A Process FMEA is a team's written answer to three questions, asked at every step of a process: what could this step get wrong, how much would it matter, and what is standing in the way. Done properly, it is where control plans come from, where error-proofing projects get chosen, and where a factory's scarce improvement hours get pointed at the risks that deserve them.
Done the way it is usually done, it is a spreadsheet produced in a hurry for a PPAP submission, rated by one engineer at a desk, filed, and reopened only when an auditor asks for it — at which point it describes a process that has since changed twice and a risk picture nobody believes. The previous article in this series called the control plan the most commonly fictional document in a factory. The PFMEA is where the fiction starts, because everything downstream inherits it.
This article walks the method as it stands today — the AIAG-VDA 7-step approach, which is not the FMEA most people were trained on. The form changed, the ratings changed, and the number everyone used to argue about is gone entirely. It also starts one document earlier than most FMEA guides do, because the handbook itself does: with the process flow.
An FMEA is not a form to fill in. It is an argument, made in writing, that you understand your process well enough to say where it will fail — and the quality of the argument is decided before the first rating, by whether the structure it analyses matches the floor.
First, the handbook: what "AIAG-VDA" means and why it exists
For decades there were two FMEA worlds. North American automotive ran on AIAG's FMEA manual (4th edition, 2008) — the classic ten-column form with Severity × Occurrence × Detection multiplied into an RPN. German automotive ran on VDA Volume 4 — a structure-tree method, more analytical, different form, different ratings. Suppliers serving both markets maintained two FMEAs for the same process, or fought their customers about which format counted.
The AIAG & VDA FMEA Handbook (1st edition, June 2019) harmonised the two into one method. As of this writing it is still the current edition — there is no second edition — and it is what most OEM customer-specific requirements now point to for new programmes. It kept VDA's structured thinking, kept AIAG's accessibility, standardised the seven steps, and replaced RPN with Action Priority. If your PFMEA training predates 2019, the method has moved.
Three practical notes before the walk-through. The handbook is a copyrighted document — your team needs a licensed copy, because the full severity, occurrence and detection criteria tables and the complete Action Priority table live there and only there. Customer-specific requirements sit above all of it: several OEMs modify the rating tables or dictate form content, and where they do, the customer wins. And the handbook covers three FMEA types — Design FMEA, Process FMEA, and FMEA-MSR, a supplement for monitoring and system response in the field. This article is about the PFMEA, which is the one the control plan depends on.
Step zero, in effect: the process flow diagram
The 7 steps formally begin with planning, but the document the whole analysis stands on is the process flow diagram — every step of the process, in the order the part actually moves. The handbook's Structure Analysis is built directly from it. A step missing from the flow is a step the PFMEA never analyses, which makes the flow's completeness the ceiling on the FMEA's.
What separates a useful flow from a wall decoration:
- It includes the unglamorous steps. Receiving, storage, transport between operations, queues, wash lines, packing. They add no value, which is exactly why they are where damage, corrosion, mix-ups and FIFO breaks live. A flow that shows only the value-adding "happy path" hands the PFMEA a censored view of the process.
- It shows every rework loop, with its re-entry rule in writing. Where do reworked parts go back in, and which downstream checks do they repeat? This is the single most audited line on the diagram, because a rework arrow with no rule means repaired parts can skip the checks that matter most. If your flow has no rework loop and your scrap ledger says otherwise, the flow is describing a different factory.
- It numbers the steps once, for all three documents. OP10, OP20, OP30 with gaps for insertions — and the PFMEA and control plan reuse those numbers verbatim. When the three documents number their steps differently, every revision updates two of them and orphans the third, and every audit turns into a reconciliation exercise.
- It names what each step creates and what each step depends on. Product characteristics (the formed height, the weld length) with their specification, and process characteristics (the tonnage, the locked weld recipe) that make them happen. These two lists become, respectively, the failure modes' subject matter and the prevention controls' raw material.
The free template with this article is exactly that document — a blank flow with step-type symbols, a worked example for a welded bracket that carries the same operation numbers as the control plan template's example, and a ten-point health check for the flows you already have.
