\1**\1**.
FMEA-style scoring can help teams prioritise work, but a number by itself is not evidence of control.
Define the process before the score
Map the process the system supports. Identify inputs, decisions, records, handoffs, interfaces, and outputs. A system function cannot be rated sensibly without knowing what happens when it is wrong or unavailable.
Include manual workarounds and upstream and downstream systems. A seemingly minor interface error can matter if it changes a critical value or causes a record to be omitted from a required review.
Describe failure modes clearly
Write failure modes in observable terms: a role can approve outside its scope, a calculation rounds a value incorrectly, an interface drops a unit, an audit trail does not capture a change, or a restore returns an incomplete record set.
Then describe the effect on the process. Avoid vague effects such as 'compliance issue' when a more useful consequence can be stated, such as an unreviewed result, an incorrect release decision, or loss of attributable evidence.
Use scoring with judgement
Severity, occurrence, and detectability can support a consistent discussion. The scoring definitions must be agreed before use, and the team should explain unusual ratings. A low occurrence estimate should not weaken a control that is required by the process or regulation.
Risk priority numbers are not a regulatory safe harbour. Use the score to focus test design, review, monitoring, and procedural controls. Retain the rationale and the names of the reviewers.
Turn risk into evidence
For each important failure mode, identify a preventive or detective control and the evidence that will demonstrate it. Evidence may be a test result, configuration record, access review, audit-trail review, interface reconciliation, restore test, or approved procedure.
Keep the risk record linked to the traceability matrix so a reviewer can move from risk to requirement to test and back again.
Review residual risk
After controls are implemented and tested, reassess residual risk. An accepted residual risk should have an owner and a reason. New incidents, changes, data trends, or process changes should trigger a review rather than waiting for a calendar date.
| Risk question | Useful answer |
|---|---|
| What can fail? | A specific function, interface, role, record, or control. |
| What is the effect? | A defined consequence for product, patient, data, or process. |
| What controls it? | A technical, procedural, or review control. |
| What proves it? | Objective evidence tied to an acceptance criterion. |
FAQ
Is FMEA mandatory for validation?
No single risk tool is universally required. The organisation should use a suitable, documented method that fits the system and process.
Should every risk receive a test?
Every important control needs appropriate evidence, but evidence may be testing, review, monitoring, or a procedure depending on the risk.
Who owns the risk assessment?
The process owner should own process risk, with input from quality, IT, validation, and subject matter experts as appropriate.
Can risk ratings be changed later?
Yes, when new evidence or a process change justifies it. Keep the change history and rationale.
Decision rule: choose evidence from the consequence of failure, the control being relied on, and the ability to detect a problem. A larger document set is not automatically stronger. Clear scope, reproducible evidence, and an approved conclusion are what make the decision defensible.
Keep the rationale with the controlled record. Future reviewers should be able to see what was considered, what was tested or reviewed, what remains uncertain, and who accepted the residual risk.
During review, compare the approved requirement with observed use, current configuration, and retained evidence. That simple comparison often finds drift before an auditor does.
For related work, read our validation traceability matrix guide.
Primary sources
Bring validation work under control
VLMS Software helps healthcare teams organise validation, evidence, and audit readiness around the work that matters.
Talk to VLMS Software