An alarm system is the only crew member that never sleeps, and on an unattended machinery space ship it is the reason the engine room can be left at all. It is also the system most likely to be quietly degraded: a sensor drifting out of calibration, a set point widened to stop a nuisance alarm, a cable repaired but never recalibrated, an extension alarm that stopped reaching one cabin months ago. None of that shows up in daily operation, because the system looks healthy right up to the moment it needs to be right. This guide covers what the alarm and monitoring system has to do under the SOLAS unattended machinery space requirements, the daily and periodic testing that proves it still does it, how to calibrate and loop-check sensors, and how to deal with the single biggest threat to a working alarm system, which is not a failed sensor but a flood of alarms nobody reads any more. The charts on this page use published alarm management benchmarks from process industry practice, because the shipping industry has no equivalent numbers and the human limits are the same. To keep test results, calibration records and set points with the equipment they belong to, try Marine Inspection free.

A tested alarm is a safety system. An untested one is a wire.

Prove the chain end to end: sensor, set point, panel, extension, cabin, bridge. Then record the value it actually tripped at.

Alarm listUMS mode
HIGHM/E jacket water outlet temp highUnack
MEDLO filter differential highAck
LOWBilge well levelAck
STBYSensor fault: FO temp transmitterStanding
A standing sensor fault is an alarm that stopped protecting anything. Count them weekly.

What the rules expect the system to cover

The requirements for ships operating with periodically unattended machinery spaces sit in SOLAS Chapter II-1, Regulations 46 to 53, with class rules and the ship's notation adding detail. These are the headline items your testing programme has to prove.

Fire detectionDetection and alarm covering machinery spaces, including the boiler air supply casing and uptake, and the scavenge spaces of propulsion machinery.
Crankcase protectionEngines of 2,250 kW and above, or with cylinder bores over 300 mm, require oil mist detection, bearing temperature monitoring, or an equivalent arrangement.
Flooding detectionBilge wells positioned and monitored so accumulation is detected at normal angles of heel and trim, with alarms during the unattended period.
Engineers' alarmAn alarm that calls the engineers, audible in cabins and public spaces and on the bridge, so an unanswered machinery alarm always reaches someone.
Bridge controlPropulsion controllable from the bridge with an independent emergency stop, and limits on consecutive automatic start attempts to protect starting air.
Power supplyThe alarm and monitoring system has to keep working through a power supply failure and changeover, with its own supply arrangement and failure indication.

The alarm numbers nobody measures on ships

Marine alarm systems are engineered to class rules but almost never measured against alarm management benchmarks. Process industry guidance is worth borrowing, because the limit is the human being reading the panel, not the ship. The widely used figures come from EEMUA 191 and ISA-18.2.

Average alarm rate: published acceptability bands
Under 1 per 10 min
Very likely acceptable
1 to 2 per 10 min
Manageable
2 to 5 per 10 min
Hard to cope with
Over 5 per 10 min
Over-demanding

Roughly one alarm per ten minutes in steady state, about 144 to 150 a day, is the benchmark these standards converge on. A study of 37 operator consoles found around a third achieved it and about a quarter more reached the manageable band, so it is demanding but realistic.

Priority mix: target
80%low
Low 80%Medium 15%High 5%
Priority mix: flattened
30%low
Low 30%Medium 40%High 30%
Why the mix matters

The commonly cited target is roughly 80% low, 15% medium and 5% high. When priorities inflate towards an even split, every alarm carries the same weight and the system has communicated no priority at all. On a ship that means the duty engineer treats a bilge level and a jacket water temperature the same way at 0300.

Review the priority assigned to every alarm point when you review set points. It costs nothing and it is the single change that makes a panel readable.

Alarm flood: what an upset does to the panel
Flood threshold: 10 per 10 min 11212418953211 Successive 10-minute periods, illustrative. The upset begins in period five.

A flood is commonly defined as more than ten alarms in ten minutes for one operator, and the flood is treated as continuing until a period carries fewer than five new alarms. This is exactly when the duty engineer most needs the panel to be readable, and exactly when an unrationalised system buries the one alarm that matters.

