Failure mode and effects analysis

Last updated
graph with an example of steps in a failure mode and effects analysis FMEA.png
graph with an example of steps in a failure mode and effects analysis

Failure mode and effects analysis (FMEA; often written with "failure modes" in plural) is the process of reviewing as many components, assemblies, and subsystems as possible to identify potential failure modes in a system and their causes and effects. For each component, the failure modes and their resulting effects on the rest of the system are recorded in a specific FMEA worksheet. There are numerous variations of such worksheets. A FMEA can be a qualitative analysis, [1] but may be put on a quantitative basis when mathematical failure rate models [2] are combined with a statistical failure mode ratio database. It was one of the first highly structured, systematic techniques for failure analysis. It was developed by reliability engineers in the late 1950s to study problems that might arise from malfunctions of military systems. An FMEA is often the first step of a system reliability study.

Contents

A few different types of FMEA analyses exist, such as:

Sometimes FMEA is extended to FMECA (failure mode, effects, and criticality analysis) to indicate that criticality analysis is performed too.

FMEA is an inductive reasoning (forward logic) single point of failure analysis and is a core task in reliability engineering, safety engineering and quality engineering.

A successful FMEA activity helps identify potential failure modes based on experience with similar products and processes—or based on common physics of failure logic. It is widely used in development and manufacturing industries in various phases of the product life cycle. Effects analysis refers to studying the consequences of those failures on different system levels.

Functional analyses are needed as an input to determine correct failure modes, at all system levels, both for functional FMEA or piece-part (hardware) FMEA. A FMEA is used to structure mitigation for risk reduction based on either failure mode or effect severity reduction, or based on lowering the probability of failure or both. The FMEA is in principle a full inductive (forward logic) analysis, however the failure probability can only be estimated or reduced by understanding the failure mechanism. Hence, FMEA may include information on causes of failure (deductive analysis) to reduce the possibility of occurrence by eliminating identified (root) causes .

Introduction

The FME(C)A is a design tool used to systematically analyze postulated component failures and identify the resultant effects on system operations. The analysis is sometimes characterized as consisting of two sub-analyses, the first being the failure modes and effects analysis (FMEA), and the second, the criticality analysis (CA). [3] Successful development of an FMEA requires that the analyst include all significant failure modes for each contributing element or part in the system. FMEAs can be performed at the system, subsystem, assembly, subassembly or part level. The FMECA should be a living document during development of a hardware design. It should be scheduled and completed concurrently with the design. If completed in a timely manner, the FMECA can help guide design decisions. The usefulness of the FMECA as a design tool and in the decision-making process is dependent on the effectiveness and timeliness with which design problems are identified. Timeliness is probably the most important consideration. In the extreme case, the FMECA would be of little value to the design decision process if the analysis is performed after the hardware is built. While the FMECA identifies all part failure modes, its primary benefit is the early identification of all critical and catastrophic subsystem or system failure modes so they can be eliminated or minimized through design modification at the earliest point in the development effort; therefore, the FMECA should be performed at the system level as soon as preliminary design information is available and extended to the lower levels as the detail design progresses.

Remark: For more complete scenario modelling another type of reliability analysis may be considered, for example fault tree analysis (FTA); a deductive (backward logic) failure analysis that may handle multiple failures within the item and/or external to the item including maintenance and logistics. It starts at higher functional / system level. An FTA may use the basic failure mode FMEA records or an effect summary as one of its inputs (the basic events). Interface hazard analysis, human error analysis and others may be added for completion in scenario modelling.

Functional failure mode and effects analysis

The analysis should always be started by someone listing the functions that the design needs to fulfill. Functions are the starting point of a well done FMEA, and using functions as baseline provides the best yield of an FMEA. After all, a design is only one possible solution to perform functions that need to be fulfilled. This way an FMEA can be done on concept designs as well as detail designs, on hardware as well as software, and no matter how complex the design.

When performing a FMECA, interfacing hardware (or software) is first considered to be operating within specification. After that it can be extended by consequently using one of the 5 possible failure modes of one function of the interfacing hardware as a cause of failure for the design element under review. This gives the opportunity to make the design robust against function failure elsewhere in the system.

In addition, each part failure postulated is considered to be the only failure in the system (i.e., it is a single failure analysis). In addition to the FMEAs done on systems to evaluate the impact lower level failures have on system operation, several other FMEAs are done. Special attention is paid to interfaces between systems and in fact at all functional interfaces. The purpose of these FMEAs is to assure that irreversible physical and/or functional damage is not propagated across the interface as a result of failures in one of the interfacing units. These analyses are done to the piece part level for the circuits that directly interface with the other units. The FMEA can be accomplished without a CA, but a CA requires that the FMEA has previously identified system level critical failures. When both steps are done, the total process is called an FMECA.

