes, and newly appearing alerts still sound. There is no state in which a crew quietly mutes a category and moves on.
- An unacknowledged warning escalates to an alarm when the danger's time frame moves from 'in due course' to 'immediate' — the system, not the operator, re-rates urgency as a situation develops.
- Aggregation and functional grouping present related alerts under one header, and headers cannot be acknowledged — the individual alerts must be. Eighty-one activations become one heading with eighty-one members, not eighty-one interruptions.
- A Central Alert Management system logs alerts and displays alert history, and shows which equipment raised each alert with any decision-support guidance the source provides.
- 'Responsibility transferred' is a defined state: equipment with more information takes over an alert and replaces it with one that better reflects context.
None of that governs a vehicle-deck fire detection system, which sits under the FSS Code and the Code on Alerts and Indicators rather than BAM, and which on Commodore Clipper could be silenced and reset without limit from two stations. The gap is the point: the navigation side of the bridge has had a harmonised, escalating, loggable alert model since 2010, and the fire side — where the Clipper crew spent seventeen minutes — has not.
What to ask a supplier, and what to design
Ask what the alarm says, not only how often it is wrong. Three questions separate a detection layer that survives contact with a bridge from one that gets reset: What does the crew see when sixteen sensors activate in sequence — 81 events, or one spreading source with a location and a direction? What second signal corroborates the first, so that an officer whose nose and camera both say 'no fire' still has a reason to act? And what is retained — is there an alert history that a master, a surveyor or an investigator can read afterwards, as a CAM system is required to keep? On the deck side, the corresponding design choices are coherence windows across neighbouring cells, multi-modal confirmation rather than a single smoke channel, and an alarm that escalates on its own when the pattern keeps growing.
For the operator there is a procedural version that costs nothing and would have changed the Clipper outcome: treat a vehicle-deck alarm as a fire until proven otherwise, and never reset a system that keeps reactivating. MAIB's conclusion is blunt about it — given the potential for rapid fire development on vehicle decks, 'it is essential that crew react positively to fire alarms and initiate the proper emergency response'.
What it means for owners and underwriters
For the owner: the false-alarm specification you negotiate is a proxy for whether your crew will act at 03:00, and it is worth less than the alarm's ability to explain itself. Ask for the alert model, the logging and the escalation behaviour in the same breath as the rate. For the underwriter: a detection system that has been informally taken offline is indistinguishable, in a loss, from one that was never fitted — and the evidence for which of those you insured is the alert history, if the system keeps one. For both, the quiet lesson of Commodore Clipper is that the failure was not in the sensors, the coverage or the response time. It was at the interface, and that is a specifiable thing.
"The first time it cried wolf, we moved fast. The second time, we did not. That is the day the system stops being a safety system and becomes background noise."— Chief Officer, 6,500-CEU PCTC
How RoRoSAFE helps
A crew that has learned to distrust alarms loses the minutes that matter. RoRoSAFE fuses thermal and battery-vent gas signals at each vehicle before it raises an alert, and grades alerts into tiers, so the bridge gets fewer, more specific alarms that name a bay. The aim is an alarm the officer of the watch believes the first time.
Pilot: one deck · installed alongside the berth · no drydock · 6 months of dashboard access
Sources
- 1. MAIB Report No 24/2011 — 'Report on the investigation of the fire on the main vehicle deck of Commodore Clipper while on passage to Portsmouth, 16 June 2010' (November 2011), read in full: §1.4.2–1.4.4 (alarm at 02:42:36, six further silences, reset at 02:45:42, second silence at 02:46:20, system ceased to function at 02:49:12 — 6 min 54 s after the first alarm, 16 sensors, 81 activations, 11 silences, 7 resets; confirmation at 02:59:20; lookout's unreliable VHF and eight unreadable calls; CCTV visibility lost by 02:54); §3.3 conclusion 5 (both officers interpreted the alarm as a technical fault, delaying the response; 'it is essential that crew react positively to fire alarms').
