FMEA Worksheet
Build a PFMEA or DFMEA worksheet — failure modes, effects, severity, occurrence and detection, risk priority number, actions and an honest re-score after the fix, with a printable report. Runs entirely in your browser. Nothing is uploaded.
Version 1.0.0 · Updated Aug 7, 2026
Overview
Frequently asked questions
How does the FMEA Worksheet licence work?
It is a one-time purchase for a downloadable tool — no subscription. You buy it once and the file is yours to keep and use.
Can I try the FMEA Worksheet before buying?
Yes. Use the Try online button for a fully interactive demo with sample data already loaded — nothing to install and nothing is saved.
Does my data stay private?
Yes. The tool is a single HTML file that runs entirely on your computer and makes no network requests, so nothing you enter is ever uploaded or shared.
Do I need Excel or any other software?
No. It replaces the spreadsheet template entirely: open the file in your browser (Chrome, Edge, Firefox or Safari) on Windows, Mac, Linux or a tablet, and start working.
How to use FMEA Worksheet
The complete in-tool guidance, reproduced here so you can read it before you download.
What this tool does
CM8-211 is a working FMEA worksheet. You record one line per failure mode: what the step or component has to do, how it can fail, what that does to the customer, why it happens, what you already do to prevent and to detect it, and the three scores. It calculates the risk priority number, ranks the worksheet, tracks the recommended actions to an owner and a date, and lets you re-score the line once the action is genuinely complete — then prints the whole thing as a report you can take to a customer audit.
Everything runs inside this single file. There is no account, no upload and no network request of any kind, so a worksheet that names your weak points, your escapes and your unproven controls never leaves the computer you are using.
When to do an FMEA
An FMEA is worth the effort at three moments, and is largely wasted at any other.
- Before production. While the process or the design is still on paper and changing it costs a meeting rather than a shutdown. This is where an FMEA earns its keep, and it is the one most organisations skip.
- After a problem. A complaint, an escape, a scrap spike. The corrective action deals with the instance; the FMEA asks whether the same weakness sits elsewhere and whether the worksheet ever predicted it. If the failure that just cost you money is not on the worksheet, that is the finding.
- After a change. New material, new supplier, new machine, new layout, new operator population, new volume. Every one of those can move an occurrence or a detection score without anyone noticing.
An FMEA is a team exercise. One person filling in a spreadsheet produces one person's blind spots in a wider font. Get the people who run the process, the people who design it and the people who inspect it in the same room; their disagreements about a score are the most valuable output of the whole session.
PFMEA and DFMEA
The two share a form and answer different questions. A process FMEA assumes the design is right and asks how the making of it can go wrong — the wrong part loaded, the fixture worn, the parameter drifted, the check skipped. Its items are process steps and its causes are things you can fix with tooling, maintenance, error-proofing and training. A design FMEA assumes the process will be capable and asks how the thing itself can fail — a section too thin, a material wrong for the temperature, a tolerance stack that will not assemble, a mode of loading nobody considered. Its causes are design decisions and its actions change drawings, materials and specifications. Keep them as separate analyses: mixing them produces a worksheet where nobody can act on half the lines, because the actions belong to a different department. The type field on each line lets you keep both in one file and filter between them.
Mode, cause and effect — the three columns everyone confuses
This is where most worksheets go wrong, and once these three are muddled nothing downstream can be scored properly.
- Failure mode — how the function fails. It is a description of the state of the part or the process. "Weld undersized." "Hole out of position." "Seal omitted."
- Cause — why the mode happens. A mechanism, upstream of the mode, that you could act on. "Wire feed speed drifts as the liner wears."
- Effect — what happens next, downstream, to the next operation, the assembly plant or the end user. "Joint strength below the design load; the bracket can detach in service."
The test is direction. Cause sits before the mode, effect sits after it. If your effect column says "weld fails inspection", you have written a detection control, not an effect. If your cause column says "poor welding", you have restated the mode without explaining anything. One mode can have several causes; give each cause its own line, because each one earns its own occurrence score and its own action.
Writing the failure mode at the right level
"Bad weld" is not a failure mode. It cannot be scored, because you cannot say how bad, how often or how visibly. "Weld undersized — leg length below 6 mm" can be scored by anybody in the room, because it names a measurable state with a threshold. The rule of thumb: write the mode as a characteristic that has gone outside its requirement. Too small, too large, wrong position, wrong material, omitted, present when it should not be, out of sequence, late.
