Chain of Custody for Bearing Failure Data

Why Chain of Custody Matters for Bearing Failure Data

When a critical bearing fails on a marine propulsion shaft, a railway axle, or a high-value industrial drive, the technical cause of failure is only half the story. The other half—often the more expensive half—is proving what happened, when it happened, and that nobody tampered with the evidence after the fact. This is where chain of custody for bearing failure data becomes essential. Without a verifiable, unbroken chain of custody, even the most compelling vibration data can be dismissed in a warranty dispute, insurance claim, or contractual disagreement.

For reliability engineers and maintenance directors managing assets where a single bearing failure can trigger six- or seven-figure disputes, understanding how to establish and maintain chain of custody for failure data is no longer optional—it is a core operational requirement.

What Is Chain of Custody in the Context of Bearing Failure?

Chain of custody is a legal and procedural concept borrowed from forensic science. It refers to the documented, chronological history of evidence—who collected it, when it was collected, how it was stored, and whether it remained unaltered throughout its lifecycle. In criminal investigations, a broken chain of custody can render physical evidence inadmissible. The same principle applies to industrial bearing failure investigations, though the stakes are financial rather than criminal.

In bearing condition monitoring, the “evidence” consists of vibration waveforms, temperature logs, acoustic emission data, and operational parameters captured by sensors mounted on or near the bearing housing. For this data to carry weight in a post-failure dispute, every link in its journey—from sensor to storage—must be documented and verifiable. A gap in that chain, or any possibility that the data was modified after collection, undermines its credibility entirely.

This concept is closely related to forensic bearing failure evidence capture, but chain of custody specifically addresses the integrity of the data after it has been recorded.

The Problem with Standard Monitoring Data

Most predictive maintenance systems are designed to detect developing faults and trigger maintenance actions before catastrophic failure occurs. They do this job well. However, these systems were never designed to produce evidence that would survive scrutiny in a dispute.

The typical predictive maintenance data pipeline introduces multiple chain-of-custody vulnerabilities. Data is often collected at relatively low sampling rates—perhaps a few hundred hertz for trend monitoring—then transmitted to a cloud platform where it is aggregated, filtered, and sometimes decimated to reduce storage costs. Timestamps may be applied by the receiving server rather than the sensor itself, creating uncertainty about when measurements were actually taken. Data may pass through multiple software layers, any of which could introduce modifications. And crucially, there is usually no cryptographic mechanism to verify that the data stored today is identical to the data originally captured.

As explored in our analysis of why predictive maintenance data fails as bearing failure evidence, these systems produce data that is useful for maintenance scheduling but fundamentally unsuitable for forensic purposes.

Common Gaps in the Data Chain

Several specific failure points commonly undermine the chain of custody in bearing monitoring data. First, timestamp integrity is frequently compromised. When a sensor transmits data to a gateway or cloud server, the timestamp is often assigned at the point of receipt rather than at the point of measurement. Network latency, buffering, and clock synchronization errors can introduce seconds or even minutes of uncertainty. In a failure investigation, the precise timing of events—the sequence in which fault indicators appeared—can determine whether a bearing failed due to a manufacturing defect, an installation error, or an operational overload.

Second, data completeness is rarely guaranteed. Most monitoring systems use threshold-based or scheduled data collection. They capture snapshots at fixed intervals or when alarm levels are exceeded, but they discard the continuous raw waveform data that would show exactly what happened in the minutes and hours surrounding a failure event. The most forensically valuable data—the high-frequency waveform that captures the actual moment of failure onset—is precisely the data that most systems are designed to throw away.

Third, access controls on stored data are often inadequate. If multiple parties—the equipment operator, the bearing manufacturer, the maintenance contractor, and the insurance provider—can each point to different versions of the same dataset, or if any party had the opportunity to modify stored data without detection, the entire dataset becomes unreliable as evidence.

Requirements for Forensic-Grade Chain of Custody

Establishing a chain of custody that will withstand scrutiny in a bearing failure dispute requires addressing each of the vulnerabilities described above. The requirements fall into four categories: data acquisition integrity, transmission security, storage immutability, and access documentation.

Data Acquisition Integrity

The chain of custody begins at the sensor. Every measurement must carry a timestamp generated by a clock source synchronized to a traceable reference—GPS time or a calibrated NTP source with documented accuracy. The sampling rate must be sufficient to capture the bearing defect frequencies of interest. For a bearing with a ball pass frequency outer race (BPFO) of 120 Hz, meaningful envelope analysis requires sampling at a minimum of 10 times the highest frequency of interest, including harmonics. This means acquisition rates of 10 kHz or higher are often necessary for forensic-quality data, compared to the few hundred hertz typical of trend monitoring systems.

The sensor itself should have a documented calibration history, including sensitivity (typically expressed in mV/g for accelerometers), frequency response range, and the date and certificate number of its most recent calibration against a traceable standard such as those specified in ISO 16063.

Transmission Security

Data in transit between the sensor and the storage system must be protected against both interception and modification. This means encrypted communication channels, but also integrity verification—each data packet should carry a hash or digital signature that allows the receiving system to confirm the data was not altered during transmission. Any packet loss or transmission error must be logged rather than silently ignored, because a gap in the data record is itself a forensically significant event.

Storage Immutability

Once data reaches its storage destination, it must be locked against modification. This is perhaps the most critical element of the chain of custody, and the one most often overlooked in conventional monitoring systems. Tamper-evident data storage uses cryptographic hashing to create a verifiable record that any post-collection modification would be detectable. The most robust implementations use hash chains—where each data block’s hash incorporates the hash of the previous block—creating a structure where altering any single record would require recalculating every subsequent hash, making undetected tampering computationally infeasible.

Storage systems should also implement write-once semantics, where data can be appended but never overwritten or deleted during the retention period. This approach, sometimes called WORM (Write Once Read Many) storage, ensures that the original data remains available regardless of any subsequent events.

Access Documentation

Every access to the stored data must be logged: who accessed it, when, what they accessed, and what they did with it. This audit trail must itself be tamper-evident. If an expert witness downloads a dataset for analysis, that download event must be permanently recorded. If a maintenance team reviews historical data during a root cause analysis, that review must be documented. The goal is to ensure that at any point in a dispute, any party can reconstruct the complete history of the data from the moment of capture to the present.

Chain of Custody in Practice: A Failure Scenario

Consider a practical example. A large double-row spherical roller bearing on a paper mill dryer section fails after 14 months of service, well short of its calculated L10 life of 60 months. The failure causes three days of unplanned downtime, costing the mill approximately $180,000 per day in lost production. The bearing manufacturer claims the failure resulted from misalignment during installation by the mill’s maintenance contractor. The maintenance contractor claims the bearing had a subsurface inclusion—a manufacturing defect. The mill’s insurance provider is evaluating whether to subrogate against either party.

Without chain-of-custody-compliant data, this dispute plays out as a battle of expert opinions, with each party’s metallurgist interpreting the physical evidence to support their client’s position. Physical evidence degrades from the moment of failure—corrosion, handling damage, and post-failure operation can obscure the original failure initiation site. The dispute may take months or years to resolve, and the outcome often depends more on negotiation leverage than on technical truth.

With chain-of-custody-compliant vibration data, the picture changes fundamentally. Tamper-evident, timestamped, high-frequency waveform data from the weeks preceding failure can show exactly when the defect first became detectable, how it progressed, and what the bearing’s operating conditions were at each stage. If the defect frequencies indicate an outer race fault that appeared immediately after installation and progressed steadily—a signature consistent with a brinelling event during mounting—the data supports the manufacturer’s position. If instead the data shows a sudden onset characteristic of a subsurface fatigue crack, with no prior indication visible in the vibration spectrum, that supports the installer’s position.

Critically, because the data carries a verifiable chain of custody, neither party can claim the data was fabricated or modified after the fact. The dispute can be resolved on its technical merits, typically in weeks rather than months. This is precisely the type of scenario that forensic bearing evidence was designed to address.

Industry Standards and Legal Considerations

While no single international standard currently addresses chain of custody for bearing condition monitoring data specifically, several existing frameworks provide relevant guidance. ISO 17025 establishes general requirements for the competence of testing and calibration laboratories, including requirements for data integrity and record keeping that align closely with chain-of-custody principles. ISO 27001 provides a framework for information security management that addresses data integrity, access controls, and audit trails.

In legal proceedings, the admissibility of digital evidence is generally governed by rules similar to those for physical evidence. In the United States, the Federal Rules of Evidence (particularly Rule 901 on authentication and Rule 702 on expert testimony) establish the framework within which bearing failure data would be evaluated. The key question is always whether the proponent of the evidence can demonstrate that it is what they claim it is—and a documented, verifiable chain of custody is the most effective way to meet that burden.

