Asset criticality analysis: learn how to combine consequences, probability, redundancy, recovery, and risk to prioritize maintenance and engineering decisions.

Check it out!

Asset criticality analysis is the process of classifying assets, systems, or functions according to the potential impact of their failures on organizational objectives. It answers a practical question: where does a failure require greater prevention, monitoring, redundancy, spare parts, maintenance priority, or engineering investment?

Criticality is not synonymous with equipment price or failure frequency. A low-cost asset can be critical if its downtime interrupts an essential process, compromises safety, or leaves a facility without contingency. A high-value item may have lower operational criticality when effective redundancy, rapid replacement, or low systemic consequence exists.

ABNT NBR ISO 55000:2024 relates a critical asset to the potential for significant impact on organizational objectives. Classification therefore needs to reflect the real context: safety, continuity, production, environment, compliance, quality, reputation, cost, and recovery capability. A good classification does not end with an A, B, or C label: it needs to change decisions.

What Asset Criticality Analysis Really Measures

Criticality seeks to represent the relevance of a failure to organizational objectives. In many methods this involves combining consequence and probability, but the exact approach depends on the purpose of the analysis.

ISO 31000:2018 defines risk as the effect of uncertainty on objectives. ISO 55000:2024 reinforces the pursuit of value by balancing performance, risk, costs, and opportunities. When criticality is used in this context, it should not be an arbitrary score: it should help select treatments consistent with asset risk.

Some organizations classify criticality only by operational impact. Others incorporate safety, environment, quality, cost, reputation, legal requirements, and recovery time. Criteria need to be explicit and consistent with objectives. Copying a matrix from another sector without adaptation can produce results that are meaningless for the facility being analyzed.

A Critical Asset and a Critical Failure Mode Are Different Concepts

An asset may be classified as critical because one or more of its functions have significant consequences. This does not mean that all of its failure modes have the same criticality.

An electrical panel may be critical to continuity, while certain components or failure modes may be easy to detect and have low impact. Conversely, an apparently secondary subsystem may have a hidden failure mode that removes protection or redundancy and therefore deserves higher treatment.

Asset criticality is useful for portfolio screening and prioritization. FMEA and FMECA deepen the assessment at the function and failure-mode level. RCM uses consequences to select maintenance policies. The tools are complementary.

Flow from Criticality Analysis to Engineering Decision

Asset or system

Required function

Consequences

Probability

Existing controls

Recovery

Criticality class

Maintenance policy

Monitoring

Design and investment

Flow from Criticality Analysis to Engineering Decision

Consequence Should Be Assessed Before Scoring

The quality of a criticality assessment depends more on the definition of consequences than on the formula used. The team needs to understand what actually happens when the function is lost.

Safety consequences may involve personnel exposure, loss of protection, arc flash, fire, emergency-system failure, or an unsafe operating condition. Continuity consequences may involve total shutdown, loss of redundancy, reduced capacity, or unavailability of an essential service. Economic consequences may include lost production, mobilization, parts, contracts, and collateral damage.

There are also regulatory and documentary consequences. An asset may require inspection, testing, or records due to legal, normative, contractual, or institutional requirements. The absence of this evidence may represent risk even while the equipment is still operating.

Consequences need to be described using objective criteria. Expressions such as “high impact” without a definition make classification dependent on individual opinion.

How to Build Consistent Consequence Criteria

Each dimension needs a scale and examples. If safety uses five levels, the distinction between moderate and severe impact needs to be specified. If continuity uses hours of downtime, the analysis should consider whether contingency exists and whether the service is actually required throughout the entire period.

An economic criterion should avoid false precision. Defining monetary ranges can help, but values need to be compatible with the size and objectives of the organization. In large portfolios, well-described qualitative criteria often produce more reliable results than complex formulas fed by weak data.

Probability Is Not Just Failure History

History is an important source, but it is not the only one. New assets, recently deployed technologies, or systems that rarely fail may have few observations and still require assessment.

Probability may consider age, condition, environment, loading, obsolescence, installation quality, history of similar failures, degradation mechanisms, and existing controls. The method needs to make clear whether it is estimating historical frequency, future probability, or a qualitative trend class.

