A structured risk-assessment tool that identifies potential failure modes, their effects, and their causes, then ranks them (often by severity × occurrence × detectability) to prioritize controls. A common QRM technique.
FMEA works through a process or design step by step, asking at each one: how could this fail, what would happen if it did, and what would cause it? Each failure mode is then scored — commonly Severity of the effect, Occurrence of the cause, and Detection (the ability to catch it before harm) — and the product of the three gives a Risk Priority Number used to rank where controls are needed.
The RPN has well-known weaknesses that a good template mitigates. It is non-continuous, so many RPN values are unreachable and small score changes cause large jumps. Very different risks can share an identical RPN — a catastrophic-but-rare failure and a trivial-but-frequent one. And a single threshold invites gaming, where scores are quietly adjusted to fall below the action line. Practical mitigations: apply a severity override so high-severity modes are actioned regardless of RPN, look at criticality (Severity × Occurrence) alongside RPN, and use a risk matrix rather than a single number where it fits better.
Scoring is only as good as the anchors behind it. Every scale point needs a written definition agreed before scoring starts, or the numbers reflect who was in the room rather than the risk. ICH Q9(R1) is explicit that subjectivity in risk assessment cannot be eliminated — only managed, through diverse expertise, defined criteria, and transparency about uncertainty.
- —For each step: failure mode → effect → cause → existing controls → score → action.
- —RPN = Severity × Occurrence × Detection; criticality = Severity × Occurrence.
- —RPN is non-continuous and lets very different risks share a value — do not rely on it alone.
- —Apply a severity override: high-severity modes get action regardless of RPN.
- —Anchor every scale point in writing before scoring, or the numbers reflect the room.
- —Re-score residual risk after actions, and keep the assessment live.
ICH Q9(R1) Quality Risk Management lists FMEA/FMECA among the recognised tools; IEC 60812 is the reference standard for the technique; applied for devices alongside ISO 14971. FMEA is a method, not a regulatory requirement in itself.
Frequently asked questions
What does FMEA stand for?
FMEA stands for Failure Mode and Effects Analysis.
What is FMEA?
A structured risk-assessment tool that identifies potential failure modes, their effects, and their causes, then ranks them (often by severity × occurrence × detectability) to prioritize controls. A common QRM technique.
Which regulations cover FMEA?
ICH Q9(R1) Quality Risk Management lists FMEA/FMECA among the recognised tools; IEC 60812 is the reference standard for the technique; applied for devices alongside ISO 14971. FMEA is a method, not a regulatory requirement in itself.
SPEQ decodes published regulatory concepts in plain language. Definitions are a practitioner reference, not legal or regulatory advice.
Get the Weekly GxP Briefing
Curated regulatory intelligence — enforcement, recalls, guidance, and quality signals — in one practitioner-grade email each week. Free.