Mid-Year Savings Are Live | Flat 30% OFF | Code: MIDYEAR
Universal Business Council
six sigma13 min read

Six Sigma Risk Priority Number Explained: How to Calculate and Use RPN

Suyash Raizada
Updated Aug 18, 2026
Six Sigma Risk Priority Number Explained

Risk Priority Number is the score Six Sigma teams use in Failure Modes and Effects Analysis, or FMEA, to decide which process or design risks deserve attention first. It combines three ratings: Severity, Occurrence, and Detection. The formula is simple: RPN = S × O × D. The hard part is not the math. It is scoring honestly. Professionals building this discipline often start with a focused credential like the Certified Six Sigma Expert program, since RPN only becomes a useful decision aid once you understand how it fits alongside DMAIC and control planning.

ASQ describes FMEA as a structured method for identifying where and how a process might fail, then assessing the relative impact of those failures. RPN gives that discussion a number, usually between 1 and 1000, so you can sort risks and act before defects reach the customer.

AI powered Digital Marketing Expert Ad

What Is Risk Priority Number in Six Sigma?

In Six Sigma, Risk Priority Number is used most often in Process FMEA and Design FMEA. You list each possible failure mode, score it, then compare it with the rest of the list.

  • Severity (S): How serious is the effect if the failure happens?

  • Occurrence (O): How likely is the cause to occur?

  • Detection (D): How likely are current controls to catch the issue before impact?

Most teams use a 1 to 10 scale. A rating of 1 usually means low risk or strong control. A rating of 10 means serious impact, frequent occurrence, or poor detectability. Multiply all three and the RPN ranges from 1 to 1000.

Use RPN as a decision aid, not as a substitute for judgment. To be blunt, a spreadsheet sorted by RPN can make a weak FMEA look scientific when the scoring behind it is guesswork. Getting a cross-functional team to score honestly, rather than negotiating numbers down to avoid action items, is a facilitation and leadership skill, which is why FMEA owners often pair Six Sigma training with broader Management Certifications, covering the facilitation and accountability habits that keep an FMEA workshop from turning into a box-ticking exercise

How to Calculate RPN

The calculation is direct:

RPN = Severity × Occurrence × Detection

If Severity = 6, Occurrence = 4, and Detection = 4, then:

RPN = 6 × 4 × 4 = 96

That number means little until you compare it with other failure modes and your organization's risk rules.

Step-by-step RPN calculation

  • Define the failure mode. Write it clearly. For example: incorrect torque applied to a fastener, missing customer approval, or wrong data entered into a billing field.

  • Describe the effect. What happens to the customer, operator, system, or compliance requirement?

  • Identify the cause. Causes might include tool wear, unclear work instructions, poor interface design, or supplier variation.

  • List current controls. Include inspection, poka-yoke devices, software validation, audits, checklists, or automated alerts.

  • Score S, O, and D. Use a rating table agreed before the workshop starts.

  • Multiply the scores. Sort the FMEA by RPN, then review the highest-risk items.

A Practical Example of RPN in a Process FMEA

Consider a packaging line where labels can be applied to the wrong product variant. The effect is serious because customers may receive the wrong dosage instruction or product information.

  • Severity: 8, because the customer impact may be significant.

  • Occurrence: 3, because changeover errors happen occasionally, not daily.

  • Detection: 6, because the current visual check catches some errors but misses issues when two labels look similar.

RPN = 8 × 3 × 6 = 144

A first-time team may jump straight to adding another inspection step. That is usually the weaker fix. A better action is to reduce occurrence through barcode verification at changeover, or to prevent the wrong label roll from being loaded at all. In real operations, detection-only fixes often look good in the FMEA but fail during a rushed shift handover.

How to Interpret RPN Scores

There is no universal cutoff that works for every business. A medical device manufacturer, a software team, and a customer service center will not share the same risk appetite.

Many teams create internal rules such as:

  • Review the top 10 RPN items in every FMEA.

  • Require action for any RPN above a defined threshold.

  • Escalate any Severity score of 8 or higher, regardless of RPN.

  • Track pre-action and post-action RPN to confirm risk reduction.

The third rule matters. A failure mode with S = 10, O = 2, and D = 2 has an RPN of only 40. But if the effect involves injury, regulatory breach, or major customer harm, it should not be buried below less severe issues.

