The harmonized FMEA (Failure Mode and Effects Analysis) is one of the most widely used tools to assess risks in industrial products and processes.
However, one of the most frequent mistakes in organizations is not to develop it incorrectly, but to not review the FMEA when it is due. Many companies develop it in the launch phase, approve it, archive it and do not review it again until a problem in the field, a complaint or a critical nonconformity appears.
The FMEA is not a static document. It is a living risk management tool that must evolve along with the product and the process. With the advent of the harmonized approach (AIAG & VDA), the FMEA has evolved into a more structured and consistent methodology, based on the clear relationship between functions, failures, effects, causes and actions. In this article we analyze when it is necessary to review FMEA and why keeping it updated is key to avoid failures, rework and unnecessary costs.
3 situations where the harmonized FMEA should be reviewed
Depending on the scope, the analysis can be applied in different scenarios. Not only when designing something new, but also when product or process conditions change. Generally speaking, there are three critical moments to review the FMEA.
New projects, technologies or processes
The most obvious case of when an FMEA should be done or reviewed is when a new product, technology, production process or a new manufacturing line is developed.
In this case, risk analysis is essential before the start of production. In this phase, the following can be applied:
- DFMEA, focused on product design.
- PFMEA, focused on the manufacturing process.
The objective is to anticipate potential failures arising from the process (the well-known “M’s”: method, machine, material, labor, environment and measurement) and to define preventive actions before defects appear. But the problem is usually not encountered here, but when the project is already underway.
2. Existing process changes
A common mistake is to think that if something already works, it does not need a new FMEA or revision. However, an existing product or process can be affected if its context of use changes:
- New operating environment.
- New customer profile.
- Technical modifications.
- Material substitution.
- Supplier changes.
- Adjustment of production parameters.
- Incorporation of new machinery.
Although the design is the same, the risk is not. For example, a component that performs well in a controlled environment may behave differently under extreme conditions of temperature or vibration. In these cases, the FMEA should be reviewed to assess the impact of the new environment on existing failure modes or to detect new risks.
New regulations/standards
Regulations are constantly evolving. Therefore, another critical time to review FMEA is when new regulations or relevant updates appear.
For example, in sectors such as the automotive industry, changes in standards such as IATF 16949, new audit interpretations, updates in specific customer requirements or modifications in functional safety regulations may force a revision of the harmonized FMEA.
When a new regulation appears, it is not enough to update a procedure or add a documentary requirement. It is necessary to evaluate how it impacts product functions, potential failure modes, assigned severity or existing preventive actions. In the new FMEA approach, any regulatory change can affect multiple levels. If not reviewed, it breaks the internal consistency of the analysis and creates a disconnect between regulatory risk and documented technical risk.
FMEA review with overall risk management (HARA / TARA)
In regulated sectors or with functional safety and cybersecurity requirements, the FMEA does not act in isolation. It must be aligned with:
- HARA (Hazard Analysis and Risk Assessment)
- TARA (Threat Analysis and Risk Assessment)
- Functional safety analysis
- Corporate risk assessments
The FMEA is part of a broader risk management ecosystem. If the overall risk analysis is updated-for example, following a new cybersecurity threat identified in a TARA or following a hazard reassessment in a HARA-but the FMEA remains intact, a silent gap begins to develop: the documented risk no longer matches the actual risk.
Furthermore, from an audit perspective (IATF or other regulatory schemes), the lack of consistency between these analyses can become a relevant non-conformity. Integration is not only a technical best practice, but a growing requirement in regulated environments.
The role of digitization in a harmonized FMEA
Digitization in the FMEA can play a key role in its maintenance and review. A digitally managed FMEA allows:
- Version control and full traceability of changes.
- Direct linkage to control plans and special features.
- Integration with HARA, TARA and other risk management systems.
- Agile updating in the event of regulatory or customer changes.
- Structured collaboration between engineering, quality and production.
A digital environment makes it easy for every change – technical, regulatory or strategic – to be automatically translated into a structured review of the analysis.

In summary: reviewing FMEA is not optional
Ultimately, the real challenge of the FMEA is to keep it aligned with the changing realities of the product, process and regulatory environment.
The harmonized approach has been an important step in this direction. By better structuring failure modes, functions, causes and actions, a more coherent and cross-cutting view of risk is achieved. However, in order for the harmonized FMEA to unfold its full potential, it needs more than just a good methodology: it needs traceability, continuous updating and connection with the rest of the management system.
In this context, digitization makes a clear difference. A digitally managed FMEA makes it possible to integrate engineering changes, lessons learned, regulatory requirements without losing consistency and version control. It facilitates collaboration between departments, ensures traceability of decisions and reduces the risk of working on obsolete information.
A digitally managed FMEA is not just an operational improvement: it is a guarantee of consistency, updating and robustness in overall risk management. And, in increasingly complex and regulated environments, this is no longer an option, but a strategic necessity.
Frequently asked questions
Related bibliography
- Automotive Industry Action Group (AIAG) & Verband der Automobilindustrie (VDA). Title: AIAG & VDA FMEA Handbook (or Manual de Análisis de Modos y Efectos de Falla AIAG y VDA in Spanish). 1st edition. 2019. Southfield. Michigan (AIAG) / Berlin, Germany (VDA)

