Jorge A. Parra / engineering tools

Home / Risk

A rattle and a recall score the same. Until now.

Multiply severity by occurrence by detection and a thousand possible combinations collapse into a hundred and twenty values. RPN 100 — the number most action rules are set on — is shared by twelve of them, with severity running from 1 to 10. Place the ratings instead of multiplying them and every combination gets its own score, with impact dominant by construction. That is RPN+, and adopting it costs nothing: the same ratings, the same tables, one line of arithmetic.

1 Rank the impact first

2 State the failure mode

3 Likelihood

4 Only now, the causes

RISK REGISTER

    Nothing is sent anywhere — this runs in your browser and closing the tab clears it. Use Copy register to keep the result. Scores are relative rankings for one team on one system; they are not comparable between organisations, and they never replace the judgement of the people who know the equipment.

    The workflow

    Two phases. Preparation establishes what can fail and how likely it is; conclusion prioritises and acts. The fork sits at the middle, where the method changes according to the evidence available — because a counted incidence can only come from defect history, and on a new design nobody has any. Rather than invent a number and multiply it by two real ones, the analysis switches metric and says so.

    Structured risk analysis workflow Preparation phase: catalogue requisites, assess impact, gate out low impact, identify the surviving failure modes, then rank Incidence if defect history exists or Likelihood if not. Only then find causes with 6M and 5 Whys, and assess prevention and detection. Conclusion phase: rank by RPN+ or RE+ accordingly, then mitigate, report and review. PREPARATION PHASE CONCLUSION PHASE Requisites catalogue Aspects, capabilities, success criteria, importance, test conditions Ponder the evidence Incident reports, customer feedback, warranty claims, former studies Assess impact Rank the impact of failure Low impact — stop here No root cause work. Next mode. Identify the failure modes what fails, and what it results in The fork Defect history → rank Incidence No history → rank Likelihood the evidence decides, not the template Now find the causes 6M then 5 Whys, on what ranked Prevention and detection methods Prioritise accordingly With history → RPN+ = 100S + 10O + D Without → RE+ = 10S + L placed, not multiplied: every combination its own score Mitigate Avoid, reduce, transfer, accept, share, add redundancy, reconsider prevent, detect, or both Report and review Action plan: what, how, who, when Assess effectiveness, next steps risk register
    The impact gate and the evidence fork are the two decisions that separate this from a standard FMEA sheet.

    Two decisions doing the work

    Most of the boxes above are recognisable practice. These two are not, and they are what the method is for.

    Impact decides, so impact goes first

    Frequency is survivable. Consequence is not always. A defect that happens weekly and costs an hour is something you schedule around; one that happens every three years and puts someone in hospital, or loses the certification, is the one that ends the business. So impact is ranked before anything else and low impact exits there. Incidence follows, because looking up a frequency is cheap; cause analysis comes last, on what survived both — which also means the 6M, the 5 Whys and the meeting are never spent on modes that were never going to matter.

    The evidence fork

    Incidence is a count. You can only score it honestly if something has occurred and somebody wrote it down. Where that history exists, use it and compute RPN. Where it doesn't, switch to Likelihood and Risk Exposure rather than inventing an incidence to keep the formula intact — and drop to a simplified 1–5 scale, because ten grades of a number nobody measured is precision that isn't there.

    What detectability does

    In the RPN path it multiplies, because a mode you cannot detect is genuinely worse. In the exposure path it is recorded but kept out of the number — exposure is probability times impact. It still governs the mitigation choice: prevent it, detect it, or both.

    The two also run on different ranges — RPN from 1 to 1000, Risk Exposure from 1 to 25 — so they are different scales twice over and must never be sorted into a single list. A register that mixes them produces a ranking where position depends partly on which method was used, which is exactly the invisible distortion the fork exists to avoid. The register above keeps them apart.

    Why a product cannot carry the decision

    A rattling panel that occurs constantly and a catastrophic failure that occurs once in a decade produce the same Risk Priority Number. Placing the ratings instead of multiplying them tells them apart:

    Ratings RPN RPN+
    Frequent, trivial I1  N10 D1 10 201
    Rare, catastrophic I10 N1  D1 10 1011
    the same three ratings, read two ways identical five ranks apart

    Under RPN these are the same failure mode as far as any sorting or any threshold is concerned, and only one of them can close the business. Under RPN+ the catastrophic one outranks the nuisance by eight hundred, because impact sits in the hundreds column and nothing occurrence or detection can do will reach it. That is the whole change: the ratings are placed rather than blended, so they can still be told apart afterwards.