Common RPN Mistakes to Avoid

Using vague rating scales

If one engineer reads Occurrence 5 as monthly and another reads it as annual, your FMEA is already in trouble. Define each rating in plain operational terms.

Multiplying ordinal scores without judgment

Severity, Occurrence, and Detection are usually ranked categories, not true measurements. Multiplication creates a useful priority signal, but it can imply more precision than exists.

Updating RPN before proof

Do not lower Occurrence because someone wrote a new work instruction yesterday. Wait for evidence: audit results, defect data, process capability, field returns, or verified control performance. When that evidence lives across disconnected systems, such as warranty claims in one database and audit results in another that will not reconcile, a Deep Tech Certification from Blockchain Council can help teams understand how integrated, traceable data systems close that gap, since an RPN update is only as credible as the evidence behind it.

Ignoring better prioritization methods

The AIAG and VDA FMEA Handbook shifted automotive FMEA practice toward Action Priority rather than relying only on RPN. Some software and systems teams also use weighted scoring when Severity should dominate the decision. RPN is useful. It is not sacred.

Best Practices for Using Risk Priority Number

  • Use evidence first. Pull defect history, warranty claims, support tickets, nonconformance reports, and process data before scoring.

  • Separate prevention from detection. Reducing the chance of failure is usually stronger than catching failure later.

  • Run FMEA with the right people. Include operators, quality engineers, process owners, maintenance, customer-facing staff, and design experts where relevant.

  • Document the action owner and due date. An FMEA without ownership becomes a risk register nobody reads.

  • Recalculate after validation. Show original RPN, action taken, evidence reviewed, revised S, O, D, and residual RPN.

Where RPN Fits in Six Sigma Training

If you are building Six Sigma capability, learn RPN alongside DMAIC, root cause analysis, control plans, process capability, and mistake-proofing. Universal Business Council learners can connect this topic with related Six Sigma certification study, quality management training, and process improvement courses.

For exam preparation, watch the wording. Candidates often know the formula but reverse the Detection scale. In most FMEA rating tables, a higher Detection score means poorer detection, not better detection. That one detail costs easy marks.

Next Step

Take one active process and build a short FMEA with five failure modes. Score Severity, Occurrence, and Detection with your team, calculate the Risk Priority Number, then challenge the highest-severity item even if its RPN looks modest. If you want a structured path, pair this exercise with Universal Business Council Six Sigma certification study and practice it until the scoring discussion feels evidence-based, not opinion-based. If your evidence keeps scattering across systems that will not talk to each other, a Tech Certification from Global Tech Council is worth adding to your plan, since some FMEA evidence problems need better systems integration, not another rating scale.

FAQs

1. What is Risk Priority Number (RPN) in Six Sigma?

Risk Priority Number (RPN) is a numerical risk-ranking measure commonly used in Failure Mode and Effects Analysis (FMEA). It helps teams compare potential failure modes and decide where risk-reduction efforts may deserve attention.

Traditional RPN uses three ratings:

Severity (S) × Occurrence (O) × Detection (D)

So:

RPN = S × O × D

If Severity = 8, Occurrence = 5, and Detection = 4:

RPN = 8 × 5 × 4 = 160

Higher RPN values generally indicate greater priority for investigation, although RPN should never be the only basis for deciding which risks matter.

2. What does RPN stand for in FMEA?

RPN stands for Risk Priority Number. It combines three dimensions of a potential failure:

Severity: How serious would the effect be?

Occurrence: How likely is the cause or failure to occur?

Detection: How likely are existing controls to detect the problem before the effect reaches the customer or next process stage?

These ratings are multiplied to produce a single ranking number.

The appeal is obvious: three messy dimensions become one tidy integer. Naturally, reality remains somewhat less cooperative.

3. How do you calculate Risk Priority Number?

The traditional calculation is:

RPN = Severity × Occurrence × Detection

Suppose an FMEA identifies a failure mode with:

Severity = 9

Occurrence = 4

Detection = 6

Then:

RPN = 9 × 4 × 6

RPN = 216

The team can compare this value with other failure modes, while also reviewing the individual Severity, Occurrence, and Detection ratings.

