RSC Topic: Risk Management & Risk Register

  • PFMEA

    PFMEA, or Process Failure Mode and Effects Analysis, is a structured method used to identify, analyze, and prioritize potential failure modes in a manufacturing or operational process before and during production. It focuses on how a process can fail to meet requirements, the effects of those failures on the customer or downstream operations, and the controls used to detect or prevent them.

    What PFMEA includes

    In regulated and industrial manufacturing environments, a PFMEA typically:

    • Maps process steps for a product or family of products
    • Lists potential failure modes at each step (for example incorrect torque, missing component, contamination, mislabeling)
    • Describes potential effects of each failure (for example safety issue, functional failure, scrap, rework, field return)
    • Identifies potential causes (for example operator error, machine instability, inadequate work instructions, incorrect parameter settings)
    • Documents existing prevention and detection controls (for example poka-yoke devices, MES checks, in-process inspection, automated test)
    • Assigns rankings for severity, occurrence, and detection to estimate risk priority
    • Defines and tracks actions to reduce risk (for example process redesign, updated control plans, additional checks, parameter limits enforced in MES)

    PFMEA is often maintained as a living document throughout the product and process lifecycle. It is typically linked to control plans, work instructions, change control, and electronic systems such as MES, QMS, and PLM.

    Use in automotive and other regulated industries

    In the automotive industry, PFMEA is a core element of advanced product quality planning (APQP) and is referenced by standards such as IATF 16949. It is used together with design FMEA (DFMEA) to manage risk from design through production. Similar approaches are used in aerospace, medical device, and other regulated manufacturing sectors, often with sector-specific formats and ranking schemes.

    What PFMEA is not

    • It is not the same as a design FMEA, which focuses on product design risk rather than process execution risk.
    • It is not a control plan, but PFMEA content is frequently used to create and update the control plan.
    • It is not, by itself, evidence of compliance or certification. It is one source of documented risk analysis within a broader quality management system.

    Operational role in manufacturing systems

    From a systems and OT/IT perspective, PFMEA information is commonly used to:

    • Drive requirements for in-process checks and interlocks in MES or SCADA
    • Define critical process parameters and alarms logged by automation systems
    • Inform sampling plans, inspection points, and test coverage in QMS or LIMS
    • Support change impact assessments when equipment, materials, or methods are modified
    • Prioritize data collection and analytics around high-risk failure modes

    Common confusion

    • PFMEA vs DFMEA: PFMEA addresses how the manufacturing or service process can fail. DFMEA addresses how the product design can fail to meet requirements. In many organizations they are linked, but they target different types of risk.
    • PFMEA vs risk register: A risk register is a general list of risks at project, program, or organizational level. PFMEA is a structured, step-by-step analysis of process risks with quantitative rankings specific to a defined process.
  • Moderate Impact

    Moderate impact is a classification level used to describe the expected consequence or severity of an event, change, failure, or risk. It indicates that the effect is noticeable and may disrupt operations, quality, safety, or compliance, but is generally considered controllable with planned responses and does not threaten the overall viability of the organization.

    How “moderate impact” is used in industrial and regulated environments

    In manufacturing, particularly in regulated sectors, the term appears in several contexts:

    • Risk assessments and FMEAs: A failure mode or hazard may be rated as moderate impact when it can cause scrap, rework, schedule slips, or local safety concerns, but is unlikely to lead to catastrophic injury, systemic quality escape, or major regulatory action.
    • Change control: Engineering changes, process changes, or software updates (such as to MES, ERP, or quality systems) may be labeled moderate impact when they affect multiple products, steps, or users but are still manageable through standard validation, training, and rollout plans.
    • Quality and nonconformance management: A nonconformance might be classified as moderate impact if it affects product fitness-for-use or yields, but can be contained, reworked, or dispositioned through normal MRB and CAPA workflows.
    • IT/OT and cybersecurity: In frameworks such as NIST, a moderate impact system or incident is one where loss of confidentiality, integrity, or availability could cause significant operational disruption or regulatory exposure, but not a complete shutdown or uncontrolled safety risk.