Resist the opposite error too. A worksheet with 400 lines, each describing a slightly different millimetre, is a document nobody will ever review. Aim for the level at which one line implies one action.
The three scales
Each line carries three scores from 1 to 10. The words attached to the numbers matter far more than the numbers themselves — two people arguing over the wording of a "7" are doing the analysis; two people guessing what a "7" means are wasting an afternoon.
- Severity is scored on the effect, and only on the effect. How bad is it when it happens? It has nothing to do with how often. 9 and 10 are reserved for safety and regulatory consequences, with 10 meaning the failure arrives without warning.
- Occurrence is scored on the cause. How often does this cause produce this mode? Use your own scrap, warranty and audit data where you have it, and similar processes where you do not.
- Detection is scored on the controls. How likely is your current control to find the failure before it escapes? This is the one that is back to front, and it deserves its own section.
Detection is inverted — the most common scoring error
Severity and occurrence run the way you expect: high number, bad news. Detection runs the other way. A detection score of 1 means you are almost certain to catch the failure. A detection score of 10 means you have no control at all and cannot detect it. Good detection scores low.
Teams get this wrong constantly, and it is not a harmless slip. A team that scores its excellent error-proofed check as a 9 because "our detection is excellent, nine out of ten" inflates that line's RPN by a factor of nine and pushes the genuinely undetectable failures down the ranking. The worksheet then directs effort at the operations you already have under control, and away from the ones you cannot see. If a worksheet's actions all seem to land on the well-instrumented stations, check the detection column before you believe it.
The way to keep it straight is to read the anchor words rather than the number, every time. "Automatic gauging that rejects the part" is a 2. "Sampled audit only" is an 8. "Found at final test or by chance" is a 9. "No control" is a 10. If you can say out loud how the failure would be caught, and the answer is a machine rather than a person, you are at the low end. If the honest answer is "the customer would tell us", you are at the top.
RPN, and what it cannot tell you
RPN = Severity × Occurrence × Detection Range 1 to 1000, from 1 × 1 × 1 to 10 × 10 × 10 RPN cut = RPN before the action − RPN after the action
The risk priority number is a ranking device. It sorts a long worksheet into a rough order so a team can start somewhere sensible. That is all it is, and treating it as a measurement causes real harm.
Consider two lines that both score 100. The first is 10 × 5 × 2: a failure that kills people without warning, happens occasionally, and is caught by an automatic check. The second is 5 × 5 × 4: a comfort complaint that happens occasionally and is usually caught. They are not the same risk, they do not deserve the same attention, and no arithmetic that multiplies three ordinal scales together will ever tell them apart. The multiplication also produces gaps and clusters — of the thousand possible products, only a few hundred distinct values occur, and a one-point move in severity can jump an RPN by fifty while a one-point move elsewhere moves it by four.
So use the number, but bound it with two rules that override it:
- Severity 9 or 10 always gets an action, whatever the RPN. A safety failure with an RPN of 54 is still a safety failure. This worksheet flags those lines separately, lists them on the action priority table regardless of RPN, and refuses to let you mark one simply "accepted".
- Read severity, occurrence and detection separately before you read the product. Modern practice has moved away from a single threshold number towards action-priority thinking: look first at how bad it is, then at how often, then at whether you would see it coming. A high severity with a high detection score — bad consequence, no way of catching it — is the most dangerous shape on any worksheet, and it can sit in the middle of an RPN ranking without anyone noticing.
The threshold on the Settings tab exists to make the ranking operational, not to make it correct. Agree one number with the team, and never move it afterwards to reduce the length of the action list.
Prevention and detection controls
The worksheet asks for both, in separate fields, because they do different work and only one of them makes the product better.
A prevention control stops the cause occurring: a locating pin that a wrong part will not fit, a locked parameter, a maintenance interval tied to wear, a specification that removes variation at the supplier. Prevention lowers the occurrence score, because fewer defects are made.
A detection control finds the failure after it has been made: a gauge, an audit, a vision check, a test. Detection lowers the detection score, because fewer defects escape. It does not lower occurrence, and it is worth being blunt about what that means: you are still making the defect, still paying for it, and still relying on an inspection that will eventually miss one. Inspection is containment dressed as improvement.