Ground rules

The ground rules of each FMEA include a set of project selected procedures; the assumptions on which the analysis is based; the hardware that has been included and excluded from the analysis and the rationale for the exclusions. The ground rules also describe the indenture level of the analysis (i.e. the level in the hierarchy of the part to the sub-system, sub-system to the system, etc.), the basic hardware status, and the criteria for system and mission success. Every effort should be made to define all ground rules before the FMEA begins; however, the ground rules may be expanded and clarified as the analysis proceeds. A typical set of ground rules (assumptions) follows: [4]

  1. Only one failure mode exists at a time.
  2. All inputs (including software commands) to the item being analyzed are present and at nominal values.
  3. All consumables are present in sufficient quantities.
  4. Nominal power is available

Benefits

Major benefits derived from a properly implemented FMECA effort are as follows:

  1. It provides a documented method for selecting a design with a high probability of successful operation and safety.
  2. A documented uniform method of assessing potential failure mechanisms, failure modes and their impact on system operation, resulting in a list of failure modes ranked according to the seriousness of their system impact and likelihood of occurrence.
  3. Early identification of single failure points (SFPS) and system interface problems, which may be critical to mission success and/or safety. They also provide a method of verifying that switching between redundant elements is not jeopardized by postulated single failures.
  4. An effective method for evaluating the effect of proposed changes to the design and/or operational procedures on mission success and safety.
  5. A basis for in-flight troubleshooting procedures and for locating performance monitoring and fault-detection devices.
  6. Criteria for early planning of tests.

From the above list, early identifications of SFPS, input to the troubleshooting procedure and locating of performance monitoring / fault detection devices are probably the most important benefits of the FMECA. In addition, the FMECA procedures are straightforward and allow orderly evaluation of the design.

History

Procedures for conducting FMECA were described in 1949 in US Armed Forces Military Procedures document MIL-P-1629, [5] revised in 1980 as MIL-STD-1629A. [6] By the early 1960s, contractors for the U.S. National Aeronautics and Space Administration (NASA) were using variations of FMECA or FMEA under a variety of names. [7] [8] NASA programs using FMEA variants included Apollo, Viking, Voyager, Magellan, Galileo, and Skylab. [9] [10] [11] The civil aviation industry was an early adopter of FMEA, with the Society for Automotive Engineers (SAE, an organization covering aviation and other transportation beyond just automotive, despite its name) publishing ARP926 in 1967. [12] After two revisions, Aerospace Recommended Practice ARP926 has been replaced by ARP4761, which is now broadly used in civil aviation.

During the 1970s, use of FMEA and related techniques spread to other industries. In 1971 NASA prepared a report for the U.S. Geological Survey recommending the use of FMEA in assessment of offshore petroleum exploration. [13] A 1973 U.S. Environmental Protection Agency report described the application of FMEA to wastewater treatment plants. [14] FMEA as application for HACCP on the Apollo Space Program moved into the food industry in general. [15]

The automotive industry began to use FMEA by the mid 1970s. [16] The Ford Motor Company introduced FMEA to the automotive industry for safety and regulatory consideration after the Pinto affair. Ford applied the same approach to processes (PFMEA) to consider potential process induced failures prior to launching production. In 1993 the Automotive Industry Action Group (AIAG) first published an FMEA standard for the automotive industry. [17] It is now in its fourth edition. [18] The SAE first published related standard J1739 in 1994. [19] This standard is also now in its fourth edition. [20] In 2019 both method descriptions were replaced by the new AIAG / VDA FMEA handbook. It is a harmonization of the former FMEA standards of AIAG, VDA, SAE and other method descriptions. [21] [22] [23] As of 2024, the AIAG / VDA FMEA Handbook is accepted by GM, Ford, Stellantis, Honda NA, BMW, Volkswagen Group, Mercedes-Benz Group AG (formerly Daimler AG), and Daimler Truck. [24]

Although initially developed by the military, FMEA methodology is now extensively used in a variety of industries including semiconductor processing, food service, plastics, software, and healthcare. [25] Toyota has taken this one step further with its design review based on failure mode (DRBFM) approach. The method is now supported by the American Society for Quality which provides detailed guides on applying the method. [26] The standard failure modes and effects analysis (FMEA) and failure modes, effects and criticality analysis (FMECA) procedures identify the product failure mechanisms, but may not model them without specialized software. This limits their applicability to provide a meaningful input to critical procedures such as virtual qualification, root cause analysis, accelerated test programs, and to remaining life assessment. To overcome the shortcomings of FMEA and FMECA a failure modes, mechanisms and effect analysis (FMMEA) has often been used.

