Risk + Safety + AMC

FMEA and FMECA Studies

Bottom-up failure mode, effects and criticality analysis to IEC 60812 · component by component, effect by effect.

FMEA starts where HAZOP does not · at the component. For each item we ask how it can fail, what each failure mode does to the function above it, how it would be detected, and what that combination justifies spending to prevent.

25 marquee operators · 21 countries · verified roster
Bayer · Pfizer · TATA · Adani · JSW · ISRO · Siemens · Bosch · DuPont · Mahindra · Hindalco · and others
Bayer
Pfizer
TATA
Adani
JSW
Nestle
ISRO
Mahindra
Siemens
Bosch
DuPont
Aditya Birla
Hindalco
Amazon
Indian Oil
ITC
Asian Paints
Dr. Reddy
Kia
Bureau Veritas
Lloyd
Halliburton
Jindal Steel
AMNS
Rolls Royce
Bayer
Pfizer
TATA
Adani
JSW
Nestle
ISRO
Mahindra
Siemens
Bosch
DuPont
Aditya Birla
Hindalco
Amazon
Indian Oil
ITC
Asian Paints
Dr. Reddy
Kia
Bureau Veritas
Lloyd
Halliburton
Jindal Steel
AMNS
Rolls Royce
Why this matters

What does FMEA find that a HAZOP does not?

They run in opposite directions, and that is the whole point. A HAZOP is top-down and process-driven · it starts from a deviation in a process parameter and works back to causes. An FMEA is bottom-up and hardware-driven · it starts from a specific component, enumerates every way that component can fail, and works forward to the effect on the assembly, the system and the plant.

The consequence is that each catches what the other structurally cannot. A HAZOP asks what happens on low flow and accepts a pump trip as one cause. An FMEA asks how the pump fails · seal, bearing, coupling, driver, controller, each with its own failure rate, its own detection method and its own effect. Failure modes that produce no process deviation at all, such as a redundant element that has silently failed and will not be there when demanded, are invisible to a HAZOP and are precisely what FMEA is built to surface.

Criticality analysis is what turns the register into a decision. Without it, an FMEA lists a few hundred failure modes with no basis for choosing between them.

Method

How we deliver FMEA and FMECA Studies

IEC 60812 methodology · component-level analysis with criticality ranking · deliverables independently reviewed and signed by a Chartered Engineer. Routes to the Risk + Safety practice lead within 24 hours.

01

System breakdown and boundary definition

The system is decomposed to the level at which the analysis will be performed · system, subsystem, assembly or component · and the boundaries and interfaces stated. Choosing the indenture level is the first real decision, because analysing too deep produces a register nobody uses and too shallow produces one that finds nothing.

02

Function and failure mode identification

Each item is assigned its required function, then every way that function can fail is enumerated · fails to operate, operates intermittently, operates out of tolerance, fails in position, fails open, fails closed, spurious operation. Failure modes are drawn from maintenance history, OEM data and reliability sources rather than invented in the room.

03

Effect and detection analysis

Each failure mode is traced to its local effect, its effect at the next level, and its end effect at plant level. Detection is assessed honestly · whether the failure announces itself, is caught by an existing test or inspection, or remains hidden until the item is demanded. Hidden failures on protective and redundant equipment are the highest-value findings.

04

Criticality assessment

Severity of end effect, occurrence from failure rate data, and detectability combined into a criticality ranking. Where the client uses risk priority numbering, an RPN is calculated as the product of the three; where consequence classes differ sharply, a criticality matrix is used instead, since an RPN can rank a frequent trivial failure alongside a rare catastrophic one.

05

Mitigation and maintenance strategy

Recommendations directed at whichever factor the analysis identifies as governing · design change or redundancy to reduce severity, condition monitoring or component change to reduce occurrence, and proof testing or instrumentation to improve detection. Output feeds directly into the maintenance strategy, spares holding and proof-test intervals rather than sitting as a standalone report.

Standards + compliance

Built to the standards your auditors quote

Studies follow the recognised failure mode analysis and reliability standards used in process, power and manufacturing sectors. Every deliverable independently reviewed and signed by a Chartered Engineer (CEng MIE India).

