A practical, evidence-led review should challenge the reasoning connecting requirements, operating duty, design and verification, not merely confirm that the drawings and calculations look complete.
A component can be correct and still be wrong for the machine
A component can be neatly modelled, correctly toleranced and supported by a tidy calculation, yet still be wrong for the machine around it.
Perhaps the calculation used the nominal load while the real peak occurs during starting. Perhaps the selected seal suits the fluid but not the cleaning cycle. Neither problem is found by checking the drawing border and confirming that the stress plot is mostly blue.
An independent engineering design review should test the reasoning that connects the requirement, the operating duty, the design and the evidence. It is not a ceremonial approval meeting, and independence does not mean arriving late to criticise somebody else’s work. It means applying a sufficiently separate perspective to expose assumptions, interfaces and failure paths that familiarity may have hidden.
Four lenses for a useful second look
Decision
Define what decision the review must support and set proportionate entrance criteria.
Operating envelope
Test nominal, transient, cleaning, maintenance and credible fault conditions.
Interfaces
Follow loads, energy and consequences beyond the immediate component boundary.
Evidence and closure
Challenge assumptions, assign actions and define the evidence required to close them.
Start with the decision the review must support
Before reviewing the design, define what the review is for. Typical decisions include:
- whether a concept is mature enough for detailed design;
- whether drawings can be released for manufacture;
- whether a modification can proceed to a controlled test;
- whether evidence supports a claimed operating envelope;
- whether unresolved risks are acceptable to the responsible decision-maker.
The review scope should match that decision. A concept review should not demand production-level detail. Equally, a release review should not accept “to be confirmed during testing” for a load-bearing interface unless the uncertainty is explicitly controlled.
Good reviews are evidence-led rather than calendar-led. NASA’s systems-engineering requirements describe life-cycle reviews as event-based, occurring when entrance criteria are satisfied and the relevant technical baseline has matured, rather than merely because a date has arrived.[2] A small industrial project does not need NASA’s process, but the principle transfers well: agree what must be ready before gathering people in a room.
Check that the requirement is real and testable
The first engineering question is not “does the CAD look complete?” It is “what must this design actually do?”
Review the stated duty, users, environment, interfaces and constraints. Look for requirements that are vague, conflicting or inherited without evidence. “Suitable for continuous service” is not useful until continuous service has a defined duration, load spectrum, temperature range, maintenance expectation and acceptable degradation.
The reviewer should distinguish:
- facts, supported by drawings, measurements, specifications or confirmed operating data;
- assumptions, deliberately adopted where evidence is missing;
- estimates, approximate values with a stated basis and uncertainty;
- decisions, choices made between alternatives;
- open questions, gaps that still block release or testing.
NASA’s design guidance treats requirements development as iterative and emphasises communication with relevant stakeholders, warning that a team can otherwise implement an unwanted solution based on a different interpretation.[1] In practical machinery work, operators, maintainers, production engineers and commissioning staff often hold requirements that never reached the original specification.
Nominal conditions are necessary, but rarely sufficient.
A useful review asks what happens during:
- start-up, shutdown and changeover;
- minimum and maximum flow, speed, pressure and temperature;
- blocked, closed, dry, flooded or partially filled conditions where credible;
- cleaning, flushing, sterilisation or maintenance;
- loss of power, utilities, cooling, lubrication or control signals;
- wear, fouling, corrosion, thermal growth and tolerance drift;
- foreseeable incorrect operation or assembly.
The reviewer is not inventing every imaginable disaster. The task is to identify credible conditions, their frequency and consequences, then check whether the design, controls and instructions deal with them proportionately.
For machinery safety, HSE guidance says risk assessment should consider intended use, likely use and misuse, hazards, potential harm, protective measures and residual risk, with risk reduction integrated into the design.[3] A design review may contribute to this work, but it does not automatically constitute a complete machinery risk assessment or conformity assessment. That distinction should be explicit in the scope.
Follow loads and energy through the system
A component check proves little if the load path is wrong.
Trace pressure, force, torque, bending moment, heat, vibration and stored energy from their source to the supporting structure. Check reactions at shafts, bearings, fasteners, foundations, pipe connections and adjacent equipment. Include dynamic amplification, pressure pulsation, thermal restraint, misalignment and assembly preload where relevant.
Then challenge the source data:
- Is the load measured, calculated, specified or assumed?
- Is it an average, peak, range or fatigue spectrum?
- Does a relief setting represent normal duty, maximum allowable pressure or a transient limit?
- Are combined loads considered, or only convenient single-axis cases?
- Does stiffness or deflection control function before material strength is reached?
This is where a design that passes isolated calculations can fail as an assembly. Shaft deflection can disturb a seal before the shaft yields. Pipe loads can distort a casing. A stiff bracket can move the problem into a weaker frame. The colour contour is not the load path, however attractive the colour contour may be.
Review interfaces and consequences beyond the component
Interfaces deserve deliberate attention because responsibility often becomes blurred at boundaries.
