FindRisk Logo
FMEA Risk Assessment for Safety: Scales and a Worked Example
All articles
FMEArisk assessmentrisk priority numberRPNprocess safetyFine-Kinney

FMEA Risk Assessment for Safety: Scales and a Worked Example

September 25, 202620 min readFindRisk Team

FMEA (Failure Mode and Effects Analysis) is a structured, step-by-step method for finding the ways a process, machine or task can fail, what each failure would do to people, and which failures to fix first. For safety work, each failure mode is scored for severity, occurrence and detection, and the scores guide which controls get priority before anyone is hurt.

FMEA was built for reliability engineering, so most guides you find talk about customer complaints and warranty costs. Safety teams in manufacturing use it anyway, because it does something a hazard list does not: it forces you to walk through a process step by step and ask "how can this step go wrong?" before you ask "how bad would it be?"

This guide adapts FMEA for occupational health and safety. You will get severity, occurrence and detection scales written for injuries and ill health, a complete worked FMEA of a stamping press line with before-and-after scores, the one flaw in the risk priority number that can hide an amputation hazard, and a decision table for choosing between FMEA and Fine-Kinney.


Two Press Line Risks With the Same Score

Picture a metal stamping plant (a fictional example). The safety team scores two failure modes on the press line.

The first is a light curtain on a mechanical press that stops working without anyone noticing. If an operator reaches into the die area, the likely outcome is an amputation. The team scores it severity 10, occurrence 2, detection 6: an RPN of 120.

The second is hydraulic oil leaking onto the walkway beside the press. Someone could slip and sprain a wrist. The team scores it severity 4, occurrence 6, detection 5: also an RPN of 120.

Same number, very different risk. If the plan says "fix everything above 150 first," neither row moves. If the plan says "fix the top five," the oil leak could get the budget before the light curtain. The rest of this guide shows how to score FMEA properly for safety and how to stop this from happening.


What Is FMEA?

FMEA is a proactive analysis technique that breaks a system or process into parts or steps, lists the ways each one can fail (the failure modes), describes the effect of each failure, and ranks them so the most important ones are addressed first. According to the University of Cambridge Institute for Manufacturing, it originated in the US military in the late 1940s as a reliability tool, was adopted in aerospace during the Apollo program in the 1960s and by the automotive industry in the 1970s.

The US Centers for Medicare & Medicaid Services FMEA guidance puts the key distinction simply: FMEA addresses failures before an adverse event occurs, while root cause analysis addresses problems after they occur.

Term Meaning in a safety FMEA
Item or process step The task, machine function or step you analyze (for example "operator loads blank into die")
Failure mode How that step can go wrong ("guard interlock bypassed", "wrong die clamp torque")
Effect What happens to people if it fails (injury, ill health, exposure)
Cause Why the failure happens (worn part, missing procedure, time pressure)
Current controls What is already in place to prevent or detect it
Severity (S) How bad the effect is
Occurrence (O) How often the failure or cause is expected
Detection (D) How likely current controls are to catch the failure before it harms someone
RPN Risk priority number, S × O × D

The current international standard is IEC 60812:2018 (edition 3.0), published by the IEC in August 2018. It covers FMEA and its variant FMECA (failure modes, effects and criticality analysis) and includes alternative ways of calculating the RPN as well as a criticality matrix method. In the automotive sector, the AIAG & VDA FMEA Handbook (June 2019) is the reference; it replaced RPN with a table-based "Action Priority", covered below.

FMEA also has a regulatory foothold in process safety. OSHA's Process Safety Management standard, 29 CFR 1910.119(e)(2), lists FMEA alongside What-If, Checklist, HAZOP and Fault Tree Analysis as an acceptable process hazard analysis methodology.


When Should You Use FMEA for Safety?

Use FMEA when the hazard comes from how a process, machine or system can fail, and when you can break the work into clear steps or components. It is strongest in these situations:

  • Machinery and production lines, where guards, interlocks, sensors and hydraulic or pneumatic systems can each fail in specific ways.
  • New or changed processes, before they start. CMS notes that FMEA is a good technique for making processes safer before full implementation.
  • Maintenance and changeover tasks, such as die changes, filter replacements or line clearing, where energy isolation and sequencing matter. Pair it with your lockout/tagout procedure.
  • Safety-critical equipment, where you need to know which component failure defeats a safeguard.

FMEA is a poor fit for broad workplace surveys (a whole warehouse, a whole office) or for risks driven mainly by exposure duration, such as ergonomics. For those, a general risk assessment method or a task-based job safety analysis usually works better. For continuous chemical processes, HAZOP with its guide words is the more common tool.


