PPAP Quality July 22, 2026 10 min read By Rajadurai R — Founder, 14 years plant-head experience

How to Complete a Process FMEA for PPAP: A Step-by-Step Guide

Direct answer: A Process FMEA (PFMEA) for PPAP is a structured risk analysis document that identifies every potential failure mode in a manufacturing process, rates it on Severity, Occurrence, and Detection (each 1–10), multiplies those three numbers into a Risk Priority Number (RPN), and defines corrective actions for high-risk items — all before production parts are submitted to the customer for approval.

Your PPAP package is sitting 80 percent complete. The Control Plan is done, the MSA studies are signed off, and the dimensional results look clean. Then the customer portal flags the submission: "PFMEA incomplete — missing recommended actions for high-RPN characteristics." The launch date slips a week while the team scrambles to reopen a document that should have been locked months ago.

This scenario plays out constantly in Tier 1 and Tier 2 supplier plants. The PFMEA is either rushed at the end of APQP or treated as a checkbox exercise rather than a genuine risk tool. Getting it right the first time protects the launch and builds long-term credibility with the OEM quality team.

What Is at Stake if the PFMEA Is Wrong

A weak PFMEA does not just get a submission rejected. It leaves real manufacturing risks undocumented, which means escape mechanisms are not designed into the process. When a defect reaches the customer, the absence of a credible PFMEA becomes Exhibit A in the warranty claim or supplier corrective action request (SCAR). AIAG's Production Part Approval Process manual (PPAP 4th Edition) lists the PFMEA as Element 8 of the 18 required elements — it is not optional for Level 3, 4, or 5 submissions.

Beyond compliance, a well-built PFMEA drives the Control Plan, informs the MSA study plan, and identifies Special Characteristics (SC/CC) that need tighter process controls. Skipping it properly means every downstream document is weaker than it should be. For a deeper look at what each PPAP level actually demands, see PPAP Levels 1 to 5 Explained.

PFMEA Steps for PPAP Submission: The Full Walkthrough

The process below follows the AIAG FMEA-4 reference manual, which remains the accepted standard for most automotive and industrial OEMs. The newer AIAG-VDA Harmonized FMEA (2019) is increasingly required by Stellantis, Ford, and GM — check your customer-specific requirements (CSRs) before choosing a format.

  1. Assemble the Cross-Functional Team

    The PFMEA must not be written by a single quality engineer alone. Minimum representation: process/manufacturing engineering, quality, production supervision, and — where the design is supplier-owned — design engineering. Tooling and maintenance representatives add value for detecting mechanical failure modes. Document the team members and their roles on the header of the FMEA form; some customers audit this.

  2. Define the Scope and Build the Process Flow Diagram

    Before opening the FMEA spreadsheet, map every operation in the manufacturing process from raw material receipt to final pack and ship. Each operation box in the Process Flow Diagram (PFD) becomes one or more rows in the PFMEA. Number the operations sequentially — 10, 20, 30, and so on — so that the PFMEA, Control Plan, and inspection sheet all share the same operation numbering. This traceability is one of the first things a customer auditor checks.

    Include sub-operations that are easy to overlook: incoming inspection, heat treatment (if applicable), inter-operation cleaning, assembly torquing, and labelling. Missing an operation in the PFD means it is unanalysed in the PFMEA and uncontrolled in the Control Plan.

  3. Identify Functions, Potential Failure Modes, and Effects

    For each process step, ask three questions: What is this operation supposed to do? (Function), In what way can it fail to do that? (Failure Mode), and What happens to the customer — internal next operation or external OEM — when it does fail? (Effect). Write these in concise, measurable terms. "Bore diameter oversized by more than 0.05 mm" is a valid failure mode. "Poor quality" is not — it cannot be measured or controlled.

    Common sources to mine for failure modes: past warranty data, internal scrap and rework records, similar-part FMEAs, operator feedback, and lessons-learned files. The AIAG FMEA-4 manual provides reference tables of generic failure modes by process type (machining, stamping, welding, assembly) that are useful starting points.

  4. Assign Severity (S) Ratings

    Severity rates the seriousness of the effect on the end customer, not the process operator. It is rated 1 (no effect) to 10 (safety hazard without warning). Severity is a property of the effect, not the failure mode. If a failure mode has multiple effects, use the highest severity rating for that row.