Bad actors: a few points cause most of the load
12345678 35%77%100% Alarm points ranked by number of activations, with cumulative share. Illustrative shape.

Alarm activity is always skewed. Published experience is that fixing the worst offenders, by correcting set points, adding suppression logic or removing the point, can cut overall alarm rates by 60 to 80 percent, and in one documented case seven alarms accounted for 98 percent of the load. That makes the first month of cleaning up an alarm list the cheapest safety work on the ship.

Nuisance alarms and how to kill them properly

The wrong way to deal with a repeating alarm is to widen the set point or disable the point. Both leave the panel quiet and the protection gone. Deal with the cause, and record whatever you change.

TypeWhat it looks likeCorrect treatment
ChatteringThe same point alarms and clears repeatedly within minutesAdd or correct deadband and on-delay, or fix the process instability causing it
StandingAn alarm that has been active for days and is simply ignoredFix the defect or the set point. Count standing alarms weekly and drive the number down
DuplicateOne event producing several alarms from related pointsRationalise: keep the one that tells the engineer what to do
Wrong set pointAlarms during normal operation, or never at allReview against the maker's figure and the operating range, and record the change with a reason
Failed sensorFault indication, frozen value, or a reading that never movesLoop check, calibrate or renew. Never leave a failed input inhibited without a plan
Inhibited or suppressedPoints switched off for maintenance and forgottenKeep an inhibit register with who, why and when it will be restored. Review it at every handover
Never leave an inhibit undocumentedAn inhibited alarm is a disabled safety function. It needs an entry in the inhibit register, the chief engineer's knowledge, and a restoration date. Class and PSC both ask about this, and it is one of the few defects that can be identified from paperwork alone.

Sensor calibration and loop checks

Calibration proves the reading. A loop check proves the whole chain from sensor to panel to extension. Both are needed, and they are not the same test.

Temperature

Resistance elements and thermocouples: compare against a reference at two points across the working range, check the transmitter output, and confirm the panel reading and alarm point. Watch for cable and terminal resistance on long runs.

Pressure and differential

Apply a known pressure with a calibrator, check zero and span, confirm the milliamp output, then confirm the panel value. Check impulse lines and isolating valves for blockage first, which is the more common fault.

Level and bilge

Float and capacitance devices need functional testing by raising the actual level where practicable. Confirm the alarm and any automatic start, and check for fouling, which is the usual cause of failure.

Flow and viscosity

Check against a second indication and against expected values at known load. Drifting flow measurement often shows up first as a control problem rather than an alarm.

Oil mist detection

Test and maintain strictly to the maker's instructions, including the test function, sampling pipe cleanliness and any lens or optics. This is a protection device, not an indication.

Loop checks

Simulate at the sensor, not at the card, wherever possible. Confirm the value at the panel, the alarm priority, the audible signal, the extension to cabins and public spaces, and the bridge indication.

Record the value it tripped at"Tested, satisfactory" proves nothing later. Record the set point, the value at which it actually operated, the reference instrument used and its calibration date. That is what a surveyor is looking for, and what tells you next year whether the sensor is drifting.

The testing programme

Split testing by how much disruption it causes, so nothing waits for an opportunity that never comes. The exact frequencies come from your safety management system, the class notation and the maker's manual.

WhenWhatEvidence to keep
Before every UMS periodChecklist round: machinery condition, bilge levels, tank levels, standby pumps in auto, dead man system armed, extension alarms to the duty cabin and bridge confirmedSigned UMS checklist with the duty engineer named
WeeklyLamp and audible test at the panel, review of standing and inhibited alarms, dead man alarm function testStanding and inhibited alarm counts, with actions
MonthlyExtension alarm test to every cabin, public space and the bridge, engineers' call alarm, battery and power failure changeoverList of locations proved, and by whom
Quarterly to annuallySensor calibration and loop checks by rotation, safety trip testing at the sensor, oil mist detector routine, fire detection zone testingCalibration sheets with set point, trip value and reference instrument
At survey and after changesFull functional demonstration for class, plus retest of any point after cable work, software change or component replacementTest reports, software version and backup record

Dead man alarm and the lone engineer

When the machinery space is unattended and someone enters it alone, the dead man or patrolman system is the only thing that will raise the alarm if they are hurt. Practice varies between ships: some systems require the timer to be reset at intervals of around ten to twenty-five minutes, and where no system is fitted the usual requirement is for the engineer to contact the bridge at intervals not exceeding fifteen minutes. Follow the ship's own procedure, and test it rather than assuming it.