Check mechanical fits, connections, control signals, process conditions, human access and supplier boundaries. Confirm who owns each interface value and which document controls it. Dimensions alone are not enough. Stiffness, allowable loads, leakage, failure states, materials compatibility and service access may matter just as much.
Also ask how a local fault propagates. Could a loose fastener release a rotating part? Could seal leakage reach a hot surface? Could a blocked passage overpressure a weaker item elsewhere? Could incorrect assembly reverse flow or disable a protective feature?
HSE’s guidance for major-hazard plant highlights simplification, limiting knock-on effects and designing critical equipment so incorrect assembly is difficult or impossible.[4] The regulatory context may differ from an ordinary machine, but these are useful design-review prompts because they seek to remove weakness at source rather than depend entirely on warnings and procedures.
The reviewer should examine whether the design can be made repeatedly, inspected meaningfully and assembled without unofficial workshop knowledge.
Questions include:
- Are materials sufficiently defined for strength, corrosion, temperature, wear and traceability?
- Do tolerances reflect function and process capability, including credible tolerance stacks?
- Are finish, coating and heat treatment specified where functional?
- Can critical features be measured with available methods?
- Is there room for tooling, lifting, adjustment and withdrawal?
- Can the design prevent incorrect assembly?
A realistic review includes wear and repeated cycles. Clearance at assembly is only the starting condition. Thermal growth, debris, coating thickness, distortion, fretting and service damage may consume the margin later.
Challenge calculations, simulation and test evidence
Evidence should be appropriate to the question.
For calculations, check units, formula applicability, input provenance, factors, load combinations and sensitivity to uncertain values. For FEA or CFD, check the model objective, geometry simplifications, material or fluid properties, boundary conditions, mesh strategy, convergence, verification checks and validation evidence. Simulation should support engineering judgement, not replace missing duty information with precise-looking output.
For testing, review instrumentation, calibration, sampling, boundary conditions, repeatability and acceptance criteria. Confirm whether the test represents normal duty, a proof condition or merely one convenient laboratory point.
NASA’s design guidance says the design effort should be deep enough to allow analytical verification against requirements and to be judged feasible and credible by knowledgeable independent reviewers.[1] The important word is credible. More pages, more decimal places and more plots do not compensate for an invalid assumption.
Make safety, serviceability and lifecycle visible
A design is not complete when it operates once.
Review access for inspection, cleaning, adjustment and replacement. Consider lifting points, trapped pressure, hot surfaces, sharp edges, rotating parts, pinch points and the isolation needed before intervention. Check whether maintenance tasks create conditions that the normal safeguards do not cover.
Then examine the lifecycle:
- inspection and acceptance after manufacture;
- transport, storage and installation;
- commissioning and foreseeable adjustment;
- routine operation and cleaning;
- planned maintenance and fault finding;
- repair, modification and replacement parts;
- decommissioning and disposal.
The review should identify residual risks and the information that must pass into drawings, instructions, test procedures or maintenance records. It should not assume that a warning label can rescue a poor mechanical arrangement.
Use a practical review sequence
A proportionate independent design review can follow this sequence:
- Define the decision and boundary. State what is being reviewed and what is excluded.
- Set entrance criteria. List the documents, calculations, models and operating data required.
- Build an assumptions register. Separate confirmed inputs from estimates and unresolved gaps.
- Trace requirements to evidence. Show how each important requirement is met and how that will be verified.
- Walk the operating envelope. Include credible abnormal, cleaning and maintenance conditions.
- Trace loads, energy and interfaces. Follow consequences beyond the immediate component.
- Review manufacture and service. Check tolerances, inspection, assembly, access and wear.
- Record findings by significance. Distinguish release blockers, risks, improvements and observations.
- Assign actions and owners. Each action needs an owner, due point, closure evidence and acceptance route.
- State the review conclusion carefully. Approved, approved with actions, or not ready should refer to the defined scope, not imply blanket certification.
What a useful design-review record contains
The output should be more than meeting minutes. A concise review record normally needs:
- the decision, scope, exclusions and review stage;
- attendees, roles and relevant independence;
- documents and revisions reviewed;
- facts, assumptions, estimates and missing information;
- findings with significance and technical basis;
- actions, owners, dates and required closure evidence;
- dissenting technical views where unresolved;
- the final recommendation and who retains decision authority.
The reviewer provides a structured challenge and recommendation. The responsible organisation still owns the design, applicable legal duties and final approval unless a contract explicitly establishes a different role.
A better second look
A worthwhile independent engineering design review does not try to redesign everything. It concentrates effort where assumptions, interfaces, operating conditions and consequences make the decision vulnerable.
The result may be confirmation that the design basis is sound. It may be a short list of targeted calculations or tests. Occasionally it may be the useful conclusion that the project is not ready to release. That is not delay for its own sake. It is cheaper information arriving before metal is cut, equipment is installed or a weakness becomes a service failure.
Need a bounded engineering second look?
Ekyos welcomes enquiries about bounded engineering diagnostics and design-review requirements. Start with a non-confidential description of the equipment, duty, evidence available and the decision that is currently blocked. Any work remains subject to an initial fit check, agreed scope, competence, capacity, conflict and insurance requirements.