“It has not failed in recent years” is not sufficient evidence of low probability without checking condition and exposure. Protection systems and standby functions can remain in a latent failed state for long periods without an apparent event.

Redundancy Changes Criticality Only When It Is Effective

Redundancy can reduce consequence, but only when the channels are sufficiently independent. Two units supplied by the same panel, installed in the same environment, or dependent on the same controller may share common-cause failure modes.

The analysis needs to verify whether redundancy is active or standby, whether it has sufficient capacity, whether automatic transfer exists, whether transfer testing is performed, and whether a channel failure is detected. Nominal redundancy alone should not automatically reduce criticality.

Recovery time also needs to be considered. A system without redundancy may have limited consequence if repair is fast, the part is available, and a tested procedure exists. Another system may remain unavailable for weeks because of lead time, access constraints, or the need for specialized engineering.

Recovery Capability Should Be Part of the Analysis

Criticality is often treated as a relationship between probability and consequence, but recovery capability can significantly change actual exposure.

Diagnostic time, spare-parts availability, physical access, team competence, special tools, manufacturer involvement, permits, and logistics influence the downtime period. NBR 5462 distinguishes administrative, logistical, and technical delays, reinforcing that restoring function depends on much more than direct repair time.

When recovery is difficult, the organization may justify strategic inventory, a support contract, redundancy, or redesign. When recovery is simple and inexpensive, a corrective policy may be acceptable for low-consequence assets.

How to Combine Consequence, Probability, and Recovery

DimensionEngineering questionEffect on criticality
ConsequenceWhat happens if the function is lost?May raise the class regardless of estimated frequency when safety, environmental, or critical-continuity impacts are involved
ProbabilityHow often, or under what conditions, does the failure mode tend to occur?Distinguishes recurring risks from rare events, provided the data set is reliable
RedundancyIs an alternative path actually available?Can reduce operational consequence only when redundancy is functional, independent, and tested
RecoveryHow much time and which resources are required to restore the function?Raises criticality when parts, access, logistics, or competence constrain recovery
DetectionCan degradation be identified with useful lead time?Influences monitoring strategy and the ability to reduce risk before failure

There is no single universal formula. An organization may use a risk matrix, weighted scoring, cutoff rules, or a hybrid approach. The important point is to prevent mathematics from hiding the technical meaning.

A rule may establish that any intolerable safety impact remains highly critical regardless of estimated probability. Another may elevate assets with no redundancy and very long replacement times. Explicit rules are often more robust than mechanically multiplying numbers from ordinal scales.

Conceptual Relationship Between Consequence, Probability, and Criticality Treatment

High consequence

Relevant probability?

Low probability?

Highest priority

Enhanced controls

Low consequence

Relevant probability?

Low probability?

Reduce recurrence

Simplified policy

Review redundancy and recovery

Conceptual Relationship Between Consequence, Probability, and Criticality Treatment

ABC Criticality Classification Should Not Be Confused with ABC Cost Classification

A, B, and C classification is common because it simplifies governance, but it needs technical meaning. Class A may represent assets whose failure requires stricter controls; B, assets with intermediate impact; and C, assets with limited consequences and simplified response.

This classification is not the same as an ABC curve for inventory value or acquisition cost. An asset classified as C financially may be A operationally. Mixing these criteria leads to incorrect maintenance and supply decisions.

It is also advisable to limit the number of classes. Systems with eight or ten levels often create distinctions that the organization cannot operationalize. If two classes receive exactly the same treatment, they may not need to exist separately.

What Should Change for Each Criticality Class

Classification is useful only when it produces different policies. Higher-criticality assets may require more detailed asset records, FMEA/FMECA, controlled procedures, condition monitoring, functional testing, strategic spares, contingency plans, and higher approval levels for changes.

Intermediate assets may use preventive maintenance and inspections calibrated to risk. Low-consequence assets may operate with simple routines, scheduled replacement, or planned corrective maintenance, provided the failure does not create hidden risk.

Treatment needs to be proportional. Applying the same rigor across the entire portfolio wastes resources and reduces the ability to focus on what truly matters.

Criticality and the Maintenance Plan

The analysis should feed directly into the maintenance plan. Criticality influences policy, inspection frequency, procedure depth, competencies, intervention windows, and acceptance criteria.