ISO 10816 and ISO 20816, which define vibration severity evaluation criteria for various machine types, provide the technical baseline for interpreting vibration data. But these standards assume the data is accurate and unmodified—an assumption that chain-of-custody procedures are designed to validate.

Implementing Chain of Custody for Your Bearing Assets

For organizations looking to implement chain-of-custody procedures for their critical bearing assets, the process begins with identifying which assets carry sufficient financial risk to justify forensic-grade data collection. Not every bearing warrants this level of attention—but any bearing whose failure could trigger a warranty claim, an insurance dispute, or a contractual penalty is a candidate.

The next step is evaluating whether your existing monitoring infrastructure can support chain-of-custody requirements, or whether purpose-built forensic capture systems are needed. Key questions to ask include: Does your system timestamp data at the point of acquisition with a traceable time source? Does it capture raw waveforms at sufficient sampling rates? Does it provide tamper-evident storage with cryptographic verification? Does it maintain a complete access audit trail?

If your current system cannot meet these requirements—and most conventional predictive maintenance systems cannot—the solution is not necessarily to replace your entire monitoring infrastructure. Forensic evidence capture can operate alongside existing predictive systems, using the same sensor locations but capturing and storing data through a parallel, forensic-grade pipeline. This dual-architecture approach preserves your existing maintenance workflows while adding the evidentiary capability that protects your organization when failures lead to disputes.

Conclusion

Chain of custody for bearing failure data is the bridge between collecting vibration measurements and using those measurements to resolve disputes definitively. Without it, even the most sophisticated condition monitoring data is vulnerable to challenges about its authenticity, completeness, and integrity. For any organization operating high-value rotating machinery where bearing failure disputes carry material financial consequences, establishing a verifiable chain of custody is not a practical necessity that directly impacts your ability to recover costs, enforce warranties, and demonstrate operational due diligence.

The organizations that recognize this early—before a failure occurs—are the ones that resolve disputes quickly and on favorable terms. Those that discover the importance of chain of custody only after a failure has already happened are left trying to reconstruct evidence from systems that were never designed to provide it.

What Is Forensic Bearing Failure Evidence Capture?

When a critical bearing fails in service, the replacement cost is rarely the largest expense. The real financial exposure comes from what happens next: warranty disputes between operators and manufacturers, insurance claim investigations, regulatory compliance reviews, and production-loss liability arguments. In every one of these scenarios, the outcome depends on evidence — specifically, on the physical record of what happened to the bearing before, during, and after the failure event.

Forensic bearing failure evidence capture is the practice of preserving high-fidelity sensor data from the moment a bearing fails, sealed in a tamper-evident format that maintains chain-of-custody integrity. It is architecturally distinct from condition monitoring: a different mode of operation, optimized for a different question — not “is this bearing degrading?” but “what physically happened when this bearing failed, and can we prove it?” In a single-mode condition-monitoring system, this question cannot be answered with the same data, because condition-monitoring data is not designed to function as evidence and is never represented as such.

Why Standard Condition Monitoring Data Is Not Evidence

Predictive maintenance systems are designed to alert operators before a failure occurs. They measure vibration periodically — typically every few minutes to every few hours — extract summary statistics like RMS velocity, peak acceleration, and spectral band energy, then trend those values over time. When a value exceeds a preset threshold, the system generates an alert.

This is valuable for maintenance planning. It is not valuable for post-failure dispute resolution, for several specific reasons:

Decimated and Averaged Data

Most condition monitoring systems discard the raw vibration waveform after extracting summary features. A 10-second capture at 25.6 kHz produces roughly 512,000 data points. The system reduces this to perhaps 10–20 derived values: overall RMS, peak, crest factor, and energy in a few spectral bands. The original waveform — which contains the bearing defect impulses, their spacing, their amplitude modulation pattern, and the precise spectral signature that identifies the failure mode — is gone.

In a dispute, an independent vibration analyst needs the raw waveform to perform root cause analysis. Summary statistics tell you a bearing was degrading. The raw waveform tells you why — and specifically whether the failure pattern is consistent with a manufacturing defect, installation error, contamination, inadequate lubrication, or overload. Without raw data, both parties in a dispute argue from interpretation rather than physical evidence.

Gaps in the Record

A monitoring system that captures a 2-second vibration snapshot every 4 hours provides 0.014% coverage of the operating period. If a bearing transitions from healthy to failed in 30 minutes — which does happen during sudden-onset failure modes like cage fracture, contamination ingress, or loss of lubrication — the monitoring record shows “healthy” in one snapshot and “failed” in the next. The failure event itself, including the critical pre-failure signatures that reveal root cause, falls in the gap.

No Tamper Protection

Standard monitoring data is stored in databases or cloud platforms where it can be edited, selectively exported, or deleted. In a multi-party dispute, there is no cryptographic proof that the data presented by one party is the same data that was originally recorded by the sensor. An operator presenting trend data showing no prior degradation has no way to prove that degradation data was not selectively removed. A manufacturer disputing the operating conditions has no way to verify that the condition data was not modified after the fact.

No Pre-Event Context

Standard monitoring systems trigger alerts after a threshold is exceeded. They do not preserve what happened before the threshold was crossed. But the most diagnostically valuable data in a bearing failure is the pre-event record: the subtle changes in vibration signature that reveal whether the root cause was progressive fatigue, sudden impact damage, thermal event, or operational overload. Without pre-event data, forensic analysis of the failure mechanism is severely limited.

What Forensic Evidence Capture Actually Involves

Forensic bearing failure evidence capture addresses each of these limitations through a fundamentally different data architecture. Rather than optimizing for maintenance alerts, it optimizes for producing a complete, tamper-evident, legally defensible record of the failure event.

Continuous High-Frequency Buffering

A forensic capture system maintains a rolling buffer of raw vibration data at high sampling rates — typically 25.6 kHz to 51.2 kHz for standard bearing applications, or higher for high-speed machinery. The buffer operates continuously, overwriting the oldest data as new data arrives. When a failure trigger fires — whether from a shock threshold, spectral discontinuity, thermal excursion, or acoustic transient — the system freezes the buffer, preserving the pre-event data, and continues capturing post-event data for a defined window.

The result is a continuous, high-fidelity record spanning the period before, during, and after the failure. For a system with a 60-second pre-trigger buffer sampling at 25.6 kHz, that represents over 1.5 million data points of pre-event context — enough for detailed spectral analysis of the bearing condition immediately before the failure, including identification of specific defect frequencies (BPFO, BPFI, BSF, FTF) and their harmonics at operating speed.

On-Device Cryptographic Sealing

The evidence package is sealed cryptographically on the sensor hardware itself, before any data leaves the device. This means the raw waveform data, timestamps (synchronized to a verified time source), sensor calibration parameters, trigger conditions, and device identification are hashed together and digitally signed using a private key stored in the sensor’s secure element.

Any modification to the sealed data — changing a single sample value, altering a timestamp, removing a segment of the record — invalidates the cryptographic signature. This provides the digital equivalent of a tamper-evident evidence bag: the evidence can be verified as unmodified by any party with access to the corresponding public key, without trusting the party that collected the evidence.

Multi-Key Access Control

In a dispute, no single party should have unilateral control over the evidence. A forensic evidence system implements multi-key access: accessing the sealed evidence package requires authorization from multiple independent parties. This prevents any single party — the operator, the manufacturer, the sensor vendor — from accessing, modifying, or suppressing the evidence without the knowledge and consent of the other parties.

This is analogous to the physical chain-of-custody procedures used in forensic investigations: evidence is sealed, access is logged, and no individual can compromise the record without detection.

Comprehensive Metadata

The evidence package includes not just the vibration data but the complete context necessary to interpret it: sensor serial number and calibration certificate, mounting location and orientation, machine identification and operating parameters (speed, load, temperature at the time of capture), firmware version and configuration, GPS coordinates and timestamp, and trigger event details. This metadata ensures that the evidence can be independently interpreted without relying on the collecting party’s verbal description of the operating conditions.

Where Forensic Evidence Capture Matters Most

Not every bearing installation warrants forensic evidence capture. The cost and complexity are justified where the financial exposure from a failure dispute significantly exceeds the cost of the bearing itself.

Marine Propulsion Systems

A stern tube or thrust bearing failure on a commercial vessel can trigger a cascade of costs: emergency towing ($50,000–$500,000+), port delay penalties, cargo demurrage, drydock repair, and classification society investigation. Disputes between the vessel operator, bearing manufacturer, and shipyard that installed the bearing can extend for years. Forensic evidence that captures the physical record at the moment of failure — the signal patterns consistent with manufacturing defect, installation error, or operational abuse — gives expert analysts something to reason from. Whether the evidence resolves a specific dispute is determined by the parties, the experts they retain, and the relevant adjudicating bodies — not by the device or its vendor.

