7.1 Risk Identification & Hazard Analysis

Key Takeaways

  • HAZOP (Hazard and Operability Study) uses standardized parameter guide words—such as NO/NOT, MORE, LESS, AS WELL AS, PART OF, REVERSE, and OTHER THAN—to systematically identify process design deviations.
  • The Failure Mode and Effects Analysis (FMEA) Risk Priority Number (RPN) is calculated as RPN = S x O x D, ranking risk severity (S), occurrence probability (O), and detection capability (D) on 1–10 ordinal scales.
  • Modern AIAG-VDA FMEA standards replace sole reliance on RPN thresholds with Action Priority (AP) tables (High, Medium, Low) to prioritize severe safety and regulatory failure modes regardless of detection ranking.
  • A Risk Breakdown Structure (RBS) hierarchically categorizes quality, operational, technical, and external risks into structured levels to prevent systematic oversight during risk identification.
Last updated: July 2026

7.1 Risk Identification & Hazard Analysis

Introduction to Risk Identification in Quality Engineering

Risk identification is the foundational phase of risk management in quality engineering. The ASQ Certified Quality Engineer (CQE) must possess a deep understanding of systematic methodologies used to identify potential failure modes, environmental hazards, operational deviations, and process vulnerabilities before they manifest as costly nonconformances, safety incidents, or product field failures. Standardized risk identification ensures that quality systems proactively build robustness into both product design and manufacturing processes.

Hazard and Operability Study (HAZOP)

A Hazard and Operability (HAZOP) study is a structured, qualitative risk identification technique originally developed for the chemical process industry, now widely applied across high-reliability manufacturing, aerospace, and medical device sectors. HAZOP examines a process step-by-step to evaluate how deviations from design intent can cause hazards or operational problems.

Multidisciplinary Team & Node Definition

A HAZOP study is conducted by a multidisciplinary team including quality engineers, process engineers, operators, safety specialists, and maintenance personnel. The team breaks the system down into manageable sections called nodes. A node represents a specific point in a process flow, pipe segment, or operational step with defined design parameters (e.g., temperature, pressure, flow rate, or concentration).

Standardized HAZOP Parameter Guide Words

The core mechanism of HAZOP involves pairing specific process parameters with standardized guide words to systematically generate potential process deviations.

Guide WordStandard DefinitionPractical Process Example
NO / NOTComplete negation of the design intentNo chemical flow through a reactant feed line due to a jammed valve.
MORE (HIGH)Quantitative increase in a parameterExcessive temperature in a curing oven exceeding polymer degradation limits.
LESS (LOW)Quantitative decrease in a parameterInsufficient pressure in a hydraulic clamping fixture causing part movement.
AS WELL ASQualitative increase / unintended extra activityContaminant moisture introduced alongside solvent feed during washing.
PART OFQualitative decrease / incomplete compositionOmission of a critical catalyst component in a raw material batch.
REVERSELogical opposite of the intended process directionReverse fluid flow in a pump due to check valve failure and backpressure.
OTHER THANComplete substitution of parameter/materialLoading incorrect grade of resin into an injection molding hopper.

The HAZOP team evaluates each deviation to determine potential causes, consequences to safety and product quality, existing safeguards, and required corrective actions.


FMEA Risk Integration into Design

Failure Mode and Effects Analysis (FMEA) is a risk prioritization tool that evaluates potential product design failure modes (DFMEA) or manufacturing process failure modes (PFMEA).

The Failure Chain

FMEA structures risk analysis around a three-element failure chain:

  1. Root Cause: The underlying flaw (e.g., operator fatigue, material contamination, or thermal stress).
  2. Failure Mode: The specific physical manner in which a component or process step fails to meet design intent (e.g., solder joint fracture, seal leakage, or dimensional oversize).
  3. Failure Effect: The impact of the failure mode on the customer, downstream assembly, or system performance (e.g., total vehicle loss of power, fluid contamination, or functional noise).

