Understand FMEA and FMECA in Maintenance Engineering: functions, failure modes, effects, causes, criticality, RPN, residual risk and Engineering actions.
Check it out!
FMEA and FMECA are structured methods for identifying how assets, systems, or processes may fail to fulfill their functions, understanding the effects of those failures, and defining treatment actions. In Maintenance Engineering, FMEA organizes functions, failure modes, effects, causes, and controls; FMECA adds an explicit criticality assessment to prioritize the risks that require intervention first.
The practical difference is significant. FMEA may be sufficient when the objective is to build a systematic view of failure modes and improve controls. FMECA becomes more important when the organization needs to distinguish which failures have the greatest impact on safety, continuity, production, the environment, quality, or cost and turn that distinction into an Engineering priority.
Neither method should be treated as an isolated scoring spreadsheet. Value emerges when the analysis connects required function, failure mechanism, field evidence, criticality, and decision-making: change the maintenance strategy, create condition-based inspection, review intervals, retain planned corrective maintenance, increase redundancy, change inventory, develop a remediation project, or renew the asset.
ABNT NBR 5462:1994 already distinguishes FMEA and FMECA within reliability and maintainability terminology. IEC 60812:2018 expands this treatment and describes how these analyses can be planned, performed, documented, and maintained across hardware, software, processes, and interfaces. In asset management, ABNT NBR ISO 55000:2024 reinforces the balance among performance, risk, and cost throughout the lifecycle.
FMEA and FMECA: what each method answers
FMEA — Failure Modes and Effects Analysis — starts from the principle that it is not enough to know the equipment by name. It is necessary to understand the function it must perform, how that function may fail, and which effects arise when this occurs. The focus is to decompose the failure logic before the event happens or before deciding how to treat it.
In NBR 5462 terminology, FMEA is a qualitative analysis of failure modes and their effects on subitems and on the required function. FMECA adds an assessment of occurrence probability and degree of criticality. IEC 60812:2018 follows the same logic but allows different prioritization methods and makes clear that criticality does not need to be reduced to a single number.
In both methods, the team seeks to understand how the item may fail, which effects arise locally and at system level, which causes or mechanisms are associated, and which controls already exist. The difference appears when the analysis needs to classify criticality explicitly. FMEA may include prioritization; in FMECA, criticality is a central part of the method.
The choice should not be dogmatic. In some projects, a detailed FMEA with prioritization criteria already meets the objective. In others, especially when there are many failure modes and very different consequences, FMECA better structures decision-making.
Starting from the function avoids superficial analyses
One of the most frequent mistakes is starting FMEA by listing parts and defects. This shifts the analysis to the component before clarifying what actually needs to be preserved. The required function must come first.
A pump may have the function of providing a given flow and pressure. A circuit breaker may have conduction, interruption, and protection functions within a specific architecture. A video surveillance system may need to capture, transmit, record, and make evidence available with a defined level of continuity. Failure does not simply mean “stop”; it may mean delivering insufficient performance, acting outside the required time, or partially losing a function.
When the function is poorly defined, failure modes become generic. Expressions such as “broken equipment,” “electrical problem,” or “motor defect” do not help determine maintenance. A failure mode needs to describe how the function ceases to be fulfilled: fails to start, does not deliver sufficient flow, does not open when commanded, operates inadvertently, loses communication, insulation degrades, overheats, or produces an incorrect measurement.
This discipline improves analysis quality because effects are evaluated against a concrete technical need. It also brings FMEA and FMECA closer to RCM, criticality analysis, and asset management.
Failure mode, effect, cause, and mechanism are not synonyms
Confusing these elements leads to incorrect actions. The failure mode describes how the function is lost. The effect describes what happens afterward. The cause indicates the circumstance that contributed to the failure. The mechanism describes the physical, chemical, logical, or human process that leads to the event.
Consider an electrical panel with abnormal heating at a connection. The failure mode may be the inability to conduct current within the intended thermal limits. The local effect may be temperature rise and insulation degradation. The system-level effect may be shutdown of a critical load. The cause may involve inadequate torque, contamination, sizing, or thermal cycling. The mechanism may be increased contact resistance and progressive heating.
The action changes according to the cause and mechanism. Indiscriminate retightening may not solve a sizing problem. Replacing a component may not eliminate an overload condition. FMEA needs to carry the investigation to a sufficient level for the treatment to be technically coherent.
