Understand asset criticality analysis: consequence, probability, redundancy, recovery, maintenance strategy, spares, projects and lifecycle decisions.
Check it out!
Asset criticality analysis is the process of classifying assets, systems, or functions according to the potential impact of their failures on organizational objectives. It answers a practical question: where does a failure require greater prevention, monitoring, redundancy, spares, maintenance priority, or Engineering investment?
Criticality is not synonymous with equipment price or failure frequency. An inexpensive asset may be critical if its unavailability interrupts an essential process, compromises safety, or leaves a facility without contingency. High-value equipment may have lower operational criticality when effective redundancy, rapid replacement, or low system-level consequence exists.
ABNT NBR ISO 55000:2024 defines a critical asset as one with the potential to significantly impact the achievement of organizational objectives. This definition connects criticality to performance, risk, and value. The analysis therefore needs to reflect the real context: safety, continuity, production, environment, compliance, quality, reputation, cost, and recovery capability.
A good classification does not end with an A, B, or C. It needs to change decisions. More critical assets may receive deeper FMEA/FMECA, condition monitoring, testing, redundancy, spare-parts requirements, and contingency plans. Less critical assets may operate with simpler and economically proportionate strategies.
What asset criticality analysis actually measures
Criticality seeks to represent the relevance of a failure to organizational objectives. In many methods, this involves combining consequence and probability, but the exact form depends on the purpose of the analysis.
ISO 31000:2018 defines risk as the effect of uncertainty on objectives. ABNT NBR ISO 55000:2024 adopts a compatible concept and reinforces that asset management seeks value by balancing performance, risk, costs, and opportunities. When criticality is used in this context, it should not be an arbitrary score: it should help select treatments that are coherent with the asset’s risk.
Some organizations classify criticality only by operational impact. Others include safety, environment, quality, cost, image, legal requirements, and recovery time. Both approaches can be valid if the criteria are explicit and coherent with the objectives.
The error begins when the matrix is copied from another sector without adaptation. The same numerical values may mean completely different things in a hospital, data center, industrial facility, public building, or power plant.
Critical asset and critical failure mode are different concepts
An asset may be classified as critical because one or more of its functions have significant consequences. This does not mean that all of its failure modes have the same criticality.
An electrical panel may be critical to continuity, but certain components or failure modes may be easy to detect and have low impact. Conversely, an apparently secondary subsystem may have a hidden failure mode that eliminates protection or redundancy and therefore deserves elevated treatment.
This distinction guides the depth of analysis. Asset criticality is useful for portfolio screening and prioritization. FMEA and FMECA deepen the assessment at the function and failure-mode level. RCM uses consequences to select maintenance policies. The tools complement each other.
Consequence should be assessed before scoring
The quality of a criticality assessment depends more on how consequences are defined than on the formula used. The team needs to understand what actually happens when the function is lost.
Safety consequences may involve exposure of people, loss of protection, arc flash, fire, emergency-system failure, or an unsafe operating condition. Continuity consequences may involve total shutdown, loss of redundancy, capacity reduction, or unavailability of an essential service. Economic consequences may include lost production, mobilization, parts, contracts, and collateral damage.
There are also regulatory and documentation consequences. An asset may require inspection, testing, or records due to legal, normative, contractual, or institutional requirements. The absence of this evidence may represent risk even when the equipment is still operating.
Consequences need to be described using objective criteria. Expressions such as “high impact” without a definition make the classification dependent on individual opinion.
How to build coherent consequence criteria
Each dimension needs a scale and examples. If safety uses five levels, it is necessary to specify what distinguishes a moderate impact from a severe one. If continuity uses hours of unavailability, the analysis should consider whether contingency exists and whether the service is actually required throughout the entire period.
An economic criterion needs to avoid false precision. Defining monetary bands can help, but values should be compatible with the size and objectives of the organization. A loss considered high for one unit may be irrelevant for another.
In large portfolios, well-described qualitative criteria often produce more reliable results than complex formulas fed by weak data. Model sophistication should match the quality of the available information.
Probability is not just failure history
History is an important source, but it is not the only one. New assets, newly implemented technologies, or systems that rarely fail may have few observations and still require assessment.
Probability may consider age, condition, environment, loading, obsolescence, installation quality, history of similar failures, degradation mechanisms, and existing controls. The method needs to make clear whether it is estimating historical frequency, future probability, or a qualitative tendency class.
