8.5 Risk Management: FMEA, SWOT & Risk-Based Prioritization

Key Takeaways

  • Body of Knowledge entry III.E names two tools explicitly — failure mode and effects analysis (FMEA) and SWOT — plus the prioritization of activities and projects based on risk.
  • FMEA rates Severity, Occurrence, and Detection on 1-to-10 scales; the risk priority number is their product, ranging from 1 to 1,000.
  • The Detection scale is inverted: 1 means the control is almost certain to catch the failure, and 10 means it cannot be detected.
  • A severity rating of 9 or 10 signals a safety or regulatory consequence and requires action regardless of how low the risk priority number is.
  • SWOT separates internal factors (strengths and weaknesses) from external factors (opportunities and threats); misclassifying an internal capability as an opportunity is the most common error.
Last updated: September 2026

8.5 Risk Management: FMEA, SWOT & Risk-Based Prioritization

BoK entry III.E reads: understand the tools and techniques used to identify and communicate risks, including failure modes and effects analysis (FMEA) and Strengths, weaknesses, opportunities, threats (SWOT). Understand prioritization of activities and projects based on risk. It is capped at the Understand level, so the exam will not ask you to build a full FMEA — it will ask you to interpret ratings, read a completed worksheet, and classify SWOT factors correctly.


1. FMEA: Failure Mode and Effects Analysis

FMEA is a structured, proactive method for identifying how a design or process could fail, what the consequences would be, how likely each failure is, and how likely current controls are to catch it — before the failure occurs. Developed for US military reliability work in the 1940s and refined through aerospace and automotive programs, it is now standard across regulated industries.

The Two Principal Types

TypeObject of analysisAsks
DFMEA (Design FMEA)The product or designHow can this design fail in the customer's hands?
PFMEA (Process FMEA)The manufacturing or service processHow can this process fail to produce a conforming output?

Core Vocabulary

The exam tests these three as a chain, and candidates confuse the first two constantly:

  • Failure modehow the item fails. The manner of failure. "Weld incomplete." "Wrong label applied." "Dosage entered in the wrong field."
  • Effect — the consequence to the customer or next process. "Joint separates under load." "Product recalled for mislabelling." Effects drive Severity.
  • Causewhy the failure mode occurs. "Weld current set below specification." Causes drive Occurrence and are what corrective action attacks.

Mnemonic: the mode is what breaks, the effect is who gets hurt, the cause is why it broke.

The Three Ratings

Each is scored 1 to 10, and the scales do not all run in the same direction.

RatingQuestion1 means10 means
Severity (S)How serious is the effect?No discernible effectHazardous; safety or regulatory consequence, possibly without warning
Occurrence (O)How often is the cause expected?Failure is essentially eliminatedFailure is almost inevitable
Detection (D)How likely are current controls to catch it before it escapes?Control almost certainly detects itNo control, or cannot be detected

The Detection scale is inverted, and this is the single most tested detail in the entry. A high Detection number is bad — it means the failure will escape. Candidates who assume "10 = excellent detection" get every Detection item wrong.

Risk Priority Number

RPN=S×O×DRPN = S \times O \times D

The RPN ranges from 1 to 1,000 and is used to rank failure modes for action.

Worked example. A pharmacy labelling process has a failure mode "patient name mismatched to prescription." Severity is 9 (potential patient harm). Occurrence is 3 (uncommon). Detection is 7 (the pharmacist's visual check frequently misses it).

RPN=9×3×7=189RPN = 9 \times 3 \times 7 = 189

Now suppose barcode verification is added, dropping Detection from 7 to 2:

RPN=9×3×2=54RPN = 9 \times 3 \times 2 = 54

Note what did not change. Severity stayed at 9, because the consequence of the failure is unchanged — better detection catches the error, it does not make the error less harmful. Severity is reduced only by changing the design or the process, never by adding inspection. That is the highest-value insight in this entry.

Limitations of RPN

RPN is a convenient ranking device with real defects, and the exam tests the first one:

  • A high severity can be buried by a low product. S=10, O=1, D=2 gives an RPN of 20 — near the bottom of any ranked list — yet it is a potential fatality. The universal convention is that any severity of 9 or 10 requires action regardless of RPN.
  • The scales are ordinal, not ratio. Multiplying ordinal ranks is not mathematically rigorous; an RPN of 200 is not "twice as risky" as 100.
  • Identical RPNs can mean very different things. 5×5×8 and 10×2×10 both equal 200 with completely different risk profiles.

