8.5 Risk Management: FMEA, SWOT & Risk-Based Prioritization
Key Takeaways
- Body of Knowledge entry III.E names two tools explicitly — failure mode and effects analysis (FMEA) and SWOT — plus the prioritization of activities and projects based on risk.
- FMEA rates Severity, Occurrence, and Detection on 1-to-10 scales; the risk priority number is their product, ranging from 1 to 1,000.
- The Detection scale is inverted: 1 means the control is almost certain to catch the failure, and 10 means it cannot be detected.
- A severity rating of 9 or 10 signals a safety or regulatory consequence and requires action regardless of how low the risk priority number is.
- SWOT separates internal factors (strengths and weaknesses) from external factors (opportunities and threats); misclassifying an internal capability as an opportunity is the most common error.
8.5 Risk Management: FMEA, SWOT & Risk-Based Prioritization
BoK entry III.E reads: understand the tools and techniques used to identify and communicate risks, including failure modes and effects analysis (FMEA) and Strengths, weaknesses, opportunities, threats (SWOT). Understand prioritization of activities and projects based on risk. It is capped at the Understand level, so the exam will not ask you to build a full FMEA — it will ask you to interpret ratings, read a completed worksheet, and classify SWOT factors correctly.
1. FMEA: Failure Mode and Effects Analysis
FMEA is a structured, proactive method for identifying how a design or process could fail, what the consequences would be, how likely each failure is, and how likely current controls are to catch it — before the failure occurs. Developed for US military reliability work in the 1940s and refined through aerospace and automotive programs, it is now standard across regulated industries.
The Two Principal Types
| Type | Object of analysis | Asks |
|---|---|---|
| DFMEA (Design FMEA) | The product or design | How can this design fail in the customer's hands? |
| PFMEA (Process FMEA) | The manufacturing or service process | How can this process fail to produce a conforming output? |
Core Vocabulary
The exam tests these three as a chain, and candidates confuse the first two constantly:
- Failure mode — how the item fails. The manner of failure. "Weld incomplete." "Wrong label applied." "Dosage entered in the wrong field."
- Effect — the consequence to the customer or next process. "Joint separates under load." "Product recalled for mislabelling." Effects drive Severity.
- Cause — why the failure mode occurs. "Weld current set below specification." Causes drive Occurrence and are what corrective action attacks.
Mnemonic: the mode is what breaks, the effect is who gets hurt, the cause is why it broke.
The Three Ratings
Each is scored 1 to 10, and the scales do not all run in the same direction.
| Rating | Question | 1 means | 10 means |
|---|---|---|---|
| Severity (S) | How serious is the effect? | No discernible effect | Hazardous; safety or regulatory consequence, possibly without warning |
| Occurrence (O) | How often is the cause expected? | Failure is essentially eliminated | Failure is almost inevitable |
| Detection (D) | How likely are current controls to catch it before it escapes? | Control almost certainly detects it | No control, or cannot be detected |
The Detection scale is inverted, and this is the single most tested detail in the entry. A high Detection number is bad — it means the failure will escape. Candidates who assume "10 = excellent detection" get every Detection item wrong.
Risk Priority Number
The RPN ranges from 1 to 1,000 and is used to rank failure modes for action.
Worked example. A pharmacy labelling process has a failure mode "patient name mismatched to prescription." Severity is 9 (potential patient harm). Occurrence is 3 (uncommon). Detection is 7 (the pharmacist's visual check frequently misses it).
Now suppose barcode verification is added, dropping Detection from 7 to 2:
Note what did not change. Severity stayed at 9, because the consequence of the failure is unchanged — better detection catches the error, it does not make the error less harmful. Severity is reduced only by changing the design or the process, never by adding inspection. That is the highest-value insight in this entry.
Limitations of RPN
RPN is a convenient ranking device with real defects, and the exam tests the first one:
- A high severity can be buried by a low product. S=10, O=1, D=2 gives an RPN of 20 — near the bottom of any ranked list — yet it is a potential fatality. The universal convention is that any severity of 9 or 10 requires action regardless of RPN.