- 2. IMO Resolution MSC.302(87), 'Adoption of Performance Standards for Bridge Alert Management', adopted 17 May 2010, with IEC TC80 WG16's supporting document for mariners (Bridge Alert Management, v4): the four alert priorities and their sound patterns (alarm three short signals every 7–10 s; warning two every 15 s to 5 min); temporary silencing of 30 s for alerts in the officer of the watch's responsibility and 5 min for others; escalation of an unacknowledged warning to an alarm; aggregation and functional grouping with headers that cannot be acknowledged; CAM system alert logging and history; the 'responsibility transferred' state; the stated goals and philosophy quoted here. Test standards IEC 62923-1/2.
- 3. EEMUA Publication 191, 'Alarm Systems: A Guide to Design, Management and Procurement' — alarm flood defined as more than ten new alarms in a ten-minute period, continuing until an interval with fewer than five; industry practice of roughly five or fewer alarms per operator per hour in normal operation. Related standards ANSI/ISA-18.2 and IEC 62682.
- 4. IMO Resolution A.1021(26), Code on Alerts and Indicators, and the FSS Code Chapter 9 — the regime that governs fixed fire detection and its alarms, as distinct from Bridge Alert Management.
- 5. Companion RoRoSAFE analyses — the Commodore Clipper incident anatomy (the full sequence and the reefer-plug ignition behind it), 'What Bridge Crew Actually Need', 'How Many Alarms Can a Bridge Team Absorb?' and 'False-Positive Suppression: Coherence Windows' (the detection-side design response).
Questions, answered
What does a false alarm actually cost at sea?+
The next alarm. On Commodore Clipper in June 2010 a genuine vehicle-deck fire was read as a detector fault: the alarm was silenced 11 times and the system reset 7 times before it stopped working, and the fire was not confirmed until 17 minutes after the first activation. MAIB records that the system had no history of spurious alarms — a single misreading was enough.
Why is a 0.5% false-positive rate not good enough?+
Because a per-cell rate multiplies by the grid. Across 1,200 sensor cells over a 14-day voyage, 0.5% is roughly six false alarms — one every 56 hours. EEMUA 191 treats more than ten new alarms in ten minutes as an alarm flood and industry practice targets about five per operator per hour, so the engineering target must sit orders of magnitude below a comfortable-sounding percentage.
Do international rules address alarm overload on ships?+
For navigation equipment, yes. IMO Resolution MSC.302(87) on Bridge Alert Management, adopted in May 2010, sets four alert priorities, bounds temporary silencing to 30 seconds or 5 minutes, escalates unacknowledged warnings, groups related alerts under headers and requires alert logging. Fixed fire detection sits under the FSS Code and the Code on Alerts and Indicators instead, and has no equivalent model.
What should an owner ask a detection supplier about false alarms?+
Three things beyond the rate: what the crew sees when many sensors activate in sequence — a spreading source with a location, or dozens of identical events; what second, independent signal corroborates the first so an officer has a reason to act; and whether the system retains an alert history that a master, surveyor or investigator can read after the event.
Continue the thread

Commodore Clipper: The Alarm Reset 7 Times
A reefer plug ignited on a Condor ro-pax in 2010. Detection worked — 16 sensors, 81 alarms. The crew read a fault, silenced it, and lost 17 minutes.
What Bridge Crew Need From Detection
We sat with masters and chief officers across four operators. The list of what they want is shorter — and more pragmatic — than most product teams assume.
Tuning Coherence Windows to Kill False Positives
Cross-cell coherence suppresses false alarms; the window length is the lever. Too short and solar gain trips the deck; too long and you lose lead time.

How Many Alarms Can a Bridge Team Absorb?
EEMUA 191 caps steady state at one alarm per ten minutes. Marine sets no equivalent rate target, and 2026 multiplies the addressable points.
Where AI Anomaly Detection Beats Rules
We use both. The interesting question is which decisions belong to which approach. The split is not where most marketing decks would put it.
Lisco Gloria: The Drencher That Gave No Water
The 2010 Lisco Gloria fire was detected within minutes and the drencher started — it delivered no water, and a 199 m DFDS ro-pax became a total loss.
The First Ten Minutes After an EV Alarm
Detection buys time only if the crew knows what to do with it. On a vehicle carrier the decisive variable isn't the alarm — it's the rehearsed response.