    The gate needs an owner, not just a threshold

    A complete table is defensible: every mode assessed, standard followed, nobody exposed. A short list is a judgement, and judgements have owners — which is why the instinct to score everything is hard to shift, and why it is not simply timidity. In regulated work an auditor will ask to see that every mode was considered. So screening out has to appear as a documented decision with a threshold and an authority behind it, never as a silence. Set the rule at management level and the analyst is applying a policy rather than defending a personal call. The export here writes the threshold and leaves a line for the signature.

    Examples that get a session moving

    All tools included in the SRA not just save time, they have plenty of examples to trigger momentum, clarity, and stronger ideas from your team particularly your brainstorming sessions.

    These examples provide a practical starting point for your creative thinking. Well-chosen examples give individuals and teams a shared reference:

    • Reducing ambiguity
    • Making it easier to move from abstract discussion to actionable ideas
    • Promote real-world solutions, increasing the likelihood that promising becomes practical
    • Inspiring new thinking, helping participants visualize possibilities and build on proven approaches
    • Creating shared context: Real-world applications clarify concepts and align the group around a common understanding
    • Introducing diverse perspectives, mixing different fields encourage participants to challenge assumptions and explore unconventional solutions
    • Used effectively, examples help teams reduce the frustration and fatigue that often come with stalled brainstorming sessions
    • Building a culture where innovation is not treated as a special event, but as an everyday organizational capability

    Start with the catalogue

    Every failure mode hangs off a requirement, so the requisites catalogue comes before the risk analysis — and it is the part most teams find hardest.

    A requirement written as prose cannot be tested, cannot enter a FAST diagram, and cannot be scored for risk. Written as a function — a verb, a noun, a unit and a tolerance — it does all three. The requisites catalogue builder is free and runs in your browser: seven aspects with their characteristics, two hundred function verbs, a hundred and fifty-eight measurable nouns, two hundred unit abbreviations, and a refusal if the requirement cannot be measured.

    It is the same catalogue the register reads from. One artefact feeding value engineering, function analysis and risk analysis, rather than three documents that drift apart.

    RIQ+ — MoSCoW that actually sorts

    Requirement Importance Quantified. MoSCoW puts requirements in four boxes and stops: inside a box nothing is ordered, so twenty Musts arrive with no sequence, and the sequence is settled by whoever speaks loudest.

    Eleven ticks

    Value — does it apply? Value, benefit, impact, scope, coverage, reach. Effort — is it large? Resources, workforce, research. Readiness — large or small? Know-how, confidence. No rating anyone must defend to a decimal place: "does reach apply here?" is answered in a second, where "how large, from 1 to 5?" is an argument.

    Placed, not multiplied

    RIQ+ = 100×Value + 10×Effort + Readiness, each digit 1 to 4: 64 distinct scores from 111 to 444, and the score reads back. 342 is value 3, effort 3, readiness 2 — the argument that makes RPN+ beat RPN, applied to requirements.

    The letter is derived, not guessed

    The hundreds digit is the MoSCoW letter: five or six ticks a Must, three or four a Should, two a Could, one or none a Won't. The letter people already use stays, and now it rests on what was counted rather than on who argued hardest.

    Cheap and ready first, inside the letter

    Effort is inverted, so of two requirements worth the same the cheaper ranks higher, and readiness breaks what is left. Effort outranks readiness because effort is what the requirement will cost whoever does the work, while readiness only says how ready this team is today.

    A Could never outranks a Must

    Given the same requirements, RICE puts a lesser one above a more valuable one in 7 % of pairs and WSJF in 17 %, because both divide by effort. RIQ+ never does: value is the leading digit. That is the promise MoSCoW makes and cannot keep.

    Urgency is a date, not a digit

    Urgency is about when, not about how much a requirement matters, so it is kept as the date it is needed by. It orders requirements of equal RIQ+ and flags what is due or overdue. A tick set in August is a lie by November; a date stays true by itself.

    RIQ+ is optional: MoSCoW alone remains the default, and switching back leaves the letters as they stand. Like RPN+ and RE+, it is free for anyone to use, with credit.

    Say the failure mode in one line

    Most risk sessions stall in the same place: nobody can state the mode clearly. The causes come later, with 6M and 5 Whys, further down this page.

