KEVOS
ArticlesServicesCase studiesAboutContact
ArticlesServicesCase studiesAboutContact
← ArticlesRisk Scoring with RFMEA: A Worked Analytical MethodProject Delivery · Research ProjectsLesson 78/85← PrevNext →
GuidePublished 16 Aug 20268 min readBy KEVOS Editorialrfmearisk priority numberrisk scoredetection factor
On this page

Ask about this page

KEVOS AIRisk Scoring with RFMEA: A Worked Analytical Method

KEVOS knowledge first · trusted web sources when needed

KEVOS/Project Delivery/Research Projects/Research Exemplars
Project DeliveryResearch ProjectsAdvancedResearch Exemplars

Risk Scoring with RFMEA: A Worked Analytical Method

Risk score, detection factor and risk priority number, Pareto ranking and a four-quadrant scatter — a complete applied technique, including the reason its thresholds are chosen rather than calculated.

Reading time9 minutes
LevelAdvanced
Topic streamResearch Exemplars
Source materialResearch Exemplars
Updated2026-08-16

In brief

  • Conventional risk assessment multiplies likelihood by severity. This technique adds a third dimension — how far ahead you can see the risk coming.
  • Risk Score = likelihood × severity. Risk Priority Number = Risk Score × detection factor.
  • The critical thresholds are chosen by the researcher, not derived. The paper says so explicitly, twice.
  • An empty top-right quadrant after treatment is the method's operational definition of 'the critical risks have been mitigated'.

What the technique adds to a conventional risk matrix

A standard project risk matrix is two-dimensional: likelihood against severity. The technique applied in the examined journal paper adds a third parameter, borrowed from a failure-analysis method used in manufacturing, and adapts its meaning for projects.

THE DETECTION FACTOR MEANS DIFFERENT THINGS IN THE TWO VARIANTS

VariantWhat the detection factor measuresHigh value means
Manufacturing parent techniqueAbility to detect a product fault before shipmentNo ability to detect
Project variant used in the paperAbility to foresee a risk event with enough lead time to plan for itLittle or no forewarning

The examined paper distinguishes the two carefully. Carrying the manufacturing meaning into a project context is the most likely way to misapply the technique.

From the source

The method was applied, not invented

The paper's authors did not create this technique. Their contribution is transferring it into research and development projects and extending it to post-treatment evaluation — applying it again after contingency plans have been actioned, so the technique's ability to detect effective contingency plans can itself be assessed.

That is a useful model for a research contribution generally: take an established method, move it somewhere it has not been tested, and add one checkable extension.

The five parameters

Inputs and derived values

Likelihood
The probability that the risk event occurs. Assessed on a numerical scale.
Severity
The magnitude of the effect on the project should the risk occur.
Risk Score (RS)
Likelihood multiplied by severity. This is the conventional two-dimensional score.
Detection factor
The ability to foresee the risk event with enough lead time to plan for it. Assessed on a numerical scale.
Risk Priority Number (RPN)
Risk Score multiplied by the detection factor. The three-dimensional score.

Because RPN contains RS, the two are correlated by construction — but not identical, because a risk with a modest RS and very poor foresight can outrank one with a high RS that you will see coming. That divergence is the whole point of the second number.

The process

The six-box flow set out in the paper

  1. Calculate the Risk Score

    Multiply likelihood by severity for every risk in the register.

  2. Plot an RS Pareto chart

    Rank the risks by RS as a bar chart to reveal the distribution profile.

  3. Calculate the Risk Priority Number

    Multiply each Risk Score by its detection factor.

  4. Plot an RPN Pareto chart

    Rank by RPN. Comparing the two Pareto charts shows which risks change position once foresight is accounted for.

  5. Plot the scatter diagram

    RS on the x-axis, RPN on the y-axis, with the two critical thresholds drawn as vertical and horizontal lines. Four quadrants result; the top-right holds risks above threshold on both attributes.

  6. Revise after treatment

    Once contingency plans are actioned, recalculate RS and RPN and redraw the scatter.

Practice note

The extension, and why it is the good part

An empty top-right quadrant after treatment is the paper's operational definition of the critical risks have been mitigated.

That is a checkable success criterion, which risk management processes very often lack. Most produce a treated register that asserts improvement; this produces a picture in which improvement is either visible or absent. It is the paper's own addition to the technique.

Where the numbers come from — and why that matters

The operational detail is more instructive than the formulas, because it is where the judgement enters.

HOW EACH VALUE WAS OBTAINED IN THE EXAMINED STUDY

ValueHow it was obtainedWhat that implies
Likelihood and severityThe organisation's registers used non-numeric scales — letters for likelihood, small integers for severity, categories for the overall score. The researchers substituted equivalent numerical scales on a 1–10 rangeA categorical scale cannot be multiplied. This substitution is a methodological decision that shapes every number downstream, and it is not neutral
Detection factorAssigned on a 1–10 range by expert judgement, in consultation with the project managerA single informant. Not an independent measurement, and not repeatable by another analyst without the same person
Critical thresholdsScaled from a prior published study. That study used RS = 20 and RPN = 125; because the maxima here were roughly twice and roughly 1.5 times those, thresholds of RS = 40 and RPN = 180 were selectedChosen, not calculated. Applied to both projects despite the paper's own warning that thresholds should be set project by project

All values shown are specific to that one study. None is a standard.

Caution

The thresholds are the weak joint, and the authors say so

The paper states plainly that there is no systematic procedure and no scientific protocol for setting the critical value, and that the leeway in defining RS and RPN makes every application unique.

It then uses thresholds anyway, applies the same pair to both projects, and lists the issue in its limitations — noting the approach "might be an oversimplification".

