Professional Documents
Culture Documents
Potential Failure Mode In what ways can the Component, Subsystem or System potentially fail and cause a safety risk?
Potential Causes List every conceivable failure and/or failure mechanism for each failure mode
Current Process Controls What are the Existing Controls, Procedures or Specifacations that prevent either the cause or the failure mode
D E T
R P N
Actions Recommended What are the actions for reducing the Occurrence of the cause, or improving Detection? Should have actions on high RPN's or EASY FIXES
Resp.& Target Date Who's Responsible for the recommende d action? What date?
Actions Taken What were the actions implemented? Include completion month/year. (Then recalculate resulting RPN.)
S E V
O C C
D E T
R P N
Leakage/Rupture
Spill to Storage Area and Dissipation of H2 Spill to Storage Area and Combustion of Vapour Spill to Storage Area and Pooling of LH2
H2 Embrittlement
4 3 3 2 6
Specification: Supplier Specification: Supplier Specification: Supplier Design: Barrier Procedure: Restricted Access
Mechanical damage (attack) Mechanical damage (structural) Operator Error Vacuum Jacket Failure Mechanical damage (impact)
5 6 4 3 6 Procedure: Operator Training Control: Vent to Stack Specification: Supplier Procedure/Design: Restricted Access Procedure: Operator Training Specification: Supplier Design: Rupture Disk - Vent to Stack Specification: Supplier Procedure/Design: Restricted Access Procedure: Operator Training Specification: Supplier Design: Rupture Disk - Vent to Stack Specification: Supplier Control: Shutdown
6 6
H2 Embrittlement
7 7
3 6
7 7
Debris H2 Embrittlement
7 4
No signal
System Fault
7 7 3
3 7 6
Out of Range Power Failure Calibration Error Electrical Damage (shock) Calibration Error Electrical Damage (shock) Calibration Error Mechanical Wear H2 Embrittlement Corrosion Control Malfunction Incorrect Design Specifications Control Malfunction Mechanical Wear H2 Embrittlement Corrosion Control Malfunction Incorrect Design Specifications Control Malfunction
5 4 7 6 7 6 7 2 4 3 4 2 4 2 4 3 4 2 4
Specification: Supplier Procedure: Supplier Calibration Procedure: Supplier Calibration Design: Rupture Disk - Vent to Stack Procedure: Supplier Calibration Control: Shutdown Specification: Supplier Specification: Supplier Control: Vent to Stack Control: Shutdown Specification: Supplier Specification: Supplier
Cryo Pump
Low Pressure
System Fault
How probable is Detection of cause? Risk Priority # to rank order concerns 4 4 4 6 10 160 120 120 120 10 10 4 4 6 216 3 84 4 6 84 252 10 3 490 84 4 10 7 84 490 126 4 10 5 10 5 10 5 7 4 4 10 2 10 7 4 4 10 10 60 120 105 0 0 360 210 42 48 36 120 28 280 42 48 36 120 60 0
600 Restricted vehicle access, ensure structure can withstand impact. 500 600 Seismic Evaluation and certification. 160 72
Page 1 of 10
Leakage/Rupture
Spill to Storage Area and Dissipation of H2 Spill to Storage Area and Combustion of Vapour Spill to Storage Area and Pooling of LH2
H2 Embrittlement
4 3 3 6
Specification: Supplier Specification: Supplier Specification: Supplier Procedure/Design: Restricted Access Procedure: Operator Training
4 4 4 6
6 6
Incorrect Design Specifications Control Malfunction Vacuum Jacket Failure Mechanical Damage Mechanical Damage
2 4 3 6 6
Control: Vent to Stack Procedure: Restricted Access Procedure: Operator Training Control: Vent to Stack
10 10 2 10 2
Pressure Regulator
System Fault
Thermally Isolate LH2 Allow Excess Heat from Environment Conduction Provide LH2 Flow Path Flow Blocked Insufficient Flow Capability Contain LH2 @10000psi Leakage/Rupture
7 3 3 3 6 7 7 3 3 8
Debris Debris Mechanical Wear Incorrect Design Specifications Debris Mechanical Damage Incorrect Design Specifications Debris H2 Embrittlement
6 6 8 2 6 6 6 6 4 3 3 6
Control: Vent to Stack Control: Shutdown Control: Shutdown Control: Shutdown Control: Vent to Stack Control: Vent to Stack Control: Shutdown