Critical assets do not necessarily need more periodic maintenance. They need a more robust strategy. In some cases, this means condition monitoring and fewer intrusive interventions. In others, it means detective testing, redundancy, or redesign.

The purpose of the plan is to convert criticality into executable tasks and evidence. If the classification exists in a separate spreadsheet and does not change scheduling, it has lost its management purpose.

Criticality and Predictive Maintenance

Continuous monitoring consumes resources. Criticality helps determine where sensors, recurring thermography, vibration analysis, testing, or analytics generate the greatest return.

Critical assets with detectable degradation mechanisms are natural candidates for condition-based strategies. Lower-criticality assets may be monitored through simple periodic inspections. Data-collection intensity should reflect risk and the ability to act on the result.

This avoids the mistake of instrumenting every asset without defining decision criteria. Data without governance generate alarms, not necessarily reliability.

Criticality and Spare Parts

Inventory policy should consider failure consequence, replenishment time, and substitution options. A low-cost component with a lead time of months may justify stocking if its unavailability stops a critical system.

Conversely, holding expensive, low-criticality parts without evidence of need ties up capital. Criticality helps procurement and maintenance discuss the same risk using common criteria.

Obsolescence also needs to be included in the analysis. Assets that are still reliable may become critical because components, support, or specialized expertise are difficult to obtain.

Criticality and Upgrade Projects

Some conditions should not be addressed by increasing maintenance. When criticality results from a single point of failure, inadequate architecture, lack of selectivity, insufficient capacity, unsafe access, or structural obsolescence, the solution may require an engineering project.

Classification helps prioritize CAPEX. Instead of renewing assets based only on age, the organization prioritizes interventions that reduce significant risks and improve performance. In this context, criticality analysis can feed a Master Plan, renewal roadmap, redundancy studies, retrofit projects, and procurement specifications.

Criticality in Electrical Installations

Electrical installations require a system-level perspective. A transformer, main low-voltage switchboard, generator, UPS, protection device, busbar, or critical circuit needs to be assessed according to the function it supports and the available contingencies.

A substation may contain individually reliable equipment and still have high criticality because redundancy is lacking. A protection device may be critical despite rarely operating. A connection may have low replacement value and high consequence if its failure interrupts essential power.

The analysis should consider coordination, selectivity, autonomy, alternative sources, the possibility of maintenance without shutdown, intervention safety, and restoration time.

Criticality in Digital and Security Systems

In networks, automation, video surveillance, access control, and management systems, criticality may reside in logical services rather than only in equipment. Servers, databases, authentication, storage, power, synchronization, and connectivity can be systemic points of failure.

Classification needs to map dependencies. Two servers do not provide redundancy if they depend on the same storage, switch, or authentication domain. Distributed cameras may depend on a single VMS. Controllers may share power or backbone infrastructure.

The critical asset may be a function or service spanning multiple physical components.

How to Validate the Matrix with Operations

An analysis performed only by Engineering may miss field knowledge. Operations and maintenance teams know recurring failure modes, access difficulties, actual recovery times, and contingencies that may exist only in informal procedures.

Validation should bring together people who understand the system and its consequences. The objective is not to negotiate scores through political consensus, but to test whether the classification represents operational reality.

Disagreements are useful when they reveal different assumptions. If Engineering considers an asset redundant while Operations knows the standby channel is unavailable, the divergence points to an information gap that needs to be resolved.

How to Audit Classification Quality

A good matrix needs to be reproducible. Different people using the same criteria and information should reach similar results.

Signs of poor quality include excessive concentration of assets in the highest class, vague criteria, lack of justification, scores without evidence, assumed redundancy, and classifications that never change even after system modifications.

It is also useful to verify whether the class actually changes decisions. If every asset receives the same maintenance, inventory policy, and priority, the model is merely decorative.

When to Review Criticality

Criticality is not an immutable attribute. Process changes, load expansion, customer changes, new redundancy, obsolescence, significant failures, regulatory changes, or operational reorganization can alter consequences and probability.

Review should occur at defined intervals and after significant changes. Expansion and commissioning projects are appropriate points to update classification before incorporating new assets into the maintenance plan.