Following the release of IATF 16949:2016, an international quality standard that requires companies to have an organization-specific documented FMEA process, many original equipment manufacturers (OEMs) like Ford are updating their Customer Specific Requirements (CSR) to include the usage of specific FMEA software. [27] For Ford specifically, these requirements had multiple-stage compliance deadlines of July and December of 2022. [28]

Basic terms

The following covers some basic FMEA terminology. [29]

Action priority (AP)
The AP replaces the former risk matrix and RPN in the AIAG / VDA FMEA handbook 2019. It makes a statement about the need for additional improvement measures.
Failure
The loss of a function under stated conditions.
Failure mode
The specific manner or way by which a failure occurs in terms of failure of the part, component, function, equipment, subsystem, or system under investigation. Depending on the type of FMEA performed, failure mode may be described at various levels of detail. A piece part FMEA will focus on detailed part or component failure modes (such as fully fractured axle or deformed axle, or electrical contact stuck open, stuck short, or intermittent). A functional FMEA will focus on functional failure modes. These may be general (such as no function, over function, under function, intermittent function, or unintended function) or more detailed and specific to the equipment being analyzed. A PFMEA will focus on process failure modes (such as inserting the wrong drill bit).
Failure cause and/or mechanism
Defects in requirements, design, process, quality control, handling or part application, which are the underlying cause or sequence of causes that initiate a process (mechanism) that leads to a failure mode over a certain time. A failure mode may have more causes. For example; "fatigue or corrosion of a structural beam" or "fretting corrosion in an electrical contact" is a failure mechanism and in itself (likely) not a failure mode. The related failure mode (end state) is a "full fracture of structural beam" or "an open electrical contact". The initial cause might have been "Improper application of corrosion protection layer (paint)" and /or "(abnormal) vibration input from another (possibly failed) system".
Failure effect
Immediate consequences of a failure on operation, or more generally on the needs for the customer / user that should be fulfilled by the function but now is not, or not fully, fulfilled.
Indenture levels (bill of material or functional breakdown)
An identifier for system level and thereby item complexity. Complexity increases as levels are closer to one.
Local effect
The failure effect as it applies to the item under analysis.
Next higher level effect
The failure effect as it applies at the next higher indenture level.
End effect
The failure effect at the highest indenture level or total system.
Detection
The means of detection of the failure mode by maintainer, operator or built in detection system, including estimated dormancy period (if applicable).
Probability
The likelihood of the failure occurring.
Risk priority number (RPN)
Severity (of the event) × probability (of the event occurring) × detection (probability that the event would not be detected before the user was aware of it).
Severity
The consequences of a failure mode. Severity considers the worst potential consequence of a failure, determined by the degree of injury, property damage, system damage and/or time lost to repair the failure.
Remarks / mitigation / actions
Additional info, including the proposed mitigation or actions used to lower a risk or justify a risk level or scenario.

Example of FMEA worksheet

Example FMEA worksheet
FMEA Ref.ItemPotential failure modePotential cause(s) / mechanismMission phaseLocal effects of failureNext higher level effectSystem-level end effect(P) Probability (estimate)(S) Severity(D) Detection (indications to operator, maintainer)Detection dormancy periodRisk level P*S (+D)Actions for further investigation / evidenceMitigation / requirements
1.1.1.1Brake manifold ref. designator 2b, channel A, o-ringInternal leakage from channel A to Ba) O-ring compression set (creep) failure

b) surface damage during assembly

LandingDecreased pressure to main brake hoseNo left wheel brakingSeverely reduced aircraft deceleration on ground and side drift. Partial loss of runway position control. Risk of collision(C) Occasional(V) Catastrophic (this is the worst case)(1) Flight computer and maintenance computer will indicate "Left main brake, pressure low"Built-in test interval is 1 minuteUnacceptableCheck dormancy period and probability of failureRequire redundant independent brake hydraulic channels and/or require redundant sealing and classify o-ring as critical part class 1

Probability (P)

It is necessary to look at the cause of a failure mode and the likelihood of occurrence. This can be done by analysis, calculations / FEM, looking at similar items or processes and the failure modes that have been documented for them in the past. A failure cause is looked upon as a design weakness. All the potential causes for a failure mode should be identified and documented. This should be in technical terms. Examples of causes are: Human errors in handling, Manufacturing induced faults, Fatigue, Creep, Abrasive wear, erroneous algorithms, excessive voltage or improper operating conditions or use (depending on the used ground rules). A failure mode may be given a Probability Ranking with a defined number of levels. This field is also often referred to as an Occurrence Rating. [26]

RatingMeaning
1Extremely unlikely (virtually impossible or No known occurrences on similar products or processes, with many running hours)
2Remote (relatively few failures)
3Occasional (occasional failures)
4Reasonably possible (repeated failures)
5Frequent (failure is almost inevitable)

For a piece part FMEA, quantitative probability may be calculated from the results of a reliability prediction analysis and the failure mode ratios from a failure mode distribution catalog, such as RAC FMD-97. [30] This method allows a quantitative FTA to use the FMEA results to verify that undesired events meet acceptable levels of risk.