How to Run an FMEA Risk Assessment in 7 Steps

An FMEA for safety follows seven practical steps. The sequence below is adapted for OHS from the CMS guidance and the seven-step structure of the AIAG & VDA handbook (planning, structure, function, failure analysis, risk analysis, optimization, documentation).

FMEA worksheet flow for safety: process step, failure mode, effect scored for severity, cause scored for occurrence, current controls scored for detection, RPN = S × O × D, severity override check, action and re-score

1. Define the scope

Pick one process, one line or one machine. CMS advises narrowing the scope as far as possible and splitting complex processes into several FMEAs. "The press line, from coil loading to finished pallet" is a workable scope. "The plant" is not.

2. Build the team

Include the people who do the work on every shift, plus maintenance, the supervisor and the safety professional. CMS stresses that knowledge of "what actually happens, not what should happen" is what makes the analysis accurate. In Turkey, Article 6 of the OHS Risk Assessment Regulation (2012) requires the risk assessment team to include the employer or their representative, the OHS specialist, the workplace physician, an employee representative, support staff and employees who know the hazards of each unit.

3. Map the process steps

Draw the process as a simple flowchart: coil loading, press operation, scrap removal, die change, palletizing. Agree on the steps before you look for failures. If the team cannot agree on how the job is done, CMS points out that the process itself is unreliable and should be standardized first.

4. List failure modes, effects and causes

For each step, ask how it can fail, what that does to a person and why it happens. Write one failure mode per row. Include health effects, such as noise or fumes, as well as injuries. OHS researchers such as Birgören and Yalçınkaya (2019) note that occupational health risks are often left out of FMEA work.

5. Score severity, occurrence and detection

Use the scales in the next section. Score the current situation with the controls that exist today, not the ones you plan to add.

6. Prioritize and act

Calculate RPN = S × O × D, sort the rows, and apply a severity override (explained below) so no high-severity row is left behind. Choose controls using the hierarchy of controls: CMS rates forcing functions and physical changes as stronger actions, and warnings, new procedures and training as weaker ones.

7. Re-score and document

Once the actions are in place, score each row again and record who did what and when. Then check in practice how often the failure still occurs. An FMEA is finished when the residual scores are verified, not when the spreadsheet is full.


Severity, Occurrence and Detection Scales for OHS

Standard FMEA scales describe customer and product impact. For safety you need scales written in terms of harm to people. The table below is our example adaptation on a 1–10 scale. Calibrate it for your site, write it down and use the same version for every FMEA so scores stay comparable.

Score Severity (S): worst credible harm Occurrence (O): how often the failure or cause happens Detection (D): chance current controls catch it before harm
10 Fatality or multiple fatalities Continuously or on almost every shift No detection; failure is invisible until someone is hurt
9 Permanent disability (amputation, blindness) Several times a week Only detectable by chance
8 Serious injury with long-term effects; occupational disease About once a week Detected only by infrequent audits
7 Serious injury, hospital admission About once a month Detected by periodic inspection (monthly or longer)
6 Lost-time injury over 3 days; noticeable health effect Several times a year Detected by a weekly check
5 Lost-time injury up to 3 days About once a year Detected by a pre-shift check that depends on the user
4 Medical treatment, no lost time Once every few years Detected by a documented daily check with sign-off
3 First aid only Has happened in the industry, not here Detected automatically, but only alarms
2 Discomfort, no treatment needed Very unlikely with current design Detected automatically and the machine stops
1 No credible harm Practically impossible Failure cannot occur undetected (fail-safe design)

Three rules keep these scales honest:

  1. Score severity on the credible outcome, not the unlikely worst case. A cut finger from a burr is not a "fatality" row. If the credible outcome of a press guard failure is amputation, score 9 or 10 even if it has never happened on your site.
  2. Detection is about the failure, not the injury. A light curtain that fails and stays failed until the next weekly test has poor detection, even if the operator would "notice" once injured.
  3. Occurrence comes from data when you have it. Use maintenance logs, near-miss reports and inspection findings. Without data, CMS suggests asking the team to estimate from experience, ideally with managers out of the room so people speak freely.

Worked Example: FMEA of a Stamping Press Line

The example below is fictional but typical: a mechanical press line with coil loading, stamping, scrap removal, die changes and forklift pickup. The team scored seven failure modes with the current controls, then again after agreed actions.