Railway Axle Bearings

Axle bearing failures on rolling stock carry safety implications beyond the immediate mechanical damage. Federal Railroad Administration investigations following bearing-related incidents require documentation of bearing condition history and the failure event itself. Forensic evidence from continuous high-frequency monitoring provides the documentation that post-incident inspection of damaged hardware often cannot.

High-Value Industrial Rotating Machinery

Large electric motors, turbines, compressors, and gearboxes in process industries can carry replacement costs in the hundreds of thousands to millions of dollars. When these bearings fail prematurely, warranty disputes between the OEM and operator routinely involve competing claims about whether the failure was caused by a manufacturing defect or by operating conditions outside the bearing’s rated envelope. The party with better evidence has the stronger position.

The Economic Argument

The cost of forensic evidence capture hardware is measured in hundreds to low thousands of dollars per monitoring point. The cost of a major bearing failure dispute — including legal fees, expert witnesses, production losses during the dispute period, and the settlement itself — is measured in tens of thousands to millions of dollars.

More importantly, the presence of forensic evidence capture capability often prevents disputes from escalating in the first place. When both parties know that a tamper-evident, high-fidelity record of the failure event exists, the incentive to negotiate in good faith increases substantially. Disputes that would otherwise require months of expert analysis and legal proceedings can be resolved by reviewing the evidence record — because the evidence record actually contains the physical information needed to determine root cause.

For organizations that have experienced bearing failure disputes, the value proposition is straightforward: the question is not whether forensic evidence capture is worth the investment, but whether the next dispute will occur before or after the system is installed.

How Forensic Evidence Capture Differs from Predictive Maintenance

It is important to understand that forensic evidence capture is not a replacement for predictive maintenance — it is a complement to it. The two functions serve different purposes, optimize for different outcomes, and require different data architectures.

Predictive maintenance answers: “Is this bearing degrading, and when should we intervene?” It optimizes for early detection and maintenance planning. Forensic evidence capture answers: “What happened when this bearing failed, and can we prove it?” It optimizes for post-failure accountability and dispute resolution.

A dual-mode sensor platform serves both functions on the same hardware: operating in condition-monitoring mode during normal operations (providing the day-to-day operational value that justifies deployment), with the on-device edge AI promoting the sensor into forensic-capture mode autonomously when a terminal failure event is detected. Mode transitions can also be initiated by Fault Ledger over the air at the operator’s request; end customers do not directly toggle the mode — this preserves vendor neutrality once the sensor is capturing forensic evidence. For a deeper discussion of how these architectures differ, see our article on why forensic bearing evidence matters in warranty disputes.

For technical details on how bearing defect frequencies are used in both predictive and forensic analysis, our companion article on understanding BPFO, BPFI, BSF, and FTF provides the mathematical foundations.

Getting Started

Organizations considering forensic bearing failure evidence capture should evaluate three factors: which bearing installations carry the highest financial exposure from failure disputes, what data architecture is required to produce evidence that will withstand scrutiny in warranty claims, insurance investigations, or regulatory reviews, and whether a dual-mode platform can provide both predictive maintenance value and forensic capture capability on the same hardware deployment.

The bearings that justify forensic evidence capture are not necessarily the ones that fail most often. They are the ones where failure triggers the most expensive disputes — and where the absence of verifiable evidence is the reason those disputes become expensive in the first place.

Edge AI vs Cloud: Why Local Processing Matters for Bearing Condition Monitoring

The bearing condition monitoring industry is in the middle of an architectural transition. For the past decade, the default architecture has been straightforward: sensors capture vibration data, transmit it to a cloud platform, and the cloud performs analysis, alerting, and reporting. This architecture works — but it has limitations that become apparent in certain deployment environments and at certain scales.

Edge AI — performing machine learning inference and signal processing on local hardware (the sensor itself or an on-site gateway) rather than in the cloud — addresses several of these limitations. But it introduces its own trade-offs. Understanding when edge processing provides genuine advantages over cloud-only architectures helps engineers make informed architecture decisions rather than following marketing trends.

The Case Against Cloud-Only Architectures

Latency

In a cloud-only architecture, vibration data travels from the sensor to a local gateway, across the internet to a cloud server, through an analysis pipeline, and back to the operator as an alert. Round-trip latency for this process is typically measured in minutes to hours — acceptable for trending and maintenance planning, but inadequate for applications that require near-real-time response.

For bearing monitoring specifically, latency matters most during rapid degradation events. A bearing that transitions from “watch” to “alarm” to “danger” in under an hour needs faster response than a system that processes data in batch intervals. Edge processing reduces detection-to-alert latency from minutes to seconds by eliminating the network round trip.

Bandwidth and Data Costs

High-frequency vibration data is large. A single accelerometer sampling at 25.6 kHz generates roughly 50 KB per second of raw data — about 4.3 GB per day. For a deployment with 50 sensors, that is over 200 GB per day of raw data that must be transmitted, stored, and processed in the cloud.

In industrial environments with ethernet connectivity, bandwidth may not be a constraint. But in remote locations — offshore platforms, mining sites, marine vessels, railway rolling stock — data transmission depends on cellular, satellite, or limited-bandwidth radio links where per-megabyte costs are measured in dollars, not fractions of cents.

Edge processing addresses this by extracting features locally — spectral peaks, defect frequency amplitudes, health scores — and transmitting only the compact results. A feature vector summarizing a 10-second vibration capture might be 200 bytes, a compression ratio of over 1,000:1 compared to the raw waveform. This makes continuous monitoring feasible on bandwidth-constrained connections.

Connectivity Dependency

Cloud-only systems stop working when the network connection fails. For permanently installed industrial plants with redundant network infrastructure, connectivity downtime is rare. For mobile assets (railway, marine, trucking), remote sites (mining, oil and gas), and facilities with unreliable network infrastructure, connectivity gaps are routine.

An edge-processing architecture continues monitoring, detecting anomalies, and generating alerts regardless of network status. Results are cached locally and synchronized when connectivity returns — but critical alerts are generated immediately, on-site, without waiting for the cloud.

Data Sovereignty and Security

Some organizations — military, defense contractors, certain government agencies, and companies operating under strict data governance policies — cannot send equipment operational data to third-party cloud platforms. Edge processing keeps sensitive data on-premises, transmitting only anonymized summaries or alerts to external systems if needed.

Even for organizations without strict data governance requirements, keeping raw vibration data local reduces the attack surface for data breaches and eliminates dependency on a third-party cloud provider’s security posture and business continuity.

What Edge AI Actually Does for Bearing Monitoring

The term “edge AI” covers a range of processing capabilities. For bearing condition monitoring, the relevant edge AI functions are:

Anomaly Detection

Statistical models running on the gateway learn the normal vibration signature of each monitored bearing during a baseline period. Subsequent measurements are compared against this baseline, and deviations that exceed a statistical threshold trigger an anomaly alert. This does not require knowing the bearing model or its defect frequencies — the system detects change from normal, which catches unexpected failure modes that frequency-based monitoring might miss.

Bearing Defect Classification

When an anomaly is detected, defect classification algorithms analyze the spectral content to determine the likely fault type: outer race (energy at BPFO and harmonics), inner race (energy at BPFI with shaft-speed sidebands), rolling element (energy at 2× BSF), or cage (modulation at FTF). This classification runs on the gateway using the bearing geometry and current shaft speed — both stored in the local configuration database.

Health Scoring

Health scores condense the multi-dimensional vibration assessment into a single value (typically 0–100) that non-specialist operators can interpret. The edge gateway computes health scores from multiple indicators — overall vibration level, defect frequency amplitudes, spectral shape changes, crest factor — and provides a simple “good / watch / alert / danger” classification without requiring the operator to interpret FFT spectra.

Trend Analysis

The gateway maintains historical health scores and spectral summaries for each bearing, enabling local trend analysis without cloud connectivity. Trend projections — “at the current degradation rate, this bearing will reach the alarm threshold in approximately 6 weeks” — run on the gateway using locally stored data.