2 7 7 7 2 2 10 7 10 4 4 4 6
Spill to Storage Area and Dissipation of H2 Spill to Storage Area and Combustion of Vapour Spill to Storage Area and Pooling of LH2
Specification: Supplier Specification: Supplier Specification: Supplier Procedure/Design: Restricted Access Procedure: Operator Training
Vapourizor
Flow Blocked
7 6 6 3 3 3 3 8
Mechanical damage (collision) Mechanical Damage (attack) Incorrect Design Specifications Debris Corrosion Mechanical Damage Debris Corrosion Mechanical Damage Incorrect Design Specifications H2 Embrittlement
2 5 2 7 3 6 7 3 6 2 4 3 3 6
Control: Vent to Stack Control: Vent to Stack Specification: Supplier Control: Shutdown Specification: Supplier
10 10 10 2 4 10 7 4 10 10 4 4 4 6
200 500 200 98 72 360 147 36 180 60 160 120 120 360
Leakage/Rupture
Spill to Storage Area and Dissipation of H2 Spill to Storage Area and Combustion of Vapour Spill to Storage Area and Pooling of LH2
Specification: Supplier Specification: Supplier Specification: Supplier Procedure/Design: Restricted Access Procedure: Operator Training
Heat Exchange; LH2 to Low Pressure -30C with Air @Varying Ambient Temperature
System fault
Mechanical damage (collision) Mechanical Damage (attack) Incorrect Design Specifications Ambient temperature too low
2 5 2 10 Control: Shutdown
10 10 10 7
3 High Pressure Output Stream Too Cold Excess Vapour Pressure System Fault 6 1 1 6 6 Printed:3/15/2013
Freezing/ice reducing heat conduction Ambient temperature too high Incorrect Design Specifications Ambient Temperature too Low Ambient Temperature too Hot Incorrect Design Specifications
10 Control: Shutdown 10 Control: Vent to Stack 2 Control: Warning 10 10 Control: Vent to Stack 2
7 2 2 10 2 10
Leakage/Rupture
Release to Storage Area and Dissipation of H2 Release to Storage Area and Combustion of Vapour
H2 Embrittlement
4 3 3 6
Specification: Supplier Specification: Supplier Specification: Supplier Procedure/Design: Restricted Access Procedure: Operator Training
4 4 4 6
Moderate CH2 Temperature Too High Excess Vapour Pressure Temperature Variations
Mechanical damage (collision) Mechanical Damage (attack) Incorrect Design Specifications Incorrect Design Specifications
2 5 2 2
10 10 10 2
System Fault
Leakage/Rupture
Release to Storage Area and Dissipation of H2 Release to Storage Area and Combustion of Vapour
6 6 6 1 1 1 1 8
Corrosion Mechanical Damage Debris Incorrect Design Specifications Corrosion Mechanical Damage Debris H2 Embrittlement
3 6 7 2 3 6 7 4 3 3 6
Specification: Supplier
Specification: Supplier
Specification: Supplier Specification: Supplier Specification: Supplier Procedure/Design: Restricted Access Procedure: Operator Training
4 10 10 10 4 10 10 4 4 4 6
System fault
3 3 3 3 6 6 6 8
Mechanical damage (collision) Mechanical Damage (attack) Incorrect Design Specifications Debris Corrosion Mechanical Damage Incorrect Design Specifications Debris Corrosion Mechanical Damage H2 Embrittlement
2 5 2 7 3 6 2 7 3 6 4 3 3 6
10 10 10 7 4 10 10 2 4 10 4 4 10 6
200 500 200 147 36 180 60 84 72 360 160 120 300 360
Flow Blocked
Leakage/Rupture
Release to Storage Area and Dissipation of H2 Release to Storage Area and Combustion of Vapour
Flow Blocked
6 6 6 3 3 3 3 9
Mechanical damage (collision) Mechanical Damage (attack) Incorrect Design Specifications Debris Corrosion Mechanical Damage Debris Corrosion Mechanical Damage Incorrect Design Specifications H2 Embrittlement
2 5 2 7 3 6 7 3 6 2 4 3 3 6 2 5 4 2 4 7 3 6
10 10 10 2 4 10 7 4 10 10 4 4 4 10 10 4 10 10 2 4 10
200 500 200 84 72 360 147 36 180 60 160 120 120 0 200 500 160 200 400 84 72 360 Page 3 of 10
Dispensor
Leakage/Rupture
Release into Occupied Area and Dissipation of H2 Release into Occupied Area and Combustion of Vapour
