18.4 FMEA, HACCP, CTQ & SWOT

Key Takeaways

  • Risk treatment includes avoidance, mitigation/reduction, transfer, and acceptance with monitoring—tradeoffs balance severity, occurrence, detectability, cost, and residual risk.
  • FMEA (including DFMEA and PFMEA) systematically lists failure modes, effects, causes, and controls, often scoring severity, occurrence, and detection to prioritize actions.
  • HACCP identifies hazards and critical control points in processes (classically food safety) with monitoring, critical limits, and corrective actions.
  • CTQs (critical-to-quality characteristics) translate customer/stakeholder needs into measurable product or process requirements that drive control and audit focus.
  • SWOT structures strengths, weaknesses, opportunities, and threats for strategic or program-level analysis; organization-level risk management frameworks also appear in BoK IV.A.8.
Last updated: August 2026

18.4 FMEA, HACCP, CTQ & SWOT (CQA BoK V.H — Understand)

/practice/cqaPractice questions with detailed explanations

Auditors do not own every risk model, but they must understand common tools well enough to challenge empty templates, missing severity logic, and “green RPN” theater. BoK V.H sits at Understand: recognize purpose, structure, and appropriate use.

Risk strategies: avoidance, mitigation, tradeoffs

Before naming tools, fix the treatment vocabulary:

StrategyMeaningExample
AvoidanceEliminate the risk source (do not do the activity / remove hazard)Discontinue a high-risk process step; do not enter a market
Mitigation / reductionLower severity, occurrence, or improve detectionPoka-yoke, redesign, training, redundant inspection
Transfer / shareShift risk contractually or via insurance (risk remains somewhere)Supplier quality agreements; insurance
AcceptanceTake residual risk knowingly with monitoringAccept rare cosmetic defects with customer agreement
TradeoffsBalance risk reduction vs cost, schedule, other risksMore inspection cost vs residual escape risk

Audit lens: Was the strategy chosen consciously? Is residual risk documented? Did “acceptance” become silent neglect?

Scenario — tradeoff

A team could 100% inspect a feature (high cost, high detection) or redesign the fixture (higher upfront cost, lower occurrence long-term). FMEA-driven mitigation chooses fixture redesign; management accepts interim inspection until redesign is validated. The tradeoff is explicit—good risk thinking.

FMEA — Failure Mode and Effects Analysis

FMEA is a structured method to identify how something can fail, what happens, why, and how the failure is prevented or detected—then prioritize actions.

Core columns (conceptual)

ElementContent
Item / functionWhat is being analyzed
Failure modeHow it fails to meet function
EffectImpact on customer, process, safety, compliance
Severity (S)How bad the effect is
CauseMechanism leading to the failure mode
Occurrence (O)How often the cause is expected
Current controlsPrevention and detection controls
Detection (D)How likely controls detect cause/failure before escape
RPN or action priorityPrioritization (RPN = S×O×D in classic form; many orgs now use action priority tables)
Actions & ownersRisk reduction tasks
Recalculated scoresAfter actions

DFMEA vs PFMEA

TypeFocusTypical ownersExamples of failure modes
DFMEA (Design)Product / design functionDesign, systems eng.Wrong material specified; inadequate strength; software requirement gap
PFMEA (Process)Manufacturing / service process stepsProcess, quality, opsMislabel, wrong torque, skipped test, contamination

System/application FMEA variants exist; software FMEA may cover cyber and data-integrity failure modes.

Auditor evaluation points (Understand → challenge)

  • Are failure modes from real process knowledge (not only brainstorming once five years ago)?
  • Does severity reflect patient/user harm—not only scrap cost?
  • Are detection scores honest about escapes (field data)?
  • Do recommended actions actually implement and update the living FMEA?
  • Is FMEA linked to control plans, inspection, and change control?
  • After process/design change, was FMEA revisited?

Scenario — weak PFMEA

PFMEA lists “operator error” everywhere with medium severity and no poke-yoke. RPN is reduced by claiming “training” as detection. Auditors should challenge: training is often weak detection; severity may be understated for safety effects; causes should go deeper (fixture, lighting, software UI).

HACCP — Hazard Analysis and Critical Control Points

HACCP is a preventive system (classic in food safety, also adapted to other process-hazard contexts) that:

  1. Conducts hazard analysis (biological, chemical, physical—and sometimes other hazard classes by industry)
  2. Determines Critical Control Points (CCPs)
  3. Sets critical limits
  4. Establishes monitoring
  5. Defines corrective actions when limits fail
  6. Requires verification procedures
  7. Keeps records
HACCP ideaAuditor check
Hazard analysis completeMissing allergens, pathogens, foreign material?
CCP justifiedIs a step truly critical or just a prerequisite program?
Critical limits scientificLimits arbitrary or based on science/reg?
Monitoring frequency adequateCan excursions be caught in time?
Corrective action includes dispositionProduct on hold / disposition documented?
VerificationCalibration of CCP instruments; record review

Relation to FMEA: Both are structured risk tools. HACCP is especially oriented to process hazards and CCPs with continuous monitoring; FMEA is broader failure-mode prioritization for design/process. Do not treat them as identical forms.