Severity (S)

Determine the Severity for the worst-case scenario adverse end effect (state). It is convenient to write these effects down in terms of what the user might see or experience in terms of functional failures. Examples of these end effects are: full loss of function x, degraded performance, functions in reversed mode, too late functioning, erratic functioning, etc. Each end effect is given a Severity number (S) from, say, I (no effect) to V (catastrophic), based on cost and/or loss of life or quality of life. These numbers prioritize the failure modes (together with probability and detectability). Below a typical classification is given. Other classifications are possible. See also hazard analysis.

RatingMeaning
1No relevant effect on reliability or safety
2Very minor, no damage, no injuries, only results in a maintenance action (only noticed by discriminating customers)
3Minor, low damage, light injuries (affects very little of the system, noticed by average customer)
4Critical (causes a loss of primary function; loss of all safety margins, 1 failure away from a catastrophe, severe damage, severe injuries, max 1 possible death)
5Catastrophic (product becomes inoperative; the failure may result in complete unsafe operation and possible multiple deaths)

Detection (D)

The means or method by which a failure is detected, isolated by operator and/or maintainer and the time it may take. This is important for maintainability control (availability of the system) and it is especially important for multiple failure scenarios. This may involve dormant failure modes (e.g. No direct system effect, while a redundant system / item automatically takes over or when the failure only is problematic during specific mission or system states) or latent failures (e.g. deterioration failure mechanisms, like metal growing a crack, but not of critical length). It should be made clear how the failure mode or cause can be discovered by an operator under normal system operation or if it can be discovered by the maintenance crew by some diagnostic action or automatic built in system test. A dormancy and/or latency period may be entered.

RatingMeaning
1Certain – fault will be caught on test –
2Almost certain
3High
4Moderate
5Low
6Fault is undetected by operators or maintainers

Dormancy or latency period

The average time that a failure mode may be undetected may be entered if known. For example:

Indication

If the undetected failure allows the system to remain in a safe / working state, a second failure situation should be explored to determine whether or not an indication will be evident to all operators and what corrective action they may or should take.

Indications to the operator should be described as follows:

PERFORM DETECTION COVERAGE ANALYSIS FOR TEST PROCESSES AND MONITORING (From ARP4761 Standard):

This type of analysis is useful to determine how effective various test processes are at the detection of latent and dormant faults. The method used to accomplish this involves an examination of the applicable failure modes to determine whether or not their effects are detected, and to determine the percentage of failure rate applicable to the failure modes which are detected. The possibility that the detection means may itself fail latently should be accounted for in the coverage analysis as a limiting factor (i.e., coverage cannot be more reliable than the detection means availability). Inclusion of the detection coverage in the FMEA can lead to each individual failure that would have been one effect category now being a separate effect category due to the detection coverage possibilities. Another way to include detection coverage is for the FTA to conservatively assume that no holes in coverage due to latent failure in the detection method affect detection of all failures assigned to the failure effect category of concern. The FMEA can be revised if necessary for those cases where this conservative assumption does not allow the top event probability requirements to be met.

After these three basic steps the Risk level may be provided.

Risk level (P×S) and (D)

Risk is the combination of end effect probability and severity where probability and severity includes the effect on non-detectability (dormancy time). This may influence the end effect probability of failure or the worst case effect Severity. The exact calculation may not be easy in all cases, such as those where multiple scenarios (with multiple events) are possible and detectability / dormancy plays a crucial role (as for redundant systems). In that case fault tree analysis and/or event trees may be needed to determine exact probability and risk levels.

Preliminary risk levels can be selected based on a risk matrix like shown below, based on Mil. Std. 882. [31] The higher the risk level, the more justification and mitigation is needed to provide evidence and lower the risk to an acceptable level. High risk should be indicated to higher level management, who are responsible for final decision-making.