4. What is Severity in an RPN calculation?

Severity (S) represents the seriousness of the consequences if a failure occurs.

Many FMEA systems use a 1-to-10 scale, where a low rating represents minimal impact and a high rating represents very serious consequences.

Potential effects could involve:

  • Customer dissatisfaction

  • Product failure

  • Safety hazards

  • Regulatory violations

  • Production shutdown

  • Financial loss

Severity focuses on the effect of the failure, not simply how frequently the problem occurs.

5. What is Occurrence in an RPN calculation?

Occurrence (O) estimates how likely a failure cause is to occur.

A typical FMEA uses a defined rating scale where:

Low Occurrence → infrequent failure

High Occurrence → frequent failure

The rating should ideally be supported by evidence such as defect history, warranty data, process capability, maintenance records, field failures, or comparable process experience.

Assigning occurrence scores based on collective facial expressions in a meeting is less rigorous than some teams seem to hope.

6. What is Detection in an RPN calculation?

Detection (D) represents the ability of existing controls to detect a failure or its cause before the undesirable effect occurs or escapes, according to the specific FMEA methodology being used.

In traditional scoring systems:

Low Detection rating → strong likelihood of detection

High Detection rating → poor likelihood of detection

This direction sometimes confuses beginners because a higher Detection score means greater detection risk, not better detection capability.

A failure that is difficult to detect can therefore receive a high D score.

7. What is an example of an RPN calculation?

Suppose a manufacturing process has a potential failure mode:

Failure Mode: Incorrect hole diameter

The team assigns:

Severity = 7

because the part may fail assembly.

Occurrence = 5

because the problem occurs occasionally.

Detection = 6

because current inspection may miss some defective parts.

The calculation is:

RPN = 7 × 5 × 6 = 210

The team can then evaluate actions to reduce occurrence or improve detection.

8. What is the highest possible RPN score?

If Severity, Occurrence, and Detection are each rated from 1 to 10, the maximum traditional RPN is:

10 × 10 × 10 = 1,000

The minimum is:

1 × 1 × 1 = 1

Therefore:

RPN range = 1 to 1,000

However, the numerical range should not be interpreted as a precise probability or financial-risk scale. An RPN of 400 is not mathematically “twice as risky” as an RPN of 200.

RPN is primarily a prioritization tool.

9. What is considered a high RPN in Six Sigma?

There is no universal RPN threshold that applies to every organization or industry.

Some organizations establish internal categories such as:

Low → Monitor

Medium → Review

High → Corrective action

However, thresholds should reflect:

  • Industry requirements

  • Customer expectations

  • Safety implications

  • Regulatory requirements

  • Product complexity

  • Organizational risk tolerance

A high-severity failure should not be ignored merely because its total RPN falls below an arbitrary cutoff.

10. Why can using only RPN be misleading?

Different combinations of Severity, Occurrence, and Detection can produce identical RPN values.

For example:

10 × 2 × 3 = 60

and:

3 × 5 × 4 = 60

Both produce an RPN of 60, but the first includes maximum severity while the second does not.

Treating them as equivalent could hide a critical safety or regulatory risk.

This is one of RPN's major limitations: multiplication compresses different risk profiles into the same number.

11. Should high Severity risks be prioritized even when RPN is low?

Often, yes.

High-severity risks involving safety, regulatory compliance, critical product functions, or severe customer consequences may require action regardless of their total RPN.

For example:

Severity = 10

Occurrence = 2

Detection = 2

RPN = 40

The RPN looks relatively modest, but a Severity rating of 10 may demand immediate attention.

Teams should therefore examine the individual ratings alongside the total RPN.

12. How is RPN used in a Six Sigma FMEA?

During FMEA, teams typically:

1. Identify process or product functions

2. Identify potential failure modes

3. Determine failure effects

4. Identify potential causes

5. Review existing controls

6. Assign S, O, and D ratings

7. Calculate or otherwise prioritize risk

8. Define improvement actions

9. Reassess risk after implementation

RPN can help focus limited improvement resources on important failure modes.

13. How can a Six Sigma team reduce RPN?

Since:

RPN = S × O × D

teams traditionally seek to reduce one or more components.

Reduce Occurrence: Eliminate root causes, redesign processes, mistake-proof operations, improve capability, or strengthen preventive maintenance.