When Cloud Still Makes Sense

Edge AI does not replace cloud processing for all use cases. The cloud retains advantages in several areas:

  • Fleet-wide analytics. Comparing bearing performance across hundreds of machines at multiple sites — identifying which bearing models fail earliest, which operating conditions accelerate degradation, which maintenance practices correlate with longer bearing life — requires aggregating data from many locations. The cloud is the natural platform for fleet-level analytics.
  • Model training. Machine learning models used for anomaly detection and classification are trained on large datasets of labeled vibration data. This training happens in the cloud (or on dedicated compute infrastructure), and the trained models are then deployed to edge devices. The edge performs inference; the cloud performs training.
  • Long-term archival. Storing years of vibration data for regulatory compliance or historical analysis is more practical and cost-effective in cloud storage than on local gateway hardware.
  • Remote access and reporting. Cloud dashboards provide remote visibility for engineering managers, reliability teams, and third-party service providers who need to review equipment condition without being physically on-site.

The Hybrid Architecture

The most practical architecture for most deployments is hybrid: edge processing for real-time monitoring, anomaly detection, and alerting; cloud for fleet analytics, model training, long-term storage, and remote access.

In this architecture, the edge gateway handles time-critical functions autonomously — it does not wait for the cloud to detect a bearing fault or generate an alert. The cloud receives summarized results (health scores, anomaly flags, spectral summaries) on a regular schedule and provides the broader analytical context that edge devices cannot generate in isolation.

The key design principle is that the edge must function independently. If the cloud goes down — or if the network connection is interrupted for days — the monitoring system continues to protect the equipment. The cloud enhances the system; it does not enable it.

For a deeper technical discussion of edge computing architectures for bearing monitoring, see our article on why local processing beats cloud-only architectures.

Evaluating Edge AI Claims

As edge AI has become a marketing term, it is worth asking specific questions when evaluating systems that claim edge processing capabilities:

  • What exactly runs on the edge? Some systems perform FFT computation locally but transmit full spectra to the cloud for anomaly detection. Others perform complete anomaly detection and classification locally. The distinction matters for latency and connectivity dependency.
  • Does the system function without cloud connectivity? This is the definitive test of edge processing. If the system cannot detect a bearing fault when the internet is down, it is not truly an edge architecture — it is cloud processing with local data buffering.
  • How are models updated? Edge AI models must be updated as new failure modes are encountered and as the system learns from more data. Ask how model updates are deployed — over the air, via manual update, or through the cloud — and whether updates require system downtime.
  • What hardware runs the inference? Edge AI computation requires more processing power than simple data acquisition. Ask what processor runs on the gateway, what its power consumption is, and whether it can handle the computational load of monitoring all connected sensors simultaneously.

Edge AI for bearing condition monitoring is not a binary choice between edge and cloud. It is an architectural decision about where to place computation for optimal latency, reliability, bandwidth efficiency, and cost. For deployments where connectivity is reliable and unlimited, cloud processing may be sufficient. For deployments where latency matters, connectivity is intermittent, bandwidth is expensive, or data sovereignty is required, edge processing is not optional — it is essential.

Bearing Monitoring for Marine Vessels: Meeting Classification Society Requirements

Marine bearing failures are expensive in ways that land-based industrial failures are not. When a bearing fails on a vessel at sea, the immediate cost includes not only the replacement part and repair labor but also potential vessel delays, port penalties, cargo demurrage, and — in the worst cases — towing costs and salvage claims. Classification societies exist, in part, to prevent these scenarios through mandatory equipment inspection and condition documentation requirements.

For vessel operators, the challenge is meeting classification society requirements in a way that is both technically rigorous and operationally practical. Traditional periodic inspection methods — stopping machinery, opening housings, visually inspecting bearing surfaces — are time-consuming, expensive, and increasingly insufficient as classification societies move toward condition-based maintenance requirements.

What Classification Societies Require

The major classification societies — DNV, Lloyd’s Register, Bureau Veritas, and the American Bureau of Shipping (ABS) — each have their own notation systems for condition monitoring. While the specifics differ, the core requirements share common themes:

Continuous or Periodic Monitoring

Some classification societies now publish notations under which condition-monitoring data can be presented during survey alongside or in place of certain time-based inspections. DNV’s Machinery Condition Monitoring notation, for example, describes circumstances in which a vessel operator may seek extended intervals between physical inspections on the basis of continuous monitoring data. Whether any specific deployment satisfies any specific notation is determined by the classification society and its surveyors — not by the equipment vendor.

Documented Trending

It is not sufficient to show that a bearing is healthy at one point in time. Classification societies want to see trends — evidence that bearing condition has been tracked over time and that any degradation is being identified early. This requires consistent measurement methodology, calibrated sensors, and a data management system that retains historical readings for survey intervals that often span years.

Alarm and Response Documentation

When monitoring systems detect abnormal conditions, classification societies request documentation of the alarm event, the investigation performed, and the corrective action taken. This creates a chain of documentation that operators may rely on when describing their maintenance practice during survey or post-incident investigation. The legal significance of any specific documentation is determined by courts, regulators, and the parties involved — not by the equipment vendor.

Surveyor Access to Data

Classification society surveyors must be able to review monitoring data during periodic surveys. The data must be presented in a format that a qualified surveyor can interpret — not buried in proprietary software that requires specialized training to access.

Why Marine Bearings Fail Differently

Marine bearing monitoring presents unique challenges that differentiate it from industrial plant monitoring:

  • Saltwater environment. Sensors mounted on marine machinery are exposed to salt spray, high humidity, and condensation. Sensor housings must resist corrosion — 316L stainless steel is the standard for marine-grade hardware. Plastic sensor housings and cable glands common in industrial applications degrade rapidly in marine environments.
  • Shock and vibration. Marine machinery experiences constant hull-transmitted vibration and periodic shock loads from wave impacts, propeller cavitation, and maneuvering transients. Monitoring systems must distinguish between bearing defect signatures and the ambient vibration environment of a working vessel.
  • Variable speed operation. Many marine bearings operate at variable speeds — propulsion shaft bearings change speed with engine load, thruster bearings reverse direction regularly, and auxiliary machinery runs at different speeds depending on operational mode. Defect frequency tracking must account for speed variation, or alarm thresholds set at one speed produce false positives at others.
  • Remote and intermittent connectivity. Vessels at sea may have limited or intermittent satellite connectivity. Monitoring systems that depend on continuous cloud connectivity for data processing or alarm generation are unreliable in marine environments. Local edge processing — performing anomaly detection and alarm generation on the vessel — is essential.
  • Limited onboard expertise. Not every vessel carries a vibration analyst. The monitoring system must provide actionable information — not just raw spectra — that engineers and officers can interpret and act on without specialized vibration analysis training.

How Dual-Mode Sensors Address Marine Requirements

A dual-mode sensor platform that combines predictive maintenance and forensic evidence capture firmware on the same hardware addresses classification society requirements while providing operational benefits that justify the installation cost:

Predictive Mode: Meeting Condition Monitoring Requirements

In condition-monitoring mode, the sensor provides continuous vibration trending of the kind typically requested during classification society surveys. Whether any specific deployment satisfies any specific notation remains a determination for the society and its surveyors. Health scores derived from spectral analysis give engineers a simple go/no-go assessment without requiring detailed vibration analysis expertise; these scores are advisory, not prescriptive. Historical trend data stored locally on the vessel — not solely in the cloud — supports surveyor access regardless of connectivity status.

AI-powered anomaly detection running on the edge gateway provides early warning of developing faults without depending on shore-side cloud connectivity. When the system detects a change in bearing condition, it generates an alert with a preliminary diagnosis — outer race defect, imbalance, misalignment — giving the engineering team time to plan corrective action at the next port of call rather than responding to an emergency at sea.

Forensic Mode: Documenting Failure Events

When a bearing does fail — despite monitoring — the same sensor hardware captures the forensic evidence record that documents what happened. Pre-event and post-event vibration data preserved in a tamper-evident format provides the detailed failure record that classification societies, insurers, and warranty counterparties require.

For marine operators, this evidence is particularly valuable in three scenarios:

  • Warranty claims against bearing or equipment manufacturers. Marine bearings often fail in environments that are more severe than the manufacturer’s test conditions. Forensic evidence distinguishes between a manufacturing defect and an environmental cause.
  • Insurance claims for machinery damage. P&I clubs and hull insurers typically request evidence relevant to whether failures were caused by negligent maintenance. Forensic evidence preserved at the moment of failure is one input that the operator can present alongside other records; whether it discharges any specific burden is determined by the insurer, the parties, and the applicable contract.
  • Classification society investigations. When failures result in safety incidents — propulsion loss, steering failure, machinery space flooding — classification societies investigate. Forensic evidence provides an objective record that supplements crew reports and physical inspection findings.