Severity
Probability
IIIIIIIVVVI
ILowLowLowLowModerateHigh
IILowLowLowModerateHighUnacceptable
IIILowLowModerateModerateHighUnacceptable
IVLowModerateModerateHighUnacceptableUnacceptable
VModerateModerateHighUnacceptableUnacceptableUnacceptable

Timing

FMEA should be used:

The FMEA should be updated whenever:

Uses

Advantages

Limitations

While FMEA identifies important hazards in a system, its results may not be comprehensive and the approach has limitations. [32] [33] [34] In the healthcare context, FMEA and other risk assessment methods, including SWIFT (Structured What If Technique) and retrospective approaches, have been found to have limited validity when used in isolation. Challenges around scoping and organisational boundaries appear to be a major factor in this lack of validity. [32]

If used as a top-down tool, FMEA may only identify major failure modes in a system. Fault tree analysis (FTA) is better suited for "top-down" analysis. When used as a bottom-up tool FMEA can augment or complement FTA and identify many more causes and failure modes resulting in top-level symptoms. It is not able to discover complex failure modes involving multiple failures within a subsystem, or to report expected failure intervals of particular failure modes up to the upper level subsystem or system.[ citation needed ]

Additionally, the multiplication of the severity, occurrence and detection rankings may result in rank reversals, where a less serious failure mode receives a higher RPN than a more serious failure mode. [35] The reason for this is that the rankings are ordinal scale numbers, and multiplication is not defined for ordinal numbers. The ordinal rankings only say that one ranking is better or worse than another, but not by how much. For instance, a ranking of "2" may not be twice as severe as a ranking of "1", or an "8" may not be twice as severe as a "4", but multiplication treats them as though they are. See Level of measurement for further discussion. Various solutions to this problems have been proposed, e.g., the use of fuzzy logic as an alternative to classic RPN model. [36] [37] [38] In the new AIAG / VDA FMEA handbook (2019) the RPN approach was replaced by the AP (action priority). [39] [40] [23]

The FMEA worksheet is hard to produce, hard to understand and read, as well as hard to maintain. The use of neural network techniques to cluster and visualise failure modes were suggested starting from 2010. [41] [42] [43] An alternative approach is to combine the traditional FMEA table with set of bow-tie diagrams. The diagrams provide a visualisation of the chains of cause and effect, while the FMEA table provides the detailed information about specific events. [44]

Types

See also

Related Research Articles

<span class="mw-page-title-main">Safety engineering</span> Engineering discipline which assures that engineered systems provide acceptable levels of safety

Safety engineering is an engineering discipline which assures that engineered systems provide acceptable levels of safety. It is strongly related to industrial engineering/systems engineering, and the subset system safety engineering. Safety engineering assures that a life-critical system behaves as needed, even when components fail.

<span class="mw-page-title-main">Fault tree analysis</span> Failure analysis system used in safety engineering and reliability engineering

Fault tree analysis (FTA) is a type of failure analysis in which an undesired state of a system is examined. This analysis method is mainly used in safety engineering and reliability engineering to understand how systems can fail, to identify the best ways to reduce risk and to determine event rates of a safety accident or a particular system level (functional) failure. FTA is used in the aerospace, nuclear power, chemical and process, pharmaceutical, petrochemical and other high-hazard industries; but is also used in fields as diverse as risk factor identification relating to social service system failure. FTA is also used in software engineering for debugging purposes and is closely related to cause-elimination technique used to detect bugs.

<span class="mw-page-title-main">Safety-critical system</span> System whose failure would be serious

A safety-critical system or life-critical system is a system whose failure or malfunction may result in one of the following outcomes:

Reliability engineering is a sub-discipline of systems engineering that emphasizes the ability of equipment to function without failure. Reliability is defined as the probability that a product, system, or service will perform its intended function adequately for a specified period of time, OR will operate in a defined environment without failure. Reliability is closely related to availability, which is typically described as the ability of a component or system to function at a specified moment or interval of time.

Advanced product quality planning (APQP) is a framework of procedures and techniques used to develop products in industry, particularly in the automotive industry. It differs from Six Sigma in that the goal of Six Sigma is to reduce variation but has similarities to Design for Six Sigma (DFSS).

In functional safety, safety integrity level (SIL) is defined as the relative level of risk-reduction provided by a safety instrumented function (SIF), i.e. the measurement of the performance required of the SIF.

A hazard analysis is one of many methods that may be used to assess risk. At its core, the process entails describing a system object that intends to conduct some activity. During the performance of that activity, an adverse event may be encountered that could cause or contribute to an occurrence. Finally, that occurrence will result in some outcome that may be measured in terms of the degree of loss or harm. This outcome may be measured on a continuous scale, such as an amount of monetary loss, or the outcomes may be categorized into various levels of severity.

