FME(C)A or FMEA?

June 29, 2017

FMEA or FMECA?

Criticality or not? Which one is better? Which one should you use?

The answer is simple: it depends.

You are probably fed up with the “it depends” answers you get in this sector.

But in this case it means “It depends on YOU”.

First the compliance bit: there is no requirement, in ISO 13485, 21 CFR 820, ISO 14971 that prescribes you have to pick one rather than the other.

It’s not even a requirement to have a FME(C)A at all.

The only requirement is to identify the hazards, the related harms and the appropriate causes. A top down analysis.

So which one is better?

It is a case by case decision (which is another way to say “it depends”, I know…)

This is our point of view on the matter:

1) You should have at least one FMECA (usually the one at a system level) that talks directly to the Top-Down analysis. Risk mitigation actions should be reported in the latter, so you will have only 1 document that will dictate the acceptability of each risk.

2) All the other bottom-up analyses should be FMEAs, limiting the effect to the local level (i.e. what happens to the subsystem covered by the FMEA)

3) FMEAs are general tools that you can use for any purpose, not necessarily to determine the acceptability of risks. A typical use (where the concept of RPN comes from – Risk Prioritization Number) is to identify the areas of higher risk to distribute resources and effort more effectively.

It is also good practice to ensure that it is aligned with your top-down analysis, and this is particularly important for a FMECA; in this case it is strongly recommended to have some sort of automated traceability software, otherwise you will soon get lost in the web of links.

We help medical device companies fast-track the development of their Quality Management System and automate their compliant Risk Management with the help of our Atlassian add-ons for Confluence and JIRA.

Table of Contents

Ready to get started?

Contact us to book a demo and learn how SoftComply can cover all your needs

RAID in Jira
Picture of Marion Lepmets

Marion Lepmets

CEO
September 16, 2025

Project managers know that uncertainty is the enemy of successful delivery. You’ve got potential risks lurking around every corner, assumptions that might prove wrong, current issues demanding attention and dependencies that could slip at any moment. This is where RAID comes in (and no, I’m not talking about the data...

27001 Jira
Picture of Marion Lepmets

Marion Lepmets

CEO
September 9, 2025

Information security isn’t optional anymore. Whether you’re handling customer data at a startup or managing intellectual property at a global enterprise, a single security incident can cost you financially, damage your reputation and destroy customer trust. That’s where ISO 27001 comes in. It’s the world’s leading standard for information security...

GRC in Jira
Picture of Marion Lepmets

Marion Lepmets

CEO
September 1, 2025

GRC (Governance, Risk and Compliance) isn’t just corporate bureaucracy – it’s your company’s shield against costly surprises. Too many organizations scramble during audits, struggle with scattered risk registers, and face regulatory nightmares that could be avoided. Watch the full video above to see exactly how to implement GRC and how...