10 Corrosion Stress Cycling/Fatigue Mechanical damage (impact) Mechanical damage (collision) Mechanical Damage (attack) Operator Error Incorrect Design Specifications Control Malfunction Debris Corrosion Mechanical Damage
6 6 6
Printed:3/15/2013
1 1 1 1 1 1 7 7 7 7 3
Debris Corrosion Mechanical Damage Incorrect Design Specifications Incorrect Design Specifications Control Malfunction Incorrect Design Specifications Control Malfunction Fueling Rate Too High Inlet Gas Too Warm Electrical Damage (shock)
7 3 6 2 2 4 2 4 6 5 6
Low Pressure
Control: Abort Fueling Control: Abort Fueling Control: Vent to Stack Control: Vent to Stack Control: Vent to Stack Control: Vent to Stack Control: Shutdown
High Pressure
System fault
Excess Tank Pressure: Potential Rupture Decreased tank Pressure: Incomplete Fueling Excess Tank Pressure: Potential Rupture Decreased tank Pressure: Incomplete Fueling Potential Gas Leakage
3 3 3 10
5 4 7 6 7 6 7 6 7 6 7 6 4 4 3 3 6 2 7 3 6 7 3 6 2 2 6 4 3 6 4 4
Procedure: Supplier Calibration Control: Shutdown Procedure: Supplier Calibration Control: Shutdown Procedure: Supplier Calibration Control: Shutdown Procedure: Supplier Calibration Control: Shutdown Procedure: Supplier Calibration Control: Shutdown
10 10 5 7 5 7 5 7 5 7 5 7 10 4 4 4 6 10 2 4 10 7 4 10 10 2 10 4 4 6 10 4
150 120 105 420 350 42 35 420 350 42 35 420 400 160 120 120 360 200 98 84 420 147 36 180 60 24 360 80 60 180 200 112
10 Calibration Error 1 Electrical Damage (shock) 1 Calibration Error 10 Electrical Damage (shock) 10 Calibration Error 1 Electrical Damage (shock) 1 Calibration Error 10 Electrical Damage (shock) 10 Power Failure 8 H2 Embrittlement 10 Corrosion 9 Stress Cycling/Fatigue Mechanical damage (impact) Incorrect Design Specifications Debris Corrosion Mechanical Damage Debris Corrosion Mechanical Damage Incorrect Design Specifications Incorrect Design Specifications Mechanical Damage H2 Embrittlement Corrosion Mechanical damage (impact) Control Malfunction H2 Embrittlement
No Shutdown Initiated
Leakage/Rupture
Spill to Storage Area and Dissipation of H2 Spill to Storage Area and Combustion of Vapour Spill to Storage Area and Pooling of LH2
Specification: Supplier Specification: Supplier Specification: Supplier Design: Restricted Access Control: Vent to Stack Specification: Supplier Design: Rupture Disk - Vent to Stack Control: Shutdown Specification: Supplier
Flow Blocked
7 7 7 3 3 3 3 6 6 5 5 5 5 7
Specification: Supplier Specification: Supplier Design: Restricted Access Control: Vent to Stack Specification: Supplier Specification: Supplier Design: Rupture Disk - Vent to Stack Design: Restricted Access Specification: Supplier Specification: Supplier Specification: Supplier Design: Restricted Access
Fails Closed
Corrosion
63
CH2 Valve
Leakage/Rupture
Release to Storage Area and Dissipation of H2 Release to Storage Area and Combustion of Vapour Release into Occupied Area and Dissipation of H2 Release into Occupied Area and Combustion of Vapour Excess Liquid Pressure
7 7 8
6 4 4 3 3 6 2 7
6 10 4 4 4 6 10 2
Flow Blocked
Corrosion
Specification: Supplier Design: Rupture Disk - Vent to Stack Control: Shutdown Specification: Supplier
63
7 3 3 3 3 5 5 5 5 7
Mechanical Damage Debris Corrosion Mechanical Damage Incorrect Design Specifications H2 Embrittlement Corrosion Mechanical damage (impact) Control Malfunction H2 Embrittlement
6 7 3 6 2 4 3 6 4 4
10 7 4 10 10 4 4 6 10 4
Fails Open
Specification: Supplier Specification: Supplier Design: Restricted Access Control: Vent to Stack Specification: Supplier Specification: Supplier Design: Restricted Access Specification: Supplier Design: Rupture Disk - Vent to Stack Design: Restricted Access Control: Vent to Stack Design: Restricted Access Control: Vent to Stack Specification: Supplier Design: Rupture Disk - Vent to Stack Control: Shutdown Specification: Supplier
Fails Closed
7 7 7 7
3 6 4 3
4 6 10 3
84 252 280 63
