MADE Module Guides > Modeling Redundancy
5 Redundancy in FMECA Reporting
The effects of redundancy can be represented in FMECA reports using the criticality of failure modes. If a redundant arrangement exists, the criticality of the redundant item and the control measures of the redundant item must be changed to reflect this redundancy.
The main steps to investigate these effects are criticality definition, control measures and FMECA reporting.
For this section of the guide please ensure the SRA Module is selected in the main toolbar.
Figure 20 ("Redundancy in FMECA Reporting Process"): Step 1 (Criticality Editing) → Step 2 (Control measures) → Step 3 (FMECA Reporting).
5.1 Criticality Editing (Step 1)
A first step to investigating the effects of redundant items in a system is to edit their criticality rankings. A system that contains redundant items should have a lower criticality (severity) than a system without redundancy. For example, when editing the criticality of redundant components (pump 1 & 2) in a system, they should have less severity associated with their failures than a component for which no redundancy is available.
To edit the criticality:
- From the main menu select Analyses → Criticality and Reliability Editor
- Ensure the element selection is set to Criticality
- Expand the Tree Diagram and select a flow property
- Edit the severity factor for each response (High & Low) using the slider or numerical field
- Repeat as necessary
- Save changes
Figure 21 ("Criticality editing") shows the "Criticality & Reliability Editor" with Element Selection = Criticality, tree (Vehicle System > Coupling > Mechanical - rotational Angular velocity ×2, Driveline, Power Generation, Vehicle), and "Function Flow Criticality" panel: Selected Profile = PHMT Risk Assessment Criteria (FAA), Criticality Method = ARP 4761 (Rev A); sliders: Difficulty of Detection = 10.0 ("Very High"), Probability/Occurrence = 1.0 ("Extremely Improbable"), Severity = 10.0 ("Catastrophic"), Controllability = 10.0 ("Controllability 3"), Software Control (MIL-STD-882E) = 0.0.
5.2 Add Control Measures (Step 2)
FMECA reports can also document the consequences of a redundant design and the reasoning for a change in criticality by applying Control Measures to a failure mode or fault in the Failure Diagram editor.
To enter control measures:
- Open the Failure Diagram editor of an item
- Right-click the Failure Mode or Fault and select Control Measures
- Select the "add" button to add a Control Measure
- Select the appropriate control measures in the dialog
- Enter a narrative if required
- Select the Barrier Matrix button to specify how each Control Measure influences criticality values
- Select OK to close the dialog & save changes
Figure 22 shows the "Primary Fuel Filter" Failure Diagram with a fault-tree-style diagram (Input flow too slow, Contaminated input flow, Insufficient cleaning, Solid particle contaminants → Silting / Buildup of debris / Abrasive wear → Blocked / Outgrowths / Contaminated / Perforated [right-clicked, showing context menu: Control Measures, Cut/Copy/Paste, Delete, Zoom In/Out] → converging via OR gates into "Refine Liquid Flow rate (Primary Fuel Filter)").
Figure 23 ("Control Measures dialogue") shows "Control Measures - Perforated (Primary Fuel Filter)" with an "Add / Edit / Remove Control Measures" toolbar, an empty table with columns Enabled/Name, Type, Mitigation, Narrative, a "Create a new Control Measure" affordance, and a "Barrier Matrix" link: "Use the Barrier Matrix to setup and define Mitigating Criticality Parameters for each enabled Control Measure."
Figure 24 ("Adding a Control Measure") shows the control measure taxonomy tree used to select a new measure: Compensating Provision > Observation, Redundancy, Abort Mission, Change System Configuration (selected), Modify Mission, Modify Sensor Set, Override System, Procedures, Redesign Component, Relief Devices, Safety Devices; Detection Methods > Equipment Testing, Inspection, On Demand, Operator Observation, Sensing Device, Warning Device; Prevention Controls > Benchmarking studies, Breakdown Repair, Breakdown Replace (and more, truncated). For the selected "Change System Configuration" measure: Narrative = "Changing the system configuration to resolve the failure." — with Add/Cancel buttons.
Note that Redundancy is itself one of the top-level Compensating Provision control-measure categories in MADE's taxonomy — meaning a redundant design can be explicitly documented as its own named control measure type, separate from the more general "Change System Configuration" measure shown selected in this example.
Figure 25 ("Editing the Barrier Matrix for a Control Measure") shows "Control Measures - Perforated (Primary Fuel Filter)" Barrier Matrix view: three columns "No Control" / "Change System Configuration" / "Revised Control", two rows:
- Difficulty of Detection: No Control = 10.0 (red) → Change System Configuration delta = -1.5 → Revised Control = 8.5 (orange)
- Probability/Occurrence: No Control = 1.0 (dark blue) → Change System Configuration delta = +1.5 → Revised Control = 2.5 (blue)
This illustrates exactly how MADE quantifies a control measure's mitigating effect: each enabled control measure contributes a signed delta to specific criticality parameters (here, Difficulty of Detection decreases by 1.5 while Probability/Occurrence increases by 1.5), and the resulting "Revised Control" value is what propagates into FMECA criticality scoring.
5.3 FMECA Reporting (Step 3)
After the control measures and failure criticality has been set for the redundant item, the next step is to generate a FMECA report of the system to document the redundancy and the effects on system criticality.
To produce a FMECA Report:
- Select Reports → Report Wizard from the main menu
- Select a FMECA report (e.g. RPN, PHMT)
- Set the Redundant Item as the end effect
- Ensure correct propagation method — FCM (this assumes a new user has a FCM model; for Bond models select Bond)
- Select Next to go to page formatting or OK to generate the report
After the FMECA report is automatically generated, scroll down to the redundant item and verify that the failure path (row) lists its criticality and control measures in their respective columns.
Figure 26 ("FMECA (RPN) report") shows a generated "FMECA (RPN, PHMT)" report for "Vehicle System": Indenture Level 1, Mission "New Group". Example row for Item VS1 "Vehicle System" ("A land vehicle consisting of a driveline and power generation system"):
- Function/Functional Narrative: Convert Mechanical - rotational Angular velocity and Convert Mechanical - rotational Angular velocity
- Functional Failure: Convert Mechanical - rotational Angular velocity High/Nominal Vehicle System, and Convert Mechanical - rotational Angular velocity Nominal (Vehicle System)
- Causes of Failure — Mechanism: N/A; Cause: Convert Mechanical - rotational Torque High (Power Generation)
- Next Higher Level / End Effects: Convert Mechanical - rotational Torque High (Power Generation)
- Control Measures: "Anti-Lock Braking System (ABS) - Reduces risk of skidding when driver loses control of the vehicle" — appearing for both a High-torque row (Criticality O=1.0, S=9.0–9.0, D=10.0, RPN=90–90) and a Low-torque row (Criticality O=10.0, S=6.0–3.0, D=10.0, RPN=600–200)
The FMECA report identifies the main impacts of redundancy on the criticality. This report allows users to prioritize the items while considering a redundant arrangement. Having altered the criticality of redundant items, this prioritization can be recreated in other MADE features such as in charting or RAM module analyses. As the FMECA report is a typical output for failure mode analysis, this is a useful way of representing the effects of redundancy in terms of criticality before reliability of the arrangement is examined.
Source: Local MADE 3.9.1 installation: com.phm.made.help.plugin/documents/help/pdf/Modeling Redundancy Guide.pdf · retrieved 2026-07-09