Authorized Mode Transitions: Operational Flexibility

Mode transitions occur without physical access to the sensor — especially valuable in marine applications where sensors may be installed in spaces that are difficult to reach at sea. A sensor monitoring a stern tube bearing can operate in condition-monitoring mode during normal operations; if the on-device edge AI detects an emerging fault, it can promote the sensor into forensic mode autonomously, or Fault Ledger can issue a signed over-the-air command to do so at the operator’s request. End customers do not directly toggle the mode — this preserves vendor neutrality once the sensor is capturing forensic evidence.

For a deeper look at the environmental challenges of marine bearing monitoring, see our technical article on marine bearing monitoring challenges and solutions in saltwater environments.

Practical Considerations for Marine Installations

  • Sensor material. 316L stainless steel enclosures are the minimum for marine environments. Avoid painted steel or plastic housings — they will fail within months in marine atmospheres.
  • Mounting method. Magnetic mounting allows rapid deployment and repositioning without drilling or welding on marine structures. Ensure the magnet material is also corrosion-resistant (neodymium magnets with nickel plating corrode quickly in marine environments; use rubber-coated or stainless-enclosed magnets).
  • Power. Battery-powered sensors eliminate cable runs through watertight bulkheads — a significant advantage on vessels where cable penetrations require certification. Lithium primary cells handle the temperature range of machinery spaces (typically 0–60°C) without derating.
  • Wireless protocol. BLE works well for close-range installations where the gateway can be mounted within 10–30 meters of the sensors. For larger vessels where sensors are distributed across multiple compartments, LoRa provides longer range through steel structures.
  • Data sovereignty. Some operators — particularly military and government vessel operators — require that monitoring data remain onboard and not be transmitted to shore-based cloud platforms. Edge processing with local data storage addresses this requirement.

Marine bearing monitoring is evolving from periodic inspection to continuous condition assessment. Classification societies are driving this transition through condition-based maintenance notations. Dual-mode sensors that operate in either condition-monitoring mode or forensic mode — architecturally distinct, never blended — offer day-to-day operational value alongside event-bound evidence preservation. Condition-monitoring outputs are advisory, not prescriptive; forensic-mode evidence is one input that classification societies, insurers, and counterparties may consider during investigations.

Combining Predictive Monitoring and Forensic Capture: The Case for Dual-Sensor Bearing Architecture

Predictive maintenance sensors and forensic failure recorders are designed for different problems. Predictive systems monitor bearing health over time, capturing periodic vibration spectra and temperature trends to detect degradation before it becomes failure. Forensic recorders capture the failure itself — high-frequency, raw physical data sealed at the moment of a terminal event. The two architectures serve different purposes, operate at different timescales, and answer different questions.

But when deployed together on the same asset, something interesting happens: the combined system captures a band of information that neither system can capture alone. The predictive sensor provides weeks or months of degradation context. The forensic recorder provides the high-fidelity, high-bandwidth physical record of the event itself. Together, they create a continuous evidentiary chain from first detectable degradation through catastrophic failure — a record that is simultaneously useful for maintenance optimization and defensible in a dispute.

The Bandwidth Gap in Standalone Systems

Every monitoring system makes tradeoffs between bandwidth, storage, and operational lifespan. Understanding these tradeoffs reveals why neither predictive nor forensic systems alone can capture the full picture.

Predictive Maintenance: Optimized for Duration

A predictive bearing monitoring sensor is designed to operate for years on a single battery, transmitting data wirelessly at regular intervals. To achieve this lifespan, the system makes deliberate compromises:

  • Sampling rate is constrained. Most wireless predictive sensors sample vibration at 3–10 kHz, sufficient to capture the fundamental bearing defect frequencies (BPFO, BPFI, BSF, FTF) and their first few harmonics for bearings running below 3,600 RPM. But this bandwidth is insufficient to capture the high-frequency resonance bands (10–40 kHz) where early-stage defects first become detectable through envelope analysis.
  • Capture is periodic, not continuous. To conserve battery, the sensor wakes up, captures a short time block (typically 1–5 seconds), computes an FFT or set of metrics, transmits the result, and returns to sleep. The interval between captures — minutes, hours, or days depending on configuration — represents an unrecorded gap.
  • Raw waveforms are typically discarded. The FFT or derived metrics are stored and transmitted; the underlying time-domain waveform is overwritten. This is an intentional design choice: transmitting and storing raw waveforms at scale would exhaust both battery and storage in days rather than years.

These tradeoffs are correct for the system’s purpose. A predictive sensor does not need 40 kHz bandwidth or continuous capture to detect that a bearing is degrading over weeks. It needs efficient, long-duration trend data — and that is exactly what it provides.

Forensic Recorder: Optimized for the Moment

A forensic bearing failure recorder is designed for a fundamentally different operating envelope:

  • Sampling rate is high. To capture the full frequency content of a bearing failure event — including high-frequency structural resonances, impact energy distribution, and the transient dynamics of catastrophic material failure — the recorder samples at 25 kHz or higher, across multiple axes simultaneously.
  • Capture is continuous. The recorder maintains a circular buffer of raw vibration data at full sample rate, continuously overwriting. There are no gaps. The buffer represents the most recent seconds or minutes of physical history at full fidelity.
  • Raw waveforms are preserved. When a terminal event triggers capture, the buffer contents — raw time-domain data, not derived metrics — are frozen and sealed. The original physical signal is the evidence; no information is discarded.

The tradeoff is obvious: the forensic recorder cannot maintain this capture rate for months or years. It is designed to record one event at maximum fidelity, not to track trends over time. Before the trigger, its data is ephemeral. After the trigger, it is permanent. But the long operational history leading up to the failure — the weeks of gradual degradation that a predictive system captures — is outside its design scope.

What Combined Deployment Captures

When a predictive sensor and a forensic recorder are deployed on the same bearing housing, the combined system eliminates the bandwidth gaps that each system has individually:

Full-Spectrum Frequency Coverage

The predictive sensor captures the low-to-mid frequency band (DC to 3–5 kHz) on a periodic basis over the bearing’s operational lifetime. This covers shaft frequency, bearing defect frequencies, gear mesh frequencies, and their harmonics — the signals that characterize gradual degradation.

The forensic recorder captures the full frequency band (DC to 12.5+ kHz at 25 kHz sample rate, or higher) continuously during the pre-event window and through the failure itself. This captures not only the defect frequencies but also the high-frequency content that reveals:

  • Early-stage spalling — detectable in the 10–30 kHz range through envelope analysis before it manifests at bearing defect frequencies
  • Impact energy distribution — the broadband energy released during material fracture or rolling element ejection
  • Structural resonance excitation — the bearing housing’s natural frequencies, which are excited by failure-related impacts and contain information about the failure’s severity and location
  • Cross-axis transient dynamics — how the failure propagates across radial and axial directions, which constrains interpretation of the failure mode

Neither system alone covers this full band with this temporal scope. The predictive sensor sees the degradation trend but misses the high-frequency failure physics. The forensic recorder sees the failure physics but not the weeks of degradation that preceded it.

Continuous Temporal Coverage

Perhaps more importantly, the combined system eliminates temporal gaps:

  • Months before failure: The predictive sensor captures periodic snapshots of bearing condition, establishing a degradation timeline. When did defect frequencies first appear? How fast did amplitudes grow? Were there any anomalous events — sudden jumps in vibration, temperature excursions, or unexplained spectral changes?
  • Minutes before failure: The forensic recorder’s continuous buffer captures the bearing’s physical state at full fidelity in the final interval before the terminal event. This is the period that predictive systems typically miss — the transition from “degraded but operational” to “terminal failure.” The buffer shows exactly what was happening at the bearing in the seconds before everything broke.
  • The failure event itself: The forensic recorder captures the terminal event — the actual moment of catastrophic failure — at full bandwidth, full sample rate, in the time domain. The raw waveform shows the sequence of events: which impact came first, how the failure propagated, what the failure mode signature looks like.
  • After failure: The forensic recorder’s post-event window captures the immediate aftermath — the bearing’s behavior after the primary failure. This post-event data can distinguish between a single catastrophic event and a cascading failure, and it captures the steady-state signature of the failed bearing, which is useful for comparison against the pre-event data.

Dual-Purpose Data Architecture

The data from each system serves its intended purpose without compromise:

  • The predictive sensor’s data feeds into maintenance planning workflows, CMMS integration, and operational dashboards. It is optimized for trend analysis and alarm management.
  • The forensic recorder’s data is sealed under tamper-evident controls with multi-party access requirements. It is optimized for evidential integrity and dispute resolution.

Neither system’s data is forced to serve a purpose it was not designed for. The predictive data remains operational intelligence. The forensic data remains sealed evidence. But together, they tell a complete story.

