FMECA is failure modes, effects and criticality analysis. It retains the FMEA structure of functions, failure modes, effects, causes and controls, then adds an explicit criticality assessment to support engineering decisions. In industrial maintenance, its value does not come from adding another spreadsheet column. It comes from distinguishing what can be monitored, what requires a recurring task, what calls for a design change, and what must receive treatment without waiting for a numerical ranking.
The public scope of IEC 60812:2018 describes FMECA as the variant in which criticality classification includes at least consequence severity and often other measures of importance. The standard covers different prioritization approaches. Therefore, no single scale, matrix or equation is the universal definition of FMECA.
What is the difference between FMEA and FMECA?
The PM Run FMEA guide in Portuguese explains how a function may fail, how effects propagate through system levels, which causes are plausible and which controls exist. FMECA preserves that analysis and adds a declared method for assessing criticality.
| Question | FMEA | FMECA |
|---|---|---|
| Starting point | Function, functional failure and failure mode | The same starting point |
| Core output | Effects, causes, controls and actions | The same elements plus a criticality assessment |
| Prioritization | May use severity, RPN, Action Priority or another adopted criterion | Uses a criticality classification defined for the analyzed context |
| Decision supported | Reduce or control failure modes | Focus analysis and resources on modes whose consequence and importance require treatment |
FMECA is not automatically better than FMEA. If an organization already has clear triggers for safety, compliance and operational consequence, and a well-run FMEA supports the required decisions, adding a poorly defined classification only creates false precision. FMECA is useful when modes must be compared consistently within a defined scope and when that comparison changes a decision.
What does criticality mean in FMECA?
Criticality is an assessment of how important a failure mode is to the objective of the study. Its calculation or classification depends on the selected method, the available evidence and the nature of the system. Some applications use qualitative consequence and likelihood classes. Others use risk matrices, categories, or quantitative models involving failure rate, the fraction attributed to a mode and exposure time.
None of these approaches permits a team to import a scale without its definitions. A class called high is comparable only across modes evaluated with the same boundaries, time horizon, consequence definitions and decision rules. The team should document:
- consequences considered: people, environment, compliance, production, quality, property and recovery;
- time horizon: mission, campaign, test interval, operating year or another coherent period;
- occurrence basis: local history, a comparable population, manufacturer data or identified engineering judgment;
- combination rule: matrix, class, criticality number or another approved logic;
- independent triggers: severe conditions that require action even when they do not occupy the highest relative rank.
Failure-mode criticality is also different from asset criticality. An asset matrix helps determine the governance, analysis depth and attention given to equipment. FMECA examines specific modes within that context. A class A asset may contain low-consequence modes, while a less critical asset may contain a mode that matters for safety or compliance.
How to structure an FMECA for maintenance
- Define the decision. State whether the study will review design, maintenance strategy, spares, protective-function testing, inspection plans or operational readiness.
- Set system boundaries and conditions. Record interfaces, operating states, standby conditions, redundancies, utilities and assumptions.
- Describe functions and performance standards. Pumping is incomplete without flow, pressure, fluid and response-time requirements.
- Identify failure modes. Connect every mode to a function and do not combine effect, cause and defect in one field.
- Develop the effects. Record local, subsystem and process effects, considering detection, protection, redundancy and recovery.
- Record causes and existing controls. Separate prevention, detection, protection and contingency. An alarm does not prevent degradation.
- Apply the criticality criterion. Use only the categories and rules approved for the study, with evidence and rationale.
- Select treatment. The response may involve design, an operating change, condition monitoring, a functional test, scheduled work, a spare or documented acceptance.
- Reassess residual risk. Verify the implemented control before lowering a classification and preserve the prior version.
NASA GSFC-HDBK-8004 treats FMECA as a living document that is updated when design, materials, operating parameters, processes or knowledge change. This principle is directly applicable to industry. A spreadsheet frozen at commissioning loses validity when the plant changes product, load, logic, components or operating policy.
Worked example: reactor cooling-water system
This example is educational and does not describe a real installation. The system must deliver at least 180 m³/h of cooling water at 3.5 bar to a reactor header. Two centrifugal pumps, P-101A and P-101B, operate in a one-duty, one-standby arrangement. They share a tank, suction piping and a filter. The standby pump should start automatically when header pressure falls.
The team defines a hypothetical internal matrix solely for the example. Consequence classes are C1, recoverable local effect; C2, limited operational loss; C3, significant production or barrier loss; and C4, severe safety, environmental or process-integrity consequence. Likelihood bands range from L1, remote under the studied conditions, to L4, recurring. A real plant would have to define boundaries, evidence and accepted combinations in its own method. These classes are neither IEC requirements nor universal recommendations.
