FMEA Step 6: understand risk as a knowledge gap! Minimising risk through knowledge generation and application

Ask three standards what a risk is, and none tells you what to do tomorrow morning. This article defines risk operationally as a knowledge gap and shows how Step 6 of the FMEA minimises the risk: through knowledge that is generated and applied in the design. This turns the action list into a plan that creates robustness instead of documenting confidence.

Minimising risk by closing knowledge gaps through knowledge that is generated and applied (AIAG-VDA Step 6).

Ask three standards what a risk is, and you get three answers, none of which tells you what to do tomorrow morning. ISO 31000 speaks of the effect of uncertainty on objectives. ISO 9001 calls for risk-based thinking, a mindset, not a method. The AIAG-VDA Handbook describes seven steps including Step 6 Optimisation, but provides no operational definition that steers your actions. In practice, prevention actions then read like wishful thinking: has held up so far, should be fine, no one has ever complained. Anyone who really wants to minimise the risk has to generate knowledge and apply it in the design. Without this twofold movement, every action remains a mere declaration.

This article provides an operational definition of risk and shows how Step 6 of the FMEA minimises the risk: through knowledge that is generated and applied in the design, each with a method, an owner and a deadline. Afterwards, your FMEA team can reliably distinguish between a knowledge plan that creates robustness and wishful thinking that merely documents confidence.

Why the standard definitions are not enough for FMEA Step 6


ISO 31000 (2018) defines risk as the effect of uncertainty on objectives. That is precise but abstract. ISO 9001 (2015) anchors risk-based thinking as a basic mindset, without prescribing a method. The AIAG-VDA Handbook (2019) structures the FMEA into seven steps, replaces the Risk Priority Number (RPN) with Action Priority (AP) in the risk evaluation, and names Step 6 as Optimisation. What none of these definitions states: what actually makes a risk manageable.

In our practice, we define risk operationally: a risk is a knowledge gap in design and process robustness. This definition is actionable, because it directly states how to minimise the risk: through knowledge that closes the gap and takes effect in the design. This also clearly defines the task of the FMEA: it surfaces the knowledge gaps, and Step 6 minimises them

Three zones of design knowledge


Every design rests on three kinds of knowledge, and the FMEA primarily surfaces the second and third.

The three zones of design knowledge: confirmed knowledge, known gaps and unproven assumptions. FMEA surfaces the gaps and assumptions and closes them in Step 6.

Confirmed knowledge is validated and may be carried over, for example carry-over parts, validated principles, qualified suppliers and proven physics. Gaps are known unknowns to be closed by action, typically with new material, new geometry, a new use case or new manufacturing technology. Assumptions, finally, hold without proof; they are the unknown unknowns and the most expensive: worked last time, should be fine, no one has ever complained. This is exactly where the FMEA comes in, by surfacing gaps and assumptions and turning them into knowledge that minimises the risk. Whether a scope belongs in zone 1 or slips into zones 2 and 3 can be checked up front with a simple filter. We ask three questions: Known? Proven? Comparable? Anyone who answers no to at least one of them has a knowledge gap and needs an action. Internationally, the NUDD filter is established for this (New, Unique, Difficult, Different), a front-end tool from hardware development. Both ask the same thing from two directions: our filter checks whether knowledge is validated, NUDD checks whether it is new territory. What matters is the role: the filter does not measure the size of the gap, it only shows that one exists and deserves attention. The size is only evaluated by the occurrence and detection ratings.

The prevention action as a knowledge acquisition plan


A prevention action is not the intention to avoid the failure. It is the plan to close a specific knowledge gap, with a method, an owner and a deadline. It is documented and evaluated in Step 5 (Risk Analysis). Step 6 (Optimisation) then takes over: where the evaluation shows an open gap, it defines additional or revised actions.