The seven steps, walked
The handbook organises the PFMEA into seven steps, grouped three-three-one: system analysis (1–3), failure analysis and risk mitigation (4–6), and communication (7). In practice a team moves left to right across the form, one process step at a time.
Step 1 — Planning and preparation
Scope, before analysis. The handbook frames it as the five Ts: InTent (why is this FMEA being done), Timing (when — ideally before process design freezes, not after the line is running), Team (who), Task (which of the seven steps, on what), and Tools (what software or format). The output is boring and vital: a named cross-functional team, a defined boundary (which part numbers, which operations, what is excluded), and the base FMEA it builds on, if a family or foundation FMEA exists.
The team requirement is not ceremony. A PFMEA rated by one quality engineer alone is one person's guesses, formatted. Occurrence ratings need the people who see the failures — production, maintenance, the setter — and severity needs someone who knows what the failure does downstream. The handbook's core team is typically manufacturing engineering, quality, production and maintenance, extended as needed.
Step 2 — Structure analysis
Here the flow diagram becomes the FMEA's skeleton. The structure has three levels: the process item (the whole process or line under analysis), the process steps (the operations off the flow — OP10 blank and form, OP20 robot weld), and the work elements — the 4M contributors to each step: man, machine, material, method (some add environment). The work element is where causes will live: a weld can fail because of the torch (machine), the wire batch (material), or the undocumented recipe edit (method), and structuring them explicitly stops the analysis collapsing into "operator error" for everything.
Step 3 — Function analysis
Every step and work element gets its function written down, in positive terms, with its characteristic: form bracket to drawing — height 24.5 ± 0.30 mm; press delivers set tonnage each stroke. This step feels bureaucratic and is quietly the most important thinking in the document, because a failure is only definable as the loss of a function. Teams that skip to failure modes produce vague entries like "bad weld"; teams that wrote the function first produce "weld length below 12 mm minimum" — a failure you can rate, detect and control.
Step 4 — Failure analysis
Now the chains. For each function: the failure mode (how the step fails to deliver its function), the failure effects (what that does — at your plant, at the next process, and at the end user, rated at the worst credible level), and the failure causes (why, at the work-element level). Effect–mode–cause, linked. The discipline that keeps this honest is to work mode-first: ask "what could this step get wrong?", then trace effects upward and causes downward, one chain per row.
Two habits mark a good Step 4. Effects are written to where they actually land — if a short weld means the bracket can separate in vehicle service, the effect says so, not "reject at next station". And causes are specific enough to act on: "torch position drift; spatter build-up on nozzle" points at a prevention control, "welding problem" points at nothing.
Step 5 — Risk analysis
Each chain gets its current controls and its ratings. The handbook is precise about a distinction older FMEAs blurred: prevention controls act on the cause and inform the occurrence rating; detection controls act on the failure mode or cause and inform the detection rating. The tool PM schedule prevents; the hourly plug-gauge check detects. Writing them in separate columns forces the team to notice when a line has plenty of detection and no prevention at all — inspection wearing a better title, as the control plan article put it.
Then Severity, Occurrence and Detection, each 1–10, each rated against the handbook's criteria tables:
- Severity belongs to the effect and never improves with controls. A safety-relevant effect is a 9 or 10 whether it happens yearly or never.
- Occurrence belongs to the cause, given the prevention controls actually in place. Only better prevention lowers it.
- Detection belongs to the current detection controls, rated as they actually run. An SPC chart nobody plots is not detection. A rating of 1 is reserved for detection the failure genuinely cannot pass — an interlock, proven and challenged — not for "we would definitely notice".
The commonest rating failure is optimism about detection, because D is the easiest number to flatter. The tell at audit is a column of 2s attached to visual checks.
Step 6 — Optimization
Actions, with owners, target dates and a status that the handbook expects you to track: open, decision pending, implementation pending, completed, not implemented. Two rules matter more than the rest. Prevention actions beat detection actions — lowering occurrence removes the failure, improving detection only catches it — and re-rating happens when an action is verified effective, not when it is installed. A camera check that is mounted but not yet proven has changed nothing about your risk; the new S/O/D wait for the evidence.
