
Introduction
Your team finishes FMEA training, feels confident, and still hands in a worksheet that gets kicked back by the auditor. Sound familiar?
It's one of the most common frustrations in quality departments:
- Engineers rebuild templates from scratch every time
- Severity and occurrence scales shift depending on who fills out the form
- RPN math errors slip through because nobody double-checks the multiplication
The result: worksheets that look thorough but still miss the failure modes that reach the customer.
This guide covers what auditors and registrars actually expect from an FMEA. You'll get the three FMEA types and when to use each, the standard template columns, a step-by-step worksheet process, and how to weigh RPN against the newer AIAG-VDA approach.
Key Takeaways
- Score each failure mode on Severity, Occurrence, and Detection to produce a Risk Priority Number (RPN)
- Pick the right type for the job: System, Design (DFMEA), or Process (PFMEA)—PFMEA is most common in manufacturing
- Keep a fixed column structure so every engineer and facility completes the worksheet the same way
- Update the worksheet as processes change so it stays audit-ready over time
What Is FMEA and When Do You Need Each Type?
Failure Mode and Effects Analysis is a proactive risk-analysis technique: identify how something could fail, understand the consequences, and act before that failure reaches a customer or end user.
The method traces back to the U.S. military, formalized in MIL-STD-1629A in 1980 after a 1949 predecessor procedure (DoD ASSIST documentation). Aerospace and automotive teams later expanded it into the versions most quality groups use today.
There are three main types, and picking the right one matters just as much as filling it out correctly.
System FMEA
Used for complete systems or sub-systems, usually at concept or early design. Focus is on how components interact—not individual part design or manufacturing steps.
Run a System FMEA when:
- You're defining a new system architecture
- Sub-systems must work together under shared requirements
- You need failure paths visible before detailed design locks in
Design FMEA (DFMEA)
DFMEA analyzes a product design before it goes to manufacturing. Trigger a DFMEA when:
- You're introducing a brand-new design
- An existing design is changing
- A design is being reused in a new operating environment or application
Process FMEA (PFMEA)
PFMEA looks at manufacturing and assembly steps rather than the product design. It is the most common of the three types and usually the simplest to run.
Trigger a PFMEA when:
- You're standing up or changing a production or assembly process
- A process moves to a new line, site, or supplier
- Recurring defects point to process variation rather than design

FMEA Template Format: Key Columns Explained
Every FMEA worksheet, regardless of type, follows a recognizable column structure. Registrars know this structure cold, and they check it first for traceability.
Header and Identification Fields
Before anything else, an auditor looks at the top of the page:
- Item or process name
- FMEA number
- Team members involved
- Prepared-by date
- Revision or key date
Missing or stale header fields are an easy red flag. If the revision date doesn't match a known process change, the auditor's next question is obvious.
Function, Failure Mode, Effects, and Severity
Each row starts with a function or process step, then lists a potential failure mode and its potential effects. Every effect gets a Severity (S) rating on a 1–10 scale, where 1 means insignificant and 10 means catastrophic.
Causes, Controls, and the O/D Ratings
Next comes the potential cause of the failure, paired with an Occurrence (O) rating. This scores likelihood or frequency, not impact.
Then come current process controls (prevention and detection), paired with a Detection (D) rating. Weak controls—or ones that rely only on an SOP with no verification—should score higher on Detection. A higher D means the control is less likely to catch the problem.
RPN: A Worked Example
Multiply the three ratings together: RPN = S × O × D. Here's a simple manufacturing defect scenario:
| Failure Mode | S | O | D | RPN |
|---|---|---|---|---|
| Undersized weld on bracket | 8 | 3 | 4 | 96 |
That 96 shows where this item sits relative to others on the same worksheet. The raw number alone isn't the whole story; ranking and action thresholds matter more than any single score.
Closed-Loop Action Columns
The final block is what separates a real FMEA from a static risk chart:
- Recommended actions
- Responsibility and due date
- Actions taken
- New RPN after the action is implemented
This block turns an assessment into a corrective action tracker. Auditors usually scrutinize it hardest: a blank "actions taken" column next to a high RPN is an easy nonconformity to write.
How to Fill Out an FMEA/PFMEA Worksheet: Step-by-Step
Follow this sequence whether you're running a DFMEA or a PFMEA. The steps stay the same; only the subject matter changes.
Assemble a cross-functional team and define scope. Decide up front whether you're analyzing design functions (DFMEA) or process steps (PFMEA). Pull in design, quality, manufacturing, and, where relevant, supplier representatives.
List key steps or functions and brainstorm failure modes. Treat each failure mode as an "anti-function": total failure, partial failure, or intermittent failure of that step or function.
Identify effects and assign Severity ratings. Any failure mode scoring 9 or 10 on Severity requires action without exception, regardless of what the Occurrence or Detection scores turn out to be.
Identify root causes and assign Occurrence ratings. Base the score on historical failure data where you have it, or a reasonable estimate where you don't.
Document detection controls and assign Detection ratings. Be honest about the difference between a control that prevents a failure and one that merely detects it after the fact.
Calculate RPN, sort by priority, assign owners, implement actions, then re-score. Re-score Occurrence and Detection only (not Severity) to confirm the action actually reduced risk.