    Typical characteristics of moderate impact

    While each organization defines thresholds differently, moderate impact classifications commonly indicate:

    • Measurable cost, schedule, or yield impact, but within planned risk tolerance
    • Limited scope of effect (for example, one site, one line, or a defined part family)
    • Corrective and preventive actions are required, but handled within standard governance
    • Potential for regulatory or customer attention if not contained, but not an immediate severe breach

    Moderate impact is usually part of an ordered scale (for example, low / moderate / high, or minor / moderate / major). The exact criteria should be defined in the organization’s risk, quality, safety, and change-control procedures.

    Common confusion

    • Moderate impact vs. likelihood: Impact describes consequence severity if an event occurs, while likelihood (or probability) describes how often it is expected to occur. Risk scoring often combines both.
    • Moderate impact vs. priority: A moderate impact issue can still be treated with high priority if it is frequent, time-critical, or tied to key customers or regulators.

    Operational considerations

    In practice, labeling something as moderate impact typically triggers:

    • Documented assessment and justification of the rating
    • Defined review or approval paths (for example, quality, engineering, IT/OT, or compliance sign-off)
    • Tracking in risk registers, change logs, or nonconformance systems for future review

    Organizations should clearly document what constitutes moderate impact in their internal procedures so that teams apply the term consistently across sites, products, and functions.

  • Failure Mode and Effects Analysis (FMEA)

    Failure Mode and Effects Analysis (FMEA) is a structured, systematic method used to identify how a product, system, or process can fail, evaluate the potential effects of those failures, and prioritize actions to reduce the likelihood or impact of those failures. In industrial and regulated manufacturing environments, FMEA is commonly applied to equipment designs, production processes, automation, and control systems.

    What FMEA includes

    FMEA typically involves a cross-functional team working through a series of steps:

    • Define scope and boundaries: Clarify the system, subsystem, or process being analyzed and the intended operating conditions.
    • Identify functions: List what the item or process is supposed to do, including performance, safety, quality, and regulatory-related functions.
    • Identify failure modes: For each function, identify specific ways it could fail to meet requirements (e.g., valve stuck open, recipe parameter out of range, incorrect batch record entry).
    • Determine effects of failure: Describe what happens if each failure occurs, including impact on safety, product quality, compliance, equipment, throughput, or downstream operations.
    • Identify causes and controls: Document likely causes (e.g., wear, misconfiguration, operator error, software bug) and existing controls that prevent or detect the failure (e.g., interlocks, alarms, procedures, inspections).
    • Estimate risk: Use a rating scheme (commonly severity, occurrence, and detection) to approximate relative risk for each failure mode, often summarized as a Risk Priority Number (RPN) or through ranked risk levels.
    • Prioritize actions: Select and document follow-up actions to reduce risk, such as design changes, process controls, automation modifications, training, or additional monitoring.

    Common types of FMEA in manufacturing

    • Design FMEA (DFMEA): Focuses on the design of products, equipment, tooling, or automation. It considers how design features, components, and interfaces could fail and affect performance, safety, or regulatory requirements.
    • Process FMEA (PFMEA): Focuses on manufacturing and assembly processes, including manual operations, machine steps, MES workflows, batch processes, data flows, and supporting utilities. It looks at failures such as incorrect parameter settings, mixing steps out of sequence, or data handoff errors between OT and IT systems.
    • System or functional FMEA: Evaluates higher-level systems such as integrated production lines, control architectures, or end-to-end value streams, including interfaces between MES, ERP, quality systems, and shop-floor controls.

