Behind every safety device's certificate is a large, patient piece of analysis that most engineers consume without ever performing: the failure modes, effects, and diagnostic analysis, or FMEDA. It takes a familiar tool, the failure mode and effects analysis, and extends it in two safety-critical directions, adding quantitative failure rates and, crucially, a judgement about whether each failure would be caught by diagnostics. The output is the set of failure-rate splits that feed straight into the safe failure fraction, the diagnostic coverage, and the probability-of-failure calculations that verify a safety loop. This page explains what an FMEDA is, how it differs from an FMEA, and how its numbers are used.
FMEDA in one line: An FMEDA (failure modes, effects, and diagnostic analysis) is a quantitative, safety-focused extension of FMEA that assigns a failure rate to each failure mode of a device and classifies each as safe or dangerous and as detected or undetected by diagnostics. Its outputs, the split of the total failure rate into these categories, are the raw inputs for calculating safe failure fraction, diagnostic coverage, and probability of failure on demand.
A traditional failure mode and effects analysis walks through a system, lists how each part can fail, and describes the effect of each failure, often ranking them qualitatively by severity, occurrence, and detectability. It is a broad reliability and design tool used across many industries to find weak points. What it usually does not do is attach hard, quantitative failure rates to each mode or decide, for functional-safety purposes, whether a failure would be automatically detected by the device's diagnostics.
An FMEDA adds exactly those two things. First, it is quantitative: each component and each failure mode is assigned a failure rate drawn from reliability databases, physics-of-failure models, or field data, so the analysis produces numbers rather than rankings. Second, it is diagnostic-aware: for every failure mode, the analysis judges whether the device's built-in diagnostics would detect that failure and drive an appropriate response, or whether it would remain hidden until a proof test or a demand. That second judgement is what puts the D in FMEDA and what makes it a safety-specific tool.
The combination of these two additions is what lets an FMEDA feed the safety calculations directly. A plain FMEA tells you a mode exists and roughly how bad it is; an FMEDA tells you how often that mode occurs and whether it hides from diagnostics, which are precisely the two facts the safety integrity math needs. That is why a device's safety certificate rests on an FMEDA rather than an ordinary FMEA, even though the two share a common ancestry and a similar structured, mode-by-mode approach.
The core output of an FMEDA is the total dangerous failure rate and total safe failure rate, each further divided into detected and undetected portions. In shorthand, the dangerous failures split into dangerous-detected and dangerous-undetected, and the safe failures split into safe-detected and safe-undetected. These four numbers, together with the failure modes judged to have no effect or to fall outside the safety function, describe the entire failure behavior of the device in the terms the safety standards care about.
From these splits, the headline safety metrics fall out directly. The diagnostic coverage is the fraction of dangerous failures that the diagnostics detect, computed from the dangerous-detected rate over the total dangerous rate. The safe failure fraction combines the safe failures and the dangerous-detected failures over the relevant total, expressing how much of the failure population is either benign or caught. And the dangerous-undetected rate, the failures that hide until a proof test, is the term that drives the probability of failure on demand once you fold in the test interval.
This is why the FMEDA is upstream of essentially every quantitative claim in a SIL verification. A change in how one failure mode is classified, dangerous versus safe, detected versus undetected, ripples through the diagnostic coverage, the safe failure fraction, and the probability calculation, and can move the integrity level a device qualifies for. Engineers rarely perform the FMEDA themselves for a certified device; instead they consume its published outputs, the failure-rate splits and the derived coverage figures, as trusted inputs to their own loop calculations.
In practice, an engineer building a safety loop takes the FMEDA-derived numbers from each device's safety datasheet, the dangerous-undetected rate, the diagnostic coverage, the safe failure fraction, and combines them across the sensor, logic solver, and final element to verify the loop meets its target integrity level. The FMEDA is the source of the per-device figures; the loop calculation is where they are assembled. Trusting those figures means trusting that the device in the field matches the one the FMEDA analyzed, in version, configuration, and operating conditions.
That last point is where operating data matters. An FMEDA assumes certain conditions, temperatures, duty, environment, and its failure rates only hold if the real installation stays within them. It also assumes the device's diagnostics are actually functioning, since the entire dangerous-detected category depends on diagnostics catching what the analysis credited them with catching. If diagnostics are disabled, ignored, or degraded in the field, the effective diagnostic coverage falls below the FMEDA value and the loop is weaker than its calculation claims.
A cloud SCADA platform helps keep the FMEDA's assumptions grounded in reality. By surfacing device diagnostic states, operating conditions, and the actual occurrence of faults across a fleet, it lets engineers check that the diagnostics the FMEDA relied on are alive and doing their job, and that the operating environment matches the analysis. Because Merobix reads field devices and their diagnostics into one browser-based view, it turns the FMEDA from a static certificate number into something an operator can continually sanity-check against how the hardware is actually behaving.
FMEA is a broad, largely qualitative analysis that lists failure modes and their effects and ranks them, often by severity, occurrence, and detectability. FMEDA extends it in two safety-specific ways: it assigns quantitative failure rates to each mode, and it judges whether each failure would be detected by diagnostics. Those additions are what let FMEDA feed the safe failure fraction, diagnostic coverage, and probability calculations that a SIL verification needs.
It produces the device's failure rates split into safe and dangerous, and each of those into detected and undetected, along with the modes judged to have no effect or to be outside the safety function. From these splits come the diagnostic coverage, the safe failure fraction, and the dangerous-undetected rate that drives the probability of failure on demand. These are the numbers that appear on a device's safety datasheet.
Usually not for a certified device. The manufacturer or a certification body performs the FMEDA and publishes its outputs on the safety datasheet. Field engineers consume those figures, the dangerous-undetected rate, diagnostic coverage, and safe failure fraction, as inputs to their own loop calculations. What engineers must still verify is that the installed device matches the one analyzed, in version, configuration, and operating conditions.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.