FME(C)A or FMEA?

June 29, 2017

FMEA or FMECA?

Criticality or not? Which one is better? Which one should you use?

The answer is simple: it depends.

You are probably fed up with the “it depends” answers you get in this sector.

But in this case it means “It depends on YOU”.

First the compliance bit: there is no requirement, in ISO 13485, 21 CFR 820, ISO 14971 that prescribes you have to pick one rather than the other.

It’s not even a requirement to have a FME(C)A at all.

The only requirement is to identify the hazards, the related harms and the appropriate causes. A top down analysis.

So which one is better?

It is a case by case decision (which is another way to say “it depends”, I know…)

This is our point of view on the matter:

1) You should have at least one FMECA (usually the one at a system level) that talks directly to the Top-Down analysis. Risk mitigation actions should be reported in the latter, so you will have only 1 document that will dictate the acceptability of each risk.

2) All the other bottom-up analyses should be FMEAs, limiting the effect to the local level (i.e. what happens to the subsystem covered by the FMEA)

3) FMEAs are general tools that you can use for any purpose, not necessarily to determine the acceptability of risks. A typical use (where the concept of RPN comes from – Risk Prioritization Number) is to identify the areas of higher risk to distribute resources and effort more effectively.

It is also good practice to ensure that it is aligned with your top-down analysis, and this is particularly important for a FMECA; in this case it is strongly recommended to have some sort of automated traceability software, otherwise you will soon get lost in the web of links.

We help medical device companies fast-track the development of their Quality Management System and automate their compliant Risk Management with the help of our Atlassian add-ons for Confluence and JIRA.

Table of Contents

Ready to get started?

Contact us to book a demo and learn how SoftComply can cover all your needs

Compliance Workshop in Anaheim
Picture of Marion Lepmets

Marion Lepmets

CEO
May 13, 2026

At Atlassian Team26, the Compliance Alliance hosted the 5th Compliance Workshop on May 7th that focused on one of the biggest questions facing regulated industries today: How can organizations adopt AI on Atlassian Cloud without compromising security, governance, compliance, or trust? The workshop brought together Atlassian Marketplace Partners and Solution...

Risk Management Lessons from Sailing
Picture of Marion Lepmets

Marion Lepmets

CEO
March 24, 2026

On March 19th, SoftComply was invited to join Not Another Webinar and present our Risk Management solution – ideally in a way that didn’t sound like, well… another webinar. So naturally, I ended up talking about sailing. Here’s a short recap of my sailing adventures and how they translate into...

Risk Management in Jira
Picture of Marion Lepmets

Marion Lepmets

CEO
March 10, 2026

Remember that time you raced for the bus, only to watch it drive away at the last second? Risk is everywhere – even in everyday life. While missing a bus is a personal risk, organizations face more significant risks every day, from data breaches to compliance infractions. That’s where SoftComply’s...