PFMEA Practice Clarification (Part 4) | Does Downstream Rework and Line Stoppage Count in Severity? —— Scoring Criteria for Impact on the Factory and Final User

By: QTank Published: 8/8/2026 Views: 77
Current rating: ★★★☆☆ Rate this Equivalent to 8 ratings

1. Another Debate at the Review Site

During a PFMEA review meeting, a similar debate arose again. A failure mode in a certain process was identified, and when the team discussed the severity (S) score, two groups argued. One group said, "This failure won't even reach the customer; downstream inspection will catch it, and at most, it will just require some rework. A severity score of 4 is just a formality." The other group countered, "The increase in downstream detection rate, rework rate, and potential line stoppage for sorting are real losses. Why shouldn't they be included in the severity score?"

The crux of this debate, like the frequency (O) scoring and failure mode identification, is a classic issue in PFMEA scoring criteria: Is severity evaluated based on "impact on the customer" or "impact on all stakeholders"? Should the impact of a failure on downstream processes—such as increased defect detection rate, rework, sorting, and line stoppage—be reflected in the severity score?

The answer is clear: Yes, and it is a mandatory requirement. Severity is evaluated based on "the most significant impact of the failure," and the impact on downstream processes (internal customers) is a statutory component of the failure impact, with specific score ranges. This article will explain the complete severity assessment criteria as outlined in the AIAG-VDA manual.

2. Standard Criteria: Severity is the "Most Severe of All Impacts"

First, let's correct a common misconception: Severity (S) is not solely evaluated based on "impact on the end customer." The PFMEA severity evaluation table in the AIAG-VDA FMEA manual (2019) has a three-column structure, requiring the assessment of failure impacts at three levels:

  • Impact on the Factory (Impact to your Plant): Internal consequences within the factory—scrap, rework, sorting, line stoppage, reduced line speed, increased manpower, injury to operators.
  • Impact on the Downstream Factory (Impact to ship-to plant, when known): Consequences for downstream processes/assembly plants—increased defect detection rate, rework, sorting, line stoppage, cessation of shipment, on-site repair.
  • Impact on the Final User (Impact to End User, when known): Safety, compliance, major/minor vehicle functions, appearance.

Each level has a corresponding 10-point scale. After the assessment, the highest score among the three is taken as the severity score for the failure mode. Quality-One's explanation is more straightforward: "The highest severity is chosen from the many potential effects and placed in the Severity Column." — The highest score from multiple potential impacts is filled in the severity column.

Therefore, the statement "severity = impact on the customer" is not incorrect, but the term "customer" in PFMEA is broad: downstream processes are internal customers, and their rework, sorting, and line stoppage are losses to the customer. Focusing only on the end user means erasing the losses of internal customers from the risk ledger.

This "two-ledger" approach is not a new invention in the latest manual. The AIAG FMEA fourth edition (2008) also uses two sets of anchor points for severity assessment: Process Effects—rework/adjustment within the station scores 2-4, rework outside the station or additional operations required scores 5-6, rework plus scrap or potential internal or customer line stoppage scores 7-8, compliance and safety issues or equipment damage scores 9-10; Design Effects—aesthetic defects that do not affect function score 2-4, minor function degradation/loss scores 5-6, major function degradation/loss scores 7-8, compliance and safety issues score 9-10. Both sets of anchor points are evaluated, and the highest score is taken. It is evident that the old manual also reserved complete score ranges for "internal rework, scrap, and line stoppage"—internal impact is a consistent principle in the FMEA methodology, not a new rule in a specific version.

3. Three-Column Impact, Each with Its Own Score Range

Looking at the PFMEA severity table in the AIAG-VDA manual, the score ranges are clear:

S Impact on the Factory (Internal) Impact on the Downstream Factory (ship-to plant) Impact on the Final User
10 Poses an acute health or safety risk to manufacturing/assembly workers Same as left Affects vehicle safety, occupant health, or pedestrians
9 Non-compliance with internal regulations Non-compliance with regulations Non-compliance with regulations
8 100% batch scrap Line stoppage exceeding a full shift, cessation of shipment, on-site repair/replacement Loss of major functions essential for normal driving
7 100% sorting + partial scrap; reduced line speed or increased manpower Line stoppage for 1 hour to a full shift, cessation of shipment Major function degradation
6 100% batch requires rework after being taken offline Line stoppage for up to 1 hour Loss of minor functions
5 100% batch requires rework within the station; triggers a major reaction plan Less than 100% affected, requires sorting without line stoppage Minor function degradation
4 Partial batch requires rework within the station; triggers a minor reaction plan Same as left Highly objectionable appearance/sound/vibration
3 Minor inconvenience to process operation or operator Feedback to supplier required Slightly objectionable appearance/sound
2 No discernible impact Same as left Same as left
1 No impact Same as left Same as left

