Langford Analytic · Knowledge Base

FMEA, Failure Modes & Functional Consequences

Failure-mode thinking asks not only "can this part fail?" but "what does the system do if it does?" This article covers the practical FMEA chain from item and function through failure mode and local effect to system-level consequence, detection and mitigation, using realistic structural and mechanical examples rather than a generic scoring exercise.

Article 12Failure & Design Assurance15 min read
fmeafailure-modesfailure-analysisfunctional-consequencessingle-point-failuresdetectionmitigationdesign-assurancesafetysystem-level-effects

What FMEA Is — and What It Is Not

FMEA — Failure Mode and Effects Analysis — is a structured method for examining a design to identify the ways in which its constituent items can fail, the effects of those failures at the local and system level, and the means by which the failures are detected and mitigated. Its purpose is to build engineering understanding of the failure behaviour of the system, so that the design can be improved where the consequences are unacceptable and the residual risk can be understood and accepted where it is not. FMEA is not a scoring exercise. It is not a spreadsheet that produces a numerical ranking of failure modes by a computed risk priority number. The scoring systems that are sometimes attached to FMEA — severity, occurrence and detection ratings multiplied to produce a risk priority number — are tools that some organisations and some certification bases use to prioritise attention. They are not universal, they are not mandatory, and they are not the analysis. The analysis is the engineering examination of the failure mode, its physical mechanism, its propagation through the system and its functional consequence. A numerical score without that examination is a ranking without understanding, and it is dangerous because it gives the appearance of thoroughness while providing none of the engineering insight that FMEA is supposed to produce.

FAILURE-MODE THINKING ASKS NOT ONLY "CAN THIS PART FAIL?" BUT "WHAT DOES THE SYSTEM DO IF IT DOES?" The value of FMEA is not in ranking failure modes by a score. It is in understanding the physical failure mechanism, how it propagates from the local item to the system level, and what the system does — or fails to do — as a consequence.

The FMEA Chain

A practical FMEA follows a chain that connects each item and its function to the system-level consequence of its failure. The chain has six links. First, the item and its function: what is the component, what is it supposed to do, what loads or conditions does it experience. Second, the failure mode: how can the item fail to perform its function — fracture, yielding, slip, jam, leak, loss of signal, loss of stiffness. Third, the local effect: what happens at the item itself and in its immediate vicinity when it fails. Fourth, the higher-level effect: what happens at the assembly, subsystem and system level as the failure propagates through interfaces and load paths. Fifth, detection: how would the failure be detected — by the operator, by a sensor, by an inspection, by a functional anomaly. Sixth, prevention or mitigation: what design feature, operational procedure, inspection or redundancy prevents the failure, limits its consequence or provides a fallback. Each link is an engineering question, and each requires engineering understanding to answer. A failure mode that is listed without understanding its physical mechanism is a guess. A higher-level effect that is listed without tracing the propagation through the system is an assumption. Detection that is listed without considering whether the detection actually occurs before the consequence becomes unacceptable is wishful thinking. The chain must be followed through to the system-level consequence, because that is where the engineering significance lies.

FMEA CHAIN — FROM FUNCTION TO MITIGATION

  Example: Bolted structural joint in a primary load path

  ┌─────────────┐    ┌─────────────┐    ┌─────────────┐    ┌─────────────┐
  │  ITEM &     │    │  FAILURE    │    │  LOCAL      │    │  SYSTEM     │
  │  FUNCTION   │──→ │  MODE       │──→ │  EFFECT     │──→ │  EFFECT     │
  │             │    │             │    │             │    │             │
  │ Bolted joint│    │ Joint slip  │    │ Bolts bear  │    │ Load path   │
  │ transfers   │    │ due to bolt │    │ against hole│    │ shifts to   │
  │ shear load  │    │ preload loss│    │ edges, hole │    │ adjacent    │
  │ between     │    │ or under-   │    │ elongates,  │    │ joint;      │
  │ two members │    │ tightened   │    │ friction    │    │ secondary   │
  │             │    │ bolts       │    │ capacity    │    │ load path   │
  │             │    │             │    │ exceeded    │    │ overloaded  │
  └─────────────┘    └─────────────┘    └─────────────┘    └──────┬──────┘
                                                                │
                           ┌─────────────┐    ┌─────────────┐   │
                           │  MITIGATION │    │  DETECTION  │   │
                           │  / PREVENTION│ ← │             │ ←─┘
                           │             │    │             │
                           │ Torque      │    │ Inspect for │
                           │ control on  │    │ witness     │
                           │ installation│    │ marks;      │
                           │; locking    │    │ strain gauge│
                           │ feature on  │    │ monitoring  │
                           │ bolts;      │    │ at joint;   │
                           │ redundant   │    │ functional  │
                           │ fasteners   │    │ anomaly in  │
                           │             │    │ adjacent    │
                           │             │    │ structure   │
                           └─────────────┘    └─────────────┘