A common mistake is to use “it has not failed in recent years” as evidence of low probability without checking condition and exposure. Protective systems and standby functions may remain in a latent failed state for long periods without an apparent event. Absence of occurrence is not proof of availability.
Redundancy changes criticality only when it is effective
Redundancy can reduce consequence, but only if the channels are sufficiently independent. Two units fed from the same panel, installed in the same environment, or dependent on the same controller may share common-cause failure modes.
The analysis needs to ask whether redundancy is active or standby, whether it has sufficient capacity, whether automatic transfer exists, whether switching tests are performed, and whether a channel failure is detected. Nominal redundancy alone should not automatically reduce criticality.
Recovery time also needs to be considered. A system without redundancy may have limited consequence if repair is fast, the part is available, and a tested procedure exists. Another system may remain unavailable for weeks due to lead time, access, or the need for specialized engineering.
Recovery capability should be included in the analysis
Criticality is often treated as a relationship between probability and consequence, but recovery capability can significantly change actual exposure.
Diagnostic time, spare-parts availability, physical access, team competence, special tools, manufacturer support, permits, and logistics influence the period of unavailability. NBR 5462 distinguishes administrative, logistical, and technical delays within the maintenance context, showing that restoring function depends on much more than direct repair time.
When recovery is difficult, the organization may justify strategic inventory, support contracts, redundancy, or redesign. When recovery is simple and inexpensive, a corrective policy may be acceptable for low-consequence assets.
How to combine consequence, probability, and recovery
| Dimension | Engineering question | Effect on criticality |
|---|---|---|
| Consequence | What happens if the function is lost? | May raise the class regardless of estimated frequency when safety, environment, or critical continuity is involved |
| Probability | How often or under what conditions is the failure mode likely to occur? | Distinguishes recurring risks from rare events, provided the data base is reliable |
| Redundancy | Is an alternative path truly available? | Can reduce operational consequence only when redundancy is functional, independent, and tested |
| Recovery | How much time and which resources are required to restore the function? | Raises criticality when parts, access, logistics, or competence limit recovery |
| Detection | Can degradation be identified with useful lead time? | Influences monitoring strategy and the ability to reduce risk before failure |
There is no single universal formula. An organization may use a risk matrix, weighted scoring, cut-off rules, or a hybrid approach. The important point is to prevent mathematics from hiding the technical meaning.
A rule may establish that any intolerable safety impact remains high criticality regardless of estimated probability. Another may elevate assets without redundancy and with very long replacement lead times. These explicit rules are often more robust than multiplying numbers from ordinal scales without reflection.
The following diagram is conceptual and does not represent actual facility data. It shows that consequence and probability should lead to different treatments, always modulated by redundancy and recovery capability.
ABC criticality classification should not be confused with ABC cost classification
A, B, and C classification is common because it facilitates governance, but it needs technical meaning. Class A may represent assets whose failure requires more rigorous controls; B, assets with intermediate impact; C, assets with limited consequence and a simplified response.
This classification is not the same as an ABC curve of inventory value or acquisition cost. An asset that is financially C may be operationally A. Mixing these criteria produces incorrect maintenance and supply decisions.
It is also advisable to limit the number of classes. Systems with eight or ten levels often create distinctions that the organization cannot operationalize. If two classes receive exactly the same treatment, they may not need to exist separately.
What should change for each criticality class
When criticality exists only in a spreadsheet and does not change maintenance, inspection, inventory, or investment, it is not functioning as a decision tool. Value appears when each class has treatment and governance proportionate to risk.
Classification is only useful when it produces distinct policies. For higher-criticality assets, greater asset-register detail, FMEA/FMECA, controlled procedures, condition monitoring, functional testing, strategic spares, contingency plans, and higher approval levels for changes may be required.
Intermediate assets may use preventive maintenance and inspections calibrated to risk. Low-consequence assets may operate with simple routines, scheduled replacement, or planned corrective maintenance, provided failure does not create hidden risk.
Treatment needs to be proportionate. Applying the same rigor to the entire portfolio wastes resources and reduces the capacity to care for what truly matters.
Criticality and the maintenance plan
The analysis should feed the maintenance plan directly. Criticality influences policy, inspection frequency, procedure depth, competencies, intervention window, and acceptance criteria.
