Key takeaways
  • An FMEA lists how a process or product can fail, how bad that is, how often it happens and how likely you are to catch it.
  • Risk Priority Number is severity x occurrence x detection, but ranking by RPN alone is a known trap: a severity 10 deserves action regardless of its RPN.
  • An FMEA is a living document. If it is not revisited after a failure, it was a compliance exercise.
The scoring mistake that matters
Detection scores the control, not the hope

Detection is how likely your current control is to catch the failure before it reaches the customer. An operator who 'would probably notice' is not a control. Scoring intent rather than mechanism is why FMEAs predict nothing.

Scope it before you start

Pick one process or one product, and define where it starts and ends. A team that tries to FMEA an entire plant produces two hundred rows of generic risk. Twenty rows about one process, written by people who run it, is worth more.

The columns and what goes in them

  • Function. What this step is supposed to achieve.
  • Failure mode. How it fails to achieve that, described physically: not tightened, tightened to the wrong torque, cross-threaded.
  • Effect. What the customer or next process experiences.
  • Severity. 1 to 10 on the effect, not on the failure.
  • Cause. Why the failure mode occurs.
  • Occurrence. 1 to 10 on how often that cause happens.
  • Current controls. Prevention and detection, listed separately.
  • Detection. 1 to 10 on how likely the control catches it, where 10 means you almost certainly will not.

Scoring honestly

  • Severity is about the effect and does not change when you add a control. Only a design change moves it.
  • Occurrence should come from data where data exists. Scrap records, complaint history, downtime logs.
  • Detection scores the actual control in place today, not the one you intend to add.
  • Use one scale, written down, applied by the same group throughout, or the numbers are not comparable between rows.

What to act on

Take action on every high severity regardless of RPN, then on the highest occurrence, then on the worst detection. RPN is a useful sort but a poor filter, because a low-frequency catastrophic failure and a frequent trivial one can score identically.

Keeping it alive

The test of an FMEA is what happens after a real failure. If the failure mode is not in the document, add it and reconsider what else was missed. If it is, ask why the assigned control did not work. An FMEA that is not touched between audits is a record of what a team once thought, and nothing more.