Possible methods include simulation and FEM, analytical calculation, design of experiments (DoE) with Parameter Design (Taguchi), iteration and prototyping, the analysis of carry-over parts, and literature and state-of-the-art research. The decisive point is the dual structure: the action generates knowledge and demonstrably applies it in a design parameter. Generating knowledge without applying it in the design is not a complete prevention action. The occurrence rating (O) measures how effective these prevention actions are.

The detection action as robustness proof


A detection action is not the test of whether something works under ideal conditions. It is the proof that the design stays robust against the noise factors from Step 1. Step 5 documents the methods that provide this proof, for example validation under noise factors (N1 to N6, including foreseeable misuse), highly accelerated life tests (HALT, Highly Accelerated Life Test, to probe the load limits during development) and highly accelerated stress screens (HASS, Highly Accelerated Stress Screen, for series assurance), field correlation, reliability tests (B10, MTBF), customer use simulation, and verification under tolerance in the worst case. The detection rating (D) measures how effective these detection actions are.

The direction of knowledge determines the classification


Prevention and detection actions both generate knowledge. The direction of the knowledge determines the classification: knowledge that flows into the design constitutes a prevention action. Knowledge that serves to provide proof constitutes a detection action. Neither the place, nor the amount, nor the timing of the knowledge generation decides this. In particular, the design freeze is not a boundary between O and D: a prototype test before the freeze remains a detection action, an FEM recalculation after the freeze remains a prevention action. The same test procedure can even carry both roles. Open-ended, with varied parameters and design values as output, it is a prevention action. Against defined acceptance criteria, with the proof as output, it is a detection action.

The detection rating (D) in four dimensions


In the Design FMEA, a single number has to answer four questions at once, otherwise the rating is a guess. First, the capability of the verification method: does the test method fit the failure mode, for example FEM resolution to the failure scale or measurement uncertainty to the specification width? Second, the representativeness of the specimens: borderline specimens rather than golden samples, measured against tooling status, material batch, sample size and coverage of the use cases. Third, the timing of detection: the later a design flaw is detected, the worse the D value. Fourth, the verification strategy: OK/NOK provides no margin information, a test to failure quantifies the failure limit and thus the margin, a degradation test traces the wear path up to lifetime extrapolation. Make the hypothesis behind the rating explicit.

Three phrasings to drop

You can recognise vague actions by their language. Instead of engineering checks the dimensions: the design is based on FEM calculation against load case X, and the result feeds into the wall-thickness specification. Instead of a DoE will be conducted: a Parameter Design with factors A, B and C in an L9 array, target value Y under the noise factors N1 and N3, with an owner and a deadline. Instead of function test on the prototype: validation under noise factors per matrix X to prove the function, robust if Y stays within tolerance. Every solid action names method, context, target value, owner and deadline.

Example

A housing is given a new geometry, so a genuine knowledge gap. Wishful thinking would note: engineering ensures strength. A knowledge plan instead formulates two actions. The prevention action: an FEM calculation against the defined load case, whose result determines the wall thickness, complemented by a Parameter Design for the critical radius. Here, knowledge is not only generated but applied in a design parameter, and that is exactly what minimises the risk. The detection action: a validation across a temperature and vibration matrix along the noise factors N1 to N6, robust only if the target value stays within tolerance. Both actions have a method, an owner and a deadline.

Result


Step 6 optimises the actions, not the design. The design is optimised by DoE and Robust Design. Do not mistake one for the other. Anyone who understands risks as knowledge gaps minimises them through knowledge that is generated and applied in the design, and turns the FMEA into a plan that creates robustness instead of documenting confidence.

Where do your prevention actions generate knowledge and apply it in the design, and where do they remain mere declarations?


Talk to the FMEA experts at Dietz Consultants: www.dietz-consultants.com

Author: Winfried Dietz, CEO Dietz Consultants GmbH
Winfried Dietz is the CEO of Dietz Consultants GmbH and has been supporting development organisations worldwide in introducing and maturing the FMEA methodology for over 30 years. He is a trainer, author and speaker for FMEA according to AIAG-VDA. Find more from the FMEA Quick Tip series on LinkedIn
.