Notice the internal impact column, from 4 to 8 points, which is entirely dedicated to internal losses such as rework, sorting, scrap, and line stoppage—these are explicitly given a place in the severity table. The "increase in downstream defect detection rate and rework rate" you mentioned corresponds to:

  • Downstream rework within the station → 4-5 points;
  • Downstream rework offline (100% batch) → 6 points;
  • Downstream sorting + partial scrap, reduced line speed, increased manpower → 7 points;
  • Downstream line stoppage → 7-8 points.

4. Key Differentiation: Downstream Detection Does Not Mean Impact Does Not Exist

This is the most easily misunderstood part and the root of the "a severity score of 4 is just a formality" viewpoint. Let's break it down:

First, "being detected downstream" changes whether the impact occurs, not the size of the impact. If the failure is caught downstream, the consequence is rework, sorting, line stoppage, and increased labor hours—these losses are real, they just occur internally rather than with the end user. Severity evaluates the size of these losses, which does not diminish because they are "detected." Conversely, if the failure is not caught downstream and reaches the end user, the severity must be evaluated based on the impact on the end user, which is often higher.

Second, "downstream detection" is a matter of detection (D), not severity (S). Downstream process inspection and error-proofing detection are part of the detection controls, which are evaluated in the D column. The earlier and more reliably the detection, the lower the D score. S and D are two independent dimensions: S evaluates "how significant the impact is," while D evaluates "how easily it can be detected." Lowering the S score because "downstream can detect it" means letting detection capability offset the impact size, leading to distorted risk prioritization—high-impact, high-occurrence, and weak detection combinations are compressed into medium to low risks, and the necessary error-proofing and process improvements are never prioritized.

This follows the same logic as frequency scoring: frequency does not decrease because of inspection interception, and severity does not decrease because of downstream detection. Interception changes whether the risk materializes, not the consequences when it does.

Going deeper, lowering the S score and lowering the D score have entirely different meanings in the risk ledger: a low D (good detection) means "defects are detected and losses are minimized in a timely manner," reflecting effective risk control in AP (Action Priority) or RPN (Risk Priority Number). A low S, however, means "the failure itself has minor consequences." If a high-impact failure is scored low because of good detection, it disguises a "high-impact but temporarily contained" risk as "low-impact"—once the detection method fails (inspector oversight, error-proofing device malfunction, sampling inspection oversight), the true consequences are immediately exposed. A useful method during reviews is to ask, "If all downstream inspections stop tomorrow, what would the severity of this failure be?"—the answer is its true S.

There is also a practical chain reaction: if the severity score is lowered, the action priority also decreases, and the error-proofing and process improvements for that failure will not be initiated, leading to long-term reliance on downstream inspections. Inspections are not free—increased downstream detection rates mean increased manpower, labor hours, and rework areas, which are ongoing costs that never make it to the improvement list because the severity score is artificially low. Evaluating internal impact in severity is not just about scoring accuracy; it is about directing improvement resources to real risks.

5. Four-Step Scoring Method: Implementing "Take the Highest"

Step 1: List All Impacts. For each failure mode, list the impacts in four directions—this process (scrap/return/line stoppage/equipment damage/operator injury), downstream process (increased detection/rework/sorting/line stoppage), shipping and after-sales (cessation of shipment/on-site repair/replacement), and end user (safety/regulations/functions/appearance).

Step 2: Match Each Impact to the Score Range. Each impact is evaluated independently. When matching, ask yourself: which category does this impact belong to—scrap, rework, sorting, line stoppage, function, safety—and what is the proportion?

Step 3: Take the Highest Score. Place all the impact scores on the table, and the highest one is the severity score. Safety or regulation-related impacts (9-10) are automatically the highest and do not need further comparison.