    The statement structure

    Four parts in a fixed order. If the action or event, it will result in the effect, because of the cause, with this incidence or probability. Say it that way and you cannot skip the consequence, which is what impact is actually scored against — a mode written as a bare noun phrase gets ranked on a feeling.

    RPN+ and RE+

    A product collapses the ratings together and cannot be taken apart again. Placing them instead gives every combination its own score, with impact dominant by construction rather than by weighting.

    The arithmetic behind the claim at the top of this page:

    Distinct RPN values 120 of 1000
    Combinations sharing a score 994
    Largest single tie 24 combinations

    The twelve combinations sharing RPN 100 run from severity 1 to severity 10: the threshold everybody acts on cannot separate a cosmetic nuisance from a fatality.

    What RPN+ is

    100 × Impact + 10 × Incidence + Detection, running 111 to 1110. Every one of the thousand combinations gets its own score. The coefficients are not weights — they are the smallest separations that stop one rating carrying into the next, which is why they are not open to argument the way a weighting would be.

    What RE+ is

    10 × Impact + Likelihood, running 11 to 55. All twenty-five combinations distinct. The product is proportionally worse than RPN — fourteen values out of twenty-five — and it scores a negligible certainty exactly the same as a catastrophic rarity.

    Why not just weight it

    Weighting reduces the collisions and never removes them: severity squared still leaves 994 combinations tied with something, and the first reviewer asks why that exponent and not another. A weight is a judgement and can be argued with. These coefficients are the smallest values that stop one rating carrying into the next — there is one correct answer and it is arithmetic.

    It reads back

    Impact 7, incidence 5, detection 4 scores 754. The number carries its own ratings, so a score in a report can be checked without opening the register. That holds for every rating below 10, and RE+ always reads back because both its scales are single digit.

    What it costs

    It costs nothing to adopt. The same three ratings, the same tables, the same scales. No new judgement is required of anyone, and the classical figure still appears beside it for whoever asks. This is arithmetic, not a method change.

    The products are still reported. Customers ask for them and suppliers report them, so RPN and RE appear in brackets beside every plus score. But the ranking is on the plus score, because a product cannot order what it cannot tell apart. Sorting a register by RPN descending is sorting by a number that has 120 rungs for a thousand things.

    Worth being straight about what this is and is not. The plus scores are an ordering, not a magnitude: 1011 is not ten times worse than 101. RPN claims to be a magnitude and fails at being either. The same trade appears elsewhere on this site — a surface finish specified before the feed is chosen, a tool life measured rather than assumed. Giving up a false precision to get a true one.

    RPN+ against Action Priority

    The AIAG & VDA handbook retired RPN in 2019 for the same reason set out above, and replaced it with Action Priority. AP and RPN+ diagnose the same disease and prescribe differently. Here is the comparison, including where AP wins.

    Action Priority RPN+ / RE+
    What it returns Three categories: high, medium, low 1000 distinct values, or 25 without history
    Ordering inside a priority None. Forty high items arrive unranked Total order, no ties anywhere
    Severity dominance Yes, built into the table Yes, built into the arithmetic
    Basis A published lookup of every rating combination One line of arithmetic, checkable by hand
    Rating scales Only valid against the handbook's own scales Any 1–10 scale, including one you wrote
    Score traces to its ratings No. "High" does not say which factor drove it Yes. 754 is impact 7, incidence 5, detection 4
    When occurrence cannot be counted Still requires an occurrence rating Switches to RE+ and records that it did
    Recognised by OEMs Yes — the automotive standard No. It is arithmetic, not a standard
    Audit position Expected. Its absence is a finding Supplementary. Report it alongside
    Cost to adopt Licensed handbook, new scales, retraining None. Same ratings, same tables

    The two cases from the top of this page, and a third

    The handbook's own rationale for retiring RPN uses the first pair, so Action Priority separates them by design. The interesting case is the second block, where three modes share a severity and any severity-driven banding must place them together.

    Ratings RPN AP RPN+
    Frequent, trivial I1  N10 D1 10 separates 201
    Rare, catastrophic I10 N1  D1 10 separates 1011
    Injury, rare, caught in-house I9 N2 D2 36 same band 922
    Injury, rare, escapes to the customer I9 N2 D9 162 same band 929
    Injury, occasional, caught I9 N6 D2 108 same band 962

    Three modes that all injure somebody. AP places them together and stops — it has told you to act, which is its job. Now decide which one to start on Monday.