    A rating of 9 or 10 automatically flags a Special Characteristic regardless of the RPN — this is a hard rule in AIAG FMEA-4 and most OEM CSRs. These characteristics must appear in the Control Plan with mandatory process controls. The table below shows the standard rating anchors:

    Severity Rating Effect Description Typical Example
    10 Safety / regulatory non-compliance — no warning Brake component fractures in service
    9 Safety / regulatory non-compliance — with warning Steering rattle audible before failure
    7–8 Product inoperable, customer very dissatisfied Engine does not start; major subsystem loss
    5–6 Degraded performance, customer dissatisfied Increased NVH, reduced fuel economy
    3–4 Minor nuisance, slight customer dissatisfaction Minor cosmetic scratch noticed by some customers
    1–2 No perceptible effect Slight variation in surface finish, within spec

    For the full AIAG rating criteria, refer to the AIAG FMEA-4 manual available from the AIAG store.

  5. Assign Occurrence (O) Ratings

    Occurrence rates the likelihood that the specific cause of the failure mode will occur during the process lifetime. It is rated 1 (failure is unlikely; Cpk ≥ 1.67) to 10 (failure is almost inevitable; Cpk < 0.33). Occurrence ratings should be based on process capability data, historical reject rates, or industry benchmarks — not guesswork. Where process data is not yet available (new process), use engineering judgment and plan to update after the pilot run.

    A key distinction: Occurrence rates the cause, not the failure mode. If a bore is oversized (failure mode) due to worn tooling (cause), the occurrence rating applies to the frequency of worn tooling causing an out-of-tolerance bore, given the current controls in place.

  6. Identify Current Process Controls and Assign Detection (D) Ratings

    List every current control that either prevents the cause from occurring (prevention control) or detects the failure mode or cause before it reaches the next customer (detection control). Detection rates how well the current controls can detect the failure — rated 1 (near-certain detection) to 10 (cannot detect or is not tested). A rating of 10 does not only mean the control is absent; it also applies when a measurement system cannot reliably distinguish conforming from non-conforming parts.

    Poka-yoke devices and 100 percent automated vision systems typically earn Detection ratings of 2–3. Manual visual inspection of a critical dimension earns 7–8. No inspection at all earns a 9–10.

  7. Calculate the RPN and Prioritise Actions

    RPN = Severity × Occurrence × Detection

    The maximum possible RPN is 1,000 (10 × 10 × 10). Most OEMs define an internal threshold — 100 or 125 is common — above which a recommended action is mandatory. However, AIAG FMEA-4 also requires action on any item where Severity = 9 or 10, regardless of RPN. Do not rely on a low RPN to avoid action when severity is critical.

    Worked RPN Calculation Example

    Consider a CNC turning operation on an aluminium housing. The bore diameter has a tolerance of ⌀25.000 +0.021/−0.000 mm (ISO H7 fit). One identified failure mode is bore diameter undersized, caused by incorrect tool offset entry after a tool change.

    Parameter Value Rationale
    Severity (S) 7 Undersized bore prevents assembly; component inoperable at customer
    Occurrence (O) 4 Tool offset errors occur roughly 1 in 500 setups; Cpk ~1.2 on this feature
    Detection (D) 5 First-off inspection with air gauge after each tool change; sampling only, not 100%
    RPN 140 Exceeds the 125 threshold — action required

    The recommended action for this row: Implement tool offset verification checklist and add in-process SPC on bore diameter with control limits at ±0.010 mm. After implementing, the team re-rates Detection from 5 to 3 (SPC catches drift before non-conformance), dropping the RPN to 7 × 4 × 3 = 84 — below threshold.

  8. Define Recommended Actions, Responsibilities, and Target Dates

    Every row with an RPN above the threshold or a Severity of 9–10 needs a specific recommended action, a named responsible person, and a target completion date. Vague actions like "improve the process" or "retrain operators" are not acceptable — they cannot be verified as complete. The action must be specific enough that an auditor can confirm it is done: "Install Keyence IM-8000 vision system on Station 30 by 15 August 2026 — responsible: P. Krishnamurthy."

    After the action is completed, recalculate S, O, and D ratings and record the revised RPN in the "Results of Action" columns. Severity should only change if the design is modified. Occurrence drops when the cause is eliminated or its frequency is reduced by a process change. Detection drops when a better detection method is added.

  9. Link the PFMEA to the Control Plan and Ballooned Drawing

    The PFMEA is not a standalone document inside a PPAP package — it is the upstream input to the Control Plan. Every high-severity or high-RPN characteristic identified in the PFMEA must appear as a controlled characteristic in the Control Plan, with the method of control, sample size, frequency, and reaction plan defined. The characteristic numbering should match the ballooned drawing dimensions so the customer can trace from the drawing balloon → PFMEA row → Control Plan line → inspection result. This cross-reference traceability is what separates a submission that sails through customer review from one that bounces back with ten open-point questions.

    For guidance on building the ballooned drawing that ties everything together, see Convert a Drawing to an Inspection Sheet and the broader PPAP Level 3 Submission Requirements guide.

