What is FMEA?
Failure Mode and Effects Analysis (FMEA) is a systematic technique for studying potential failures of functions, equipment, or processes. It starts by defining what an element should do and asks how it might fail to do so, what the resulting effects would be, and why.
Its value for risk assessment lies in anticipating hazardous situations and guiding improvements in design, operation, and maintenance. Not every quality deviation poses a risk to people. The study must explicitly define the occupational health and safety (OSH) consequences it will examine and not be limited to defects in the final product.
Team scope and preparation
Before completing a table, the system, its functions, and interfaces must be defined. An overly broad scope leads to vague descriptions; one that is too narrow may omit important interactions. Operating modes must be understood, including startup, shutdown, cleaning, adjustments, and foreseeable abnormal conditions.
The team needs design knowledge and practical experience, with input from operations, maintenance, and prevention as needed. Available drawings, incident reports, manuals, and data help support the hypotheses. The person coordinating the analysis must ensure common criteria are established and document any doubts, avoiding resolving them through agreed-upon scores without evidence.
Function, failure, cause and effect
These elements must be distinguished. The function describes the expected result; the failure mode indicates how it is lost or degraded; the cause explains a possible mechanism; the effect expresses its consequences. It is common to confuse a cause, such as wear, with a failure mode, such as loss of sealing.
Each relationship should be written in a verifiable manner. If the same cause can produce different effects, these should be studied in sufficient detail. It is also necessary to identify existing controls and verify whether they prevent the failure, detect it, or reduce its consequences. These functions are not interchangeable and should not be attributed to a piece of equipment without technical justification.
Prioritize without depending on a single number
Classical schemes consider severity, occurrence, and detectability. Some versions combine these into a risk priority number. Scales and rules must be defined before comparing results, and their application requires consistency among participants.
Multiplying ordinal scores has its limits: very different combinations can produce the same result. A serious effect should not be disregarded simply because another assessment reduces the final product. Legal obligations and technical safety requirements remain applicable. The criteria for action must consider critical consequences and not merely order rows from highest to lowest score.
From analysis to measures
Actions should primarily focus on the design and the root causes of the failure, without disregarding barriers that limit its effects. A recommendation such as “improve attention” provides little information if it doesn’t define what changes in the task. It’s more useful to specify the modification, who is responsible for it, and how the result will be verified.
After implementing a measure, the assessment is reviewed with evidence. It is not enough to simply reduce numbers because there is a purchase order or scheduled training. The verification must confirm that the measure works under the intended conditions and does not introduce other risks, including its impact on safety during maintenance.
Relationship with other methods
Fault tree analysis starts with an undesired event and studies combinations that can produce it. FMEA examines functions or elements and their potential failures and effects. Both approaches can complement each other, especially when it is necessary to understand dependencies or failures that simultaneously affect several protections.
HAZOP and the What-if method offer other ways to explore deviations and scenarios. The choice depends on the system and the purpose of the study. An FMEA of one component does not demonstrate that the entire process has been assessed, nor does it automatically cover all occupational exposures.
Practical example
A piece of equipment uses a cooling circuit whose function is to maintain a defined operating condition. The FMEA identifies loss of circulation as a failure mode and studies several possible causes. The team analyzes what happens if this loss is not detected and what consequences it may have for people.
The actual detection capability, the expected response, and the maintenance conditions are verified. Actions are assigned and verified before reviewing the priority. The example does not provide a protection design; it shows how to move from a function to a specific failure and to decisions based on system information.
Registration, updates, and common errors
The record must document scope, participants, version, criteria, assumptions, and actions. Change management must trigger a review when functions, equipment, materials, or conditions are modified. It is also necessary to record observed incidents and failures that contradict the initial assumptions.
Common errors include copying generic tables, confusing detection with prevention, assigning scores without criteria, and closing actions without verifying them. FMEA provides value when it maintains a clear relationship between what can go wrong, the relevant consequences, and the improvements actually implemented in the workplace.