Because of these defects, the 2019 AIAG and VDA FMEA handbook replaced RPN in the automotive sector with Action Priority (AP) — a High, Medium, or Low rating derived from a published lookup table that weights Severity most heavily. Classic S/O/D and RPN remain the general-industry convention and are what the CQIA Body of Knowledge references.


2. SWOT Analysis

SWOT is a strategic assessment framework that sorts factors on two axes: origin (internal vs. external) and helpfulness (helpful vs. harmful).

HelpfulHarmful
Internal (within the organization's control)StrengthsWeaknesses
External (in the environment)OpportunitiesThreats

The internal/external split is the whole test. Strengths and weaknesses are things the organization has or is — capabilities, skills, equipment, certifications, culture, capital. Opportunities and threats are things that exist in the environment whether or not the organization acts — market shifts, new regulation, a competitor's move, technology change, supply disruption.

The classic error: calling an internal capability an opportunity. "Our engineers are highly skilled" is a strength, not an opportunity. "A new emissions regulation will create demand for our filtration technology" is an opportunity. If the factor would still exist if your organization vanished tomorrow, it is external.

SWOT enters the quality world through ISO 9001:2015 Clause 4.1, which requires organizations to determine the internal and external issues relevant to their purpose — SWOT and PESTLE are the tools most commonly used to satisfy it — and it feeds Clause 6.1's requirement to address risks and opportunities.

FMEA vs. SWOT

FMEASWOT
LevelOperational — a specific design or processStrategic — the whole organization or business unit
DirectionDownside only: what can failBoth upside and downside
OutputQuantified, ranked failure modes with actionsA qualitative four-quadrant picture informing strategy
Typical userCross-functional engineering/process teamLeadership team

3. Prioritizing Activities and Projects by Risk

The BoK's third clause — understand prioritization of activities and projects based on risk — is about deciding where to spend finite improvement capacity.

The Risk Matrix

The general-purpose tool is a likelihood × consequence matrix:

              CONSEQUENCE ->
            Minor  Moderate  Major  Severe
  Almost    | MED |  HIGH  | HIGH |  HIGH |
  Likely    | LOW |  MED   | HIGH |  HIGH |
  Possible  | LOW |  MED   | MED  |  HIGH |
  Unlikely  | LOW |  LOW   | MED  |  MED  |

Cells are graded Low, Medium, or High, and the grade sets the response: accept, monitor, mitigate, or avoid. Note the top-right bias — severe consequences are graded High even at lower likelihood, the same asymmetry that makes an FMEA severity of 9 or 10 actionable regardless of RPN.

Risk-Based Prioritization in Practice

Risk-based thinking directs effort in several places you will meet on the exam:

  • Project selection. Charter improvement teams against the highest-risk and highest-cost processes rather than the easiest ones.
  • Audit frequency. ISO 9001 Clause 9.2 requires the audit programme to consider process importance and prior results — high-risk processes are audited more often.
  • Control plan intensity. Characteristics with high severity receive tighter controls, more frequent verification, and error-proofing rather than inspection.
  • Supplier oversight. Higher-risk suppliers get on-site audits and source inspection; low-risk suppliers move to dock-to-stock.

The governing principle: risk is a resource-allocation tool. You cannot control everything equally, so risk analysis tells you where the finite control effort produces the greatest reduction in expected harm.

Test Your Knowledge

In an FMEA, a team adds automated vision verification to a labelling process. The Detection rating falls from 8 to 2, but the team leaves the Severity rating at 9. Is this correct?

A
B
C
D
Test Your Knowledge

Two failure modes are documented in a PFMEA. Mode A has S=10, O=1, D=2. Mode B has S=4, O=6, D=6. How should the team prioritize them?

A
B
C
D
Test Your Knowledge

A team conducting a SWOT analysis lists 'our ISO 13485 certification and experienced regulatory affairs staff' under Opportunities. How should this be classified?

A
B
C
D
Test Your Knowledge

In FMEA scoring, what does a Detection rating of 10 indicate?

A
B
C
D