Changes in criticality also need to be traceable. The organization should know why a particular asset was reclassified and which policies changed as a result.

How to Connect Criticality with Asset Management

ABNT NBR ISO 55000:2024 positions asset management as a coordinated activity for realizing value from assets by balancing performance, risks, opportunities, and costs. Criticality is one of the tools that makes this balance operational.

It creates a common language among maintenance, Engineering, operations, supply, and management. Instead of each area defending priorities using its own criteria, the organization establishes a shared basis for deciding where to monitor, maintain, stock, and invest.

This is the point at which criticality stops being a maintenance exercise and becomes a lifecycle-management instrument.

When to Engage Engineering Support

Specialized support is useful when the portfolio is large, current criteria are inconsistent, multiple disciplines are involved, asset registers are incomplete, or the classification needs to support CAPEX and reliability decisions.

The work may combine asset-register surveys and cleansing, definition of criteria, workshops, risk analysis, classification, FMEA/FMECA of critical assets, maintenance-plan review, and development of an upgrade roadmap.

When the facility has physical or documentary deficiencies, the analysis can also direct inspections, testing, engineering projects, procurement, and oversight.

Final Considerations

Asset criticality analysis is a tool for focusing Engineering effort where failure can genuinely compromise objectives. Its value is not in the matrix itself, but in the decisions it changes.

A mature classification considers consequences, probability, controls, redundancy, and recovery capability. It distinguishes a critical asset from a critical failure mode and avoids confusing acquisition value with operational importance.

When integrated with the maintenance plan and asset management, criticality guides monitoring, spare parts, inspections, engineering projects, investments, and lifecycle governance. The final question is not only “what is the asset class?”, but “what will the organization do differently because of that class?”.

Technical references

[1] ASSOCIAÇÃO BRASILEIRA DE NORMAS TÉCNICAS. ABNT NBR ISO 55000:2024 — Asset management — Vocabulary, overview and principles. Rio de Janeiro: ABNT, 2024.

[2] INTERNATIONAL ORGANIZATION FOR STANDARDIZATION. ISO 55001:2024 — Asset management — Asset management system — Requirements. Geneva: ISO, 2024. Available at: https://www.iso.org/standard/83054.html

[3] INTERNATIONAL ORGANIZATION FOR STANDARDIZATION. ISO 31000:2018 — Risk management — Guidelines. Geneva: ISO, 2018. Available at: https://www.iso.org/standard/65694.html

[4] INTERNATIONAL ELECTROTECHNICAL COMMISSION. IEC 60812:2018 — Failure modes and effects analysis (FMEA and FMECA). Geneva: IEC, 2018. Available at: https://webstore.iec.ch/en/publication/26359

[5] ASSOCIAÇÃO BRASILEIRA DE NORMAS TÉCNICAS. ABNT NBR 5462:1994 — Reliability and maintainability — Terminology. Rio de Janeiro: ABNT, 1994.

Frequently asked questions
What is asset criticality analysis?

It is the process of classifying assets, systems, or functions according to the potential impact of their failures on organizational objectives, supporting decisions on maintenance, monitoring, inventory, redundancy, and investment.

Is criticality the same as risk?

Not necessarily. Criticality is a classification used to prioritize assets or failure modes. Risk is a broader concept related to the effect of uncertainty on objectives. Criticality may use risk elements such as consequence and probability.

Is an expensive asset always critical?

No. Acquisition value does not determine criticality. A low-cost asset may be critical if its failure interrupts an essential service, while an expensive asset may have lower impact when effective redundancy exists.

How does redundancy influence criticality?

Redundancy can reduce consequence when it is effective, independent, tested, and has sufficient capacity. Redundancies exposed to common-cause failures should not automatically reduce criticality.

What should be done with high-criticality assets?

The class should lead to proportional controls such as FMEA/FMECA, condition monitoring, testing, strategic spares, contingency planning, design review, and stronger change governance.

How often should criticality be reviewed?

At defined intervals and whenever significant changes affect function, consequence, probability, redundancy, condition, obsolescence, or recovery capability.

Related technical materials

Related services

Related solutions

Main content on this topic

Related technical content