FMEA (Failure Mode and Effects Analysis)
FMEA (Failure Mode and Effects Analysis) is a systematic, inductive analysis method: it identifies possible failure modes of a system, evaluates their causes and effects and prioritises countermeasures — before the failures occur in the product. As a preventive method, it is one of the established safety and quality analyses in automotive, industry and medical technology.
How does an FMEA proceed?
An FMEA works systematically through the object under consideration: first, the structure of the system is captured and functions are assigned to its elements. Then, for each function, the questions are asked how it can fail (failure mode), what this causes (failure effect) and what the reason may be (failure cause). Each chain is evaluated using three criteria:
| Criterion | Question |
|---|---|
| S — Severity | How serious is the failure effect? |
| O — Occurrence | How likely is the failure cause? |
| D — Detection | How well is the failure detected by existing measures before it takes effect? |
The evaluation leads to the prioritisation of actions: prevention actions reduce the occurrence, detection actions improve the detection. After implementation, the ratings are revised — the FMEA is designed as an iterative control loop, not as a one-off table.
RPN or Action Priority?
Classically, the three ratings were multiplied into the Risk Priority Number (RPN). The harmonised FMEA handbook by AIAG and VDA replaced the RPN with the Action Priority (AP): instead of a product in which very different risk situations can yield the same numerical value, the AP assigns each rating combination directly a priority for action (high, medium, low). In both cases, the same applies: the figure is a prioritisation tool for actions, not a safety proof.
What types of FMEA exist?
- System FMEA: analyses malfunctions at system and architecture level, including the interfaces between components.
- Design FMEA: analyses failure modes in the design of individual components.
- Process FMEA: analyses sources of error in manufacturing and assembly processes.
Distinction: FMEA and FTA
In safety critical projects, the FMEA is often confused with neighbouring analyses. The FMEA checks inductively (bottom-up) which failure modes of elements have which consequences. The FTA (fault tree analysis) works deductively (top-down) from an undesired event to its combinations of causes. FMEA and FTA are closely interlinked: failure modes from the FMEA enter the fault tree as basic events — a change in the FMEA propagates directly into the FTA.
FMEA in practice: from table to living work product
The most common weakness of real FMEAs is not the method, but its maintenance: maintained as an isolated table, the analysis becomes outdated with the first architecture change — and nobody notices. If an architecture element changes, the associated FMEA entries must be re-evaluated; without a digital link between architecture, FMEA and FTA, this relationship has to be reconstructed by hand with every change. Only when the FMEA is model-based and its dependencies can be evaluated by machine does the compliance exercise become a work product that actually makes changes manageable in everyday development.