Anonymous case anchors

What this looks like in production

Three landmark engagements from our verified roster · quantified outcomes, no client names disclosed without written permission.

Power plant, India · boiler feed pump train

Component-level analysis across pump, driver, coupling and control loop. Criticality ranking identified a small group of failure modes with severe end effect and no existing detection, which were addressed through condition monitoring rather than through the spare-holding increase originally proposed.

Manufacturing site, South Asia · packaging line

Line-wide analysis at assembly level, ranking modes by criticality against production loss. The dominant contributors proved to be a handful of intermittent failure modes that had never been recorded as failures because each was cleared by an operator reset.

Process plant, GCC · protective device population

Hidden failure analysis across protective and redundant equipment, identifying items whose failure would not be revealed until demand and setting proof test intervals against that finding.

Frequently asked

FMEA and FMECA · the questions reliability engineers ask

What is the difference between FMEA and FMECA?
FMEA identifies failure modes and traces their effects. FMECA adds the criticality step, ranking each mode so effort can be allocated · the C is the difference between a list and a decision tool. Criticality can be assessed qualitatively on a severity-occurrence matrix or quantitatively using failure rate data and mode ratios. In practice most industrial work labelled FMEA includes some form of criticality assessment, because a register of several hundred failure modes without ranking is not actionable.
How is a Risk Priority Number calculated?
RPN is the product of three ratings, conventionally each on a one to ten scale · severity of the end effect, occurrence of the failure mode, and detection, where a high detection rating means the failure is hard to detect. The product runs from 1 to 1000 and is used to prioritise action. Its known weakness is that identical RPNs can represent very different risks · a severity-10 mode with low occurrence can score the same as a severity-3 mode that happens often, and those are not equivalent situations. For that reason we apply a severity threshold above which action is required regardless of RPN.
When should FMEA be used instead of HAZOP?
Use HAZOP where the hazard arises from the process · continuous fluid systems, reaction chemistry, anything where a parameter deviation propagates. Use FMEA where the concern is hardware · rotating equipment, machinery, electrical and control systems, protective devices, discrete manufacturing. Most plants need both, applied to different scopes. Where a HAZOP has flagged a safeguard as critical, an FMEA of that safeguard's hardware is often the logical next step.
What data is needed for an FMEA?
A system breakdown to the intended indenture level, functional specifications, P&IDs or schematics, and failure rate information · ideally your own maintenance and failure history, supplemented by OEM data and published reliability databases where site history is thin. Site history is worth more than generic data because it reflects the actual service, duty cycle and maintenance regime, and generic failure rates applied to equipment running well outside their assumed conditions produce confident but wrong occurrence ratings.
How does FMEA support maintenance strategy?
Directly. Once failure modes are ranked and detection is assessed, the appropriate maintenance response follows · condition monitoring where a mode develops with a detectable warning period, scheduled replacement where it is age-related, proof testing where the failure is hidden, and design change or redundancy where none of those is adequate. This is the same logic reliability-centred maintenance uses, and an FMEA is the usual analytical input to an RCM programme.
Can FMEA be used for safety instrumented systems?
A specialised form of it is required. FMEDA, failure modes, effects and diagnostic analysis, extends FMEA by classifying each failure as safe or dangerous and as detected or undetected by diagnostics. Those classifications produce the safe failure fraction and the dangerous undetected failure rate that feed the PFD calculation under IEC 61508. It is a distinct exercise from a general reliability FMEA and is normally performed alongside functional safety work rather than in place of it.

Scope your FMEA and FMECA Studies engagement.

Tell us your plant, region, and scope · a named Chartered Engineer responds within 24 hours.

  • 4 fields. No phone interview to start.
  • Per-discipline routing to the Risk + Safety + AMC practice lead.
  • Anonymous case anchors sent with first reply.
  • Same-day callback for deadline-driven enquiries.

Risk + Safety + AMC Scoping

HAZOP/LOPA/SIL/QRA · 5-year AMC retainer · Practice Lead Safety responds in 24 hr.