The Investigative Advantage

When a failure occurs on an asset equipped with both systems, the investigating parties have access to a dataset that fundamentally changes the analysis:

The degradation timeline narrows causation. If the predictive data shows that BPFI amplitudes began rising three months before failure, the investigation can focus on events that occurred around that time — a maintenance intervention, a load change, a lubrication schedule modification. If the predictive data shows no degradation trend at all, the investigation shifts to acute causes — foreign object damage, sudden overload, manufacturing defect.

The failure event constrains failure mode. The forensic recorder’s high-frequency, multi-axis waveform of the failure itself contains the physical signature of the failure mode. An outer race spall produces a different impact pattern than an inner race crack, which is different from a cage failure or a rolling element fracture. The raw time-domain data allows a vibration analyst to identify not just that the bearing failed, but how it failed — and to do so with a level of confidence that periodic spectra cannot support.

The combination rules out competing narratives. In a dispute, each party proposes a failure narrative that minimizes their liability. The combined dataset constrains which narratives are physically plausible. If the degradation trend shows progressive outer race wear and the failure event signature is consistent with outer race spalling, a narrative claiming sudden foreign object damage is contradicted by both datasets. The space of plausible narratives shrinks to those that are consistent with the full evidentiary record — degradation trend and failure physics.

Practical Deployment Considerations

Deploying both systems on the same asset is straightforward for several reasons:

Independent mounting. Both sensors mount directly to the bearing housing via threaded stud, adhesive, or magnetic mount. They do not interfere with each other electrically or mechanically. Each sensor has its own accelerometer, its own processing, and its own data path.

Independent power. Both systems run on battery power. The predictive sensor is optimized for multi-year battery life with periodic wake-up. The forensic recorder is optimized for continuous buffering over a deployment period measured in months to years, with a single terminal capture event. Neither system depends on the other’s power source.

Independent communication. The predictive sensor communicates wirelessly (BLE, LoRa, Wi-Fi, or cellular) to a gateway and cloud platform for trend monitoring. The forensic recorder stores data locally and does not transmit until evidence extraction is initiated under controlled conditions. The two data paths are architecturally separate, which is essential for maintaining the forensic recorder’s evidential independence.

No additional infrastructure. If you already have a predictive monitoring system deployed, adding a forensic recorder requires no changes to your existing infrastructure. The recorder operates autonomously. If you are deploying fresh, both systems can be installed simultaneously during a single maintenance window.

Who Benefits Most

The combined deployment is most valuable for assets where:

  • Bearing replacement costs are high — and warranty or liability allocation depends on demonstrating root cause
  • Failure consequences extend beyond the bearing itself — collateral damage to shafts, seals, gearboxes, or structures multiplies the financial stakes
  • Multiple parties are involved in bearing specification, installation, operation, and maintenance — each with potential liability exposure
  • Insurance claims or regulatory investigations are likely — where evidential rigor determines outcome
  • The asset operates in harsh or remote environments — where failure recovery is expensive and post-failure forensic examination of the physical bearing may be difficult or impossible

Marine propulsion systems, wind turbine drivetrains, railway axle assemblies, large industrial pumps, and critical process machinery are all candidates where the combined approach delivers the strongest return: operational optimization through predictive monitoring, and evidential protection through forensic capture.

The Complete Record

No single sensor architecture can simultaneously optimize for long-duration trend monitoring and high-fidelity event capture. The physics of battery life, storage capacity, and sampling rate create fundamental tradeoffs that force every system to choose. Predictive systems choose duration. Forensic systems choose fidelity.

By deploying both, you stop choosing. You get the degradation trend and the failure event. The maintenance intelligence and the sealed evidence. The operational picture and the forensic record.

For critical bearings where both uptime and accountability matter, the combined architecture is not a luxury — it is the only way to capture the complete record.

Why Predictive Maintenance Data Fails as Bearing Failure Evidence

Predictive maintenance has become the dominant paradigm in bearing condition monitoring. The premise is compelling: by continuously monitoring vibration, temperature, and other physical parameters, you can detect degradation early enough to schedule replacement before failure occurs. Downtime is planned rather than unplanned. Costs are predictable. The bearing never reaches catastrophic failure.

Except when it does.

Predictive maintenance systems are designed to prevent failures. They are not designed to document failures that occur despite prediction — or failures that were never predictable in the first place. When a bearing fails and the question shifts from “how do we fix this?” to “who pays for this?”, predictive maintenance data is structurally inadequate for the task. Understanding why requires examining what predictive systems actually capture, what they discard, and what they were never intended to record.

What Predictive Maintenance Systems Capture

A typical predictive maintenance system for bearing monitoring collects data on a scheduled or continuous basis:

  • Periodic vibration spectra — FFT snapshots taken at regular intervals (hourly, daily, or weekly), stored as frequency-domain representations. These show the distribution of vibration energy across frequencies at a single point in time.
  • Trend data — Time-series of derived metrics such as overall vibration amplitude (velocity RMS, acceleration peak), bearing condition indicators (envelope spectrum amplitudes at defect frequencies), and temperature. These are stored as scalar values over time.
  • Alarm events — Timestamped records of when a monitored parameter exceeded a configured threshold. These include the parameter name, the threshold value, and the measured value at the time of the alarm.
  • Health scores — Composite indices computed by proprietary algorithms that combine multiple parameters into a single “health” value, often on a 0–100 or traffic-light scale.

This data is well suited to its intended purpose. A maintenance planner can observe a bearing’s health score declining from 95 to 72 over three months, correlate this with rising BPFO amplitudes in the vibration spectra, and schedule replacement during the next planned outage. The system has done its job: failure was predicted and prevented.

What Predictive Maintenance Systems Discard

To maintain storage efficiency and analytical clarity, predictive systems routinely discard the data that would be most valuable in a forensic investigation:

Raw Time-Domain Waveforms

The FFT spectrum that gets stored is computed from a raw vibration waveform — a time-series of acceleration values sampled at high frequency (typically 10–50 kHz for bearing applications). This waveform is the primary physical measurement. The FFT is a derived representation that discards phase information and temporal structure. Most systems compute the FFT at the edge or gateway level and transmit only the spectrum. The raw waveform is overwritten.

In a forensic investigation, the raw waveform is often more informative than the spectrum. Impulse patterns, modulation characteristics, transient events, and the temporal relationship between different vibration sources are all visible in the time domain and invisible — or ambiguous — in the frequency domain. Once the waveform is discarded, this information is permanently lost.

High-Frequency Content

Many predictive systems sample at rates sufficient for routine monitoring (5–10 kHz) but insufficient for forensic analysis of high-speed bearings or early-stage defects. The characteristic frequencies of an incipient spall on a high-speed bearing can exceed 20 kHz. Envelope analysis, which demodulates the high-frequency resonance excited by bearing impacts, requires even higher sampling rates. Standard monitoring systems often lack the bandwidth to capture these signals, meaning the earliest physical evidence of the defect was never recorded.

Continuous Pre-Event Data

Predictive systems capture data at intervals — once per hour, once per day, or in response to triggered events. Between captures, the bearing’s physical state is unrecorded. If a failure occurs between scheduled measurements, the last available data point may be hours or days old. The progression of the failure from its final detectable state to catastrophic failure — the most forensically critical interval — falls in the gap between measurements.

The Three Failure Modes That Predictive Systems Cannot Document

1. The Unpredicted Failure

Not all bearing failures are predictable. A foreign object drawn into the bearing, a sudden loss of lubrication due to a seal failure, a transient overload from a process upset, or a manufacturing defect that manifests as a sudden fracture rather than progressive fatigue — these events do not produce the gradual degradation signature that predictive systems are designed to detect. The first indication of failure is the failure itself.

When this happens, the predictive maintenance record shows a healthy bearing right up to the moment of catastrophic failure. The data proves that prediction was attempted and that no degradation was detected — but it says nothing about what actually caused the failure. The forensic gap is total.

2. The Disputed Failure

When multiple parties contest a failure, the question is not just “what happened?” but “can the data be trusted?” Predictive maintenance data is stored on systems controlled by one of the parties to the dispute. The equipment operator controls the local SCADA system and historian. The monitoring vendor controls the cloud analytics platform. Neither party can provide data that the other party is obligated to accept as unaltered.

Even when the data is perfectly accurate, its provenance is suspect. A bearing manufacturer accused of a product defect will question whether the operator’s monitoring data was collected correctly, stored properly, and exported completely. An operator accused of abuse will question whether the vendor’s analytics algorithm was properly calibrated. The data becomes a new axis of dispute rather than a basis for resolution.