Before actions

# Step Failure mode Effect S O D RPN Rank
1 Die change Energy not isolated; ram drifts during die change Crush or amputation 10 4 6 240 2
2 Press operation Light curtain fails and stays failed Hand amputation 10 2 6 120 6
3 Press operation Press noise above exposure limit, no enclosure Noise-induced hearing loss 6 8 7 336 1
4 Coil loading Coil band cut without restraint; band springs back Laceration, eye injury 7 4 5 140 3
5 Palletizing Forklift and pedestrian share the aisle Struck-by, serious injury 9 3 5 135 4
6 Scrap removal Scrap cleared from chute by hand Deep cuts 5 7 3 105 7
7 Press operation Hydraulic oil leak on walkway Slip, sprain 4 6 5 120 5

Look at rows 2 and 7. The light curtain failure, with a credible outcome of amputation, has the same RPN as the oil leak and ranks below it once ties are broken by occurrence. This is the RPN trap from the opening scenario, on a real worksheet.

Actions chosen

# Action (hierarchy level) Owner Due
1 Written LOTO procedure with lock points per press, ram blocks during die change, trained authorized persons (engineering + administrative) Maintenance lead 30 days
2 Replace with a safety-rated, monitored light curtain; add a daily function test with sign-off (engineering + administrative) Maintenance lead 14 days
3 Acoustic enclosure around the press; noise survey and audiometric testing; hearing protection as interim control (engineering + administrative + PPE) Plant manager 90 days
4 Band cutter with guarded blade and coil restraint; defined standing position (engineering + administrative) Production supervisor 30 days
5 Physical barriers separating the pedestrian walkway from the forklift aisle (engineering) Plant manager 60 days
6 Scrap conveyor from chute to bin (elimination of the manual task) Engineering 60 days
7 Fix the leaking fitting; add a drip tray and include it in the weekly check Maintenance 7 days

After actions

# Failure mode S O D RPN before RPN after
1 Energy not isolated during die change 10 2 3 240 60
2 Light curtain fails 10 2 2 120 40
3 Noise above exposure limit 6 3 3 336 54
4 Coil band springs back 7 2 3 140 42
5 Forklift-pedestrian contact 9 2 3 135 54
6 Hand in scrap chute 5 1 2 105 10
7 Oil on walkway 4 2 4 120 32

Three points about this worksheet:

  • Severity rarely changes. An amputation is still an amputation. Only elimination (row 6, where the manual task disappears) or a real change in the hazard reduces what can happen. Most controls reduce occurrence or improve detection.
  • Detection improvements are cheap but weaker. Row 2 improved mostly through a better device and a daily test. That is fine as long as the daily test actually happens, so check it during inspections.
  • The residual RPNs are not "safe" by themselves. Rows 1, 2 and 5 still have severity 9–10. They stay on the watch list, and their controls get verified in every audit.

The RPN Trap and How to Avoid It

The risk priority number multiplies three ordinal scores, so very different risks can produce the same number. A 10 × 2 × 6 amputation hazard and a 4 × 6 × 5 slip hazard both give 120. RPN values run from 1 to 1,000, but many numbers in that range are impossible to produce, and the steps between them are not equal.

This is why the AIAG & VDA FMEA Handbook (June 2019) replaced RPN with Action Priority (AP): a reference table across severity, occurrence and detection that assigns a high, medium or low need for action, with severity weighted first (Quality Digest summary). IEC 60812:2018 also offers a criticality matrix as an alternative to RPN.

For safety FMEAs, the simplest fix is a written severity override. Our recommendation:

Rule What it means
S ≥ 9 Action required regardless of RPN. Aim for engineering controls or elimination.
S = 7–8 and O ≥ 4 Action required regardless of RPN.
Otherwise Rank by RPN, and set your own action threshold in the procedure

There is no universal "acceptable RPN" in any standard. Published thresholds vary widely, so pick yours, justify it in your procedure and apply it consistently.


FMEA vs Fine-Kinney: Which Should You Use?

FMEA and Fine-Kinney both multiply three scores, but they answer different questions. Fine-Kinney (R = P × F × C: probability, frequency of exposure and consequence) scores a hazard as it exists. FMEA scores how a step or component fails and whether you would catch it. The Fine-Kinney method guide covers its scales in detail.

Question FMEA Fine-Kinney
Unit of analysis Failure mode of a step or component Hazard in an activity or area
Third factor Detection of the failure Frequency of exposure
Scale Usually 1–10 each, RPN 1–1,000 Fixed non-linear values (for example C up to 100)
Best for Machines, lines, changeovers, new processes Whole-workplace assessments, mixed activities
Effort High: step-by-step team workshop Moderate
Output Prioritized failure list with owners and re-scores Risk classes with action timelines
Weak spot RPN can hide high-severity rows Does not ask how controls might fail

Many sites use both: Fine-Kinney for the workplace-wide risk assessment, and FMEA for the few machines or processes where the question is "what if this safeguard fails?"


