Risk Scoring with RFMEA: A Worked Analytical Method
Risk score, detection factor and risk priority number, Pareto ranking and a four-quadrant scatter — a complete applied technique, including the reason its thresholds are chosen rather than calculated.
What the technique adds to a conventional risk matrix
A standard project risk matrix is two-dimensional: likelihood against severity. The technique applied in the examined journal paper adds a third parameter, borrowed from a failure-analysis method used in manufacturing, and adapts its meaning for projects.
THE DETECTION FACTOR MEANS DIFFERENT THINGS IN THE TWO VARIANTS
| Variant | What the detection factor measures | High value means |
|---|---|---|
| Manufacturing parent technique | Ability to detect a product fault before shipment | No ability to detect |
| Project variant used in the paper | Ability to foresee a risk event with enough lead time to plan for it | Little or no forewarning |
The examined paper distinguishes the two carefully. Carrying the manufacturing meaning into a project context is the most likely way to misapply the technique.
The five parameters
Inputs and derived values
- Likelihood
- The probability that the risk event occurs. Assessed on a numerical scale.
- Severity
- The magnitude of the effect on the project should the risk occur.
- Risk Score (RS)
- Likelihood multiplied by severity. This is the conventional two-dimensional score.
- Detection factor
- The ability to foresee the risk event with enough lead time to plan for it. Assessed on a numerical scale.
- Risk Priority Number (RPN)
- Risk Score multiplied by the detection factor. The three-dimensional score.
Because RPN contains RS, the two are correlated by construction — but not identical, because a risk with a modest RS and very poor foresight can outrank one with a high RS that you will see coming. That divergence is the whole point of the second number.
The process
The six-box flow set out in the paper
Calculate the Risk Score
Multiply likelihood by severity for every risk in the register.
Plot an RS Pareto chart
Rank the risks by RS as a bar chart to reveal the distribution profile.
Calculate the Risk Priority Number
Multiply each Risk Score by its detection factor.
Plot an RPN Pareto chart
Rank by RPN. Comparing the two Pareto charts shows which risks change position once foresight is accounted for.
Plot the scatter diagram
RS on the x-axis, RPN on the y-axis, with the two critical thresholds drawn as vertical and horizontal lines. Four quadrants result; the top-right holds risks above threshold on both attributes.
Revise after treatment
Once contingency plans are actioned, recalculate RS and RPN and redraw the scatter.
Where the numbers come from — and why that matters
The operational detail is more instructive than the formulas, because it is where the judgement enters.
HOW EACH VALUE WAS OBTAINED IN THE EXAMINED STUDY
| Value | How it was obtained | What that implies |
|---|---|---|
| Likelihood and severity | The organisation's registers used non-numeric scales — letters for likelihood, small integers for severity, categories for the overall score. The researchers substituted equivalent numerical scales on a 1–10 range | A categorical scale cannot be multiplied. This substitution is a methodological decision that shapes every number downstream, and it is not neutral |
| Detection factor | Assigned on a 1–10 range by expert judgement, in consultation with the project manager | A single informant. Not an independent measurement, and not repeatable by another analyst without the same person |
| Critical thresholds | Scaled from a prior published study. That study used RS = 20 and RPN = 125; because the maxima here were roughly twice and roughly 1.5 times those, thresholds of RS = 40 and RPN = 180 were selected | Chosen, not calculated. Applied to both projects despite the paper's own warning that thresholds should be set project by project |
All values shown are specific to that one study. None is a standard.
What the study reported
What makes this a good exemplar
Practices worth copying
- Two explicit project selection criteria, stated before the cases were chosen
- The first case worked through in full narrative detail, the second compressed — replication demonstrated without repeating the exposition
- The same three exhibit types repeated once per case, making the two directly comparable by eye
- The known weakness flagged voluntarily, repeatedly, and again in the limitations
- A reader's likely count-check anticipated — the authors explain that only five points appear in a scatter containing six critical risks because two share identical coordinates
Soft spots to notice
- Thresholds selected by the researchers then used to measure the improvement they claim
- Detection factors from a single informant, so the analysis is not independently repeatable
- Both cases from one organisation
- The interview strand functions as warrant for relevance, not as evidence about the technique — none of the nine interviewees had ever used it
- The abstract calls the interviews unstructured while the methods section describes ten fixed open-ended questions, which is semi-structured
How published work handles its own weak joints is developed in Stating limitations and contribution.
What to carry forward
- RS = likelihood × severity. RPN = RS × detection factor. The third dimension is how far ahead you can see the risk coming.
- In a project context the detection factor means lead time to plan, not ability to catch a defect. Do not carry the manufacturing meaning across.
- Substituting numerical scales for categorical ones is a methodological decision that shapes every downstream number. State it.
- The thresholds are chosen, not derived. Do not reuse another study's values as if they were standards.
- An empty top-right quadrant after treatment is a checkable success criterion — the most useful idea in the method.
Frequently asked questions
What does the detection factor actually measure?
In the project variant used in the examined paper, it measures the ability to foresee a risk event with enough lead time to plan for it. In the manufacturing technique it came from, it measures the ability to detect a product fault before shipment. The two are not interchangeable.
What thresholds should I use?
None that appear in the paper. The authors state explicitly that there is no systematic procedure for setting them, chose theirs by scaling from another study, applied the same pair to both projects, and then listed the approach in their own limitations as a possible oversimplification.
Why add a second score when RPN already contains RS?
Because they can diverge. A risk with a moderate Risk Score but very poor foresight can outrank one with a high Risk Score you will see coming. Plotting both gives two attributes for prioritisation rather than one.
Does the technique find better risks?
The paper does not claim that. It claims fewer risks to focus on, which frees effort for reallocation. Whether fewer flagged risks is genuinely better, or a consequence of the thresholds the researchers chose, was not tested.
Can I apply this to my own risk register?
The mechanics are straightforward if your register carries likelihood and severity. The two things to decide deliberately are how you convert any categorical scales to numbers, and who assigns the detection factors — a single informant makes the analysis unrepeatable by anyone else.
References and source attribution
- Five examined research works supplied as exemplars: two doctoral theses (1999, 2016), a doctoral portfolio thesis (2004), a peer-reviewed journal paper (2014) and a conference paper (2017/2018). Structural observations only; chapter bodies were not reproduced.
- Supplied teaching source, Weeks 2-4: Introduction to Research Methods, Developing a Research Topic, Reviewing the Literature.
- Bryman, A. 2016, Social Research Methods, 5th ed., Oxford University Press, Oxford.
- O'Leary, Z. 2017, The Essential Guide to Doing Your Research Project, 3rd ed., Sage Publications, London.
Suggested questions for Ask KEVOS
- Walk me through calculating RS and RPN for a risk register I describe.
- How should I set critical thresholds for my own project rather than borrowing them?
- What is the difference between the manufacturing and project versions of the detection factor?
- How do I convert a categorical risk scale into numbers defensibly?
- How would I design a study that tests whether a risk technique actually works?
