Arc Skills / Safety
Review an FMEA for missing failure modes
This task audits coverage of an existing FMEA at its stated analysis level. Arc Skills returns a gap list tied to the nearest current row so analysts can add only distinct credible behaviors.
Use this skill
Use Arc Skills to review this existing FMEA for missing failure modes. Preserve its row IDs and wording, and compare them with the current architecture, interfaces, operating modes and change history.
Inputs:
- Existing FMEA and analysis boundary.
- Current function/interface definition and diagnostic design.
- Relevant incidents, tests or design changes.
Return candidate omissions with nearest existing row, coverage judgment, possible effect and evidence request. Classify each as missing, possibly covered or not applicable with rationale.What you provide and what you get
| What you have | How it is used | What you get |
|---|---|---|
| Current FMEA | Sets analyzed rows and scope | Nearest-row comparison |
| Interface and mode definition | Reveals physically plausible behaviors | Candidate gaps |
| Diagnostic/change evidence | Tests whether effects or controls are already covered | Analyst action |
An open-sensor row may miss a frozen plausible value
Illustrative engineering example.
Synthetic FMEA row F-04 says “temperature sensor open → fault flag.” The current digital interface can retain its last value after a communication stall. No row names stale but plausible data, and the diagnostic design is unclear.
| Candidate behavior | Nearest row | Judgment | Needed evidence/action |
|---|---|---|---|
| Open circuit | F-04 explicitly covers open and fault flag | Covered | Retain original row; inspect its test evidence separately |
| Last-value freeze during normal mode | F-04 detects open, not necessarily stale data | Possibly missing | Inspect interface timeout and stale-value diagnostic |
| Brief intermittent dropout during startup | F-04 wording unclear on transients | Possibly covered but ambiguous | Ask analyst whether F-04 effects/controls include startup recovery |
The proposed freeze mode is credible because the interface can retain a sample. It is distinct from an electrical open if the retained value looks valid. But the review cannot assert the end effect or definitely demand a new row until the timeout, voting and annunciation logic are inspected.
The startup dropout is treated differently: an existing row might legitimately cover it if the same effects and controls apply. The gap list preserves that ambiguity rather than inflating the FMEA with duplicate rows. The examined scope here is one sensor and two operating contexts; no other elements were assessed.
Test coverage before adding rows
- Fix the current FMEA level, version and operating modes.
- Build a function × behavior × mode view from real interfaces and changes.
- Compare each candidate with the nearest row’s effects and controls.
- Request design evidence when coverage depends on undocumented behavior.
Questions about this task
Is every textbook failure mode required?
No. Include a mode when it is credible for the actual element and boundary, then show why current rows do not cover it.
When is a new FMEA row unnecessary?
When an existing row already captures equivalent effects and detection across the relevant modes, with clear scope.
Sources and further reading
- NASA Software Engineering Handbook: FMEA: Describes function, failure mode and effect reasoning.