A Failure Mode and Effects Analysis (FMEA) is a methodology to identify ways a product, safety device, process or system can fail. The FMEA adopts a systematic approach to evaluate the effects of different component failure modes to determine what could eliminate or reduce the chance of failure.
The FMEDA is an extension of the FMEA. An FMEDA consists of two separate analyses, FMEA and Diagnostic Analysis (DA). It combines standard FMEA techniques with the analysis of diagnostic capabilities, considering failure rates, diagnostic coverage, and safe failure fractions, to provide a more accurate assessment of the system’s reliability and performance.
FMEDA is based on the different approaches highlighted in IEC standards (IEC 61508) and MIL standards (MIL-STD-1629A) but is oriented to provide the necessary information for a Safety Integrity Level (SIL) reliability assessment, according to clause 7.4.5 and Route 1H of IEC 61508-2. Therefore, FMEDA can be considered to specifically target safety-critical systems and uses a structured methodology for evaluating failures in Safety Instrumented Systems (SIS), incorporating diagnostic capabilities assessment and quantitative analysis to ensure compliance with these standards.
Safety Instrumented Functions (SIF) in an SIS are designed to detect hazardous conditions and initiate appropriate actions to prevent a dangerous situation from arising. They consist of sensors, logic solvers, and final control elements working together to ensure the safe operation of critical processes. However, these components can fail, potentially compromising the SIS’s ability to perform the SIF.
The FMEDA evaluates the parts in the whole SIS and analyses how their failures can impact the safety functions. FMEDA is used to identify the various modes of failure (safety detected, safe undetected, dangerous detected, dangerous undetected, fail high, fail low etc) of the different elements of the SIS and generate failure rates for each failure mode. It involves collecting data on component failure rates, diagnostic coverage, and safe failure fractions. By performing a comprehensive assessment, FMEDA helps engineers identify potential failure modes, estimate their likelihood of occurrence, and evaluate the system’s ability to diagnose and tolerate these failures.

The FMEDA process typically involves the following steps
- Component Identification –The first step in FMEDA is to identify all components within the SIS that could potentially contribute to a failure. This includes sensors, logic solvers, final control elements, and any other relevant electrical, electronic, electromechanical, or mechanical device necessary to enable the element to process the safety functions required by the safety system. FMEDA is a bottom-up approach, where the failure rates and failure modes are first analysed at the component level and are used to predict failure rates and modes of a sub-system and higher-level architectures blocks of the safety-critical system. For example, a transmitter is built with components such as gaskets, bolts, membranes, electronic circuits, etc.
- Failure Modes Identification – Once the components are identified, the next step is to determine all the possible failure modes associated with each component. This includes considering both systematic failures, such as design or configuration errors, and random hardware failures, such as component wear-out or environmental influences. For example, for the sensor element of the SIS, the failure modes could be as follows
- Output Saturated High
- Output Saturated Low
- Indication Drift High
- Indication Drift Low
- Frozen Output
- Diagnostic Failure
- LCD Display Failure
- Failure Rates Determination – The FMEDA is only as good as the component database it uses. Collecting accurate data on failure rates is crucial. Engineers gather relevant information from industry databases, historical records, and vendor information. The data includes failure rates for each identified failure mode. These failure rates can be expressed in terms of the number of failures per unit of time or the failure rate per hour of operation. The FMEDA should account for important failure rate variables from both Product Designers for example physical materials used, electrical stress of components, ambient temperature variations and Product End Users for example power cycle variations, and operating environment. Therefore, the component databases used should be comprehensive to cover failure rates and failure modes for the different design and operating environment profiles.
- Diagnostic Capabilities Assessment – An important aspect of FMEDA is evaluating the ability of the system to detect and diagnose failures. While the previous two steps are part of the FMEA and help identify the components and the device failure modes and failure rates, they serve as inputs to the FMEDA. The FMEDA assesses the diagnostic coverage and probability of the diagnostics to detect different failure modes. This assessment typically involves the inspection of hardware architecture drawings with failure modes of each sub-system block and a review of the hardware drawings, equipment bill of materials and component specifications.
- Quantitative Analysis – Once all the necessary data is gathered, a quantitative analysis is performed to calculate the probability of failure for each failure mode and to determine the safe failure fractions (SFF). This analysis provides valuable insights into the overall reliability and performance of the SIS. While performing the analysis, it is important to establish the operating and environmental conditions of the SIF, for instance, the failure data for the way a device fails in one condition can change when the same device or arrangement is working in a different condition, like a valve required to operate as normally open or normally closed.
Safe Failure Fraction and Diagnostic Coverage
Safe Failure Fraction (SFF) is the fraction of the overall random hardware failure rate of a device that results in either a safe failure or a detected dangerous failure.
SFF = (λSD + λSU + λDD) / (λSD + λSU + λDD + λDU)
- λSD = SAFE DETECTED FAILURES
- λSU = SAFE UNDETECTED FAILURES
- λDD = DANGEROUS DETECTED FAILURES
- λDU = DANGEROUS UNDETECTED FAILURES
Diagnostic coverage (DC) refers to the fraction of dangerous failures detected by the online diagnostics within the SIS, while safe failure fractions measure the fraction of failures that do not result in a hazardous condition. A high diagnostic coverage and a low safe failure fraction are desirable for an effective SIS. In other words, the lower the dangerous undetected failure rate, the better.
DC = λDD / λDD+ λDU
Using the FMEDA results
The FMEDA data obtained from the analysis of the components of the SIS is used to do the SIL verification of the Safety Instrumented Functions (SIFs). Nowadays, commercial FMEDA tools like FMEDAx from Exida are available to obtain component data, analyse subsystems and review results for different operating profiles.
The FMEDA can help identify which failures are and are not covered by diagnostic coverage in an SIS. The diagnostic coverage claimed in the FMEDA can also be validated by performing Fault Injection Testing. During this test, component failures are simulated and are used to verify that the automatic diagnostics perform as documented. The tests to be carried out are usually guided by the FMEDA findings.
The FMEDA can also help identify which failures are and are not covered by proof testing for an SIS. A proof test for a SIS is a periodic test performed to detect dangerous undetected failures, so that, if necessary, a repair can restore the system to an “as new” condition or as close as practical to this condition. Evaluating the proof test procedure against the FMEDA enables the identification of the portion of dangerous undetected failures that can be identified by proof test i.e. the proof test coverage. More importantly, since the FMEDA provided details of automatic diagnostic coverage, the proof test procedures can be more strategic, focusing specifically on dangerous undetected failures to improve the effectiveness of the proof tests.
In conclusion, although the FMEDA can often be a time-consuming process, by identifying critical failure modes, engineers working at an operating facility can then focus resources on components or failure modes that require additional attention – namely dangerous undetected failures, leading to more efficient testing and allocation of resources.