  10. Review, Sign Off, and Version-Control the Document

    The PFMEA header must include the part number, part name, process responsibility (the supplier plant), customer name, model year/vehicle, key date (PPAP submission date), FMEA date (original) and revision date, and the names of the core team. All core team members should sign or approve the document before it is included in the PPAP package. Version-control is non-negotiable: if the PFMEA is updated post-submission, the revision level must increment and the change history must be logged.

FMEA Severity, Occurrence, and Detection Ratings: Quick Reference

The three rating scales each run 1–10 with specific anchors defined by AIAG FMEA-4. The Severity scale is anchored to the effect on the end user or next operation. The Occurrence scale is anchored to defect rates or process capability indices (Cpk). The Detection scale is anchored to the probability that the current control will catch the failure before it escapes. For detailed rating tables with Cpk values mapped to each Occurrence level, the ASQ FMEA resource page and the AIAG FMEA-4 manual are the authoritative references.

A common shortcut that causes problems: teams assign the same Detection rating for every row because "we do 100 percent inspection." A 100 percent manual inspection with a go/no-go gauge on a safety-critical torque characteristic earns a Detection of 5–6, not a 1 or 2, because the gauge itself has measurement uncertainty and the operator is fallible. Only error-proofing (poka-yoke) devices and fully automated in-line gauging systems consistently earn Detection ratings of 2–3.

Common Mistakes That Get PFMEA Submissions Rejected

How CadNexa Helps with PPAP Documentation

The PFMEA drives every downstream PPAP document, but the ballooned engineering drawing is what ties the entire package together. Every characteristic listed in the PFMEA needs a corresponding balloon number on the drawing so the customer can trace from risk analysis to measured result. That ballooning step — done manually — typically occupies several hours for a complex part drawing.

CadNexa's Smart Detect tool scans an entire drawing in one click, auto-detecting dimensions, tolerances, and GD&T frames for engineer review and approval. The FAI Report Generator then produces inspection reports from that balloon data in PPAP format, exportable as interactive HTML, PDF, or CSV. When the balloon numbers on the drawing align with the characteristic numbers in the PFMEA, the cross-reference audit trail the customer requires is straightforward to demonstrate. Balloon your PPAP drawing at cadnexa.com/app.html.

For a complete picture of how ballooning and FAI reports connect to the PPAP submission workflow, see FAI Reports and Balloon Drawings in 10 Minutes.

Frequently Asked Questions

Is a Process FMEA mandatory for all PPAP levels?

PFMEA is required for PPAP Levels 2, 3, 4, and 5. Level 1 requires only a Part Submission Warrant. However, most OEMs request PFMEA even at Level 2, so it is best practice to have one ready regardless of level.

What is an acceptable RPN score for PPAP submission?

AIAG's FMEA-4 manual does not mandate a single cut-off RPN. Most OEMs set an internal threshold — commonly 100 or 125 — above which corrective action is mandatory before submission. Always check your customer-specific requirements before finalising.

How often should the Process FMEA be updated after PPAP approval?

The PFMEA is a living document. It must be revised whenever a design change, process change, new failure mode is discovered, or a customer complaint occurs. AIAG FMEA-4 recommends annual reviews at a minimum, and most QMS auditors will ask for evidence of this.

What is the difference between DFMEA and PFMEA in the context of PPAP?

DFMEA is owned by the design engineer and analyses product design failures. PFMEA is owned by the process or manufacturing engineer and analyses how the manufacturing process can cause non-conformances. PPAP requires both when the supplier is responsible for the design; otherwise only PFMEA is required for a supplier-manufactured, customer-designed part.

Can the Control Plan replace the PFMEA in a PPAP package?

No. The Control Plan and PFMEA are separate PPAP elements. The Control Plan references the PFMEA outputs — high-RPN characteristics and detection controls — but cannot substitute for it. Both must be present for a complete Level 3 or higher submission. The AIAG APQP and Control Plan manual covers this relationship in detail.

Conclusion

A properly completed Process FMEA is the backbone of a credible PPAP package. It documents that the manufacturing team has systematically analysed every way the process can fail, rated the risk against defined criteria, and implemented controls before production begins. Done well, it shortens the customer review cycle, reduces warranty exposure, and gives the process team a documented baseline for continuous improvement.

The ballooned drawing and PPAP-format inspection report are the documents that prove the PFMEA's identified characteristics were actually measured on physical parts. CadNexa's PDF Balloon Tool balloons drawings in a browser from PDF, TIFF, PNG, JPG, or BMP files; the FAI Report Generator produces reports from that balloon data in PPAP format, exportable as interactive HTML, PDF, or CSV.

Try CadNexa free — 14 days, no credit card required. Balloon your PPAP drawing, generate a PPAP-format inspection report, and build the traceability link between your PFMEA characteristics and your dimensional results. Start at cadnexa.com/app.html →