  The chain must reach the SYSTEM-LEVEL consequence.
  A failure mode listed without tracing its propagation
  is a guess, not an analysis.

FMEA Elements and Engineering Content

The following table summarises each element of the FMEA chain, what it identifies, how it is determined, what it drives and what is lost without it. Each element carries engineering content that the others do not. An FMEA that omits the higher-level effect loses the system understanding. An FMEA that omits the detection loses the ability to assess whether the failure is discoverable before the consequence becomes unacceptable. An FMEA that omits the mitigation loses the design improvement that the analysis is supposed to produce.

FMEA elementWhat it identifiesHow it is determinedWhat it drivesWhat is lost without it
Item / functionThe component or feature being analysed and the function it performs in the systemFrom the design definition, the functional analysis and the system architecture; the item must be identified at a level of detail that makes the failure modes physically meaningfulThe scope of the analysis — which items are examined and at what level of detail; determines whether the FMEA covers the critical items or only the obvious onesThe FMEA may analyse the wrong items, at the wrong level of detail, or may omit items whose failure matters but is not obvious
Failure modeThe specific way in which the item fails to perform its function — fracture, yield, slip, jam, leak, loss of signal, loss of stiffness, fatigue crackFrom knowledge of the item's physics, its loading, its environment and its material behaviour; from experience with similar items in similar service; from FMEA of comparable structuresThe set of failure scenarios that the design must address; determines whether the design prevents, mitigates or accepts each modeThe FMEA may list "failure" as a generic mode without identifying the physical mechanism, which prevents meaningful mitigation — "the bolt fails" is not as useful as "the bolt fails by fatigue crack initiation at the thread root under cyclic tension"
Local effectWhat happens at the item and in its immediate vicinity when the failure mode occurs — the local structural, mechanical or functional consequenceFrom analysis of the item in isolation: what load path is lost, what clearance is violated, what leak occurs, what signal is lost, what stiffness changesThe immediate engineering consequence that must be assessed for its propagation; determines whether the local effect is tolerable or whether it propagates to a higher-level effectThe FMEA jumps from "the item failed" to "the system fails" without understanding the intermediate physical behaviour, which hides the mechanism of propagation and prevents targeted mitigation
Higher-level effectWhat happens at the assembly, subsystem and system level as the failure propagates through interfaces, load paths and functional dependenciesFrom the system architecture, the interface definitions, the load path analysis and the functional dependencies: where does the load go, what function is lost, what redundancy is activated, what the operator observesThe system-level consequence that determines the safety significance of the failure; drives the decision on whether the failure is acceptable, tolerable or unacceptableThe FMEA assesses only the local effect and misses the system consequence — a failure that is locally minor may be system-critical if it disables a primary load path or a safety function, and this is invisible without tracing the propagation
DetectionHow the failure would be detected — by the operator, by a sensor, by an inspection, by a functional anomaly, by a periodic checkFrom the operational concept, the instrumentation, the inspection programme and the failure characteristics: is the failure evident in normal operation, does it produce a symptom, is it hidden until inspectionThe detectability of the failure, which determines whether the consequence can be prevented or limited by timely action; drives the need for inspection, monitoring or fail-safe design featuresThe FMEA assumes the failure will be detected without examining how — a hidden failure that progresses undetected to a system-level consequence is far more dangerous than an evident failure that is caught early
Prevention / mitigationWhat design feature, operational procedure, inspection or redundancy prevents the failure, limits its consequence or provides a fallbackFrom the engineering response to the failure mode and its consequence: redesign to eliminate the mode, redundancy to provide a backup, inspection to detect before consequence, fail-safe design to limit the effectThe design improvement that the FMEA is supposed to produce; determines whether the failure is prevented, mitigated or accepted with residual riskThe FMEA identifies failures but does not drive design improvement — it becomes a documentation exercise rather than a design tool, and the known failure modes remain unaddressed in the design