3. The Infrastructure-Correlated Failure

Catastrophic bearing failures often correlate with infrastructure disruptions. The same event that destroys the bearing — a power surge, a coolant system failure, a structural overload — often disrupts the monitoring infrastructure. Sensors lose power. Network connections drop. Cloud uploads fail. The monitoring system goes blind at the precise moment when recording matters most.

Predictive maintenance systems are designed to operate within normal infrastructure conditions. They are not designed to survive the conditions that accompany catastrophic failures. A battery-less vibration sensor that relies on facility power and Wi-Fi connectivity will capture nothing during a power-loss event — which is exactly the type of event most likely to cause or accompany a bearing failure.

What Failure Evidence Requires Instead

Documenting bearing failures for forensic and dispute-resolution purposes requires a fundamentally different architecture than predictive maintenance. The system must be designed around the assumption that failure will occur and that the recording must survive it.

  • Continuous high-frequency buffering. Raw vibration data must be captured continuously at sample rates sufficient for forensic analysis (25+ kHz), not at periodic intervals. The data is continuously overwritten in a circular buffer — no long-term storage burden — but at the moment a terminal event is detected, the buffer contents are frozen and preserved.
  • Event-triggered, single-shot capture. The trigger is the failure itself. The system detects a terminal physical event (impact above threshold, vibration amplitude exceeding a catastrophic limit, sudden temperature excursion) and immediately seals the buffer contents — typically several seconds to minutes of pre-event data and a fixed post-event window. This is a one-time, irreversible capture.
  • Power and infrastructure independence. The capture system must operate on battery power, store data locally, and function with zero dependency on facility power, network connectivity, or cloud services. If the lights go out and the network drops, the recorder keeps running.
  • Tamper-evident sealing. Captured data must be cryptographically sealed at the moment of capture and stored under multi-party access controls. No single party can access, modify, or delete the data unilaterally.

This is not an enhanced monitoring system. It is a different instrument with a different purpose. Predictive maintenance and failure evidence capture are complementary — the first prevents failures; the second documents the failures that prevention cannot stop.

The Complementary Architecture

The strongest position for any critical asset is to deploy both:

  1. A predictive maintenance system that monitors the bearing continuously, detects degradation trends, and enables planned replacement before failure. This system prevents the majority of bearing failures and reduces unplanned downtime.
  2. A forensic evidence recorder that operates independently, captures the failure event if and when it occurs, and preserves a tamper-evident physical record for dispute resolution. This system addresses the failures that prediction cannot prevent — the rare, catastrophic, disputed events where ambiguity is the most expensive outcome.

The predictive system optimizes uptime. The forensic recorder preserves truth. Together, they address both the operational and the adversarial dimensions of bearing failure — which, for critical assets, are the two dimensions that matter most.

Tamper-Evident Bearing Condition Data: What It Is and Why It Matters

Every bearing condition monitoring system generates data. Vibration spectra, temperature trends, health scores, alarm logs — the volume of data produced by modern monitoring platforms is substantial. But volume is not the same as evidential weight. When a bearing failure triggers a dispute between an equipment operator, a bearing manufacturer, a maintenance contractor, and an insurer, the critical question is not whether data exists. The critical question is whether any party can demonstrate that the data has not been altered since capture.

This is the problem of tamper evidence — and it is the problem that separates operational monitoring data from forensic evidence.

The Difference Between Data and Evidence

Operational data serves operational purposes. A vibration trend shows whether a bearing is degrading. A temperature alarm triggers a maintenance work order. A health score informs a scheduling decision. None of these functions require the data to be provably unmodified. If a maintenance manager looks at a trend plot and decides to schedule a bearing replacement, the integrity of the underlying data points is not in question — the manager trusts the system because they control it.

Evidence serves a different function. Evidence must be credible to parties who do not control it, did not collect it, and may have strong incentives to dispute it. In a failure investigation, every party examines the data with a specific question: could the data have been modified by a party with an interest in the outcome?

If the answer is yes — if the data was stored on systems controlled by one of the parties, transmitted through infrastructure managed by one of the parties, or processed by software maintained by one of the parties — then the evidential weight of the data is compromised regardless of whether any modification actually occurred. The mere possibility of tampering is sufficient to undermine credibility.

How Standard Monitoring Data Is Vulnerable

Most bearing condition monitoring data passes through a chain of systems, each controlled by a specific party:

Sensor to Gateway

Data flows from the sensor to a local gateway or edge device, typically installed and maintained by the monitoring vendor or the equipment operator. At this stage, raw data may be preprocessed, filtered, compressed, or aggregated. The original waveform may never leave the gateway — only derived metrics are forwarded. Any modification at this stage is invisible to downstream consumers of the data.

Gateway to Cloud

Data is transmitted to a cloud platform operated by the monitoring vendor. During transmission, data passes through network infrastructure controlled by the operator or a third-party provider. At the cloud platform, data is stored in databases managed by the vendor. The vendor has administrative access to these databases. Retention policies, data migration, and software updates all create windows in which data could theoretically be modified without detection.

Cloud to Report

When a failure occurs and data is retrieved for analysis, it is typically exported from the cloud platform by the vendor, formatted into reports, and delivered to the investigating parties. The parties receiving the report have no way to verify that the exported data matches what was originally captured at the sensor. They receive a processed artifact, not a sealed original.

At no point in this chain is there a mechanism that would make unauthorized modification detectable. The data may be perfectly accurate — but its accuracy cannot be independently verified.

What Tamper Evidence Requires

Tamper evidence is not encryption. Encryption protects data from being read by unauthorized parties. Tamper evidence protects data from being modified without detection. They are complementary but distinct properties.

A tamper-evident data system must satisfy three requirements:

1. Integrity Verification

Any party must be able to verify that the data has not been modified since the moment of capture. This typically involves cryptographic hashing — computing a fixed-length digest of the data at capture time, then storing that digest in a way that is independent of the data itself. If any bit of the data changes, the hash will not match, and the modification is detectable. The verification process must be reproducible by any party with access to the data and the hash, without requiring trust in the party that captured the data.

2. Seal Independence

The integrity seal must be independent of the system that stores the data. If the hash is stored alongside the data on the same system controlled by the same party, both can be modified simultaneously. For the seal to be credible, it must be stored or registered in a way that no single party can alter. Options include multi-party key escrow, independent timestamp authorities, or distributed registration systems where modification would require collusion among multiple independent parties.

3. Access Auditability

Every access to the sealed data must be logged in a way that is itself tamper-evident. If a party accessed the data — even read-only access — this must be recorded. In a dispute, the access log establishes who has seen the data and when, which is relevant to evaluating any claims about the data’s integrity.

Architectural Approaches

Several architectural patterns can deliver tamper evidence for bearing condition data:

Capture-Time Sealing

The strongest approach seals data at the moment of capture, before it enters any system controlled by a party to a potential dispute. The sensor node itself computes a cryptographic hash of the raw captured data and stores both the data and the hash in local, non-volatile memory. The hash is additionally registered with an independent authority or distributed to multiple parties at the time of capture. From this point forward, any modification to the data will be detectable by comparing it against the original hash.

Multi-Party Key Control

Access to the sealed data requires agreement among multiple parties. No single party — not the equipment operator, not the monitoring vendor, not the sensor manufacturer — can unilaterally decrypt, export, or release the data. This prevents any party from accessing the data privately, modifying it, and re-sealing it. It also ensures that when the data is eventually released for analysis, all relevant parties are aware of and can observe the release.

Invalidation Transparency

If any condition occurs that could compromise the integrity of the captured data — physical tampering with the sensor housing, removal of the sensor from its mounting, loss of power to the sealing mechanism — this must be recorded and made evident. A tamper-evident system does not merely protect against intentional modification; it also records any event that could cast doubt on the data’s integrity, even if no modification occurred.

Why This Changes Dispute Dynamics

When bearing failure data is tamper-evident, the dynamics of a failure dispute change fundamentally:

  • Credibility is architectural, not testimonial. The data’s integrity does not depend on anyone’s testimony about what happened to it. It is verifiable by cryptographic proof. An expert witness can confirm the data is unmodified without relying on the word of any party.
  • Selective disclosure is impossible. Because all parties share key control, no party can selectively release favorable data while withholding unfavorable data. The record is complete or it is nothing.
  • Narratives must be consistent with physics. When the physical record is trustworthy, competing narratives are constrained by what the data actually shows. A party cannot claim the bearing was properly lubricated if the vibration data shows amplitude patterns consistent with dry running. A party cannot claim the failure was sudden if the data shows progressive degradation over hours.
  • Settlement becomes rational. When both parties can see the same unmodified evidence, settlement negotiations shift from a war of attrition to a rational assessment of liability. The party whose narrative is contradicted by the physical evidence has a strong incentive to settle rather than incur further legal costs defending an untenable position.

