Mediconomics – für individuelle CRO-Lösungen.

Glossar

FMEA for Medical Devices

Failure Mode and Effects Analysis, abbreviated as FMEA, is a systematic bottom-up method used to identify and evaluate potential failure modes, their causes, and their effects for the elements of a product or process. It is methodologically described in IEC 60812, which also covers the variant with criticality analysis. In the medical device sector, FMEA is not an independent regulatory proof, but rather a tool within the risk management process according to ISO 14971 and is mentioned in ISO/TR 24971 as one of several suitable analysis techniques. Regulation (EU) 2017/745 mandates a risk management system in Annex I, Section 3, but leaves the choice of analysis method to the manufacturer.

Methodology and Evaluation Parameters

FMEA works element by element: The object under consideration is broken down into functions or process steps; for each element, the possible failure modes are identified, followed by their causes, local consequences, and effects at the system level. Traditionally, three parameters are scaled and evaluated, usually on ordinal scales: the probability of occurrence of the cause, the significance or severity of the effect, and the probability of detection through existing control and test measures. The product of these three metrics forms the Risk Priority Number, abbreviated RPN, which serves to prioritize measures. After implementing the measures, the evaluations are updated, so that the FMEA remains a living, versioned working document and incorporates evidence of effectiveness. Newer approaches replace the pure RPN ranking with action priorities to avoid the known weaknesses of multiplicative metrics.

Variants and Integration into Risk Management

In practice, several forms are distinguished. The Design FMEA, often referred to as DFMEA, investigates design failure modes and provides input for design requirements, verification tests, and the selection of control measures. The Process FMEA, abbreviated PFMEA, examines manufacturing, assembly, cleaning, packaging, and sterilization steps and is thus closely linked to process validation, test plans, and the definition of critical characteristics. For use errors, the use-related risk analysis according to IEC 62366-1 supplements the consideration, and for software, the analysis according to IEC 62304. The connection to ISO 14971 requires a conscious translation: The standard evaluates risks per hazardous situation based on probability and severity of harm, not on three metrics. Failure modes and causes from the FMEA are therefore transferred into hazards and hazardous situations, and the acceptability decision is made according to the criteria of the risk management plan.

Distinction from Risk Analysis according to ISO 14971 and Top-down Methods

FMEA is not to be equated with risk analysis according to ISO 14971. It typically considers individual failures and their consequences, thus not capturing combinations of multiple failures or hazards without a technical failure event, such as material- or use-related risks with a flawlessly functioning product. It also primarily evaluates failure detection in the manufacturing process, not harm to the patient. Top-down methods such as fault tree analysis complement it by calculating back from an undesirable event to combinations of causes; approaches like HAZOP are suitable for process deviations. The probability of detection must not be used to mathematically minimize risks that could be controlled by design. An FMEA therefore neither replaces the risk management file nor the risk management report, but provides input data for both.

Relevance for clinical trials

For clinical trials, FMEA is primarily a source for safety planning and documentation. The evaluated failure modes and the residual risks derived from them lead to precautions, handling instructions, training content for investigators and users, expected adverse events for the clinical investigation plan, and content for the investigator’s brochure according to Annex XV of Regulation (EU) 2017/745. Failure modes with high significance and limited data are also candidates for targeted safety endpoints to be collected.

Similarly, findings from Process FMEA can provide indications for handling and reprocessing steps that need particular instruction in the clinical investigation plan. The method is also transferable to study processes themselves: risk-based quality planning according to ISO 14155 can be underpinned by an FMEA-like consideration of data flow, randomization, device dispensing, calibration, and site logistics to prioritize monitoring scope and controls. Results from studies and vigilance then feed back into the analysis as updated probabilities of occurrence. Full-service CROs like Mediconomics support manufacturers and sponsors in translating insights from such analyses into the clinical investigation plan, investigator’s brochure, and safety reporting, and in preparing study data for updating the risk assessment.

Frequently Asked Questions (FAQ)

Is an FMEA mandatory under MDR?

No. A risk management system according to Annex I, Section 3 of Regulation (EU) 2017/745 is mandatory, implemented in practice according to ISO 14971. FMEA is a recognized, but not mandatory, analysis technique.

Is an FMEA sufficient as a risk analysis?

Generally not. It predominantly covers individual failures and must be supplemented by considerations of materials, use errors, software, failure combinations, and the evaluation of overall residual risk.

How is the Risk Priority Number handled?

As a prioritization aid within the FMEA. For the acceptability decision, the criteria defined in the risk management plan regarding severity and probability are decisive; identical numerical values can mean very different severities of harm.

Regulatory References

  • IEC 60812:2018 – Failure modes and effects analysis, procedures for FMEA and FMECA
  • ISO 14971:2019, Sections 5 to 8 – Risk analysis, risk evaluation, risk control, overall residual risk
  • ISO/TR 24971:2020 – Guidance on the application of ISO 14971, including analysis techniques
  • Regulation (EU) 2017/745, Annex I Sections 3 and 4 – Risk management system and risk control
  • IEC 62366-1 and IEC 62304 – use-related risk analysis and software lifecycle processes
Scroll to Top