Step 6 is also where the PFMEA hands the control plan its content: a completed detection action becomes a control-plan evaluation method and frequency; a completed prevention action becomes a control method. If you trace a good control plan line backwards, you usually land on a Step 6 row with a completion date.
Step 7 — Results documentation
The report-out: scope, how the analysis was done, the risk summary, the high-priority items and what was done about them, and the plan for keeping the document alive. For most suppliers this is the FMEA itself plus a one-page summary for management — which matters more than it sounds, because the handbook expects severity-9 and -10 risks to have management visibility, and Step 7 is where they get it.
Action Priority: why RPN is gone, and what the letters oblige you to do
For thirty years FMEA risk was ranked by RPN — Severity × Occurrence × Detection, a number from 1 to 1000, usually with a company threshold ("act on anything over 100"). The 2019 handbook retired it, for reasons every practitioner had already met:
- Equal RPNs hide unequal risks. S9 × O2 × D2 = 36: a safety-relevant failure, quietly rated as less urgent than a cosmetic issue at 48. S2 × O10 × D10 = 200: an annoyance you cannot detect, outranking both. Multiplication treats the three numbers as interchangeable, and they are not — severity is a different kind of fact than the other two.
- Thresholds get gamed. Any team can find one point of detection optimism to bring 105 under 100. The threshold becomes the target, and the ratings bend around it.
- The scale is an illusion. The three ratings are ordinal — rankings, not measurements — and multiplying rankings produces a number with the texture of precision and none of its meaning. Of the 1000 possible products, only 120 distinct values exist, unevenly spread.
Action Priority replaces the number with a lookup. For every combination of S, O and D, the handbook's AP table assigns High, Medium or Low — a thousand combinations, decided once, weighted deliberately: severity first, then occurrence, then detection. Your spreadsheet or FMEA software resolves it the moment the three ratings are in; nobody computes anything, and there is no threshold to negotiate.
The letters carry defined obligations, and the wording rewards attention:
- High — the team must either define an appropriate action to lower occurrence and/or improve detection, or document why the current controls are adequate as they are. Justification in writing is a legitimate close-out; silence is not.
- Medium — the team should do the same.
- Low — the team could act to improve further.
Notice what AP is not. It is not a risk-acceptance stamp — the handbook is explicit that AP prioritises the need for action, it never declares a risk acceptable. And it has corners that surprise people trained on criticality thinking: a severity-9 effect with genuinely excellent prevention and detection can come out Low, which is the table working as designed — occurrence and detection are what you can change; severity is what you are stuck with. The counterweight is the management-visibility expectation on all severity-9/10 lines, whatever their letter. The two habits that keep the system honest: rate first and read the letter after, never the reverse; and treat a surprising letter as information about your controls, not as a scoring error to tune away.
Can you still quote RPN? Some customers' requirements still reference it during the long transition tail, and nothing stops you computing it alongside. But for new programmes under AIAG-VDA-aligned customer requirements, AP is the method — and running both usually means arguing about two rankings instead of one.
Special characteristics: the thread that ties the three documents
Step 5 is also where special characteristics get identified — the product and process characteristics where variation disproportionately affects safety, compliance, fit or function, flagged with your customer's symbol. The flag is a routing instruction: a special characteristic identified in the PFMEA must appear on the drawing, on the process flow, on the control plan with visibly tighter controls, and in the operator's work instruction — same symbol everywhere, one correlation an IATF auditor reads across all four documents. An SC that exists in the PFMEA and nowhere else is one of the fastest findings in the business, and the fix is procedural, not clever: every document that carries characteristics gets updated in the same change event, or the set drifts.
What auditors actually find
The same handful of PFMEA findings account for most of the audit pain, and none of them is subtle:
- The three documents disagree. Operation numbers, characteristics or SC flags that differ between flow, PFMEA and control plan. Ten minutes with a highlighter finds it; a shared numbering rule prevents it.