The Standard That Should Exist

There is no current ISO or IEC standard specifically addressing tamper-evident requirements for bearing condition monitoring data. Standards like ISO 13373 (condition monitoring and diagnostics of machines) and ISO 18436 (condition monitoring and diagnostics) address data collection methodologies and analyst competency, but they do not address the evidential integrity of the data itself.

This is a gap. As bearing condition monitoring becomes ubiquitous and as the financial stakes of failure disputes continue to grow, the absence of tamper-evidence requirements means that an increasing volume of monitoring data is being generated that cannot withstand adversarial scrutiny. The data is useful for operations but insufficient for dispute resolution — which is precisely when it matters most.

Until standards catch up, the burden falls on system architects to build tamper evidence into the capture and storage architecture from the ground up. Retrofitting tamper evidence onto an existing monitoring system is architecturally difficult and forensically weak. The integrity of the data must be established at the moment of capture, not applied after the fact.

Conclusion

Tamper-evident bearing condition data is not a feature. It is a requirement for any data that will be used as evidence in a failure dispute. Standard monitoring systems, however sophisticated their analytics, cannot provide this property because they were not designed for it. They were designed to support maintenance decisions, not to withstand adversarial scrutiny.

The difference is architectural. Tamper evidence must be built into the capture mechanism, the storage mechanism, and the access control mechanism from the beginning. When it is, the data becomes something more than operational intelligence — it becomes a neutral, verifiable physical record that can resolve disputes on the basis of evidence rather than leverage.

Why Forensic Bearing Evidence Matters in Warranty Disputes

When a critical bearing fails — in a marine propulsion shaft, a railway axle, a wind turbine gearbox, or an industrial pump — the mechanical failure is rarely the most expensive outcome. The bearing is replaceable. The downtime is quantifiable. What often costs far more, and drags on far longer, is the dispute about why it failed.

In high-value failure scenarios, multiple parties share the loss and the liability: the equipment operator, the bearing manufacturer, the OEM who specified the bearing, the maintenance provider who last serviced it, and the insurer who underwrites the risk. Each party has incentives to reconstruct the failure narrative in ways that minimize their exposure. Without an authoritative record of what happened at the bearing in the moments before and during failure, these disputes are settled by leverage rather than physics — by which party can sustain the longest legal engagement, not by what the evidence shows.

This is the problem forensic bearing evidence solves.

What Forensic Bearing Evidence Actually Is

Forensic bearing evidence is not a trend log. It is not a health score. It is not a periodic vibration spectrum taken during a maintenance route.

Forensic bearing evidence is a high-fidelity, time-localized physical record of the bearing’s condition at the moment of failure — captured automatically, preserved immutably, and maintained under a defensible chain of custody.

The distinction matters. Standard condition monitoring data is designed for maintenance planning. It answers questions like “is this bearing degrading?” and “when should we schedule replacement?” These are valuable operational questions, but they are not the questions that arise in a failure dispute.

In a dispute, the questions are different:

  • What was the physical state of the bearing at the exact moment of failure?
  • Was the failure sudden or progressive?
  • Did the bearing exhibit defect frequencies consistent with a manufacturing flaw, an installation error, or operational abuse?
  • Was the failure preceded by conditions indicating inadequate lubrication, misalignment, or overload?
  • Can any party’s narrative be ruled out by the physical evidence?

Answering these questions requires data that most monitoring systems do not retain: raw, high-frequency vibration waveforms captured at the moment of the terminal event, with enough pre-event history to establish progression, and enough post-event data to characterize the failure mode.

Why Standard Monitoring Data Falls Short

Most installed bearing monitoring systems generate operational data: trend logs, health scores, alarm histories, periodic vibration spectra. This data is genuinely useful for maintenance planning. It is not, in general, useful as forensic evidence in a contested failure investigation.

The Resolution Problem

Trend data is averaged and compressed. A daily or hourly health score tells you that something changed, but the raw high-frequency vibration record — the actual physical signal from which defect frequencies are computed — is typically not stored. By the time a failure occurs, the detailed signal that would allow a forensic analyst to determine the fault type, progression rate, and sequence of events has been discarded as part of normal data management.

The Survivability Problem

Most monitoring systems depend on facility power and network connectivity. The same event that destroys a bearing often disrupts the infrastructure that a monitoring system needs to function. A power surge that damages a motor also kills the monitoring system collecting data from it. A shaft seizure in a marine vessel can trip breakers that take the monitoring network offline. The critical seconds of data surrounding the failure event are precisely the seconds most likely to be lost.

The Chain of Custody Problem

Even when monitoring data survives a failure, it is typically stored on systems controlled by one of the parties to the dispute. The equipment operator controls the SCADA historian. The monitoring vendor controls the cloud platform. Neither party can demonstrate to a neutral third party that the data has not been altered, selectively deleted, or reinterpreted after the fact. Without a tamper-evident chain of custody, the evidential weight of the data is fundamentally compromised.

What a Forensic Evidence System Must Deliver

For bearing failure data to function as forensic evidence — data that can narrow disputes, accelerate expert analysis, and withstand scrutiny in adversarial proceedings — it must satisfy four requirements:

1. Event-Bound Capture

The system must capture the failure event itself, not just the operational period leading up to it. This means continuous buffering of raw, high-frequency vibration data with automatic detection of the terminal event. When the failure occurs, the system preserves a fixed window of pre-event and post-event data — the last seconds or minutes before the failure, the failure itself, and the immediate aftermath. This is a single-shot, irreversible capture: once triggered, the data is sealed.

2. Survivability

The system must survive the failure it records. This means battery-powered operation independent of facility power. It means local data storage independent of network connectivity. It means physical packaging that persists through the vibration, shock, temperature, and contamination conditions present during a catastrophic bearing failure. If the recorder dies with the bearing, it has no forensic value.

3. Tamper Evidence

The captured data must be demonstrably unaltered from the moment of capture. This is not merely encryption — it is architectural. The system must make it evident if any party has attempted to modify, delete, or selectively access the data. Tamper evidence means that the integrity of the record is verifiable by any party, including parties who did not control the capture device.

4. Neutral Access

No single party should have unilateral access to the captured evidence. In a multi-party dispute, the party that controls the evidence has an inherent advantage. A forensic evidence system must enforce access controls that require agreement among relevant parties before the data is released. This is not a policy choice — it is an architectural requirement for the data to be credible as neutral evidence.

The Economic Case

Bearing failure disputes in high-value industrial equipment routinely involve six- and seven-figure sums. A single propulsion bearing failure on a commercial vessel can generate claims exceeding $2 million when hull damage, port delays, cargo delays, and liability are included. A bearing failure in a wind turbine gearbox can cost $500,000 in crane mobilization and replacement costs alone, before the question of who pays is even addressed.

The dispute itself adds cost on top of the failure cost. Expert witness fees, legal engagement, forensic analysis of recovered hardware, and lost management time during extended proceedings can easily double the total cost of a failure. These disputes often settle not on the strength of evidence, but on the relative willingness of each party to continue paying legal fees — a process that systematically favors parties with deeper resources, regardless of actual fault.

Forensic bearing evidence disrupts this dynamic. When an authoritative physical record of the failure event exists, the space of plausible narratives shrinks. Experts can focus on analyzing real data rather than constructing competing hypotheses. Disputes that previously took 18 months to settle can be resolved in weeks. The party that is actually responsible cannot hide behind ambiguity, and the party that is not responsible cannot be coerced into an unfavorable settlement.

Where This Matters Most

Forensic bearing evidence is most valuable in environments where:

  • Failures are rare but catastrophic. If a bearing fails every month, you have statistical data and operational history. If it fails once in five years, you have one chance to capture the event.
  • Multiple parties share liability. Equipment operators, OEMs, bearing manufacturers, maintenance contractors, and insurers each have something at stake and something to lose.
  • Downtime is secondary to dispute. The cost of the failure itself is dwarfed by the cost of determining who pays for it.
  • Existing monitoring cannot reconstruct the failure. If the SCADA system and vibration monitoring were sufficient, the dispute would already be resolved.

Typical applications include marine propulsion bearings, railway axle bearings, wind turbine gearbox bearings, large industrial pump bearings, and any other critical rotating equipment where failure triggers a multi-party investigation.

The Principle

When failure is inevitable — and on a long enough timeline, all bearings fail — truth at failure is non-optional. The only question is whether you captured it.

Forensic bearing evidence does not prevent failures. It does not predict them. It ensures that when a failure occurs, there is a physical record that survives the event, resists manipulation, and provides neutral ground for resolution. In an industry where ambiguity is the most expensive outcome, that record changes everything.