<span class="mw-page-title-main">ARP4761</span> Aerospace recommended practice from SAE International

ARP4761, Guidelines for Conducting the Safety Assessment Process on Civil Aircraft, Systems, and Equipment is an Aerospace Recommended Practice from SAE International. In conjunction with ARP4754, ARP4761 is used to demonstrate compliance with 14 CFR 25.1309 in the U.S. Federal Aviation Administration (FAA) airworthiness regulations for transport category aircraft, and also harmonized international airworthiness regulations such as European Aviation Safety Agency (EASA) CS–25.1309.

A measurement system analysis (MSA) is a thorough assessment of a measurement process, and typically includes a specially designed experiment that seeks to identify the components of variation in that measurement process. Just as processes that produce a product may vary, the process of obtaining measurements and data may also have variation and produce incorrect results. A measurement systems analysis evaluates the test method, measuring instruments, and the entire process of obtaining measurements to ensure the integrity of data used for analysis and to understand the implications of measurement error for decisions made about a product or process. Proper measurement system analysis is critical for producing a consistent product in manufacturing and when left uncontrolled can result in a drift of key parameters and unusable final products. MSA is also an important element of Six Sigma methodology and of other quality management systems. MSA analyzes the collection of equipment, operations, procedures, software and personnel that affects the assignment of a number to a measurement characteristic.

Failure mode effects and criticality analysis (FMECA) is an extension of failure mode and effects analysis (FMEA).

IEC 61508 is an international standard published by the International Electrotechnical Commission (IEC) consisting of methods on how to apply, design, deploy and maintain automatic protection systems called safety-related systems. It is titled Functional Safety of Electrical/Electronic/Programmable Electronic Safety-related Systems.

Software safety is an engineering discipline that aims to ensure that software, which is used in safety-related systems, does not contribute to any hazards such a system might pose. There are numerous standards that govern the way how safety-related software should be developed and assured in various domains. Most of them classify software according to their criticality and propose techniques and measures that should be employed during the development and assurance:

Production Part Approval Process (PPAP) is used in the Aerospace or automotive supply chain for establishing confidence in suppliers and their production processes. Actual measurements are taken from the parts produced and are used to complete the various test sheets of PPAP.

"All customer engineering design record and specification requirements are properly understood by the supplier and that the process has the potential to produce product consistently meeting these requirements during an actual production run at the quoted production rate." Version 4, 1 March 2006

Design review based on failure mode (DRBFM) is a tool originally developed by the Toyota Motor Corporation. This tool was developed based on the philosophy that design problems occur when changes are made to existing engineering designs that have already been proven successful.

Engineering analysis involves the application of scientific/mathematical analytic principles and processes to reveal the properties and state of a system, device or mechanism under study.

Functional safety is the part of the overall safety of a system or piece of equipment that depends on automatic protection operating correctly in response to its inputs or failure in a predictable manner (fail-safe). The automatic protection system should be designed to properly handle likely systematic errors, hardware failures and operational/environmental stress.

ISO 26262, titled "Road vehicles – Functional safety", is an international standard for functional safety of electrical and/or electronic systems that are installed in serial production road vehicles, defined by the International Organization for Standardization (ISO) in 2011, and revised in 2018.

Automotive Safety Integrity Level (ASIL) is a risk classification scheme defined by the ISO 26262 - Functional Safety for Road Vehicles standard. This is an adaptation of the Safety Integrity Level (SIL) used in IEC 61508 for the automotive industry. This classification helps defining the safety requirements necessary to be in line with the ISO 26262 standard. The ASIL is established by performing a risk analysis of a potential hazard by looking at the Severity, Exposure and Controllability of the vehicle operating scenario. The safety goal for that hazard in turn carries the ASIL requirements.

<span class="mw-page-title-main">AC 25.1309-1</span> American aviation regulatory document

AC 25.1309–1 is an FAA Advisory Circular (AC) that identifies acceptable means for showing compliance with the airworthiness requirements of § 25.1309 of the Federal Aviation Regulations. Revision A was released in 1988. In 2002, work was done on Revision B, but it was not formally released; the result is the Rulemaking Advisory Committee-recommended revision B-Arsenal Draft (2002). The Arsenal Draft is "considered to exist as a relatively mature draft". The FAA and EASA have subsequently accepted proposals by type certificate applicants to use the Arsenal Draft on development programs.