    Operational use in industrial and regulated environments

    In operations and manufacturing systems, FMEA commonly appears as:

    • Input to control strategies: Results inform critical control points in MES, recipe management, interlocks, alarm strategies, and quality checks.
    • Basis for preventive maintenance and monitoring: Identified failure modes drive maintenance tasks, instrument calibrations, and condition monitoring on key assets.
    • Support for validation and qualification: In regulated industries, FMEA-style risk analysis is often used to justify testing focus, documentation depth, and segregation of critical and non-critical functions.
    • Link to CAPA and quality systems: High-risk failure modes can be tracked through corrective and preventive action (CAPA) processes, with FMEA updated as actions are implemented.
    • Design of MES and data flows: For integrated OT/IT systems, FMEA can be applied to data entry, recipe execution, electronic batch records, and interface failures that can affect product quality or traceability.

    What FMEA is not

    FMEA is:

    • Not a guarantee of safety or compliance: It is a structured tool for risk identification and prioritization, but it does not by itself ensure that all risks are eliminated or that any regulatory requirement is fulfilled.
    • Not a one-time exercise: It should be maintained as designs, processes, automation, and quality controls change.
    • Not the same as root cause analysis: FMEA is forward-looking, considering potential failures before they occur, whereas root cause analysis investigates failures after the fact.

    Common confusion and related concepts

    • FMEA vs. FMECA: Failure Mode, Effects, and Criticality Analysis (FMECA) extends FMEA by adding more explicit criticality evaluation and ranking methods. In many industrial settings, the term FMEA is used broadly even when criticality scoring is included.
    • FMEA vs. risk matrix: A risk matrix is a higher-level risk visualization tool, while FMEA is a detailed, line-by-line analysis of specific failure modes, often feeding into or supporting a risk matrix.
    • FMEA vs. HACCP or process hazard analysis: In some regulated sectors, specialized hazard analysis frameworks exist. These may use FMEA-like concepts but follow sector-specific terminology and structures.

    Integration with standards and frameworks

    FMEA is referenced or aligned with various industry and corporate risk management frameworks. In manufacturing, it is often linked with:

    • Quality management standards: Used as a method within broader risk-based quality management and continual improvement approaches.
    • Reliability and maintenance practices: Integrated into reliability-centered maintenance and asset management planning.
    • Manufacturing systems models: Applied at different levels of manufacturing system hierarchy, from equipment modules to integrated OT/IT architectures.

    Regardless of the specific standard or sector, FMEA commonly refers to the same core idea: a structured, team-based method for identifying potential failure modes, understanding their effects, and prioritizing actions to manage risk in products and processes.

  • Risk control

    Risk control commonly refers to the process of selecting, implementing, and maintaining measures that reduce identified risks to an acceptable level. In industrial operations and regulated manufacturing environments, it is a core part of formal risk management, bridging the gap between risk assessment and daily operational practice.

    What risk control includes

    In a manufacturing or industrial context, risk control typically includes:

    • Defining control measures such as engineering controls, procedural controls, administrative controls, system safeguards, and training.
    • Implementing controls in processes, equipment, IT/OT systems, and workflows (for example, interlocks, standardized work, segregation of duties, or system access rules).
    • Documenting controls in policies, work instructions, SOPs, and configuration baselines so that they are visible, auditable, and repeatable.
    • Monitoring control effectiveness through audits, KPIs, incident and nonconformance data, and system logs.
    • Maintaining and improving controls when conditions change, new hazards are identified, or residual risk is no longer acceptable.

    Risk control applies to different risk types relevant to manufacturing, such as product quality risk, worker safety risk, cybersecurity and data integrity risk, supply chain disruption risk, and environmental or regulatory noncompliance risk.

    Operational meaning in manufacturing and regulated environments

    On the shop floor and in supporting systems, risk control shows up as concrete safeguards built into processes and tools, for example:

    • Process and quality controls, such as in-process inspections, poka-yoke devices, mandatory checklist steps in MES, and automated recipe controls that limit parameter changes.
    • IT/OT and cybersecurity controls, such as access control, network segmentation, change management on PLC programs, system logging, and hardened configurations aligned with common security frameworks.
    • Documented procedures and training, where standard operating procedures, digital work instructions, and training records define how operators and engineers must act to keep risk within defined limits.
    • Supply chain and logistics controls, such as dual sourcing strategies, controlled supplier qualification, inspection on receipt, and traceability and genealogy in ERP/MES.
    • Governance and review mechanisms, such as internal process audits, layered process audits, management review, and CAPA that modify or add controls when issues are detected.