When a worksheet's actions are overwhelmingly "add a check", the team has taken the cheap route. Ask of every action: does this stop the failure being made, or only stop it getting out? Both are legitimate, but a worksheet with no prevention actions at all is describing a process that will keep producing scrap indefinitely.
Re-scoring after the action
A line is not finished when the action is done; it is finished when the line has been scored again with evidence. The three new-score fields are deliberately optional and deliberately blank until then, and the worksheet will not let you close a line without all three.
Severity almost never moves. This surprises people, and it is the honest position: you have usually not made the consequence less bad, you have only made it rarer or easier to catch. Severity changes only when the design changes so that the failure no longer has that effect — a redundant fixing, a fail-safe, a redesign that removes the joint. If your re-score drops severity, be ready to explain what changed in the product, not in the process.
Occurrence should drop only with data behind it. "We fitted the alarm last week" is not evidence; eight weeks of production without the failure is. Detection drops when a genuinely better control is in place and has been validated. The before-and-after chart shows the RPN cut for every re-scored line, which makes an unsupported re-score visible to anyone reading the report.
From the FMEA to the control plan
An FMEA that ends in a filing cabinet has achieved nothing. Every detection control you relied on to justify a detection score, and every prevention control that earned an occurrence score, has to exist as an instruction somebody follows on a specific day: what is checked, by whom, how often, with what, and what happens when it fails. That is the control plan, and if you keep one, the Control Plan Builder is where those lines belong. The discipline is that the two documents agree — a detection score of 2 in this worksheet with no corresponding check anywhere in the control plan is a score with nothing behind it.
FAQ
How many lines should a worksheet have? Enough that every significant way the step can fail is on it, few enough that a team will review it. For one welding cell, ten to thirty lines is normal. If you have three hundred, you have written the mode at too fine a level.
Should every line have an action? No. A line with a low RPN, a low severity and controls that already work is an honest "accepted" — and recording that decision is valuable, because it stops the same question being reopened every year. High-severity lines are the exception: they always need something recorded.
Can I compare RPNs between two different worksheets? Only if both used the same scale definitions and the same team culture. Even then, treat it as a conversation starter. RPNs are not a metric to report upward or to compare between sites.
What if the team cannot agree a score? Take the higher one and write the disagreement into the effect or cause field. The argument itself usually reveals that two people are describing two different failure modes, which is worth two lines.
How often should the worksheet be reviewed? At every change, after every escape, and otherwise on a fixed cycle — annually for a stable process. The date field records when each line was last scored, so an old worksheet cannot pretend to be current.
Saving your work
Lines, settings and the report header are written to this browser's local storage as you type, and the toolbar shows the time of the last save. That storage belongs to one browser on one computer: another browser, a private window, a second machine or a clean-up tool that clears site data will not have it.
Treat Export .json as the real save — one file containing everything, which Import .json restores anywhere. Export CSV gives you the worksheet for spreadsheet work and includes every filtered line, not only those drawn on screen. Reset asks twice, then erases everything this tool has stored. There is no undo. An FMEA is commercially sensitive — it is a written list of the ways your product can fail — so treat exports accordingly.
Accuracy & disclaimer
The arithmetic here is deliberately simple, and the tool does it faithfully. Everything that matters sits underneath it: whether the failure modes on the worksheet are the real ones, whether the causes are mechanisms or guesses, whether the controls described actually happen on the shop floor, and whether the three scores reflect evidence or the mood of the meeting. A score of 1 to 10 on an ordinal scale is structured judgement, not measurement.
An RPN ranks; it does not decide. A low RPN on a safety-critical failure is still a safety-critical failure, and severity is the one number an action can rarely change. This is a record-keeping and prioritisation aid, not engineering advice, not a safety assessment, and not a substitute for the design, process and quality expertise of the people who produced the entries.
Related tools
Run 8D problem-solving reports discipline by discipline — team, containment, verified root cause, corrective action, prevention — with a board that shows exactly where each report is stuck. Nothing is uploaded.
Run 5 Why root cause analyses: state the problem, walk the why chain, name the root cause, then track the countermeasure through to verified. Runs entirely in your browser — nothing is uploaded.
Build consistent machining quotes from cycle times, material, tooling and margin targets.
5S Audit
Run a 5S workplace audit — score Sort, Set in order, Shine, Standardise and Sustain checkpoint by checkpoint from 0 to 4, track the audit score over time, and turn every low score into a corrective action with an owner and a date. Nothing is uploaded.