RCM Process · Phase 5

Failure Consequences

Answer RCM Question 5: does this failure matter? Classify every mode as Hidden, Safety/Environmental, Operational or Non-operational.

Purpose

RCM manages consequences, not failures. The consequence category chosen here drives the task-selection logic in Phase 6 — get it wrong and the task type will be wrong.

Scope

  • Hidden failures (protective devices, standby equipment)
  • Safety & environmental consequences
  • Operational consequences (production, quality, cost)
  • Non-operational consequences (repair cost only)

Process Steps

  1. 01

    Is the failure evident to the operating crew under normal duty?

    Intent

    If the operator can't tell it has occurred during normal work, it's a Hidden failure and failure-finding is likely mandatory.

    Inputs
    • Failure-mode + effects rows from Phase 4
    • Alarm and trip schedules
    • Operator round sheets and shift-log conventions
    Actions
    • Check every protective and standby function individually
    • Confirm alarms and trips are proven to be functional, not assumed
    • Flag as Hidden when there is no operator-visible evidence
    People

    Facilitator, operations supervisor, HSE. Instrument technician confirms alarm/trip proving history.

    Process

    Hidden is asked before Safety — a hidden failure that also carries safety consequence gets both flags.

    Technology

    Consequence column added to the FMEA worksheet (H flag + S/E/O/N below).

    What Good Looks Like
    • Every reliability, maintenance and operations lead can point to where this step lives — decisions, evidence and outputs are in one place, not in someone's inbox.
    • The opposite of: assuming alarms are proven when the last function-test was years ago
    • The opposite of: treating standby equipment failures as evident
    • The opposite of: missing hidden functions that live inside PLC logic
    What Bad Looks Like
    • Assuming alarms are proven when the last function-test was years ago
    • Treating standby equipment failures as evident
    • Missing hidden functions that live inside PLC logic
    Outputs
    • Hidden-failure flag on every relevant FMEA row
    • List of protective functions requiring failure-finding tasks in Phase 6
  2. 02

    Could the failure hurt or kill someone, or breach environmental limits?

    Intent

    If yes, the task must reduce probability to a tolerable level and redesign is on the table.

    Inputs
    • Effects column from Phase 4
    • Site risk matrix and tolerable-risk criteria
    • Regulatory environmental limits and licence conditions
    Actions
    • Use the site risk matrix consistently
    • Involve HSE representative for edge cases
    • Flag redesign candidates when residual risk stays above tolerable
    People

    HSE representative is a required signatory. Asset owner endorses tolerability judgements.

    Process

    Safety and environmental categorisation is never a maintenance-only decision — HSE must be in the room.

    Technology

    FMEA worksheet consequence column; site risk-matrix reference; redesign register.

    What Good Looks Like
    • Every reliability, maintenance and operations lead can point to where this step lives — decisions, evidence and outputs are in one place, not in someone's inbox.
    • The opposite of: flagging every failure as safety
    • The opposite of: under-flagging environmental impact because it isn't headline safety
    • The opposite of: no HSE signatory
    What Bad Looks Like
    • Flagging every failure as safety — dilutes the real safety-critical tasks
    • Under-flagging environmental impact because it isn't headline safety
    • No HSE signatory — decisions get overturned later
    Outputs
    • S / E consequence flag on every relevant FMEA row
    • Redesign candidate register entries
  3. 03

    Does the failure impact production, quality or throughput?

    Intent

    If yes, treat as Operational — the task must be cost-effective against the operational loss.

    Inputs
    • Downtime and quality-loss data from the CMMS and ERP
    • Standard rate for cost of downtime / kg / hour
    • Buffer, redundancy and by-pass capability
    Actions
    • Cost the downtime and quality loss per event and annualised
    • Account for redundancy or buffer capacity
    • Flag Operational consequence on the FMEA row
    People

    Operations manager confirms the loss rate. Finance supplies the standard cost inputs.

    Process

    Operational category is driven by cost, not perceived importance. Numbers are documented, not remembered.

    Technology

    CMMS downtime report; ERP cost data; loss-rate reference table.

    What Good Looks Like
    • Every reliability, maintenance and operations lead can point to where this step lives — decisions, evidence and outputs are in one place, not in someone's inbox.
    • The opposite of: loss figures pulled from memory rather than data
    • The opposite of: ignoring buffer / redundancy so losses look bigger than reality
    • The opposite of: treating maintenance cost as operational cost
    What Bad Looks Like
    • Loss figures pulled from memory rather than data
    • Ignoring buffer / redundancy so losses look bigger than reality
    • Treating maintenance cost as operational cost
    Outputs
    • Operational consequence flag with a defensible loss figure
    • Input to the Phase 6 cost-effectiveness decision
  4. 04

    Otherwise Non-operational — only repair cost matters.

    Intent

    Where the failure isn't Hidden, Safety/Environmental or Operational, the only test is whether a planned task costs less over life than run-to-failure.

    Inputs
    • Repair-cost history from the CMMS
    • Planned-task cost estimate (labour + materials + downtime)
    • Failure-rate data or MTBF
    Actions
    • Compare life-cycle planned-task cost vs corrective cost
    • Flag N consequence on the FMEA row
    • Push the row to Phase 6 for cost-only decision
    People

    Reliability engineer runs the numbers. Maintenance planner confirms task-cost inputs.

    Process

    Non-operational is not a dumping ground — every N flag carries an explicit cost rationale.

    Technology

    CMMS cost history; task-cost estimator; run-to-failure register.

    What Good Looks Like
    • Every reliability, maintenance and operations lead can point to where this step lives — decisions, evidence and outputs are in one place, not in someone's inbox.
    • The opposite of: using N as the default when the team is unsure
    • The opposite of: ignoring secondary-damage cost in the comparison
    • The opposite of: no documented rationale
    What Bad Looks Like
    • Using N as the default when the team is unsure
    • Ignoring secondary-damage cost in the comparison
    • No documented rationale — Phase 6 can't audit the decision
    Outputs
    • Non-operational consequence flag with cost comparison
    • Candidate run-to-failure list where planned cost > corrective cost

People

Facilitator, operations, HSE and asset owner. Safety and environmental categorisation is not a maintenance-only decision.

Process

The consequence category is stamped on every failure mode row and drives Phase 6.

Technology

FMEA worksheet gains a consequence column (H / S / E / O / N).

Phase Outputs

  • Every failure mode classified H, S, E, O or N
  • Redesign candidates flagged where risk cannot be tolerably reduced

What Good Looks Like

  • Every reliability, maintenance and operations lead can point to where this phase lives — decisions, evidence and outputs are all in one place, not in someone's inbox.
  • The opposite of: treating all failures as safety issues
  • The opposite of: missing hidden failures on standby equipment
  • The opposite of: categorising by asset instead of by failure mode

Common Pitfalls

  • Treating all failures as safety issues — dilutes real safety-critical tasks
  • Missing hidden failures on standby equipment
  • Categorising by asset instead of by failure mode