Common FMEA Mistakes in Safety Work

1. Copying product FMEA scales

Quality scales rate customer annoyance and scrap cost. Used for safety, they compress everything from a bruise to a fatality into the top two scores. Use harm-based scales like the ones above.

2. Scoring the ideal process, not the real one

If the team scores the procedure as written, the FMEA misses the workarounds. Invite operators from every shift and ask what really happens during breakdowns and rush orders.

3. Ranking only by RPN

Without a severity override, a frequent minor hazard can outrank a rare fatal one. Write the override rule into the procedure before the first workshop.

4. Treating detection as a substitute for prevention

Adding an inspection lowers D and the RPN, but the failure still happens. Prefer actions that lower occurrence or remove the failure mode, and use detection as a second line.

5. Leaving out health risks

Noise, dust, fumes and vibration fail slowly and silently, so they often get skipped. In the example above, noise was the highest RPN on the line.

6. Never re-scoring

An FMEA with "planned actions" and no after-scores is a wish list. Re-score after implementation and check effectiveness in the field, the way you would close any corrective action.


How FindRisk Supports Risk Assessment

An FMEA workshop depends on good field evidence: what the guard looks like today, where the leak is, how close the walkway runs to the forklift aisle. With FindRisk you can take photos on the line, mark the hazards directly on the image and let the AI analyze the photo to suggest hazards you may have missed. Those observations feed the failure-mode list before the workshop starts.

For the workplace-wide assessment that sits alongside your FMEA, FindRisk supports Fine-Kinney risk assessment and can generate an AI inspection checklist for the press line, so the daily and weekly checks that your FMEA relies on for detection scores get done and recorded. Reports are produced in seconds, and the app runs on iOS and Android.


Frequently Asked Questions

What is a good RPN score in FMEA?

There is no universal good or acceptable RPN. Standards such as IEC 60812 do not set one, and published thresholds vary widely. Each organization should define its own action threshold in writing and combine it with a severity rule, so that any failure mode with a severity of 9 or 10 gets action regardless of its RPN.

Can FMEA be used for occupational health and safety risk assessment?

Yes. FMEA works well for safety when the hazard comes from how a machine, process or safeguard can fail, such as guards, interlocks, energy isolation and changeovers. OSHA's Process Safety Management standard lists FMEA as an acceptable process hazard analysis method. Adapt the severity scale to injuries and ill health rather than product defects.

What is the difference between FMEA and HAZOP?

FMEA works component by component or step by step and asks how each can fail. HAZOP works node by node through a process and applies guide words such as "more", "less" and "no" to process parameters like flow, pressure and temperature. HAZOP suits continuous chemical processes; FMEA suits machines, assembly lines and discrete tasks.

What is the difference between FMEA and FMECA?

FMECA (failure modes, effects and criticality analysis) is FMEA with an added criticality step that ranks failure modes by combining severity and probability, often in a criticality matrix. IEC 60812:2018 covers both methods. In practice, a safety FMEA with a severity override already behaves much like a simple FMECA.

Has Action Priority replaced RPN?

In the automotive industry, yes. The AIAG & VDA FMEA Handbook published in June 2019 replaced RPN with Action Priority, a lookup table that gives each combination of severity, occurrence and detection a high, medium or low need for action. Outside automotive, RPN is still widely used, ideally with a severity override rule.

How often should an FMEA be reviewed?

Review an FMEA whenever the process, equipment, materials or layout changes, after any incident or near miss involving the analyzed process, and on a fixed cycle. For processes under OSHA PSM, the process hazard analysis must be revalidated at least every five years. In Turkey, the workplace risk assessment renewal periods are 2, 4 or 6 years depending on the hazard class.


Conclusion

FMEA gives safety teams a disciplined way to ask how each step and safeguard can fail before someone gets hurt. Its strength is the step-by-step walk through a real process with the people who run it. Its weakness is the risk priority number, which can hide a fatal failure mode behind a comfortable score.

Use harm-based scales, score the process as it really runs, add a severity override, and re-score after every action. Use FMEA for the machines and processes where safeguard failure is the question, and keep Fine-Kinney or your usual method for the wider workplace assessment.

Download FindRisk to capture hazards on the line with photos, run Fine-Kinney assessments alongside your FMEA and turn your findings into a professional report in seconds.

Try FindRisk

Ready to modernize your safety workflow?

Conduct AI-powered risk assessments, generate reports instantly, and keep your team safe — anywhere, anytime.