Thermaly Isolate LH2 from Environment Check Valve Provide Single Direction Flow Path
7 7 6 6 7 7
Mechanical damage (impact) Control Malfunction Incorrect Design Specifications Mechanical damage (impact) Debris Corrosion
6 4 2
6 10 2 6 2 3
252 280 24 0 98 63
7 3
7 3 3 3 3 10 10 10 10 8
Mechanical Damage Debris Corrosion Mechanical Damage Incorrect Design Specifications H2 Embrittlement Corrosion Mechanical damage (impact) Incorrect Design Specifications H2 Embrittlement
6 7 3 6 2 4 3 6 2 4 3 3 6 2 2
10 7 4 10 10 4 4 6 10 4 4 4 6 10 2 6 2
420 147 36 180 60 160 120 360 200 160 120 120 360 0 24 0 36
Fails to Check
Specification: Supplier Specification: Supplier Design: Restricted Access Specification: Supplier Specification: Supplier Specification: Supplier Design: Restricted Access
Leakage/Rupture
Release to Storage Area and Dissipation of H2 Release to Storage Area and Combustion of Vapour Release into Occupied Area and Dissipation of H2 Release into Occupied Area and Combustion of Vapour Excess Vapour Pressure
10 Mechanical damage (impact) Incorrect Design Specifications Incorrect Design Specifications Mechanical damage (impact) Vacuum Jacket Failure
Thermaly Isolate LH2 from Environment Vacuum Jacket Thermally Isolate LH2 from Environment Lines (LH2)
6 6 6
6 6
2 Procedure/Design: Restricted Access Procedure: Operator Training Specification: Supplier Specification: Supplier Specification: Supplier Procedure/Design: Restricted Access Procedure: Operator Training Procedure: Operator Training Control: Vent to Stack
10 6
120 0
Spill to Storage Area and Dissipation of H2 Spill to Storage Area and Combustion of Vapour Spill to Storage Area and Pooling of LH2
H2 Embrittlement
4 3 3 6
4 4 4 6
4 2 7
4 10 2
Corrosion
Specification: Supplier Design: Rupture Disk - Vent to Stack Control: Shutdown Specification: Supplier
63
7 3 3 3 3 8
Mechanical Damage Debris Corrosion Mechanical Damage Incorrect Design Specifications H2 Embrittlement
6 7 3 6 2 4 3 3 6 2 7 6 7
10 7 4 10 10 4 4 4 6 10 5 10 5
Leakage/Rupture
Spill to Storage Area and Dissipation of H2 Spill to Storage Area and Combustion of Vapour Spill to Storage Area and Pooling of LH2
Specification: Supplier Specification: Supplier Specification: Supplier Design: Restricted Access Procedure: Supplier Calibration
10 Corrosion 9 Stress Cycling/Fatigue Mechanical damage (impact) Incorrect Design Specifications Calibration Error Electrical Damage (shock) Calibration Error
No Signal
System fault
Leakage/Rupture
Release to Storage Area and Dissipation of H2 Release to Storage Area and Combustion of Vapour Release into Occupied Area and Dissipation of H2 Release into Occupied Area and Combustion of Vapour
3 3 3 3 8
Electrical Damage (shock) Out of Range Power Failure Calibration Error H2 Embrittlement
6 5 4 7 4 3 3 6 2 7 6 7
Procedure: Supplier Calibration Design: Rupture Disk - Vent to Stack Procedure: Supplier Calibration Design: Rupture Disk - Vent to Stack Control: Shutdown Control: Shutdown Control: Shutdown Procedure: Supplier Calibration Specification: Supplier Specification: Supplier Specification: Supplier Design: Restricted Access
10
420
7 7 7 5 4 4 4 6 10 5 10 5
10 Mechanical damage (impact) Incorrect Design Specifications Calibration Error Electrical Damage (shock) Calibration Error
1 1 7
No Signal
System fault
Leakage/Rupture
Spill to Storage Area and Dissipation of H2 Spill to Storage Area and Combustion of Vapour Spill to Storage Area and Pooling of LH2
7 3 3 3 3 8
Electrical Damage (shock) Electrical Damage (shock) Out of Range Power Failure Calibration Error H2 Embrittlement
6 6 5 4 7 4 3 3 6 2 7 6 6 7 6 5 4 7 7 3