Calculating the Risk Priority Number (RPN)

Traditionally, failure modes are scored on three criteria using 1 to 10 ordinal scales:

  • Severity ($S$): Assess the severity of the failure effect (1 = negligible, 10 = hazardous safety violation without warning).
  • Occurrence ($O$): Assess the probability or frequency of the root cause occurring (1 = extremely unlikely, 10 = almost inevitable).
  • Detection ($D$): Assess the capability of current design controls or process inspections to detect the cause or failure mode before reaching the customer (1 = guaranteed detection, 10 = no detection mechanism).

The Risk Priority Number (RPN) is calculated as: RPN=S×O×DRPN = S \times O \times D

RPN values range from 1 to 1,000. Historically, teams applied an arbitrary RPN threshold (e.g., action required if $RPN > 100$).

Transition to AIAG-VDA Action Priority (AP)

Modern automotive and industrial standards (specifically the AIAG-VDA 1st Edition FMEA Handbook) have phased out sole reliance on RPN thresholding. High RPN values can mask severe risks; for instance, a high-severity, low-detection failure ($S=10, O=2, D=2 \implies RPN=40$) might be overlooked under a threshold of 100, whereas a moderate risk ($S=4, O=5, D=5 \implies RPN=100$) would trigger action.

The Action Priority (AP) system replaces RPN thresholds with logic tables classifying risk priority into three discrete categories:

  • High (H): Action mandatory; requires engineering changes to reduce Severity or Occurrence.
  • Medium (M): Action recommended to reduce Occurrence or Detection.
  • Low (L): Current controls are acceptable; action optional.

Risk Registers & Risk Breakdown Structure (RBS)

To maintain enterprise-wide visibility of quality and process risks, organizations deploy a Risk Breakdown Structure (RBS) and a dynamic Risk Register.

Risk Breakdown Structure (RBS)

An RBS is a hierarchical taxonomy that categorizes risks into structured domain levels:

  1. Technical Risks: Material nonconformances, design complexity, equipment reliability, technology maturity.
  2. Management Risks: Resource constraints, training deficiencies, schedule pressures, communication gaps.
  3. Commercial/Supply Chain Risks: Single-source supplier vulnerability, vendor quality drift, freight delays.
  4. External Risks: Regulatory changes, environmental compliance standards, market demand shifts.

Standard Risk Register Structure

The Risk Register is a live repository that records identified risks alongside management metadata:

[Risk ID][RBS Category][Risk Description][Root Cause][Initial S, O, D / AP][Risk Owner][Mitigation Plan][Residual Score][Status]\text{[Risk ID]} \rightarrow \text{[RBS Category]} \rightarrow \text{[Risk Description]} \rightarrow \text{[Root Cause]} \rightarrow \text{[Initial S, O, D / AP]} \rightarrow \text{[Risk Owner]} \rightarrow \text{[Mitigation Plan]} \rightarrow \text{[Residual Score]} \rightarrow \text{[Status]}

By systematically conducting HAZOP studies, maintaining design-integrated FMEAs, and tracking items in a Risk Register, quality engineers build an empirical barrier against nonconformances and operational failures.

Loading diagram...
HAZOP Deviation Analysis Flowchart
Test Your Knowledge

During a HAZOP study on an automated liquid filling line, the team evaluates the scenario where an incorrect chemical fluid is loaded into the delivery tank instead of the specified cleaning solvent. Which standardized HAZOP guide word correctly classifies this deviation?

A
B
C
D
Test Your Knowledge

A design team is evaluating a potential failure mode during a DFMEA. The failure effect involves potential user injury due to thermal overload (Severity S = 9). The occurrence probability is very low (Occurrence O = 2), and current testing controls are highly effective (Detection D = 2). The resulting RPN is 9 x 2 x 2 = 36. Under the AIAG-VDA Action Priority (AP) framework, how should this risk be prioritized compared to traditional RPN thresholding?

A
B
C
D
Test Your Knowledge

An ASQ CQE is organizing an enterprise risk taxonomy to ensure supplier quality drift, single-source vulnerabilities, and logistics delays are systematically captured. Under which level-1 branch of a Risk Breakdown Structure (RBS) should these specific risks be categorized?

A
B
C
D