- The scales are ordinal, not ratio. Multiplying ordinal ranks is not mathematically rigorous; an RPN of 200 is not "twice as risky" as 100.
- Identical RPNs can mean very different things. 5×5×8 and 10×2×10 both equal 200 with completely different risk profiles.
Because of these defects, the 2019 AIAG and VDA FMEA handbook replaced RPN in the automotive sector with Action Priority (AP) — a High, Medium, or Low rating derived from a published lookup table that weights Severity most heavily. Classic S/O/D and RPN remain the general-industry convention and are what the CQIA Body of Knowledge references.
2. SWOT Analysis
SWOT is a strategic assessment framework that sorts factors on two axes: origin (internal vs. external) and helpfulness (helpful vs. harmful).
| Helpful | Harmful | |
|---|---|---|
| Internal (within the organization's control) | Strengths | Weaknesses |
| External (in the environment) | Opportunities | Threats |
The internal/external split is the whole test. Strengths and weaknesses are things the organization has or is — capabilities, skills, equipment, certifications, culture, capital. Opportunities and threats are things that exist in the environment whether or not the organization acts — market shifts, new regulation, a competitor's move, technology change, supply disruption.
The classic error: calling an internal capability an opportunity. "Our engineers are highly skilled" is a strength, not an opportunity. "A new emissions regulation will create demand for our filtration technology" is an opportunity. If the factor would still exist if your organization vanished tomorrow, it is external.
SWOT enters the quality world through ISO 9001:2015 Clause 4.1, which requires organizations to determine the internal and external issues relevant to their purpose — SWOT and PESTLE are the tools most commonly used to satisfy it — and it feeds Clause 6.1's requirement to address risks and opportunities.
FMEA vs. SWOT
| FMEA | SWOT | |
|---|---|---|
| Level | Operational — a specific design or process | Strategic — the whole organization or business unit |
| Direction | Downside only: what can fail | Both upside and downside |
| Output | Quantified, ranked failure modes with actions | A qualitative four-quadrant picture informing strategy |
| Typical user | Cross-functional engineering/process team | Leadership team |
3. Prioritizing Activities and Projects by Risk
The BoK's third clause — understand prioritization of activities and projects based on risk — is about deciding where to spend finite improvement capacity.
The Risk Matrix
The general-purpose tool is a likelihood × consequence matrix:
CONSEQUENCE ->
Minor Moderate Major Severe
Almost | MED | HIGH | HIGH | HIGH |
Likely | LOW | MED | HIGH | HIGH |
Possible | LOW | MED | MED | HIGH |
Unlikely | LOW | LOW | MED | MED |
Cells are graded Low, Medium, or High, and the grade sets the response: accept, monitor, mitigate, or avoid. Note the top-right bias — severe consequences are graded High even at lower likelihood, the same asymmetry that makes an FMEA severity of 9 or 10 actionable regardless of RPN.
Risk-Based Prioritization in Practice
Risk-based thinking directs effort in several places you will meet on the exam:
- Project selection. Charter improvement teams against the highest-risk and highest-cost processes rather than the easiest ones.
- Audit frequency. ISO 9001 Clause 9.2 requires the audit programme to consider process importance and prior results — high-risk processes are audited more often.
- Control plan intensity. Characteristics with high severity receive tighter controls, more frequent verification, and error-proofing rather than inspection.
- Supplier oversight. Higher-risk suppliers get on-site audits and source inspection; low-risk suppliers move to dock-to-stock.
The governing principle: risk is a resource-allocation tool. You cannot control everything equally, so risk analysis tells you where the finite control effort produces the greatest reduction in expected harm.
In an FMEA, a team adds automated vision verification to a labelling process. The Detection rating falls from 8 to 2, but the team leaves the Severity rating at 9. Is this correct?
Two failure modes are documented in a PFMEA. Mode A has S=10, O=1, D=2. Mode B has S=4, O=6, D=6. How should the team prioritize them?
A team conducting a SWOT analysis lists 'our ISO 13485 certification and experienced regulatory affairs staff' under Opportunities. How should this be classified?
In FMEA scoring, what does a Detection rating of 10 indicate?