    RPN answers, and answers wrongly. It puts the escaping one first at 162, ahead of the one that happens three times as often at 108 — because a bad detection rating multiplies harder than a real frequency does. RPN+ orders them 962, 929, 922: most frequent first, then the one that escapes, then the one already caught. Incidence outranks detection because it sits in the higher column, which is the order you would have chosen anyway.

    Read that table honestly and AP wins the argument that matters most in automotive. If your customer asks for Action Priority, you give them Action Priority — nothing here replaces it, and this tool does not pretend to. RPN+ is not a standard and will not satisfy an auditor who came looking for one.

    Where RPN+ earns its place is the row AP leaves blank: ordering inside a priority. AP tells you that forty modes need action. It cannot tell you which to start on Monday, and in practice teams fall back to sorting by RPN — which reintroduces every flaw AP was created to remove. RPN+ is what that fallback should be. Use AP to decide whether to act; use RPN+ to decide the order. They answer different questions and neither answers both.

    The second row worth noticing is the last but one. AP assumes an occurrence rating exists. On a new design it does not, and the handbook has no mechanism to record that the number was estimated rather than counted. That gap is the one this method was built around, and it is why the fork and RPN+ belong together rather than as two separate ideas.

    What 6M is actually for

    Identifying causes is what it does. Preventing premature convergence is why it is worth doing.

    The empty categories earn their keep

    The first plausible cause arrives within about ninety seconds of a problem being described, and without a structure the room converges on it. Six categories force a look at five places nobody wanted to look. Much of the value sits in the ones that come back empty, because you can now say you looked.

    Where they land is itself a finding

    All in Manpower and you are blaming people, and the analysis has not started. All in Methods and it is organisational, so no shop-floor fix will touch it. Spread evenly and it is either systemic or the problem is stated too broadly to analyse. Clustered in Materials and Machinery and it is physical, with an owner and a budget.

    Two domains answer who fixes it

    Splitting the six into knowhow and physical answers a question the categories alone do not. Physical causes have equipment owners and capital behind them. Knowhow causes need management, and no amount of maintenance will move them. That is the difference between a work order and a decision.

    6M and 5 Whys are a pair, not alternatives. 6M gives breadth, 5 Whys gives depth. 6M alone produces a wide, shallow list nobody can act on. 5 Whys alone produces one deep chain that may have started down the wrong branch — ask why a defective product reached a customer and you follow detection; ask why the defect exists and you follow creation. Both are legitimate readings of the same observation, and only the deeper levels reveal that they share a root.

    A worked chain from the deck: customers are dissatisfied, because the product is defective, because material quality control is ineffective, because the standards are unclear, because design and production standards are poor, because there is no engineering standards function and no engineering management. The root cause is an organisational gap, not a product defect — and no amount of inspection would have found it.

    Three things it cannot do

    It will not tell you which cause dominates. That is what the scoring is for, and treating a long cause list as a priority list is the most common way the two get confused.

    It cannot express interaction. Causes that only produce failure in combination appear as two independent entries. There is no way to write the AND between them, and that AND is often the whole mechanism.

    The categories are not mutually exclusive. A gauge that drifted is Measurements or Machinery depending on who is classifying it, and arguing the point is wasted time. When a cause fits two, the useful question is which domain it sits in — who fixes it — not which M it belongs to.

    What the register application does today

    The method above is the point; this is the state of the tool that runs it. It is a desktop application: one analysis file per site, no server, no account.

    It saves itself

    There is no save button. Every change is written as it is made, and an unfinished failure mode survives closing the window. A mode is filed in the analysis by itself once it is complete — requirement, ID, description, effect and score.

    Sign-off is the only formal act

    When the analysis is ready, an approver signs it off: the decision on the residual risk, with a name and a date, and the whole analysis frozen as a numbered revision that can never change. Work continues on the working copy, and the report says on its face which one it is.

    The criteria are written down

    Rule 0, impact 1 is always screened out, then the screening gate, the act-regardless threshold, the evidence thresholds, the review interval and the committee dispute spread. They belong to the organisation, are printed in every report, and are changed only by the criteria manager, inside the tool, as a new table version.

    A rating is a claim; a control is the evidence

    A low incidence with no prevention control, a good detectability on an unverified method, a control checked more than a year ago, a critical mode with no action, an action done but never re-rated, a review overdue: the tool names each one as a finding, and the report prints them.

    Monitoring, not just scoring

    Each mode carries its controls with the date they were last verified, its actions with owner and due date, and its reviews of whether the action worked, each setting the next review date. Scores are kept as a history, so the report shows the risk before and after the action.