How to turn FMEA into a maintenance tool
When failure modes, criticality, and actions are scattered among maintenance, operations, and projects, the organization loses traceability over why a given risk was accepted or treated. A structured analysis creates the technical basis for deciding priorities and investments.
In maintenance, FMEA is useful for structuring the reasoning before selecting tasks. For each relevant failure mode, the team asks whether there is a technically applicable way to prevent, detect, or reduce the consequence. This avoids creating plans based only on inherited intervals.
A gradual and detectable failure mode may justify condition monitoring. An age-related mode may justify periodic replacement. A hidden protective-function failure may require functional testing or a failure-finding task. A random low-consequence failure may be accepted as planned corrective maintenance. A recurring failure associated with a design deficiency may require redesign.
The method also helps review existing tasks. If a preventive task is not associated with a clear failure mode, does not produce useful evidence, or does not change probability or consequence, its justification needs to be reviewed.
This is an important point for Maintenance Engineering: FMEA is not intended to increase the amount of maintenance. It is intended to make maintenance policy technically justifiable.
When FMECA adds real value
FMECA is particularly useful when the number of failure modes grows and the organization needs to decide where to invest time, inspection, budget, and Engineering resources. It adds criticality to FMEA.
Criticality is not merely probability. An infrequent failure may be a priority if its consequence is severe. Likewise, a recurring low-impact failure may be economically relevant without being critical to safety or continuity.
The analysis may use qualitative methods, semi-quantitative matrices, or quantitative models. IEC 60812:2018 allows different prioritization methods, including criticality matrices and alternatives to RPN. The choice depends on available data, analysis purpose, and organizational maturity.
RPN should not be the only decision criterion
The Risk Priority Number, when used, typically combines severity, occurrence, and detection. It can be useful for ranking risks within a consistent methodology, but it has known limitations.
Very different combinations can produce the same number. In addition, multiplying ordinal scales gives an appearance of mathematical precision to an assessment that may be essentially qualitative. A failure with extreme severity may end up with an RPN similar to another much less severe failure because the other factors offset the value.
For this reason, criticality should preserve visibility of consequence. Escalation rules may determine, for example, that certain levels of safety, environmental impact, or critical unavailability require action regardless of the final RPN.
IEC 60812:2018 itself recognizes alternative prioritization approaches and does not restrict FMEA/FMECA to a single formula. For Engineering, this is healthy: the method should support decision-making, not replace technical judgment.
How to structure an FMEA/FMECA step by step
A robust analysis begins with preparation. The scope should specify the system, boundaries, purpose, level of decomposition, assumptions, operating conditions, and criticality criteria. Without this, different participants analyze different objects under the same title.
The work can follow an organized sequence:
- define the system, boundaries, and objective;
- identify functions and performance standards;
- identify technically plausible failure modes;
- describe local and system-level effects;
- identify relevant causes and mechanisms;
- record existing controls;
- assess criticality according to the defined method;
- establish actions, owners, and deadlines;
- reassess residual risk after treatment;
- update the analysis when design, operation, or evidence changes.
Each step should produce traceable information. The objective is not to fill as many rows as possible, but to capture failure modes that influence decisions.
Criticality criteria should arise from the asset context
A criticality matrix copied from another organization may generate incorrect priorities. The criteria need to represent the objectives and consequences relevant to the analyzed context.
In critical infrastructure, availability and continuity may dominate. In industrial processes, production losses, quality, and safety may carry greater weight. In building facilities, safety, compliance, continuity of essential services, and cost may be central. In protective systems, hidden failures need differentiated treatment.
ABNT NBR ISO 55000:2024 defines a critical asset as one capable of significantly impacting organizational objectives. This definition is more useful than classifying criticality solely by equipment replacement price.
An inexpensive asset may be critical if its failure interrupts the entire process. An expensive redundant asset may have lower immediate operational consequence. Criticality should therefore be assessed by its effect on objectives, not by purchase value alone.
How to relate FMECA to asset criticality analysis
FMECA and asset criticality analysis are not identical. Criticality analysis may classify assets or systems at a higher level using aggregated consequences and probabilities. FMECA deepens the reasoning at the failure-mode level.