CTQ — Critical to Quality

CTQs are the measurable characteristics that must be achieved to satisfy customer or stakeholder requirements. They translate “voice of the customer” into specs and controls.

Flow (conceptual)

Customer need → CTQ characteristic → specification / target → process control → measurement → audit evidence

Customer languageExample CTQControl idea
“Battery lasts all day”Runtime ≥ 12 h at defined loadDesign + process for capacity; sample test
“Label is readable”Contrast, font size, adhesionPrint process controls; vision system
“No contamination”Bioburden / particulate limitsClean process, environmental monitoring

Why auditors care

  • CTQs should drive inspection plans, SPC, and FMEA severity.
  • If CTQs are undefined, teams may control convenient metrics while missing what customers value.
  • Audit sampling should prefer CTQ-related records under risk-based approaches.

Scenario

A dashboard glows green on OEE while CTQ dimensional capability is poor and complaints rise. The organization optimized a non-CTQ metric—an auditor links findings to misaligned CTQ deployment.

SWOT — Strengths, Weaknesses, Opportunities, Threats

SWOT is a simple strategic matrix:

HelpfulHarmful
InternalStrengthsWeaknesses
ExternalOpportunitiesThreats

Quality / audit program uses

  • Planning audit program focus for the year
  • Supplier strategy sessions
  • CAPA system health discussions with management
  • Preparing for new standards or markets

Limits

  • SWOT is qualitative and can be vague without evidence.
  • It does not replace FMEA, HACCP, quantitative risk matrices, or formal enterprise risk management.
  • “Threat: competitors” without linkage to quality risk is weak audit evidence.
ToolBest forWeak when
FMEAStructured failure modes & prioritizationLiving document never updated; gaming RPN
HACCPHazard + CCP control in process chainsPaper CCPs without real monitoring
CTQLinking customer needs to measuresCTQs not measurable or not controlled
SWOTStrategic framingEmpty buzzwords; no action

Note: organizational risk management (IV.A.8)

BoK IV.A.8 addresses broader organizational risk management (program/business context). Domain V.H is the quality tools set—FMEA, HACCP, CTQ, SWOT, and treatment concepts. On the exam:

  • Use V.H when the stem is about tool structure, failure modes, CCPs, CTQs, SWOT cells.
  • Think IV.A.8 when the stem is enterprise risk frameworks, audit program risk, or business risk integration.

They connect (tools feed programs) but are not the same leaf of the BoK.

Putting tools together in an audit narrative

  1. CTQs define what matters.
  2. FMEA/HACCP analyze how it fails or which hazards matter.
  3. Controls and sampling manage residual risk.
  4. Change control updates tools when design/process changes.
  5. SWOT may frame annual priorities at management review.

Integrated mini-case

A dairy plant’s HACCP identifies pasteurization as a CCP with critical time/temperature limits. PFMEA for filling highlights mislabel allergen risk (high severity). CTQs include pathogen absence and correct allergen labeling. SWOT notes a strength (strong lab) and a threat (new allergen regulations). An auditor samples CCP charts, label verification, and whether FMEA actions closed after a filler change—tool coherence is the story.

Audit application checklist (Understand-level)

  1. Identify which tool the auditee claims to use—and whether the artifact matches that tool.
  2. Check linkage: CTQ ↔ FMEA severity ↔ control plan ↔ monitoring.
  3. For FMEA: challenge stale scores, weak detection, missing safety severity.
  4. For HACCP: verify CCP monitoring, critical limits, corrections, and verification.
  5. For SWOT: look for evidence-based inputs and resulting actions—not wallpaper.
  6. Confirm risk treatment (avoid/mitigate/accept) is explicit for high residual risks.
  7. After changes, confirm risk tools were updated (connects to V.F–G).

Common exam traps

  • Swapping DFMEA (design) and PFMEA (process)
  • Treating RPN as the only modern prioritization method without understanding S/O/D meaning
  • Confusing HACCP CCPs with every process step
  • Calling any customer wish a CTQ without measurability
  • Using SWOT as if it were quantitative process control
  • Mixing V.H tools with IV.A.8 organizational risk program detail
  • Assuming mitigation always means “more inspection” (redesign/avoidance may be better)

Link forward

/practice/cqaPractice questions with detailed explanations
Test Your Knowledge

A design team analyzes how a gear might fail to transmit torque, the effect on vehicle safety, and design controls before production tooling is finalized. Which tool is most appropriate?

A
B
C
D
Test Your Knowledge

In a HACCP plan, a step is designated a CCP with a critical temperature limit, continuous monitoring, and documented corrective action when the limit is exceeded. What is the primary purpose of that CCP designation?

A
B
C
D
Test Your Knowledge

“Door closing force must be 15–25 N so users can operate the door with one hand” is best classified as:

A
B
C
D
Test Your Knowledge

Management decides not to offer a high-liability product line at all after risk review. Which risk strategy does this best illustrate?

A
B
C
D
Congratulations!

You've completed this section

Continue exploring other exams