Step 4: Detection Information Goes to D. Record which stage can detect the failure, how quickly it can be detected, and the probability of detection in the detection control assessment, evaluating the D column, not the S column.

Three additional rules to follow during reviews, posted on the table:

Rule 1: List All Impacts Before Scoring. Before scoring, review the four-direction checklist (this process, downstream, shipping and after-sales, end user). Missing any direction can lead to incorrect "take the highest" scoring—the high-impact item often determines the S score.

Rule 2: Evaluate Based on the "Worst Reasonable Scenario" When Uncertain. If it is uncertain whether the failure will reach the end user, evaluate the end user impact as if it will, and then take the highest score with the internal impact. This is the conservative principle of FMEA: severity should be overestimated rather than underestimated, as underestimation can kick high-risk items out of the improvement list, while overestimation only leads to additional review confirmation by the team.

Rule 3: Special Characteristics Must Be Compared with Design Impact. If the process controls special characteristics (key characteristics, safety characteristics), the severity must also be evaluated based on the impact on "end users/vehicle functions"—failures of special characteristics typically correspond to 7-10 points and should not be scored solely based on internal impact.

6. Two Complete Examples

Example 1: Welding Defect in a Safety Component. Failure mode: "weld seam defect (insufficient strength)." Impact assessment: no internal impact in this process; during downstream assembly, the defective weld may break under force, leading to increased detection and rework, scoring 5-6 points in the "downstream factory" column; the component is a safety part, and if the defect reaches the entire vehicle, structural failure during driving would score 10 points in the "end user" column. Take the highest → S=10. Similarly, downstream non-destructive testing and destructive tensile testing are evaluated as detection controls in the D column. If the team lowers the S score to 6 because "downstream has non-destructive testing," the safety risk disappears from the risk ranking—this is the most unacceptable analysis error during audits.

Example 2: Surface Scratch on an Aesthetic Component. Failure mode: "decoration surface scratch (exceeding depth limit)." Impact assessment: no impact in this process; during downstream assembly, scratches require polishing and rework, scoring 4 points in the "factory" column; if scratches flow out, customer dissatisfaction with appearance would score 4 points in the "end user" column. Take the highest → S=4. The same logic applies: if the scratch leads to a seal damage and leakage, the end user impact jumps to 7-8 points, and the severity follows—the same failure mode can have different final impacts, and thus different S scores, which is the significance of taking the highest.

7. Common Misunderstandings and Self-Checklist

Misunderstanding Correct Approach
"No impact if it doesn't reach the customer" Downstream rework, sorting, and line stoppage are internal customer impacts, S=4-7 must be reflected
"Downstream can detect it, so the severity score can be low" Downstream detection is a detection control, evaluated in D, not S; S evaluates the size of the impact
"Severity only looks at the most severe impact" Yes, but all impacts must be listed first, then take the highest, not just the end user
"Internal impact scores too high make risks seem large" Match the score range table: scrap 8, sorting + partial scrap 7, offline rework 6, in-station rework 4-5
"Safety components are fine if intercepted" If it could reach the end user, S is evaluated based on the end user (8-10), regardless of interception
"Increased rework rate is a minor issue" Rework is a real cost loss, corresponding to S=4-6, and it amplifies the combined risk of frequency × detection

During reviews, add a practical question: randomly select a failure mode and ask, "Are all its impacts listed—what are the consequences in this process, downstream, shipping, and for the end user?" If the list is incomplete, the severity score is definitely too low.

8. Conclusion

Severity evaluates the most significant impact of a failure, and the ledger includes not only the end user but also internal customers. Each entry in the downstream rework, sorting, and line stoppage is a real loss, and the standard provides clear score ranges for them. Downstream detection capability belongs to the detection score, which is a separate ledger. Each ledger is recorded independently, and together they form the complete risk. Remember this: Severity measures impact, detection measures discovery; impact is not about whether it can be intercepted, discovery is about whether it can be intercepted.


Severity takes the highest impact, internal rework and line stoppage count; detection goes to D and does not offset.

Knowledge code: 8.3.1

Version: v20260808

Author: Quality Think Tank Quality Think Tank is dedicated to providing systematic professional knowledge, methodologies, and practical tools for quality management practitioners, helping enterprises continuously improve their quality capabilities.