“What if one could travel briefly into the future, identify a forthcoming error, return to the present before it occurs, and intervene to prevent it?”
That idea sits at the heart of risk analysis. To identify risks at the start and build on them as new ones emerge. In any manufacturing setup, small, unnoticed issues can quietly grow into serious consequences. In an industry like pharmaceutical manufacturing, that would mean patient safety. Risk analysis is therefore a fundamental part of every exercise in pharma, be it buying equipment, developing a new product or setting up its manufacturing process.
ICH Q9 lists many risk management tools. FMEA is one of them. Yet teams prefer it over others like HAZOP or HACCP, to name some. Its value lies in its simplicity and adaptability across design, manufacturing, maintenance, software, and quality systems, like a Swiss army knife.
What is FMEA?
Failure Mode and Effects Analysis (FMEA) is a systematic method for identifying potential failure modes, their causes, and their effects on a system, product, or process. It focuses on “what could go wrong” at the level of assets/components, process steps, or activities and evaluates how those failures impact safety, quality, and reliability.
Regulatory and standards frameworks (for example, ISO 14971 for medical devices or ICH Q9 principles in pharma) expect a structured, documented approach to risk management, and FMEA is a commonly accepted method to support these expectations.
Core Elements of FMEA
A typical FMEA analysis involves using a template, typically made using a spreadsheet. Key column headings in the spreadsheet are:
- Component/Step: Break the item you’re analysing into components, process steps, or functions
- Potential Failure mode: Define the risk and how the failure will happen.
- Effect of failure: The consequence of that failure on the next step, the system, the product, or the patient/user.
- Severity (S): How serious the effect of the failure is on the patient, product, process, or business (e.g., from minor inconvenience to critical safety impact)? Teams set up a scale in the spreadsheet, for example, 1–5, with each level defined to avoid confusion.
- Cause of failure: Underlying reasons, such as human error, equipment malfunction, design weakness, or inadequate procedure.
- Occurrence (O): The estimated frequency or likelihood that a particular cause will lead to the failure mode. Like the severity scale, teams set up a separate scale in the spreadsheet for occurrence
- Current controls: Preventive or detective measures already in place (alarms, SOPs, in‑process tests, automation, training, etc.).
- Detection (D): The likelihood that existing controls will detect the failure mode before it causes the effect. As with the severity and occurrence scales, teams set up one for detection, too.
- RPN Score: Teams either multiply the severity, occurrence, and detectability scores to give a single composite score (RPN=S×O×D), or use a traffic light matrix to identify the final risk score.
a. The first method involves setting up 3-level bands and converting the RPN composite score to a risk level,
| RPN Score Range | Risk level | What the team should do |
| 1-15 | Low | No immediate action needed |
| 16-60 | Medium | Plan corrective action |
| 60-125 | High | Risk is unacceptable. Assign owner. Escalate to design controls. |
b. The second method is where, for a certain severity score and occurrence score, you find the risk class (Low being green, yellow being medium and red being High). You then determine the risk level by comparing the detectability score against the risk class. Various versions of this method exist.


Teams can also carry out the same analysis qualitatively, as shown in the figure below.

Best Practices for Effective FMEA Usage
FMEA is not without flaws, but knowing its limitations and compensating for them is vital. In addition, the same simplicity that makes FMEA popular also creates weaknesses when organisations apply it mechanically, score it inconsistently, or treat it as a documentation exercise rather than a decision-making tool.
- Risk Template Setup
It is better to avoid the consolidated RPN Score approach as it masks fundamentally different risk profiles. For example, a failure mode with Severity 5, Occurrence 1, Detectability 5 has the same RPN as one with Severity 5, Occurrence 5, Detectability 1. Yet the first clearly represents a much higher potential impact.
In a traffic‑light matrix, the same issue may also happen. A Severity of 5 with Occurrence 1 can have the same risk class as Severity 1 and Occurrence 5. Knowing this piece of information allows the user to change the colour of the former to red and the latter to green.
- Subjective Scoring
A quantitative approach is difficult to work with. Different team members often interpret the same failure differently, leading to scores driven more by opinion than by harmonised criteria or historical evidence. As a result, the same process can receive very different risk ratings across departments, sites, or even separate meetings. A qualitative scale is easier to work with.
- Static Vs Live
People perform FMEA analysis, and people are fallible; the team will inevitably miss some risks. Teams must therefore link the FMEA to the QMS, feed every newly identified root cause back, and continuously update the analysis.
In addition, processes change, equipment ages, and new knowledge emerges over time. An outdated FMEA gives the appearance of control without reflecting the current reality.
- Scope of Analysis
Any risk analysis works best when the team defines its scope clearly. Carrying out, for example, risk analysis for an entire facility or a project does not provide focus on each component of the systems/functions that the project covers.
- Poor linkage to Actions
Risk analysis loses its purpose if teams don’t link it to design controls or procedural controls when the risk score is high. ISPE C&Q and PDA TR54 provide great examples of risk analysis.
conclusion
Ultimately, FMEA only adds value when it moves beyond numbers and colour codes to actual action taken due to high-risk scores. When teams use FMEA the right way—tightly linked to the QMS, kept current, and revisited as knowledge grows—it becomes far more than a form to complete; it becomes a practical way to ‘visit the future’ long enough to prevent today’s risks from becoming tomorrow’s deviations, recalls, or patient harm.