An efficient architecture uses both levels. First, the organization identifies which assets or systems deserve greater attention. Then it applies FMEA/FMECA where analytical depth creates value. This avoids performing detailed FMECA on thousands of assets without priority differentiation.
This hierarchy also improves scalability. Critical-class assets may receive detailed studies, greater monitoring, and redundancy requirements. Lower-criticality assets may operate with simplified policies.
Field data improve the analysis over time
The first FMEA is rarely perfect. It combines design knowledge, history, manuals, operating experience, and expert judgment. Over time, actual failures, inspections, and maintenance work orders make it possible to validate or challenge assumptions.
NBR 5462 emphasizes that observed data should record relevant conditions and criteria. This is essential for FMEA/FMECA. A failure mode recorded without context may appear more or less frequent than it actually is.
Useful data include operating regime, operating hours, loading, environmental condition, confirmed failure mode, restoration time, parts used, determined cause, operational effect, and action performed. The quality of these records directly influences the quality of future prioritization.
How to use FMEA/FMECA in electrical installations
In electrical installations, FMEA and FMECA help structure problems that should not be treated merely as “electrical failures.” Power supply, protection, sectionalization, grounding, control, supervision, and redundancy have their own functions.
A transformer may lose capacity due to thermal or dielectric degradation. A circuit breaker may fail to open, fail to close, or operate inadvertently. A protection system may be unavailable without operations noticing immediately. A connection may progressively degrade and produce heating before functional failure.
Each mode requires different treatment. Some are detectable through thermography, testing, or monitoring. Others require periodic functional testing. Some call for review of coordination and selectivity. Others reveal design deficiencies, obsolescence, or the need for remediation.
FMECA makes the consequence of each mode explicit and helps prioritize inspections, tests, shutdowns, and projects.
How to use FMEA/FMECA in automation, telecom, and electronic security systems
Digital and communication systems also have relevant functional failure modes: loss of power, network unavailability, storage failure, loss of synchronization, authentication failure, communication degradation, server unavailability, configuration error, or loss of redundancy.
In these systems, failure is not always physical. Software, configuration, and human interaction fall within the scope of IEC 60812:2018. This allows the analysis to cover interfaces among hardware, software, procedures, and operators.
In critical architectures, FMECA may reveal single points of failure that do not appear when each equipment item is analyzed in isolation. System-level consequence is, again, more important than the price of each component.
FMEA/FMECA in design and Design Review
If FMECA reveals recurring systemic failures, lack of redundancy, or design limitations, increasing maintenance frequency rarely solves the cause. The finding needs to be converted into a requirement, engineering design, and remediation plan.
Using FMEA only after implementation loses part of its potential. During design, it can identify failure modes before decisions become expensive to correct.
During Design Review, the team can assess critical functions, interfaces, redundancy, maintenance accessibility, common-cause failure modes, protection, alarms, test points, and isolation capability. A design change can reduce risk more structurally than any later maintenance task.
This use brings FMEA closer to Reliability by Design. Failure treatment stops being merely operational and begins to influence Engineering requirements.
How to convert results into an action plan
A risk matrix only creates value when actions reach the maintenance plan, asset register, procurement, and projects. Governance should track owners, evidence, residual criticality, and study updates.
An FMEA/FMECA without an action plan becomes passive documentation. Every risk that requires treatment needs to generate a concrete and traceable output.
Actions may be of different types:
- review of maintenance tasks and intervals;
- implementation of condition monitoring;
- creation of a functional test or failure-finding task;
- improvement of procedures and acceptance criteria;
- change to spare-parts inventory;
- training or operational change;
- review of protection, redundancy, or architecture;
- remediation, retrofit, or replacement project.
Separating these categories helps route each problem to the correct process. A design failure should not remain open indefinitely as a maintenance work order. A documentation deficiency needs to generate an As-Built or asset-register update. A supply vulnerability may require an inventory or procurement strategy.
Residual criticality should be reassessed after the action
Completing an action does not mean the risk has disappeared. The actual effect of the treatment needs to be verified.
If a sensor was installed, does it detect the failure mechanism with sufficient lead time? If redundancy was added, does it eliminate the single point of failure or share power and environment with the primary channel? If the interval was reduced, does the task actually control the failure mode?
Reassessing residual criticality prevents actions from being closed merely because they were performed. The outcome needs to be technically demonstrable.