RS = 40 and RPN = 180 are that study's selections, scaled from another study's selections. They are not benchmarks, they are not defaults, and reusing them because they appear in a published paper would repeat the very arbitrariness the authors flagged.

What the study reported

13total risks in each of the two case projects
12 → 5critical risks in project A: original method → this technique
13 → 6critical risks in project B: original method → this technique
0 vs 4critical risks remaining after treatment: this technique vs the original method
Source example — illustrative only

Findings of one study, on two projects, in one organisation

Both case projects came from the same organisation — the paper lists this in its limitations. Two projects in one company is not evidence that the technique reduces critical-risk counts in general, and the paper does not claim it is.

Also note the claimed benefit: efficiency, not accuracy. The paper does not argue the technique finds better risks. It argues it finds fewer risks to focus on, freeing effort for reallocation. Whether fewer flagged risks is genuinely better, or an artefact of thresholds the researchers themselves chose, is not tested.

What makes this a good exemplar

Practices worth copying

  • Two explicit project selection criteria, stated before the cases were chosen
  • The first case worked through in full narrative detail, the second compressed — replication demonstrated without repeating the exposition
  • The same three exhibit types repeated once per case, making the two directly comparable by eye
  • The known weakness flagged voluntarily, repeatedly, and again in the limitations
  • A reader's likely count-check anticipated — the authors explain that only five points appear in a scatter containing six critical risks because two share identical coordinates

Soft spots to notice

  • Thresholds selected by the researchers then used to measure the improvement they claim
  • Detection factors from a single informant, so the analysis is not independently repeatable
  • Both cases from one organisation
  • The interview strand functions as warrant for relevance, not as evidence about the technique — none of the nine interviewees had ever used it
  • The abstract calls the interviews unstructured while the methods section describes ten fixed open-ended questions, which is semi-structured

How published work handles its own weak joints is developed in Stating limitations and contribution.

What to carry forward

  1. RS = likelihood × severity. RPN = RS × detection factor. The third dimension is how far ahead you can see the risk coming.
  2. In a project context the detection factor means lead time to plan, not ability to catch a defect. Do not carry the manufacturing meaning across.
  3. Substituting numerical scales for categorical ones is a methodological decision that shapes every downstream number. State it.
  4. The thresholds are chosen, not derived. Do not reuse another study's values as if they were standards.
  5. An empty top-right quadrant after treatment is a checkable success criterion — the most useful idea in the method.

Frequently asked questions

What does the detection factor actually measure?

In the project variant used in the examined paper, it measures the ability to foresee a risk event with enough lead time to plan for it. In the manufacturing technique it came from, it measures the ability to detect a product fault before shipment. The two are not interchangeable.

What thresholds should I use?

None that appear in the paper. The authors state explicitly that there is no systematic procedure for setting them, chose theirs by scaling from another study, applied the same pair to both projects, and then listed the approach in their own limitations as a possible oversimplification.

Why add a second score when RPN already contains RS?

Because they can diverge. A risk with a moderate Risk Score but very poor foresight can outrank one with a high Risk Score you will see coming. Plotting both gives two attributes for prioritisation rather than one.

Does the technique find better risks?

The paper does not claim that. It claims fewer risks to focus on, which frees effort for reallocation. Whether fewer flagged risks is genuinely better, or a consequence of the thresholds the researchers chose, was not tested.

Can I apply this to my own risk register?

The mechanics are straightforward if your register carries likelihood and severity. The two things to decide deliberately are how you convert any categorical scales to numbers, and who assigns the detection factors — a single informant makes the analysis unrepeatable by anyone else.

References and source attribution

  1. Five examined research works supplied as exemplars: two doctoral theses (1999, 2016), a doctoral portfolio thesis (2004), a peer-reviewed journal paper (2014) and a conference paper (2017/2018). Structural observations only; chapter bodies were not reproduced.
  2. Supplied teaching source, Weeks 2-4: Introduction to Research Methods, Developing a Research Topic, Reviewing the Literature.
  3. Bryman, A. 2016, Social Research Methods, 5th ed., Oxford University Press, Oxford.
  4. O'Leary, Z. 2017, The Essential Guide to Doing Your Research Project, 3rd ed., Sage Publications, London.

Suggested questions for Ask KEVOS

  • Walk me through calculating RS and RPN for a risk register I describe.
  • How should I set critical thresholds for my own project rather than borrowing them?
  • What is the difference between the manufacturing and project versions of the detection factor?
  • How do I convert a categorical risk scale into numbers defensibly?
  • How would I design a study that tests whether a risk technique actually works?

Related KEVOS knowledge

Evaluation and Action Research MethodologiesCore · research methodologySeventeen Worked Research Designs in Project ManagementAdvanced · research practiceStating Limitations and ContributionCore · research exemplarsBibliometric Trend Analysis as a Research MethodAdvanced · research exemplarsInterview Design in Project ResearchCore · research exemplarsCorrelation and Experimental MethodologiesCore · research methodology
KEVOS® · Project Delivery · Research Projects Page KVS-PM-RES-0078 · v1.0.0 · content 2026.08 Last reviewed 2026-08-16

Continue learning

Interview Design in Project ResearchGuide · Research ProjectsNEXT LESSON →Bibliometric Trend Analysis as a Research MethodGuide · Research ProjectsSurvey Design and Response Rates in PracticeGuide · Research ProjectsDeclaring a Research Paradigm — Or NotGuide · Research Projects
KEVOS · Engineering, manufacturing and project improvement
ArticlesServicesCase studiesAboutContact
© 2026 KEVOS®