Understanding RPN and Prioritizing Corrective Actions
The RPN formula is straightforward: Severity × Occurrence × Detection. With three 1–10 scales, the math ranges anywhere from 1 to 1,000. The trap is treating that single number as gospel.
Consider a worked comparison from HBK's risk priority number analysis:
| Item | S | O | D | RPN |
|---|---|---|---|---|
| A (safety-related) | 10 | 4 | 2 | 80 |
| B (non-safety) | 7 | 4 | 4 | 112 |
Item B has the higher RPN. But Item A carries a Severity of 10, a safety or regulatory concern, and deserves priority attention even with the lower total. Don't sort your worksheet by RPN alone.
Why Severity Should Drive Priority
Severity is usually the hardest rating to engineer down. You often can't redesign away the consequence of a failure—only how often it happens or how likely you are to catch it first.
Most corrective effort should target Occurrence and Detection. Flag any Severity of 9–10 for review regardless of the RPN math.
RPN vs. AIAG-VDA Action Priority
Some industries have moved away from a single RPN number entirely. The 2019 AIAG & VDA FMEA Handbook replaced RPN with an Action Priority (AP) table. It ranks items High, Medium, or Low from the S-O-D combination, evaluated Severity first, then Occurrence, then Detection.
Whether you use RPN or AP usually depends on what your customer or contract specifies. Check that requirement before you lock either method into your template.
Common FMEA Mistakes — and How to Build In-House Capability to Avoid Them
Most FMEA problems aren't technical. They're procedural habits that compound over time.
- Treating the FMEA as a one-time document. It gets filed after the initial review and never revisited, even as the design or process changes underneath it.
- Letting S-O-D scales drift between engineers or facilities. One engineer's "6" is another's "8." Auditors flag this inconsistency as an objective evidence gap because risk scoring isn't repeatable.
- Junior engineers not knowing which tool to reach for. A nonconformity comes in, and nobody's sure whether it needs a full FMEA, a quick 5-Why, or a formal CAPA. Everything escalates to the one senior quality manager who can make that call.
That last problem is a bottleneck, and it's the gap QMS Learning's AI Workbench and Method Router were built to close. A team member describes the compliance problem in plain language; the Method Router diagnoses it and selects the right methodology, FMEA included, rather than defaulting every issue to the most senior person on site.
Once FMEA is the right call, the Workbench generates a draft artifact that feeds into the platform's audit-evidence package. Evidence compiles in minutes instead of getting rebuilt from scratch every audit cycle. That capability sits in the Commercial Aviation training pathway alongside 8D, 5-Why, and CAPA effectiveness verification.

Frequently Asked Questions
What are the steps of FMEA and PFMEA?
Both follow the same core sequence: define scope, list failure modes, score Severity, Occurrence, and Detection, calculate RPN, act, then re-score. PFMEA simply applies that sequence to process steps rather than design functions.
What is the FMEA template format?
A standard worksheet includes item or function, failure mode, effects, Severity, causes, Occurrence, controls, Detection, RPN, and a closed-loop action section with owner, due date, and revised score.
Is FMEA a Lean Six Sigma tool?
Yes. It's commonly applied during the Analyze and Improve phases of DMAIC and appears in Green Belt and Black Belt curricula, though exact phase placement varies by certifying body.
What is a good RPN score in FMEA?
There's no universal "good" number. No standards body publishes one. Set your own organizational threshold, but act on any high-severity item regardless of where the total RPN lands.
What's the difference between DFMEA and PFMEA?
DFMEA analyzes product or design functions before production begins. PFMEA analyzes manufacturing and assembly process steps when the design moves to the shop floor.
How often should an FMEA be updated?
Revisit it whenever the design, process, or controls change, and re-score after every corrective action. An FMEA filed away after one use stops protecting anyone.