Realistic Failure Modes — Structural and Mechanical Examples

The value of FMEA is best illustrated with realistic failure modes rather than abstract categories. The following examples show how the FMEA chain works for specific structural and mechanical items that engineers commonly encounter. Each example traces the failure from the item and its function through the failure mode, the local effect, the higher-level effect, the detection and the mitigation. The examples are illustrative; the specific failure modes, effects and mitigations for any real item depend on its design, its loading, its environment and its system context.

  • JOINT SLIP: A bolted structural joint transfers shear load between two members by friction, maintained by bolt preload. Failure mode: the bolt preload is lost — by under-torquing at installation, by relaxation over time, by thermal cycling — and the friction capacity is exceeded. Local effect: the joint slips, the bolts bear against the hole edges, the holes elongate. Higher-level effect: the load path shifts to adjacent joints or to a secondary path that may not be designed for the load; the structure redistributes, potentially overloading a neighbouring joint. Detection: witness marks on the bolt heads or the mating surfaces, strain-gauge monitoring at the joint, functional anomaly in the adjacent structure. Mitigation: torque control at installation, locking features on the bolts, redundant fasteners, designed shear pins that carry load if slip occurs.
  • SENSOR FAILURE: A position sensor provides feedback for a control system that actuates a structural surface. Failure mode: the sensor produces an erroneous signal — a hard-over signal, a loss of signal, or a drifted calibration. Local effect: the control system receives incorrect position information. Higher-level effect: the control system commands the surface to an incorrect position, potentially producing an aerodynamic disturbance or a structural overload. Detection: cross-checking against a redundant sensor, plausibility checking in the controller, observation by the operator. Mitigation: redundant sensors with voting logic, fail-safe mode that drives the surface to a neutral position on sensor disagreement, independent position monitoring.
  • ACTUATOR JAM: A hydraulic or electromechanical actuator positions a structural surface. Failure mode: the actuator jams at a fixed position due to mechanical seizure, contamination or control failure. Local effect: the surface is held at a fixed position regardless of command. Higher-level effect: the system cannot reposition the surface; if the surface is aerodynamically significant, the fixed position may produce an asymmetric load or a controllability issue. Detection: command-response monitoring, position feedback disagreement, operator observation. Mitigation: redundant actuator with bypass or fail-safe mode, structural design that tolerates the jammed position, operational procedure for jam recovery.
  • SEAL LEAK: A static or dynamic seal contains a fluid within a structural housing. Failure mode: the seal degrades — by ageing, by thermal cycling, by mechanical wear — and allows fluid to leak past it. Local effect: fluid escapes from the sealed cavity, pressure may be lost. Higher-level effect: the fluid loss may cause a hydraulic system to lose pressure, a fuel system to leak, a lubrication system to fail; the leaked fluid may cause secondary damage by contamination or fire. Detection: fluid level monitoring, pressure monitoring, visual inspection for leaks, leak detection sensors. Mitigation: redundant seals, leak-before-burst design, secondary containment, periodic seal replacement, material selection for the operating environment.
  • STRUCTURAL CRACK: A structural component develops a fatigue crack at a stress concentration — a fastener hole, a fillet radius, a welded joint. Failure mode: the crack initiates under cyclic loading and propagates over service life. Local effect: the cracked section loses stiffness and load-carrying capacity at the crack location. Higher-level effect: if the crack propagates to a critical length, the component fails; if the component is in a primary load path, the load redistributes to adjacent structure that may not be designed for it; the system may lose structural capability. Detection: non-destructive inspection at defined intervals, crack growth analysis to set the inspection interval, in-service crack monitoring where feasible. Mitigation: damage-tolerant design with inspection intervals set by crack growth analysis, redundant load paths, material selection for crack growth resistance, stress reduction at the concentration feature.

