READING 10 · MARGINS · AROUND THE KNEE
Redundancy Is About the Second Path
Remove one member and see what happens. If the answer is nothing, the structure has redundancy. If the answer is collapse, the distinction between those two outcomes is almost the whole story of modern structural design philosophy.

§ 01What Redundancy Actually Means
The word gets borrowed into engineering from everyday speech, where it usually means something unnecessary, superfluous, there without purpose. In structures, the meaning is almost the reverse. A redundant member is one that the structure does not strictly need in normal conditions — but that the structure desperately needs the moment something else goes wrong.
The formal definition turns on alternate load paths. A structure has redundancy when a load can reach its support by more than one route. Sever one route and the load redistributes: other members pick up the share shed by the one that failed, stresses rise but stay below critical levels, and the structure continues to stand. Remove the single path in a structure without redundancy, and the load has nowhere to go. The system collapses as a direct consequence of that first failure, with no opportunity for intervention.
Engineers call the opposite condition a statically determinate structure — one in which every member carries exactly the load that equilibrium requires, no more and no less. Determinacy is not inherently bad; it is easy to analyse, and knowing the exact force in every member is genuinely useful. But it comes at a cost that is sometimes underweighted: remove any load-carrying member and the system is no longer in equilibrium. There is no redundant path, no internal redistribution, no warning interval. The failure of one is the failure of all.
The key word in that passage is warning. A redundant structure, overloaded to the point where one member yields or fractures, typically deforms visibly before the remaining system approaches collapse. The structure tells you something is wrong. A determinate structure offers no such interval. Both can be designed safely, but only one of them gives you a second chance.
A second load path only works if the second path can actually carry the load
§ 02How the Distinction Enters the Codes
Modern design standards do not simply ask whether a structure can carry its design loads. Many of them — particularly in bridge, offshore and building design — ask a structurally different question: what does this structure do after a credible local failure? The requirement goes by several names: alternate load path analysis, progressive collapse resistance, notional removal. The names differ; the underlying logic is the same. Postulate the sudden loss of a single load-carrying element. Show that the resulting damaged structure can carry some fraction of the original design load without progressive collapse.
The provisions that appear in building codes after several high-profile collapses — Ronan Point in east London in 1968 being the event that most directly drove the UK's initial response — reflect the insight that the triggering event almost does not matter. A gas explosion, a vehicle impact, a fabrication defect: the question that structural codes increasingly ask is not whether you can prevent every possible trigger, but whether a single trigger can unzip an entire structure. The goal is to prevent disproportionate collapse — a phrase that now appears explicitly in several national standards — meaning a collapse out of all proportion to its initiating cause.
This is where redundancy and the size of the safety factor part company conceptually. A safety factor makes the structure harder to load to failure in the first place. Redundancy changes what happens after a local failure occurs. They address different problems. A heavily factored determinate structure remains vulnerable to the failure mode that redundancy prevents: one member lost, system gone. A structure with genuine alternate paths but modest factors can survive local damage that would destroy its determinate equivalent. The two properties are complementary, not interchangeable.
§ 03The Geometry of the Second Path
Redundancy is fundamentally geometric. It lives in how a structure is configured, not just in how strong its members are. A simply supported beam — resting at each end, connected to nothing — carries its load to two supports along one path. If the beam fractures at midspan, there is no alternate path and the load falls. A continuous beam over three supports carries the same load through internal bending moments that redistribute when any one section yields: the beam can survive a crack that would be fatal to its simply-supported equivalent.
The cable-stayed bridge and the suspension bridge illustrate the same distinction at larger scale. A suspension bridge with a single main cable is a serial system: the cable is the path, and its failure is the failure of the bridge. Most suspension bridge designs achieve a degree of redundancy by using wire ropes composed of many parallel wires; locally, if a wire snaps, its neighbours carry on. At system level, the number of independent load paths through the main structure is still limited, which is why the Silver Bridge collapse of 1967 — in which a single eyebar link failed and the entire bridge followed within seconds — produced such a thorough re-examination of inspection regimes and structural form. A single point of failure that can unzip a system is, the profession eventually concluded, worth eliminating by design wherever possible.
Space frames, ring-stiffened pressure vessels, and welded plate grillages all embody the same idea: the load is shared across many elements simultaneously, so no single element's failure is decisive. Offshore platform jacket structures, designed under codes that explicitly require surviving the loss of a primary brace, are built around this principle. The redundancy is not accidental; it is sized.
How the idea moves through scales
- Single wire in a cableindividual wire failure, adjacent wires carry on
- Continuous beam over multiple supportsmoment redistribution after local yield, visible as deflection before collapse
- Space frame or grillageload shared across many elements; no single element is decisive
- Offshore jacket structureexplicitly designed to codes requiring survival after loss of a primary brace
- Cable-stayed or suspension bridgesystem-level vulnerability depends on how many truly independent load paths exist
§ 04What Redundancy Does Not Do
A second load path only works if the second path can actually carry the load. This sounds obvious, and it is — but the subtlety is that the redistribution after a local failure typically imposes loads on the remaining structure that it was not the primary carrier for during normal service. Those members must be detailed for that secondary condition: connected, continuous, with enough ductility to accept the new demands without brittle fracture.
Ductility matters here because redistribution requires deformation. A structure that can redistribute load only does so by deflecting more than it normally would; if the alternate-path members are brittle, they may fracture before the redistribution completes. The redundancy is notional if the detailing does not allow the deformation required to activate it. This is why tying requirements in building codes — specifying minimum tension capacities for floor-to-wall and floor-to-column connections — exist alongside the alternate-path philosophy. The connection has to hold under loads it was not primarily designed for.
Redundancy also does not help against a failure mode that simultaneously affects all paths. Corrosion that destroys all the cables in a bridge, a fire that weakens the whole floor plate, an overload applied to every member at once: these are not local failures, and the presence of multiple paths does not protect against them. The principle is specifically aimed at the initiating local event — one member, one weld, one connection — propagating to become a catastrophic whole-structure event. That is the failure class it prevents, and it is the failure class that determinate structures are most exposed to.
From the notes — The distinction that keeps getting blurred| Term | What it means here |
|---|---|
| Safety factor and redundancy | address different failure classes; one makes failure harder to initiate, the other changes what happens after a local failure occurs |
| Statically determinate vs. indeterminate | both can be designed safely; only one allows load redistribution after a member loss |
| Redundancy vs. notional-removal analysis | the code requirement makes you calculate the redistribution; the design decision that makes it survivable is made earlier, in the geometry |
§ 05The Number You Cannot Put on It
Safety margins, proof loads and allowable stresses are all numbers. Redundancy, in the end, is not. It is a property of topology — of how elements connect — and it resists being collapsed into a single coefficient. A structure either has alternate paths capable of carrying the load shed by a failed element or it does not. You can quantify the reserve capacity in those paths, measure the ductility of the connections, calculate the redistribution scenario. But the presence or absence of the second path itself is a design decision made in the configuration of the structure, before any load number is applied.
That is what makes it conceptually different from a factor. A factor is a number you multiply by. Redundancy is something you either build in or you do not. The structure with the alternate path and the structure without it may look identical from a distance, carry identical loads under identical service conditions, and satisfy identical allowable-stress requirements. The difference only becomes visible when something breaks — at which point, for one of them, it is already too late to add a second path.