Failure modes, effects, and diagnostic analysis (FMEDA) is a systematic analysis technique to obtain subsystem / device level failure rates, failure modes and diagnostic capability. The FMEDA technique considers:

References

  1. Rausand, Marvin; Høyland, Arnljot (2004). System Reliability Theory: Models, Statistical Methods, and Applications (2nd ed.). Wiley. p. 88.
  2. Tay K. M.; Lim C.P. (2008). "On the use of fuzzy inference techniques in assessment models: part II: industrial applications" (PDF). Fuzzy Optimization and Decision Making. 7 (3): 283–302. doi:10.1007/s10700-008-9037-y. S2CID   12269658.
  3. Project Reliability Group (July 1990). Koch, John E. (ed.). Jet Propulsion Laboratory Reliability Analysis Handbook (pdf). Pasadena, California: Jet Propulsion Laboratory. JPL-D-5703. Retrieved 2013-08-25.
  4. Goddard Space Flight Center (GSFC) (1996-08-10). Performing a Failure Mode and Effects Analysis (pdf). Goddard Space Flight Center. 431-REF-000370. Retrieved 2013-08-25.
  5. United States Department of Defense (9 November 1949). MIL-P-1629 – Procedures for performing a failure mode effect and critical analysis. Department of Defense (US). MIL-P-1629.
  6. United States Department of Defense (24 November 1980). MIL-STD-1629A – Procedures for performing a failure mode effect and criticality analysis. Department of Defense (USA). MIL-STD-1629A. Archived from the original on 22 July 2011.
  7. Neal, R.A. (1962). Modes of Failure Analysis Summary for the Nerva B-2 Reactor. Westinghouse Electric Corporation Astronuclear Laboratory. hdl:2060/19760069385. WANL–TNR–042.
  8. Dill, Robert; et al. (1963). State of the Art Reliability Estimate of Saturn V Propulsion Systems. General Electric Company. hdl:2060/19930075105. RM 63TMP–22.
  9. Procedure for Failure Mode, Effects and Criticality Analysis (FMECA). National Aeronautics and Space Administration. 1966. hdl:2060/19700076494. RA–006–013–1A.
  10. Failure Modes, Effects, and Criticality Analysis (FMECA) (PDF). National Aeronautics and Space Administration JPL. PD–AD–1307. Retrieved 2010-03-13.
  11. Experimenters' Reference Based Upon Skylab Experiment Management (PDF). National Aeronautics and Space Administration George C. Marshall Space Flight Center. 1974. M–GA–75–1. Retrieved 2011-08-16.
  12. Design Analysis Procedure For Failure Modes, Effects and Criticality Analysis (FMECA). Society for Automotive Engineers. 1967. ARP926.
  13. Dyer, Morris K.; Dewey G. Little; Earl G. Hoard; Alfred C. Taylor; Rayford Campbell (1972). Applicability of NASA Contract Quality Management and Failure Mode Effect Analysis Procedures to the USFS Outer Continental Shelf Oil and Gas Lease Management Program (PDF). National Aeronautics and Space Administration George C. Marshall Space Flight Center. TM X–2567. Retrieved 2011-08-16.
  14. Mallory, Charles W.; Robert Waller (1973). Application of Selected Industrial Engineering Techniques to Wastewater Treatment Plants (PDF). United States Environmental Protection Agency. pp. 107–110. EPA R2–73–176. Retrieved 2012-11-10.
  15. Sperber, William H.; Stier, Richard F. (December 2009 – January 2010). "Happy 50th Birthday to HACCP: Retrospective and Prospective". FoodSafety Magazine: 42, 44–46.
  16. Matsumoto, K.; T. Matsumoto; Y. Goto (1975). "Reliability Analysis of Catalytic Converter as an Automotive Emission Control System". SAE Technical Paper 750178. SAE Technical Paper Series. 1. doi:10.4271/750178.
  17. AIAG (1993). Potential Failure Mode and Effect Analysis. Automotive Industry Action Group.
  18. AIAG (2008). Potential Failure Mode and Effect Analysis (FMEA), 4th Edition. Automotive Industry Action Group. ISBN   978-1-60534-136-1.
  19. SAE (1994). Potential Failure Mode and Effects Analysis in Design (Design FMEA), Potential Failure Mode and Effects Analysis in Manufacturing and Assembly Processes (Process FMEA), and Potential Failure Mode and Effects Analysis for Machinery (Machinery FMEA). SAE International.
  20. SAE (2008). Potential Failure Mode and Effects Analysis in Design (Design FMEA) and Potential Failure Mode and Effects Analysis in Manufacturing and Assembly Processes (Process FMEA) and Effects Analysis for Machinery (Machinery FMEA). SAE International.