    Risk control measures are usually derived from structured risk assessments, hazard analyses, FMEAs, cybersecurity risk assessments, or similar methods. The output of those activities frequently becomes requirements for controls to be configured in MES, QMS, ERP, PLM, or OT systems.

    Risk control versus related terms

    • Risk control vs. risk assessment: Risk assessment identifies and analyzes risks (likelihood, impact, causes). Risk control is about what is done in response, and how safeguards are implemented and maintained.
    • Risk control vs. risk mitigation: In many industrial and quality contexts, the terms are used interchangeably. Some frameworks use “risk control” for the specific measures, and “risk mitigation” for the broader process of reducing risk, which can include accepting, transferring, or avoiding risk.
    • Risk control vs. monitoring: Control consists of the measures that act on the process or system (e.g., interlocks, approvals, workflows). Monitoring observes and reports on performance (e.g., alarms, dashboards, audit trails) to check whether controls are effective.

    Common confusion

    Risk control is sometimes loosely used to describe any risk-related activity. In regulated manufacturing and quality systems, it more precisely refers to the set of measures that are selected based on a prior assessment and then embedded into processes, systems, and documentation. It should not be limited to a single department, such as EHS or IT, because effective risk control typically spans operations, engineering, quality, supply chain, and information security.

  • Business Impact

    Business impact commonly refers to the measurable effect that an event, decision, change, failure, or risk has on an organization’s ability to achieve its objectives. In industrial and regulated manufacturing environments, it focuses on how operations, quality, compliance, financial performance, and reputation are affected.

    Core meaning

    In an operational and risk context, business impact typically includes:

    • Operational impact: Disruption to production, schedules, throughput, or delivery commitments.
    • Financial impact: Direct costs (scrap, rework, downtime, expedited freight) and indirect costs (lost margin, penalties, lost opportunities).
    • Quality and compliance impact: Effects on product quality, batch release, deviations, recalls, or regulatory findings.
    • Customer and market impact: Effects on service levels, lead times, contract performance, and reputation.
    • Information and cybersecurity impact: Consequences of data loss, OT/IT incidents, or system unavailability on safe and compliant production.

    Business impact is usually expressed in quantitative terms (cost, time, volume, likelihood) or with defined impact levels (for example: minor, moderate, major, critical) within a risk or change framework.

    Use in manufacturing workflows

    In manufacturing systems and governance processes, business impact often appears as a required field or assessment step, for example:

    • Risk assessments and business impact analysis (BIA): Evaluating how loss of a process, system, or supplier would affect production, compliance, and safety-critical obligations.
    • Change control: Classifying and approving changes to equipment, recipes, MES, ERP, or procedures by assessing their potential business impact.
    • Incident and deviation management: Determining the impact of quality events, OT/IT outages, or nonconformances on product, batches, and customers.
    • Prioritization of work: Using impact scores to prioritize CAPA, maintenance, upgrades, or cybersecurity hardening activities.

    Business impact vs. related concepts

    • Business impact vs. risk: Risk combines the likelihood of an event with its impact. Business impact focuses on the consequence side only, assuming the event occurs.
    • Business impact vs. root cause: Root cause explains why something happened. Business impact describes what that event did to the business.
    • Business impact vs. criticality: Criticality is a property of an asset, process, or system (how important it is). Business impact is the effect when that asset, process, or system is disrupted or changed.

    Common confusion

    The term is sometimes used loosely as a synonym for “importance” or “priority.” In formal risk management, change control, and business continuity planning, business impact should be tied to specific, documented effect types (such as production loss, regulatory exposure, or contractual breach) and to defined impact scales.