FMEA/FMECA governance and updating
The analysis should have an owner, version, date, and review criteria. Design changes, operating-regime changes, unforeseen failures, new data, and obsolescence may require updates.
An old FMEA may continue to exist formally while being technically obsolete. The document needs to follow the asset lifecycle.
Asset management reinforces this principle. ABNT NBR ISO 55000:2024 treats documented information, performance, risk, knowledge, and continual improvement as elements related to realizing value from assets. FMEA and FMECA fit well within this system when used as living decision-making instruments.
When to engage specialized support
Engineering support makes sense when the system has high criticality, multidisciplinary interfaces, incomplete documentation, recurring failures, divergence between design and field conditions, or a need to turn the analysis into an investment plan.
In such situations, the work may involve asset surveys, document analysis, inspections, criticality review, FMEA/FMECA, failure analysis, definition of action plans, remediation design, technical specifications, procurement, and implementation follow-up.
The objective is to prevent the analysis from ending as an isolated matrix. The final product should support decisions on maintenance, reliability, risk, and lifecycle.
Final considerations
FMEA and FMECA are most valuable when they stop being treated as forms and begin to structure Engineering reasoning. FMEA structures functions, failure modes, effects, causes, and controls. FMECA adds criticality to prioritize where consequences require greater attention.
In Maintenance Engineering, the methods help select coherent policies for each failure mode and separate maintenance problems from design, operations, documentation, or supply problems. In Asset Management, they connect risk and performance to lifecycle decisions.
The quality criterion is simple: a good analysis should allow another team to understand why a given risk was considered relevant, which treatment was selected, what evidence supports the decision, and how residual risk will be verified.
Technical references
[1] BRAZILIAN ASSOCIATION OF TECHNICAL STANDARDS. ABNT NBR 5462:1994 — Reliability and maintainability — Terminology. Rio de Janeiro: ABNT, 1994.
[2] INTERNATIONAL ELECTROTECHNICAL COMMISSION. IEC 60812:2018 — Failure modes and effects analysis (FMEA and FMECA). Geneva: IEC, 2018. Available at: [IEC 60812:2018](https://webstore.iec.ch/en/publication/26359).
[3] BRAZILIAN ASSOCIATION OF TECHNICAL STANDARDS. ABNT NBR ISO 55000:2024 — Asset management — Vocabulary, overview, and principles. Rio de Janeiro: ABNT, 2024.
[4] INTERNATIONAL ORGANIZATION FOR STANDARDIZATION. ISO 55001:2024 — Asset management — Asset management system — Requirements. Geneva: ISO, 2024. Available at: [ISO 55001:2024](https://www.iso.org/standard/83054.html).
[5] INTERNATIONAL ELECTROTECHNICAL COMMISSION. IEC 60300-3-10:2025 — Dependability management — Part 3-10: Application guide — Maintainability and maintenance. Geneva: IEC, 2025. Available at: [IEC 60300-3-10:2025](https://webstore.iec.ch/en/publication/65334).
Frequently asked questions
FMEA identifies functions, failure modes, effects, causes, and controls. FMECA adds an explicit criticality assessment, allowing failure modes to be prioritized according to consequence, probability, or other defined criteria.
No. FMECA requires a criticality assessment, but that assessment may use qualitative methods, semi-quantitative matrices, or quantitative approaches. RPN is only one possible form of prioritization and should not hide severe consequences.
Yes. It helps relate failure modes to maintenance policies such as preventive maintenance, condition monitoring, failure-finding tasks, planned corrective maintenance, or redesign.
When there are many failure modes, very different consequences, or a need to prioritize maintenance, inspection, design, and investment resources based on criticality.
No. FMEA is predominantly proactive and analyzes potential failure modes. Root-cause analysis investigates events that have already occurred to determine causes and mechanisms. The two approaches complement each other.
The team should combine design, operations, maintenance, safety, and process knowledge. Additional specialists may participate when specific failure modes require specialized expertise.
Additional technical resources
Related services
Related solutions
- Requirements, Evidence, and Acceptance Criteria Management
- Field Applications, Inspection, and Technical Data Collection
Core content on the topic
- FMEA in Engineering: how to analyze failure modes, effects, and causes
- FMECA: how to analyze failure modes, effects, and criticality
