Alarm Monitoring & Control System (AMCS)
An AMCS collects sensor signals from engines, boilers, pumps and tanks into a central logic that raises alarms, logs trends and can start standby equipment automatically, turning the engine room into a space that can legally run unmanned for set periods rather than under continuous watch.
Read more — Alarm Monitoring & Control System (AMCS) explained ▾
What makes an AMCS different from a single instrument
A standalone gauge or alarm switch tells you about one parameter. An AMCS ties hundreds of sensors - temperatures, pressures, levels, flows, running status - into a common data acquisition and logic system, so that a single fault can be cross-checked against related readings before an alarm reaches the bridge or the duty engineer's cabin. It also holds the sequential logic for automatic actions such as standby pump start on a drop in pressure, or slowdown and shutdown of the main engine on a serious fault, which a collection of individual local alarms cannot coordinate on its own.
Main components
Field sensors and transmitters
Resistance thermometers, pressure transmitters, level probes and flow switches convert the physical measurement into an electrical signal, usually 4-20mA or a digital fieldbus signal.
Remote I/O and controllers
Distributed input/output cabinets local to the engine room, cargo area or steering gear room gather signals and pass them over a redundant network to the central processing units.
Central processing and logic
Dual or triplicated controllers run the alarm logic, sequence control for standby equipment, and safety shutdown functions, with a changeover on failure of the primary unit.
Operator stations
Screens in the engine control room, on the bridge and in duty officer cabins display alarms, mimic diagrams and trend logs, with an audible alarm and dead-man call-back system for the unmanned machinery space watch.
Power supply
An uninterruptible power supply keeps the system running through a mains supply interruption long enough for controlled action or changeover to emergency power.
Selection and sizing
Sizing follows the number and type of monitored points, the required response time for safety functions, and the level of automation the class notation demands. A ship aiming for an unmanned machinery space notation needs a documented alarm printer, dead-man alarm system and defined watchkeeper response time, which drives the choice of controller redundancy and network architecture rather than the raw point count alone.
Regulations and class
SOLAS Chapter II-1 sets requirements for machinery space alarm and safety systems supporting periodically unattended operation. Class societies issue an unmanned machinery space notation only after the AMCS demonstrates correct alarm annunciation, automatic standby start, and safety shutdown behaviour during sea trials. Periodic testing of alarms and safety trips is required at survey and is normally also carried out by the crew on a fixed schedule between surveys.
Typical faults
- Sensor drift - an uncalibrated transmitter reads a false value, triggering nuisance alarms or, worse, masking a real fault until it grows.
- Field cabling faults - moisture ingress or chafed cable in an engine room duct produces intermittent signals that are hard to trace and erode crew trust in the alarm system.
- Software or firmware faults after an update - an incompletely tested update can silently disable a logic function; verification against the original approved logic is needed after any change.
- UPS battery degradation - an aging battery with reduced capacity fails exactly when a mains interruption occurs, taking the alarm system down with the power event it should have survived.
- Alarm flooding - a single upstream fault (for example a common power rail) triggers dozens of secondary alarms at once, burying the real cause under noise.
What to look for in a supplier
- A track record of the same platform on similar vessel types, with available spares and software support over the ship's service life, not just at delivery.
- Open or at least documented data protocols, so the system can be integrated with later additions such as fuel monitoring or condition-based maintenance tools.
- Local service presence or trained technicians in the ports the ship regularly calls at.
- Clear change-management documentation for logic and software updates, so later modifications remain traceable against the class-approved baseline.
Treat every disabled or bypassed alarm point as a live risk, not paperwork - log it, time-limit it, and chase the repair, because a silenced alarm is a blind spot exactly where the system was meant to be watching.