Failure modes are only one route to harm

A device can present unacceptable risk even when every component behaves exactly as designed. Inadequate performance, confusing interaction, incorrect clinical assumptions, compromised security or unsuitable use conditions may all create hazardous situations without a conventional component failure.

  • Normal-use hazards
  • Use error and foreseeable misuse
  • Systematic software behaviour
  • Cybersecurity compromise
  • Incorrect or delayed information
  • Loss or degradation of essential performance

Use FMEA for what it does well

FMEA is a strong bottom-up technique for exploring how component, process or functional failures propagate. It should support—not replace—a top-down analysis beginning with hazards, sequences of events, hazardous situations and harms.

Create one connected risk picture

Different analyses should feed a common risk-management system. Controls derived from them need owners, design implementation, verification of implementation, verification of effectiveness and residual-risk evaluation.

Key takeaways

  • No single analysis technique finds every relevant risk.
  • Normal behaviour can contribute to harm as well as failure behaviour.
  • The risk-management file should reconcile the outputs of complementary analyses.
This article provides general educational information. Applicable requirements depend on the device, jurisdiction, lifecycle stage and current regulatory position.