    The team is on the record

    Who took part, and what they speak for. A mode can be scored as a committee — one rating per person, the median scored, every vote kept — and a wide spread of impact is flagged as disputed, because that is where the misunderstanding is.

    Requirements are ordered, not just lettered

    MoSCoW by default; RIQ+ where an order inside each letter is wanted. Eleven ticks give the letter and a score of 64 distinct values, the catalogue sorts by it, and every report prints the ticks behind each score.

    Requirements are tested before they are filed

    Ten checks after ISO/IEC/IEEE 29148: is it verifiable, is the noun a quantity, does the unit fit the noun, is the tolerance usable, is it unambiguous, singular, solution-independent, complete, consistent with the catalogue — and the three only a reviewer can answer. Advisory: the tool tells you, you decide.

    Search instead of a second register

    One box searches every analysis in the file: failure modes, causes, controls, actions, reviews, requirements and the people named in them. The questions that serious management should be asking about risk continuously are included in ready-made searches: what is overdue, what is due for review, which critical risks carry no action, and which controls nobody has verified. A result opens the analysis at that very row.

    The tables are yours

    Rules, verbs, nouns, requirement domains and aspects, the impact, incidence, likelihood and detectability wording, and the cause descriptions — all edited in the tool by the criteria manager. Anything typed in because a list lacked it waits as a proposal for them to accept, correct or reject.

    Everything the analysis holds is in one file, so a report can be printed at any time and a signed revision reprinted exactly as it was signed. Nothing is sent anywhere.

    Where it goes next: the corporate register

    A risk study generates far more than a ranking, and almost all of it is thrown away. The tables record the conclusions and lose the reasoning — which is why the same failure mode gets argued from scratch at the next review, and why a study nobody can reconstruct gets redone rather than updated.

    It keeps what forms discard

    Which branch each score came from. What was screened out, by whose authority, under which threshold. The 6M category and the 5 Whys chain behind a cause. What changed between revisions and why. A standard FMEA sheet has a column for none of it.

    The tables belong to the company

    No two organisations mean the same thing by a impact of 7. Every published 1–10 scale is somebody's industry presented as a universal. So the impact, incidence and detection tables are editable, set once at corporate level — and then everyone is held to them. Consistency comes from a fixed local standard, not a borrowed global one.

    Someone owns it

    A Risk Leader holds the tables, the thresholds and the register itself — the same authority the gate needs, so screening out is a published rule rather than a personal call. Tables are versioned rather than overwritten, and every score records the version it was given under, so an old report still means what it meant.

    The report is then a view, not a document. Print it as often as it is needed, for the review, for the auditor, for the board — always from the same register, always current, never a copy that drifted.

    The workflow deck, and word when the register ships

    The diagram above is the summary. The deck is the sequence: what to prepare, how to run the room, the scoring bases, where the gate and the fork sit in a live discussion, and the review cadence afterwards. Built for real project reviews, not for a compliance binder.

    The deck now, and first word when the corporate register is ready.

    RPN+, RE+ and RIQ+ are free to use

    Free for anyone to use. No patent has been sought and none will be.

    Anyone may implement RPN+, RE+ and RIQ+ — software vendors, standards bodies, consultancies, end users — without permission, licence or fee. The technical note is published to establish prior art, so that the method cannot later be patented by anyone and withheld from use. A formula is not subject to copyright in any case; the statement is made to remove doubt rather than to grant a right that would otherwise be withheld.

    The only thing asked in return is credit:

    Where the method is implemented, described or taught, please attribute it as:

    RPN+ and RE+, from Structured Risk Analysis by Jorge A. Parra.

    They provide clear, tie-free risk rankings with distinct scores that prioritize impact.

    RIQ+ — Requirement Importance Quantified, from Structured Risk Analysis by Jorge A. Parra.

    It orders requirements inside each MoSCoW letter without ties, value first.

    The technical note sets out the derivation of the coefficients, the full enumeration behind every figure quoted on this page, and a statement of what in the method is prior art and what is not. The note is © 2026 Jorge A. Parra and licensed CC BY 4.0: it may be copied, adapted and built on, commercially or not, with credit.

    Working sessions

    The register handles the arithmetic. The hard part is getting a room to say out loud what can go wrong, and to admit which failure modes have no history behind them. That is where an outside facilitator earns the cost. I run risk workshops on site or remote.