Module 17 · Lesson 17.2
Assurance, and what a design does not know
Every level of checking has a blind spot it cannot remove. And every design relies on things nobody has verified — which is only dangerous when it is not written down.
Why this matters
A design is issued into the world and someone builds it. Between those two events sits everything this lesson is about: who checked it, what that level of checking could not possibly have found, what the design has taken on trust, and whether it may be issued for construction at all. None of it is calculation, and it is the part that decides whether the calculation matters.
By the end of this lesson you should be able to
- Distinguish the levels of checking by what each can and cannot find
- Classify a finding by its consequence
- Keep a register of values taken on trust
- Decide what a design with an open register may be issued for
Levels of checking, and what each is blind to
Checking is usually described by who does it. It is more useful to describe it by what it shares with the design, because that is where it cannot see.
| Level | Finds | Cannot find |
|---|---|---|
| Self-check | Arithmetic, transcription, omitted steps | A misunderstood brief; a wrong idealisation — it is made of the designer's assumptions |
| Peer, same project | The above, plus misapplied clauses | A shared misreading of the brief; anything the project has normalised |
| Independent, separate team | Wrong idealisations, missing load cases, errors of approach | An error in the organisation's own standard methods or software |
| Third party, separate organisation | The above, plus errors embedded in the original organisation's templates and software | An error in the brief itself, if both were given the same wrong brief |
Each level removes one shared thing and gains the ability to find errors in it. Each still shares something, and that is its blind spot — permanently, not for want of care.
The last row is worth sitting with. Even a third-party check shares the brief. That is why the brief is checked separately, by someone whose job is to ask whether the right structure is being designed at all.
Predict first
A designer checks their own work extremely carefully, three times, over three days. What class of error remains untouched?
Severity is about consequence, not size
A checker who reports everything at the same volume is as unhelpful as one who reports nothing, because the important finding is lost among the typographical ones.
What decides severity is not how large the discrepancy is. It is what would happen if it were not corrected:
- A 15% error on a member at 0.50 utilisation moves it to 0.58. Record it; nothing follows.
- A 3% error on a member at 0.99 moves it to 1.02. The member fails, and it must change.
The second is smaller and far more serious. Severity therefore needs the utilisation, not just the arithmetic.
One thing sharpens it further: how the affected member would fail. A ductile flexural member at 1.02 will sag, crack, and give warning. A punching-shear or buckling check at 1.02 will not — it fails suddenly and completely. The same overshoot on a brittle check is a different finding, and should be reported as one.
Try it
Which check catches which error?
Introduce a real error into the building designed in Module 16 and see which of the four checking methods notices. Each method owns a class of error and is blind to the others — which is why checking is a set of methods rather than one thorough one.
Introduce an error
The design as issued.
- Order of magnitude nothing to find
Beam moment: the approximate route gives 527 against 552 — within 25%, which is as close as a rough check can claim.
- Equilibrium audit nothing to find
Applied 3500 kN, arriving 3500 kN — balances to within 0.0%.
- Sanity band nothing to find
Bearing pressure of 187 kN/m² is in the usual range — nothing to query.
- Independent check from the brief nothing to find
Nothing to find.
- Beam load as reported
- 78.4 kN/m
- Span used
- 7.5 m
- Moment as reported
- 552 kNm
- The correct moment
- 552 kNm
- Checker's rough moment
- 527 kNm
- Ratio, reported / rough
- 1.05
- Pad sized for / actually needs
- 1.00
- Load applied / arriving
- 3500 / 3500 kN
- Bearing pressure
- 187 kN/m²
- Beam utilisation, was 0.71
- 0.71
- Severity of the finding
- —
No error introduced. Every check agrees, which is what agreement is supposed to look like.
What each result is telling you
- Omitted partitions: the hardest of the four, and the largest in its effect on the beam. Every arithmetic check starts from the same load list and so inherits the omission — including the equilibrium audit, whose totals are wrong at both ends and therefore still balance.
- Double-counted self-weight: only 2.2%, far too small for any order-of-magnitude band, and caught instantly by equilibrium — more load arrives at the ground than was ever applied. This is the class of error equilibrium owns.
- Pad on the factored load: conservative, so nothing falls down. It is still an error: 38% of every foundation is a great deal of concrete, and nobody yet knows whether the same misunderstanding was applied somewhere it is NOT conservative. Note that the SANITY BAND misses it — 136 kN/m² is comfortably inside 100 to 400. Bands catch gross outliers, and a 38% oversize is not gross.
- Span scaled wrong: 13% in a length becomes 28% in the moment, because moment goes with the square — and note the beam's utilisation moving from 0.71 to 0.91. It is caught here ONLY because the checker took the span from the grid on the layout drawing rather than from the designer's beam sheet. Take it from the designer's sheet and both routes share the error, and the check reports agreement. Where a check gets its inputs decides what it is capable of finding.
- Watch the severity as you switch between errors. It depends on the utilisation the member started at, not on how large the discrepancy looks — which is why a checker needs the design's utilisations and not just its answers.
Worked example
Four errors, and which check finds each
Given
- The Module 16 building: 200 mm slab, 350 × 650 beams at 5.0 m centres, 400 mm columns, 2.6 m pads
- Reported: beam w = 78.4 kN/m, M = 551 kNm; column NEd = 1602 kN; bearing pressure 187 kN/m²
Find
Which checking method catches each of four plausible mistakes.
The register of what a design does not know
Every design relies on things nobody has verified. A bearing pressure assumed before the ground investigation. A National Annex value taken from a textbook. A supplier's capacity taken from a datasheet. An assumption about how the building will be used.
None of these is wrong. Each is a liability, and the only thing that makes it dangerous is being invisible.
So a design carries a register: what has been taken on trust, why, what would happen if it turned out otherwise, and who has to resolve it. A design that cannot produce this list does not know what it is relying on.
That register also decides what the design may be issued for:
- For information or for comment — permitted with an open register, provided the register goes with it. An issue without its caveats is a claim the design does not support.
- For tender — permitted, and the register belongs in the tender documents, because it is where the risk sits.
- For construction — not permitted until every entry is either verified or formally accepted by someone entitled to accept it.
That last phrase is the whole discipline. "Someone decided it was probably fine" is not acceptance.
Practice
A finding would increase the demand on a member by 3%. The member's utilisation was 0.99. What is the utilisation afterwards?
Practice
A span is scaled as 8.5 m when it is really 7.5 m. By what factor is the design moment overstated?
Practice
A pad is sized on the factored load of 1602 kN instead of the characteristic 1162 kN. By what factor is its plan area overstated?
Check yourself
A design has 17 unverified values in its register. It is issued for tender. Is that legitimate?
Check yourself
An independent check by a separate team in the same organisation agrees with the design throughout. What can still be wrong?
Summary
- Describe a check by what it SHARES with the design — that is where it is blind
- Even a third-party check shares the brief, which is why the brief is checked separately
- Severity is consequence: 3% on a member at 0.99 beats 15% on one at 0.50
- Failure of a brittle check is a different finding from failure of a ductile one
- A conservative error is still an error — report it, at lower volume
- A design that cannot list what it took on trust does not know what it relies on
- An open register permits issue for information, comment and tender — never for construction
- This course's register has 17 of 17 entries unverified, and it is generated, not written
This is educational material. It uses simplified examples to teach principles, and must not be relied on for real design or safety-critical decisions. Module overview and checkpoint