  21. AIAG / VDA FMEA handbook 2019. Retrieved 2020-09-14.
  22. VDA: German automotive industry demands the highest quality from its products Archived 2021-03-02 at the Wayback Machine . Retrieved 2020-09-14.
  23. 1 2 Kymal, Chad; Gruska, Gregory F. (19 June 2019). "Introducing the AIAG-VDA DFMEA". qualitydigest. Retrieved 2020-12-02.
  24. Webmaster, AIAG. "(FMEA/DFMEA/PFMEA) Failure Mode & Effects Analysis". www.aiag.org. Retrieved 2024-07-30.
  25. Fadlovich, Erik (December 31, 2007). "Performing Failure Mode and Effect Analysis". Embedded Technology. Archived from the original on 2011-11-17.
  26. 1 2 3 "Failure Mode Effects Analysis (FMEA)". ASQ. Retrieved 2012-02-15.
  27. "17 December 2021 – Ford CSRs for use with IATF 16949 – International Automotive Task Force" . Retrieved 2024-07-30.
  28. Ford Motor Company (January 3, 2022). "Ford Motor Company Customer-Specific Requirements For IATF-16949:2016" (PDF). Ford IATF CSR: 23 via International Automotive Task Force.
  29. Langford, J. W. (1995). Logistics: Principles and Applications. McGraw Hill. p. 488.
  30. Failure Mode/Mechanism Distributions. Reliability Analysis Center. 1997. FMD–97.
  31. "MIL-STD-882 E SYSTEM SAFETY". www.everyspec.com. Retrieved 2017-01-04.
  32. 1 2 Potts H.W.W.; Anderson J.E.; Colligan L.; Leach P.; Davis S.; Berman J. (2014). "Assessing the validity of prospective hazard analysis methods: A comparison of two techniques". BMC Health Services Research. 14: 41. doi: 10.1186/1472-6963-14-41 . PMC   3906758 . PMID   24467813.
  33. Franklin, Bryony Dean; Shebl, Nada Atef; Barber, Nick (2012). "Failure mode and effects analysis: too little for too much?". BMJ Quality & Safety. 21 (7): 607–611. doi:10.1136/bmjqs-2011-000723. PMID   22447819. S2CID   46106670.
  34. Shebl, N. A.; Franklin, B. D.; Barber, N. (2009). "Is failure mode and effect analysis reliable?". Journal of Patient Safety. 5 (2): 86–94. doi:10.1097/PTS.0b013e3181a6f040. PMID   19920447. S2CID   45635417.
  35. Kmenta, Steven; Ishii, Koshuke (2004). "Scenario-Based Failure Modes and Effects Analysis Using Expected Cost". Journal of Mechanical Design. 126 (6): 1027. doi:10.1115/1.1799614.
  36. Jee T.L.; Tay K. M.; Lim C.P. (2015). "A new two-stage fuzzy inference system-based approach to prioritize failures in failure mode and effect analysis" (PDF). IEEE Transactions on Reliability. 64 (3): 869–877. doi:10.1109/TR.2015.2420300. S2CID   20987880.
  37. Kerk Y.W.; Tay K. M.; Lim C.P. (2017). "n Analytical Interval Fuzzy Inference System for Risk Evaluation and Prioritization in Failure Mode and Effect Analysis". IEEE Systems Journal. 11 (3): 1–12. Bibcode:2017ISysJ..11.1589K. doi:10.1109/JSYST.2015.2478150. S2CID   5878974.
  38. Chai K.C.; Tay K. M.; Lim C.P. (2016). "A perceptual computing-based method to prioritize failure modes in failure mode and effect analysis and its application to edible bird nest farming" (PDF). Applied Soft Computing. 49: 734–747. doi:10.1016/j.asoc.2016.08.043.
  39. AIAG / VDA FMEA handbook 2019. Retrieved 2020-11-23.
  40. VDA: German automotive industry demands the highest quality from its products Archived 2021-03-02 at the Wayback Machine . Retrieved 2020-11-23.
  41. Tay K.M.; Jong C.H.; Lim C.P. (2015). "A clustering-based failure mode and effect analysis model and its application to the edible bird nest industry" (PDF). Neural Computing and Applications. 26 (3): 551–560. doi:10.1007/s00521-014-1647-4. S2CID   7821836. Archived from the original (PDF) on 2017-09-22. Retrieved 2019-07-14.
  42. Chang, Wui Lee; Tay, Kai Meng; Lim, Chee Peng (Nov 2015). "Clustering and visualization of failure modes using an evolving tree" (PDF). Expert Systems with Applications. 42 (20): 7235–7244. doi:10.1016/j.eswa.2015.04.036.
  43. Chang, Wui Lee; Pang, Lie Meng; Tay, Kai Meng (March 2017). "Application of Self-Organizing Map to Failure Modes and Effects Analysis Methodology" (PDF). Neurocomputing. PP: 314–320. doi:10.1016/j.neucom.2016.04.073.
  44. "Building a FMEA". Diametric Software Ltd. Retrieved 13 March 2020.