Procedure: Supplier Calibration Design: Rupture Disk - Vent to Stack Control: Shutdown Control: Shutdown Control: Shutdown Control: Shutdown Procedure: Supplier Calibration Specification: Supplier Specification: Supplier Specification: Supplier Design: Restricted Access System Fault: Shutdown Procedure: Supplier Calibration Design: Rupture Disk - Vent to Stack Procedure: Supplier Calibration Control: Shutdown Control: Shutdown Control: Shutdown Procedure: Supplier Calibration Control: Vent to Stack Specification: Supplier Design: Rupture Disk - Vent to Stack Control: Shutdown Control: Shutdown
7 7 7 7 5 4 4 4 6 10 7 7 10 5 7 7 7 5 2 3
294 126 105 84 105 160 120 120 360 200 147 126 360 210 126 105 84 105 98 63
10 Corrosion 9 Stress Cycling/Fatigue Mechanical damage (impact) Incorrect Design Specifications Calibration Error Electrical Damage (shock) Electrical Damage (shock) Calibration Error Electrical Damage (shock) Out of Range Power Failure Calibration Error Debris Corrosion
3 3 6 6 3 3 3 3 7 7
No Signal
System fault
Flow Blocked
7 3
6 7
7 7
Leakage/Rupture
Release to Storage Area and Dissipation of H2 Release to Storage Area and Combustion of Vapour
3 3 3 8
3 6 2 4 3 3 6 2 6 7
Specification: Supplier Control: Shutdown Control: Shutdown Specification: Supplier Specification: Supplier Specification: Supplier Design: Restricted Access System Fault: Shutdown Procedure: Supplier Calibration Design: Rupture Disk - Vent to Stack Control: Vent to Stack Procedure: Supplier Calibration Control: Shutdown Control: Shutdown Control: Shutdown Procedure: Supplier Calibration Control: Vent to Stack Specification: Supplier Design: Rupture Disk - Vent to Stack Control: Vent to Stack Control: Shutdown Specification: Supplier Control: Shutdown Control: Shutdown Specification: Supplier Specification: Supplier Specification: Supplier Design: Restricted Access
4 7 7 4 4 4 6 10 5
10 Corrosion Stress Cycling/Fatigue Mechanical damage (impact) Incorrect Design Specifications Electrical Damage (shock) Calibration Error
3 6
Flow Blocked
7 7 3 3 3 3 7 7
Electrical Damage (shock) Calibration Error Electrical Damage (shock) Out of Range Power Failure Calibration Error Debris Corrosion
6 7 6 5 4 7 7 3
2 5 7 7 7 5 2 3
7 3 3 3 3 8
Mechanical Damage Debris Corrosion Mechanical Damage Incorrect Design Specifications H2 Embrittlement
6 7 3 6 2 4 3 3 6 2 7 3
10 7 4 10 10 4 4 4 6 10 2 3
Leakage/Rupture
Release to Storage Area and Dissipation of H2 Release to Storage Area and Combustion of Vapour Release into Occupied Area and Dissipation of H2 Release into Occupied Area and Combustion of Vapour Excess Liquid Pressure Excess Pressure Buildup
Flow Blocked
7 7
Control: Vent to Stack Specification: Supplier Design: Rupture Disk - Vent to Stack Control: Vent to Stack Control: Shutdown Specification: Supplier Control: Shutdown Control: Shutdown Specification: Supplier Specification: Supplier Specification: Supplier Design: Restricted Access Control: Vent to Stack Specification: Supplier Design: Rupture Disk - Vent to Stack Control: Vent to Stack Control: Shutdown Specification: Supplier Control: Shutdown Control: Shutdown Control: Shutdown
7 3 3 3 3 9
Mechanical damage Debris Corrosion Mechanical damage Incorrect Design Specifications H2 Embrittlement
6 7 3 6 2 4 3 3 6 2 7 3
3 7 4 10 10 4 4 4 6 10 3 3
Fittings (Cryogenic)
Leakage/Rupture
Spill to Storage Area and Dissipation of H2 Spill to Storage Area and Combustion of Vapour Spill to Storage Area and Pooling of LH2
10 Corrosion 9 Stress Cycling/Fatigue Mechanical damage (impact) Incorrect Design Specifications Debris Corrosion
Flow Blocked
7 7
7 3 3 3 3 8
Mechanical damage Debris Corrosion Mechanical damage Incorrect Design Specifications Ignition Source
6 7 3 6 2 2
3 7 4 7 7 10
Vent Stack
Combustion of Gas
8 Printed:3/15/2013
Control Malfunction
10
320 Page 7 of 10
Vent Stack
Blockage
10 Corrosion 10 Mechanical damage (impact) 10 Mechanical damage (attack) 10 Mechanical damage (structural)
3 6 5 6
4 6 10 10
120 360 500 600 Structural Modifications and assesment 360 108 324 450 540 Structural Modifications and assesment
Restricted
Insufficient Venting