The Most Common FMEA Failure

The most common failure of FMEA is the reduction of the analysis to a scoring exercise. When the FMEA consists of a spreadsheet with failure modes listed, severity-occurrence-detection ratings assigned, and a risk priority number computed — without examining the physical failure mechanism, without tracing the propagation from local effect to system consequence, and without connecting the mitigation to the specific failure mode — the FMEA has produced a numerical ranking without engineering understanding. The ranking may prioritise some failure modes over others, but the prioritisation is based on scores that are themselves judgements, and the underlying engineering questions — what is the physical mechanism, how does it propagate, what does the system do, how is it detected, what prevents it — have not been answered. This is particularly dangerous because the FMEA has been "performed" in an administrative sense: a document exists, a process has been followed, a score has been computed. But the engineering insight that FMEA is supposed to produce — the understanding of the system's failure behaviour that drives design improvement — is absent. The score is not the analysis. The analysis is the engineering examination of the failure mode, its mechanism, its propagation and its consequence.

TREATING FMEA AS A SCORING EXERCISE WITHOUT EXAMINING THE PHYSICAL FAILURE MECHANISM AND ITS SYSTEM-LEVEL CONSEQUENCE PRODUCES A NUMERICAL RANKING WITHOUT ENGINEERING UNDERSTANDING. The score is not the analysis. The analysis is the engineering examination of how the item fails, how the failure propagates, what the system does, how it is detected and what prevents or limits it. A score without this examination is a number without engineering content.

FMEA Checklist

The following checklist supports the conduct of an FMEA that produces engineering understanding rather than a numerical ranking. It is not a mandated procedure; it is a set of engineering questions that, if addressed, produce an FMEA that drives design improvement. The specific format and any scoring system depend on the organisation, the customer and the certification basis; the engineering content must be present regardless.

  • Each item is identified at a physically meaningful level of detail — "The bolted joint" not "the fasteners" — the level must make the failure mode physically meaningful
  • Each failure mode is described by its physical mechanism — "Fatigue crack initiation at the thread root under cyclic tension" not "bolt fails"
  • The local effect is traced from the failure mode — What happens at the item and in its vicinity — the immediate physical consequence
  • The higher-level effect is traced through the system — How does the failure propagate through interfaces and load paths to the system level?
  • Detection is examined for whether it occurs before the consequence becomes unacceptable — A failure that is detected after the consequence has occurred is not effectively detectable for that consequence
  • Mitigation is connected to the specific failure mode — Not a generic "improve quality" — a specific design feature, inspection or redundancy that addresses the mechanism
  • Hidden failures are identified — A failure that produces no evident symptom until inspection is far more dangerous than an evident failure
  • Single-point failures are identified — A failure that has no redundancy and leads directly to a system-level consequence is a single-point failure — see the dedicated article on fault tolerance

Key Takeaways

FMEA is a structured method for understanding the failure behaviour of a system. Its value is in the engineering examination of the failure mechanism, its propagation and its consequence — not in a numerical score. The chain from item and function through failure mode, local effect, higher-level effect, detection and mitigation must be followed through to the system-level consequence, because that is where the engineering significance lies. Realistic failure modes — joint slip, sensor failure, actuator jam, seal leak, structural crack — illustrate how the chain works for specific structural and mechanical items. Treating FMEA as a scoring exercise produces a ranking without understanding. The score is not the analysis.

  • FMEA asks not only "can this part fail?" but "what does the system do if it does?"
  • The chain: item/function → failure mode → local effect → higher-level effect → detection → prevention/mitigation
  • Each failure mode must be described by its physical mechanism, not a generic "failure"
  • The higher-level effect must be traced through the system — a locally minor failure may be system-critical
  • Detection must be examined for whether it occurs before the consequence becomes unacceptable
  • Mitigation must be connected to the specific failure mode — not a generic improvement
  • Scoring systems are tools for prioritisation, not the analysis itself — they are not universal or mandatory
  • The score is not the analysis — the analysis is the engineering examination of the failure behaviour