Improve Detection: Introduce better controls, automated monitoring, sensors, inspections, or error detection.

Reduce Severity: This often requires changing the product, process, system, or design so that the consequence of failure becomes less serious.

Simply changing the score in the spreadsheet remains disappointingly ineffective.

14. Can Severity be reduced in an FMEA?

Yes, but reducing Severity is usually harder than reducing Occurrence or improving Detection.

Severity represents the consequence of failure. To reduce it, the team generally needs to change the design or process so that the failure has a less serious effect.

For example, adding a redundant safety mechanism could prevent a component failure from creating a dangerous system-level consequence.

Additional inspection normally improves Detection rather than reducing Severity.

15. How does Poka Yoke help reduce RPN?

Poka Yoke, or mistake-proofing, can reduce risk by preventing errors from occurring or detecting them immediately.

For example:

Before improvement:

Operator can install component backward.

After Poka Yoke:

Fixture physically allows only correct orientation.

This may substantially reduce the Occurrence rating because the error becomes much less likely or impossible under normal conditions.

Well-designed prevention is generally stronger than relying solely on downstream inspection.

16. What is the difference between RPN and risk matrix scoring?

RPN traditionally combines:

Severity × Occurrence × Detection

A conventional risk matrix more commonly compares:

Impact × Likelihood

Risk matrices may classify risks into categories such as low, medium, high, or critical.

RPN adds the detection dimension, making it useful for FMEA where existing controls matter.

Neither method provides perfect mathematical measurement of risk. Both are structured decision aids rather than tiny numerical oracles.

17. What is the difference between RPN and FMEA Action Priority?

Modern AIAG-VDA FMEA methodology uses Action Priority (AP) rather than relying on RPN as the primary prioritization method.

Action Priority evaluates combinations of:

Severity + Occurrence + Detection

and categorizes action priority as:

High (H)

Medium (M)

Low (L)

This approach gives stronger consideration to high-severity situations and avoids some weaknesses created by simply multiplying three ordinal ratings.

Organizations should therefore follow the FMEA standard or customer-specific methodology applicable to their work.

18. When should RPN be recalculated?

RPN should be reassessed after meaningful risk-reduction actions are implemented.

The process is:

Initial S, O, D → Initial RPN

Implement corrective/preventive action

Evaluate new controls and evidence

Assign revised S, O, D

Calculate revised RPN

For example:

Before improvement:

8 × 6 × 5 = 240

After improvement:

8 × 2 × 3 = 48

The revised score provides evidence of how the assessed risk profile changed, assuming the new ratings are justified.

19. What are common mistakes when using RPN?

Common mistakes include:

  • Treating RPN as an exact quantitative risk measure

  • Ignoring high Severity because total RPN is low

  • Using arbitrary universal cutoff values

  • Assigning ratings without evidence

  • Confusing a high Detection score with good detection

  • Reducing scores without changing the process

  • Focusing on inspection instead of prevention

  • Failing to reassess risks after improvements

  • Using outdated FMEA documents

The FMEA should be a living risk-management tool, not a spreadsheet excavated immediately before an audit.

20. How should Six Sigma teams use RPN effectively?

RPN works best when used as one part of a broader risk-based decision process rather than as an automatic ranking formula.

A practical approach is:

Identify Failure Mode

Evaluate Severity

Estimate Occurrence

Assess Detection Controls

Calculate RPN

Review High-Severity Risks Separately

Prioritize Actions

Prevent or Reduce Failure Causes

Improve Detection Where Necessary

Verify Effectiveness

Recalculate and Document Residual Risk

For example:

Failure Mode

S

O

D

RPN

Incorrect assembly

8

6

5

240

Missing label

4

7

3

84

Safety-system failure

10

2

3

60

If the team blindly ranks only by RPN, the safety-system failure appears least important. That illustrates exactly why RPN should support professional judgment rather than replace it.

The most useful principle is:

RPN identifies where to look. Risk analysis determines what to do.

Six Sigma teams should combine RPN with FMEA analysis, customer requirements, safety considerations, regulatory obligations, process data, root-cause analysis, and the effectiveness of existing controls.

The arithmetic takes seconds. Understanding whether a failure deserves action is the part humans are still expected to contribute.

Related Articles

View All

Trending Articles

View All