9 9 9 9 9
Debris Corrosion Mechanical damage (impact) Mechanical damage (attack) Mechanical damage (structural)
4 3 6 5 6
10 4 6 10 10
Printed:3/15/2013
Page 8 of 10
Potential Failure Mode In what ways can the Process Step, Variable, or Key Input go wrong? (chance of not meeting requirements)
Potential Failure Effects What is the impact on the Key Output Variables (customer requirements) or internal requirements?
Potential Causes What causes the Key Input to go wrong? (How could the failure mode occur?)
Current Process Controls What are the existing controls that either prevent the failure mode from occurring or detect it should it occur?
Actions Recommended What are the actions for reducing the Occurrence of the cause, or improving Detection? Should have actions on high RPN's or Severity of 9 or 10.
Resp.& Target Date Who's Responsible for the recommended action? What date?
Actions Taken What were the actions implemented? Include completion month/year. (Then recalculate resulting RPN.)
S E V
O C C
D E T
R P N
######
9 of10
RATING FACTORS
RATING
DEGREE OF SEVERITY
PROBABILITY OF OCCURRENCE
FREQUENCY ( 1 in ) Cpk
ABILITY TO DETECT
Detection Certainty Sure that the potential failure will be found or prevented before producing a safety risk Almost certain that the potential failure will be found or prevented before producing a safety risk Low likelihood that the potential failure will be prevented before producing a safety risk Controls may detect or prevent the potential failure from occuring during operation Moderate likelihood that the potential failure will occur before producing a safety risk Controls are unlikely to detect or prevent the potential failure during operation
1 2 3 4 5
Safety or environmental impact is insignificant; customer will Likelihood of occurrence is not notice any adverse effects remote Safety or environmental impact is slight; customer will probably experience slight annoyance Low failure rate with supporting documentation
100% 99% 95 90 85
Safety and/or environmental impact will be affected due to Low failure rate without the slight degradation of performance of components; supporting documentation customer will experience annoyance Safety and/or environmental impact affected due to Occasional failures continually poor system performance; customer dissatisfied Considerable safety and/or environmental Impact due to failure of components; customer is made uncomfortable Relatively moderate failure rate with supporting documentation Considerable safety and/or environmental Impact due to Moderate failure rate without continued degredation of components; warranty repair, down supporting documentation time or significant manufacturing or assembly complaint High safety risk and/or severe environmental Impact without Relatively high failure rate with violating existing codes/standards; High degree of customer supporting documentation dissatisfaction; productivity impacted by high scrap or rework levels. High safety risk and/or severe environmental Impact violating existing codes/standards; very high degree of customer dissatisfaction High failure rate without supporting documentation
100
80
50
Poor likelihood that the potential failure will be detected or prevented before producing a safety risk
70
20
Very poor likelihood that the potential failure will be detected or prevented before producing a safety risk Current controls probably will not even detect the potential failure
60
Severe Safety impact with warning before failure or violation Failure is almost certain based of safety codes/regulations; customer endangered on specifications or significant DV testing
10
Absolute certainty that the current controls will not detect the potential failure
50
Severe Safety impact without warning before failure or violation of safety codes/regulations; customer endangered
10
< 50
Page 10