- The PFMEA stopped in time. Revision date two years old; three customer complaints since; none of them reflected. Corrective action that does not end with "does the PFMEA change?" answered in writing is corrective action that changes nothing upstream.
- Orphan special characteristics — flagged here, invisible on the control plan, or vice versa.
- Detection ratings of hope. D=2 against "operator visual check". The criteria tables are specific about what earns low numbers, and visual checks do not.
- Happy-path structure. No storage, no transport, no rework in the structure analysis — because the flow it was built from had none.
- One-author FMEAs. A document with no team behind it reads like one, and the occurrence column usually gives it away first.
Keeping it alive
The PFMEA reopens on events, not anniversaries: a process, tooling, layout or supplier change; a new or transferred part; a customer complaint or warranty claim; an internal defect trend the current ratings say should not exist; a control that failed in practice; an audit finding. The handbook's expectation — and ISO 9001's own change-control logic in gentler words — is that the FMEA is the living risk record of the process, with the control plan revised in the same event. A useful standing rule mirrors the control plan article's: every complaint and every engineering change closes with the written question does the PFMEA change? — yes or no, with a name against it.
Frequently asked questions
What is the difference between a DFMEA and a PFMEA? The DFMEA analyses the product design — can this geometry, material or tolerance fail in use? The PFMEA analyses the manufacturing process — can this step make the part wrong? They meet at special characteristics: what the DFMEA flags as critical to the design, the PFMEA must control in the process. This article, and the toolkit behind it, cover the PFMEA.
Do I need a PFMEA if I am only certified to ISO 9001? Not by name — ISO 9001 asks you to address risks and run controlled production, and lets you choose the method. But if a process failure would hurt a customer, some structured what-could-go-wrong analysis is the only serious answer, and the PFMEA is the best-developed one there is. IATF 16949 suppliers have no choice: it is required, per customer-specific requirements.
Is the 7-step method mandatory? For most automotive customers, effectively yes for new programmes — their customer-specific requirements name the AIAG-VDA handbook. Existing FMEAs in the old format are generally allowed to live out their programme; check your CSRs rather than folklore, because transition arrangements differ by OEM.
Can severity change with better controls? No. Severity belongs to the effect. If the bracket separating endangers the driver, it does so however rarely it happens. Only design changes that change the effect itself move S — which is why prevention and detection actions re-rate O and D, never S.
How many lines should a PFMEA have? As many as there are real failure chains — which for a modest machining-and-assembly line is typically dozens, not thousands. A 4,000-line PFMEA generated by permuting every cause against every mode is not thorough, it is unreadable, and unreadable means unmaintained. Foundation (family) FMEAs are the handbook's answer to repeated content: analyse the common process once, inherit it, and analyse only the part-specific differences.
Do I need FMEA software? No. Software helps with structure trees, foundation FMEAs and multi-plant reuse, and at some scale it earns its licence. But the method is the value, not the tool — a disciplined spreadsheet with the AP logic built in covers a single plant's needs perfectly well, which is exactly what the PFMEA Toolkit is.
What is FMEA-MSR, and do I need it? A supplement for systems where failures are detected and responded to in the field by monitoring — sensors, diagnostics, limp-home strategies. It matters for electronics and safety systems; most machining, forming, welding and assembly suppliers never need it.
Where does the 8D meet the PFMEA? At D7, prevent recurrence. Every real escape is evidence the PFMEA rated something wrong — the occurrence that "couldn't happen", the detection that was supposed to catch it. Closing an 8D without revising the PFMEA line that failed is how the same defect returns with a new date on it.
Interpretive guidance only — not a substitute for the AIAG & VDA FMEA Handbook, ISO 9001 or IATF 16949; rate against the criteria tables in your licensed copy of the handbook, and follow your customer-specific requirements, which take precedence throughout. Clause links follow ISO 9001:2015 numbering; we re-verify against the published ISO 9001:2026 text on 16 September 2026.