1Tell the bridge before entering, and state how long you expect to be below
2Arm the system at the entrance or in the control room, as the ship's arrangement requires
3Reset at the signal columns within the set interval while working
4If the reset is missed, the pre-warning sounds locally first, then the alarm extends to the bridge and accommodation
5Report to the bridge on leaving, and confirm the space is secured and back in unattended mode
6Test the full chain, including the extension, at the interval in the safety management system

Keeping the system itself alive

The monitoring system is a machine too, and its failure modes are boring: a flat battery, a failed power supply card, a corrupted configuration with no backup, or a laptop nobody can find the password for.

Power supplies and batteriesTest the changeover and the backup supply, and record battery replacement dates. A monitoring system that dies with the main supply protects nothing.
Configuration backupsKeep a current backup of the system configuration and alarm database, stored off the system itself, and take a new one after every change.
SparesInput and output cards, power supply modules, common sensors and fuses. A single failed card can blind a whole section of the plant.
Access controlKnow who has engineering-level access and how it is controlled. Set point changes should be traceable to a person.
DocumentationLoop lists, set point schedules, cable schedules and the alarm list itself, kept current after every modification.
CyberTreat the automation network as part of the ship's cyber risk management, including software updates and removable media discipline.

Troubleshooting matrix

SymptomCheck firstLikely causes
Alarm at the panel but not in the cabinsExtension unit, wiring, cabin selector, volume and isolation switchesExtension alarm fault, selector left in the wrong position, blown fuse
Reading frozen or implausibleSensor, cable, terminals, card inputFailed sensor, broken or wet cable, failed input channel
Repeating alarm that clears itselfDeadband, delay, process conditionChattering point, set point too close to normal running value
Alarm never operates on testSet point, inhibit status, loop continuityPoint inhibited, set point wrong, break in the loop
Multiple alarms from one eventAlarm list logic and groupingUnrationalised list, no first-up or grouping logic
System resets or loses timePower supply, battery, earth faultsFailing supply module, flat backup battery, supply disturbance
Bridge indication missingBridge panel, network link, configurationLink failure, panel fault, configuration changed without testing
Set points, trip values and inhibits in one recordLog each test with the set point, the value it operated at and the reference instrument, keep an inhibit register that cannot be lost, and hand the whole file to the surveyor.
Book a free demo

Frequently asked questions

What does SOLAS require for unattended machinery spaces?

SOLAS Chapter II-1, Regulations 46 to 53 cover fire detection, flooding detection, bridge control of propulsion, the engineers' alarm and the monitoring arrangements. Class rules and the ship's notation add the detail, including the test programme.

Which engines need oil mist detection?

Engines of 2,250 kW and above, or with cylinders of more than 300 mm bore, require oil mist detection, bearing temperature monitoring or an equivalent arrangement.

How many alarms is too many?

Process industry guidance converges on about one alarm per ten minutes in steady state, roughly 144 to 150 a day, with more than ten in ten minutes counted as a flood. There is no marine equivalent, but the human limit is the same.

Can we widen a set point to stop a nuisance alarm?

Only as a deliberate, recorded engineering decision against the maker's figures, never as a quick fix. Fix the cause, or add the correct deadband or delay, and write down what was changed and why.

How often should the dead man alarm be tested?

At the interval in the safety management system, commonly before each unattended period as part of the checklist, and as a full functional test with the extension chain at the periodic interval.

What records will a surveyor expect?

UMS checklists, alarm and trip test records with set points and measured trip values, calibration records with reference instruments, the inhibit register and the configuration backup record. See our auxiliary engine guide and switchboard inspection guide.

Every test, set point and inhibit in one place

Marine Inspection records alarm tests, calibration values and inhibit registers at the panel, offline, links them to the equipment and running hours, and builds the survey pack from the same data.