Skip to main content

FMEA (Failure Mode and Effects Analysis)

FMEA (Failure Mode and Effects Analysis) is a systematic, inductive analysis method: it identifies possible failure modes of a system, evaluates their causes and effects and prioritises countermeasures — before the failures occur in the product. As a preventive method, it is one of the established safety and quality analyses in automotive, industry and medical technology.

How does an FMEA proceed?

An FMEA works systematically through the object under consideration: first, the structure of the system is captured and functions are assigned to its elements. Then, for each function, the questions are asked how it can fail (failure mode), what this causes (failure effect) and what the reason may be (failure cause). Each chain is evaluated using three criteria:

CriterionQuestion
S — SeverityHow serious is the failure effect?
O — OccurrenceHow likely is the failure cause?
D — DetectionHow well is the failure detected by existing measures before it takes effect?

The evaluation leads to the prioritisation of actions: prevention actions reduce the occurrence, detection actions improve the detection. After implementation, the ratings are revised — the FMEA is designed as an iterative control loop, not as a one-off table.

RPN or Action Priority?

Classically, the three ratings were multiplied into the Risk Priority Number (RPN). The harmonised FMEA handbook by AIAG and VDA replaced the RPN with the Action Priority (AP): instead of a product in which very different risk situations can yield the same numerical value, the AP assigns each rating combination directly a priority for action (high, medium, low). In both cases, the same applies: the figure is a prioritisation tool for actions, not a safety proof.

What types of FMEA exist?

  • System FMEA: analyses malfunctions at system and architecture level, including the interfaces between components.
  • Design FMEA: analyses failure modes in the design of individual components.
  • Process FMEA: analyses sources of error in manufacturing and assembly processes.

Distinction: FMEA and FTA

In safety critical projects, the FMEA is often confused with neighbouring analyses. The FMEA checks inductively (bottom-up) which failure modes of elements have which consequences. The FTA (fault tree analysis) works deductively (top-down) from an undesired event to its combinations of causes. FMEA and FTA are closely interlinked: failure modes from the FMEA enter the fault tree as basic events — a change in the FMEA propagates directly into the FTA.

FMEA in practice: from table to living work product

The most common weakness of real FMEAs is not the method, but its maintenance: maintained as an isolated table, the analysis becomes outdated with the first architecture change — and nobody notices. If an architecture element changes, the associated FMEA entries must be re-evaluated; without a digital link between architecture, FMEA and FTA, this relationship has to be reconstructed by hand with every change. Only when the FMEA is model-based and its dependencies can be evaluated by machine does the compliance exercise become a work product that actually makes changes manageable in everyday development.

Frequently asked questions

What is the difference between FMEA and FTA?
The FMEA works inductively from the bottom up: it starts from possible failure modes of individual elements and asks about their effects on the system. The FTA (fault tree analysis) works deductively from the top down: it starts from an undesired top event and searches for its combinations of causes. The two complement each other — failure modes from the FMEA enter the fault tree as basic events.
What is the difference between FMEA and HARA?
The HARA evaluates hazards and resulting risks in the concept phase and derives safety goals and measures from them — it asks how dangerous a malfunction is for people. The FMEA analyses later in the design which concrete failure modes can occur in architecture, design or process and what their effects are. The HARA sets the goals, the FMEA checks the implementation for weaknesses.
What do RPN and Action Priority (AP) mean?
The classic Risk Priority Number (RPN) multiplies the ratings for severity, occurrence and detection into a single figure. Because identical products can mask very different risk situations, the harmonised AIAG-VDA FMEA handbook replaced the RPN with the Action Priority (AP): it assigns each rating combination directly a priority (high/medium/low) for actions.

Related terms

Reviewed by Dr. Alexander Nyßen, Executive Vice President Digital Engineering on July 20, 2026