Bottom-up failure mode, effects and criticality analysis to IEC 60812 · component by component, effect by effect.
FMEA starts where HAZOP does not · at the component. For each item we ask how it can fail, what each failure mode does to the function above it, how it would be detected, and what that combination justifies spending to prevent.
They run in opposite directions, and that is the whole point. A HAZOP is top-down and process-driven · it starts from a deviation in a process parameter and works back to causes. An FMEA is bottom-up and hardware-driven · it starts from a specific component, enumerates every way that component can fail, and works forward to the effect on the assembly, the system and the plant.
The consequence is that each catches what the other structurally cannot. A HAZOP asks what happens on low flow and accepts a pump trip as one cause. An FMEA asks how the pump fails · seal, bearing, coupling, driver, controller, each with its own failure rate, its own detection method and its own effect. Failure modes that produce no process deviation at all, such as a redundant element that has silently failed and will not be there when demanded, are invisible to a HAZOP and are precisely what FMEA is built to surface.
Criticality analysis is what turns the register into a decision. Without it, an FMEA lists a few hundred failure modes with no basis for choosing between them.
IEC 60812 methodology · component-level analysis with criticality ranking · deliverables independently reviewed and signed by a Chartered Engineer. Routes to the Risk + Safety practice lead within 24 hours.
The system is decomposed to the level at which the analysis will be performed · system, subsystem, assembly or component · and the boundaries and interfaces stated. Choosing the indenture level is the first real decision, because analysing too deep produces a register nobody uses and too shallow produces one that finds nothing.
Each item is assigned its required function, then every way that function can fail is enumerated · fails to operate, operates intermittently, operates out of tolerance, fails in position, fails open, fails closed, spurious operation. Failure modes are drawn from maintenance history, OEM data and reliability sources rather than invented in the room.
Each failure mode is traced to its local effect, its effect at the next level, and its end effect at plant level. Detection is assessed honestly · whether the failure announces itself, is caught by an existing test or inspection, or remains hidden until the item is demanded. Hidden failures on protective and redundant equipment are the highest-value findings.
Severity of end effect, occurrence from failure rate data, and detectability combined into a criticality ranking. Where the client uses risk priority numbering, an RPN is calculated as the product of the three; where consequence classes differ sharply, a criticality matrix is used instead, since an RPN can rank a frequent trivial failure alongside a rare catastrophic one.
Recommendations directed at whichever factor the analysis identifies as governing · design change or redundancy to reduce severity, condition monitoring or component change to reduce occurrence, and proof testing or instrumentation to improve detection. Output feeds directly into the maintenance strategy, spares holding and proof-test intervals rather than sitting as a standalone report.
Studies follow the recognised failure mode analysis and reliability standards used in process, power and manufacturing sectors. Every deliverable independently reviewed and signed by a Chartered Engineer (CEng MIE India).
Three landmark engagements from our verified roster · quantified outcomes, no client names disclosed without written permission.
Component-level analysis across pump, driver, coupling and control loop. Criticality ranking identified a small group of failure modes with severe end effect and no existing detection, which were addressed through condition monitoring rather than through the spare-holding increase originally proposed.
Line-wide analysis at assembly level, ranking modes by criticality against production loss. The dominant contributors proved to be a handful of intermittent failure modes that had never been recorded as failures because each was cleared by an operator reset.
Hidden failure analysis across protective and redundant equipment, identifying items whose failure would not be revealed until demand and setting proof test intervals against that finding.
Tell us your plant, region, and scope · a named Chartered Engineer responds within 24 hours.