Critical assets do not necessarily need more periodic maintenance. What they need is a more robust strategy. In some cases, this means condition monitoring and fewer disassemblies. In others, failure-finding tests, redundancy, or redesign.
The role of the plan is to transform criticality into executable tasks and evidence. If classification exists in a separate spreadsheet and does not change scheduling, it has lost its management function.
Criticality and predictive maintenance
Continuous monitoring consumes resources. Criticality helps determine where sensors, recurring thermography, vibration analysis, testing, or analytics generate greater returns.
Critical assets with detectable degradation mechanisms are natural candidates for condition-based strategies. Lower-criticality assets may be monitored through simple periodic inspections. Data-collection intensity should reflect risk and the ability to act on the result.
This avoids the mistake of instrumenting every asset without defining decision criteria. Ungoverned data generate alarms, not necessarily reliability.
Criticality and spares
Inventory policy should consider failure consequence, replenishment time, and substitution possibilities. An inexpensive component with a months-long lead time may justify inventory if its unavailability stops a critical system.
On the other hand, holding expensive low-criticality parts without evidence of need ties up capital. Criticality helps procurement and maintenance discuss the same risk using common criteria.
Obsolescence also needs to be included in this analysis. Assets that are still reliable may become critical because of difficulty obtaining components, support, or specialized knowledge.
Criticality and remediation projects
Single points of failure, merely nominal redundancy, and long recovery times often require more than maintenance. Criticality can reveal where design, retrofit, or renewal strategy is necessary.
Some conditions should not be treated by increasing maintenance. When criticality stems from a single point of failure, inadequate architecture, lack of selectivity, insufficient capacity, unsafe access, or structural obsolescence, the solution may be an engineering project.
Classification helps prioritize CAPEX. Instead of renewing assets solely by age, the organization prioritizes interventions that reduce relevant risks and improve performance.
In this context, criticality analysis can feed a Master Plan, renewal roadmap, redundancy studies, retrofit, and procurement specifications.
Criticality in electrical installations
Electrical installations require a system-level view. A transformer, main LV switchboard, generator, UPS, protection system, busbar, or critical circuit needs to be assessed by the function it supports and the contingencies available.
A substation may have individually reliable equipment and still have high criticality due to lack of redundancy. A protection device may be critical despite rarely operating. A connection may have low replacement value and high consequence if its failure interrupts essential power.
The analysis should consider coordination, selectivity, autonomy, alternative sources, the possibility of maintenance without shutdown, intervention safety, and restoration time.
Criticality in digital and security systems
In networks, automation, video surveillance, access control, and management systems, criticality may lie in logical services rather than only equipment. Servers, databases, authentication, storage, power, synchronization, and connectivity may be system-level failure points.
Classification needs to map dependencies. Two servers do not represent redundancy if they depend on the same storage, switch, or authentication domain. Distributed cameras may depend on a single VMS. Controllers may share power or backbone.
The critical asset may be a function or service spanning several physical components.
How to validate the matrix with operations
An analysis performed only by Engineering may miss field knowledge. Operations and maintenance know recurring failure modes, access difficulties, actual recovery times, and contingencies that exist only in informal procedures.
Validation should bring together people who know the system and its consequences. The objective is not to negotiate scores through political consensus, but to test whether the classification represents operational reality.
Disagreements are useful when they reveal different assumptions. If Engineering considers an asset redundant and Operations knows the standby channel is unavailable, the divergence identifies an information gap that needs to be resolved.
How to audit classification quality
A reliable classification depends on the asset register, condition, history, and field evidence. When these data are weak, the analysis itself should identify which surveys, inspections, and tests are needed before priorities are consolidated.
A good matrix needs to be reproducible. Different people using the same criteria and information should arrive at similar results.
Signs of poor quality include excessive concentration of assets in the highest class, vague criteria, lack of justification, scores without evidence, assumed redundancy, and classifications that never change even after system modifications.
It is also useful to verify whether the class actually changes decisions. If everyone receives the same maintenance, inventory, and priority, the model is decorative.
When to review criticality
Criticality is not an immutable attribute. Process changes, load expansion, customer changes, new redundancy, obsolescence, relevant failures, regulatory changes, or operational reorganization may change consequences and probability.