The decision rule is also declared before evaluating modes: every C4 mode is high criticality regardless of likelihood; C3 combined with L2 or higher is also high; C2 with L3 is moderate. A condition with insufficient data remains pending rather than receiving a convenient class. Another operation may use different boundaries if it defines them before scoring.
| Failure mode | Effect and current controls | Educational assessment | Decision |
|---|---|---|---|
| Common suction filter functionally blocked | Reduces available NPSH to both pumps and may cause cavitation and loss of header pressure. Local pressure gauges exist, but there is no differential trend or alarm. | C4 and L2. High criticality because a common element defeats redundancy and operating warning is limited. | Add differential measurement with a defined limit and response, review filter capacity and arrangement, and use condition-based inspection until the engineering solution is complete. |
| Duty-pump bearing degradation | Rising vibration may stop the pump. The standby unit can take over if it is available. A monthly vibration route exists, without a criterion tied to reaction time. | C2 and L3. Moderate in the present context, conditional on demonstrated standby availability. | Review route frequency and limits using observed behavior, correct the lubrication cause if confirmed, and record standby condition. |
| Standby discharge check valve stuck closed | The standby pump may start without delivering flow. A test that confirms only that the motor runs leaves the failure hidden. | C3 and L2. High because redundancy is removed without clear evidence during normal operation. | Replace the motor-start check with a functional test of the complete chain, including pressure or flow confirmation, and review the component if history supports it. |
| Loss of containment at the duty-pump seal | Local leakage and possible shutdown. Consequence depends on contamination, drainage, access and isolation capability. Visual inspection exists. | Pending. Assigning C2 or C3 before characterizing product, exposure and barriers would be guesswork. | Establish the actual consequence, dominant mechanism, seal plan and response before closing criticality and task selection. |
How criticality changed the decision
Bearing degradation has the higher likelihood, but it does not automatically come first. The common filter can disable both pumps, and the stuck check valve makes redundancy nominal rather than effective. FMECA moves the discussion from which item fails most often to which mode threatens the required function and which controls truly reduce consequence.
The seal mode remains unclassified. That is a technically valid result. The evidence gap becomes an action with ownership and a due date instead of being hidden by a score selected in a meeting.
When to combine FMECA with FTA, RCA and RCM
FMECA moves forward from items and failure modes to their effects. When a severe event depends on combinations, common-cause conditions or redundant paths, fault tree analysis starts with the undesired event and works backward through the combinations that can produce it. The methods meet, but they are not interchangeable.
Root cause analysis investigates an event that occurred and tests why it happened. Confirmed learning should update FMECA modes, causes, controls and criticality. The RCM guide in Portuguese covers the broader decision about maintenance policy, functions, functional failures, consequences and task applicability. In practice, FMECA provides a structured basis while RCM tests which policy and task are technically applicable and effective.
From engineering decisions to plans and SAP PM work orders
FMECA is complete when actions have been implemented and verified, not when a spreadsheet cell has been colored. Each decision needs the correct route:
- design change: engineering change control, documentation, installation and commissioning;
- recurring task: after approval, the appropriate SAP PM task list, strategy or maintenance plan;
- hidden-function test: a test of the complete chain with an acceptance criterion, not merely proof that an order exists;
- condition monitoring: a parameter, technique, limit, frequency, owner and response time;
- field discovery: a traceable notification, measurement, as-found condition and follow-up action.
Engineering remains responsible for strategy, method and interval, using the appropriate SAP PM objects. Once approved work generates orders, maintenance planning must load resources, sequence and release work, manage constraints and close the evidence loop.
PM Run operates in this planning and execution layer over SAP PM. Planning organizes orders and resources. Mobility delivers work to the field and returns operation-level confirmations, technical notes, images, PDFs and measurements when applicable. This traceability gives the next FMECA review better as-found and execution evidence without assigning the criticality decision to software.
How to keep FMECA technically useful
- Version the boundary, configuration, assumptions and criteria.
- Separate initial risk, recommended action, completed action and residual risk.
- Do not lower criticality because an action has only been promised.
- Record the source and quality of occurrence data.
- Reopen the analysis after a relevant failure, operating change, modification or field discovery.
- Use reliability engineering to test whether tasks remain effective.
Technical references
- IEC 60812:2018, official public scope for FMEA and FMECA.
- NASA GSFC-HDBK-8004, a public FMECA and risk-assessment guide that treats the analysis as a living document.
- NASA Reliability-Centered Maintenance Guide, a public reference for connecting modes and consequences to maintenance policies and tasks.
Frequently asked questions
What does FMECA stand for?
FMECA stands for Failure Modes, Effects and Criticality Analysis. It adds an explicit criticality assessment to the failure-mode and effects structure of FMEA.
Are FMEA and FMECA the same?
Not exactly. Every FMECA contains failure-mode and effects analysis, but it also includes a criticality classification defined for the study. An FMEA may prioritize actions through other criteria without being presented as FMECA.
Is there a universal criticality equation?
No. Qualitative, matrix-based and quantitative methods exist. The organization must declare consequence definitions, horizon, evidence and the combination rule. Results obtained with different methods should not be compared directly.
Does FMECA replace an asset criticality matrix?
No. An asset matrix classifies equipment or systems according to their role in the operation. FMECA evaluates specific failure modes. They support different units of analysis.
Does FMECA automatically define the preventive plan?
No. It identifies risk and treatment needs. Engineering must still determine whether a time-based, condition-based or failure-finding task, a design change, or another policy is applicable and effective.
How does FMECA connect to SAP PM?
After engineering approval, recurring tasks can be structured in SAP PM task lists, strategies and maintenance plans. Generated orders are scheduled and executed, and their as-found and confirmation history informs future analysis updates.
If the challenge is turning approved tasks into traceable execution, see how PM Run connects planning and mobility to SAP PM. Engineering continues to own the method, criticality criteria and maintenance strategy.
