IEC 60812 makes FMEA a maintained analysis—not a risk score
The standard's public record treats failure analysis as planned, documented, and maintained work whose conclusions depend on scope and evidence.
Editorial figure by Maintenance Operations Ledger. Source context: IEC 60812:2018 — FMEA and FMECA.
The analysis starts with a defined subject
IEC's public metadata describes a structured analysis of failure modes and effects. Before a team can identify a failure mode, it needs to define the item, function, boundary, operating context, interfaces, assumptions, and level of decomposition. The same component can have different effects depending on duty, configuration, surrounding safeguards, and the function being protected.
Maintenance software should preserve that scope alongside the analysis. A row labeled with a component and score is not enough when reviewers cannot tell which version, function, environment, interface, or consequence path was considered. The record should distinguish an observed failure from a hypothesized mode and retain the evidence supporting each.
Prioritization supports treatment; it does not determine it
The standard's public description includes ways to prioritize failure modes for treatment. Prioritization can help teams direct limited attention, but a number is an input to judgment rather than the risk itself. Scales, categories, assumptions, missing data, consequence types, detectability, existing safeguards, and organizational criteria all affect what a ranking means.
Buyers should be wary when a product turns one composite score into an automatic maintenance, engineering, or safety decision. Different failure modes can produce the same number while requiring different owners and controls. Low-frequency, high-consequence cases may also demand escalation beyond the ordinary ranking method.
Maintenance is part of the method
IEC describes FMEA as work that is planned, performed, documented, and maintained. That last term is operationally important. Assets change, software is revised, operating envelopes move, failures occur, inspections find new evidence, suppliers alter components, and safeguards are added or removed. An analysis detached from those changes becomes a historical artifact rather than a current decision record.
A credible system links analysis revisions to configuration, work history, condition data, incidents, engineering changes, action owners, due dates, verification, and approval. It should preserve earlier states and explain why a mode, effect, rating, or treatment changed. Merely showing the latest score hides the learning trail.
The method does not certify asset risk
IEC's public scope reaches hardware, software, processes, human action, and interfaces, but the standard record does not establish that a particular analysis is complete or correct. It does not set a safe operating condition, authorize continued operation, validate a design, prescribe a maintenance interval, or prove reliability, availability, or compliance.
Maintenance Operations Ledger uses IEC 60812 as an evidence boundary. Applicability, method detail, analysis competence, source data, acceptance criteria, treatment, and operational decisions remain organization- and asset-specific. Qualified engineering, operations, maintenance, safety, reliability, and regulatory review must address the actual context.
Enterprise buyer test
Translate this change into the exact population, record type, workflow stage, decision owner, effective date, and evidence that could be affected. Ask current or prospective providers to demonstrate the named workflow with representative data and an exception—not a polished feature tour. Record what official documentation establishes, what a provider states, what the team observes, and what remains unresolved.
A defensible review also identifies the dependency outside the product. Authority interpretation, policy configuration, data quality, integrations, human judgment, approval rights, release governance, training, and retained evidence may remain customer or service responsibilities. The evaluation should preserve those boundaries instead of treating a technology claim as the complete operating model.
What we will watch next
Maintenance Operations Ledger will watch the named source and affected market records for later evidence that changes status, scope, availability, implementation timing, workflow consequence, or the limits of the initial report. A later announcement does not silently overwrite this dated account; the change ledger preserves the sequence.