Review should occur in defined cycles and after significant changes. Expansion projects and commissioning are appropriate times to update classification before incorporating new assets into the maintenance plan.
Changes in criticality also need to be traceable. The organization should know why a given asset was reclassified and which policies changed as a result.
How to connect criticality to asset management
ABNT NBR ISO 55000:2024 positions asset management as coordinated activity to realize value from assets by balancing performance, risks, opportunities, and costs. Criticality is one of the tools that makes this balance operational.
It creates a common language among maintenance, Engineering, operations, supply, and management. Instead of each area defending priorities using its own criteria, the organization establishes a shared basis for deciding where to monitor, where to maintain, where to stock, and where to invest.
This is the point at which criticality stops being merely a maintenance exercise and becomes a lifecycle-management instrument.
When to engage Engineering support
Specialized support is useful when the portfolio is large, current criteria are inconsistent, multiple disciplines exist, the asset register is incomplete, or the classification needs to support CAPEX and reliability decisions.
The work may combine asset surveys and register cleansing, definition of criteria, workshops, risk analysis, classification, FMEA/FMECA of critical assets, maintenance-plan review, and development of a remediation roadmap.
When the facility has physical or documentation deficiencies, the analysis can also direct inspections, testing, engineering projects, procurement, and oversight.
Final considerations
Asset criticality analysis is a tool for concentrating Engineering effort where failure can truly compromise objectives. Its value is not in the matrix itself, but in the decisions it changes.
A mature classification considers consequences, probability, controls, redundancy, and recovery capability. It distinguishes a critical asset from a critical failure mode and avoids confusing acquisition value with operational importance.
When integrated into the maintenance plan and asset management, criticality guides monitoring, spares, inspections, projects, investments, and lifecycle governance. The final question is not merely “what is the asset’s class?” but “what will the organization do differently because of that class?”
Technical references
[1] BRAZILIAN ASSOCIATION OF TECHNICAL STANDARDS. ABNT NBR ISO 55000:2024 — Asset management — Vocabulary, overview, and principles. Rio de Janeiro: ABNT, 2024.
[2] INTERNATIONAL ORGANIZATION FOR STANDARDIZATION. ISO 55001:2024 — Asset management — Asset management system — Requirements. Geneva: ISO, 2024. Available at: [ISO 55001:2024](https://www.iso.org/standard/83054.html).
[3] INTERNATIONAL ORGANIZATION FOR STANDARDIZATION. ISO 31000:2018 — Risk management — Guidelines. Geneva: ISO, 2018. Available at: [ISO 31000:2018](https://www.iso.org/standard/65694.html).
[4] INTERNATIONAL ELECTROTECHNICAL COMMISSION. IEC 60812:2018 — Failure modes and effects analysis (FMEA and FMECA). Geneva: IEC, 2018. Available at: [IEC 60812:2018](https://webstore.iec.ch/en/publication/26359).
[5] BRAZILIAN ASSOCIATION OF TECHNICAL STANDARDS. ABNT NBR 5462:1994 — Reliability and maintainability — Terminology. Rio de Janeiro: ABNT, 1994.
Frequently asked questions
It is the process of classifying assets, systems, or functions according to the potential impact of their failures on organizational objectives, supporting decisions on maintenance, monitoring, inventory, redundancy, and investment.
Not necessarily. Criticality is a classification used to prioritize assets or failure modes. Risk is a broader concept related to the effect of uncertainty on objectives. Criticality may use risk elements such as consequence and probability.
No. Acquisition value does not determine criticality. An inexpensive asset may be critical if its failure interrupts an essential service, while an expensive asset may have lower impact when effective redundancy exists.
Redundancy can reduce consequence when it is effective, independent, tested, and has sufficient capacity. Redundancy with common-cause failure should not automatically reduce criticality.
The class should lead to proportionate controls such as FMEA/FMECA, condition monitoring, testing, strategic spares, contingency, design review, and stronger change governance.
At defined intervals and whenever relevant changes alter function, consequence, probability, redundancy, condition, obsolescence, or recovery capability.
Additional technical resources
Related services
Related solutions
- Requirements, Evidence, and Acceptance Criteria Management
- Field Applications, Inspection, and Technical Data Collection
Core content on the topic
- FMEA and FMECA in Maintenance Engineering
- FMECA: how to analyze failure modes, effects, and criticality
