Six Sigma Risk Priority Number Explained: How to Calculate and Use RPN

Risk Priority Number is the score Six Sigma teams use in Failure Modes and Effects Analysis, or FMEA, to decide which process or design risks deserve attention first. It combines three ratings: Severity, Occurrence, and Detection. The formula is simple: RPN = S × O × D. The hard part is not the math. It is scoring honestly. Professionals building this discipline often start with a focused credential like the Certified Six Sigma Expert program, since RPN only becomes a useful decision aid once you understand how it fits alongside DMAIC and control planning.
ASQ describes FMEA as a structured method for identifying where and how a process might fail, then assessing the relative impact of those failures. RPN gives that discussion a number, usually between 1 and 1000, so you can sort risks and act before defects reach the customer.

What Is Risk Priority Number in Six Sigma?
In Six Sigma, Risk Priority Number is used most often in Process FMEA and Design FMEA. You list each possible failure mode, score it, then compare it with the rest of the list.
Severity (S): How serious is the effect if the failure happens?
Occurrence (O): How likely is the cause to occur?
Detection (D): How likely are current controls to catch the issue before impact?
Most teams use a 1 to 10 scale. A rating of 1 usually means low risk or strong control. A rating of 10 means serious impact, frequent occurrence, or poor detectability. Multiply all three and the RPN ranges from 1 to 1000.
Use RPN as a decision aid, not as a substitute for judgment. To be blunt, a spreadsheet sorted by RPN can make a weak FMEA look scientific when the scoring behind it is guesswork. Getting a cross-functional team to score honestly, rather than negotiating numbers down to avoid action items, is a facilitation and leadership skill, which is why FMEA owners often pair Six Sigma training with broader Management Certifications, covering the facilitation and accountability habits that keep an FMEA workshop from turning into a box-ticking exercise
How to Calculate RPN
The calculation is direct:
RPN = Severity × Occurrence × Detection
If Severity = 6, Occurrence = 4, and Detection = 4, then:
RPN = 6 × 4 × 4 = 96
That number means little until you compare it with other failure modes and your organization's risk rules.
Step-by-step RPN calculation
Define the failure mode. Write it clearly. For example: incorrect torque applied to a fastener, missing customer approval, or wrong data entered into a billing field.
Describe the effect. What happens to the customer, operator, system, or compliance requirement?
Identify the cause. Causes might include tool wear, unclear work instructions, poor interface design, or supplier variation.
List current controls. Include inspection, poka-yoke devices, software validation, audits, checklists, or automated alerts.
Score S, O, and D. Use a rating table agreed before the workshop starts.
Multiply the scores. Sort the FMEA by RPN, then review the highest-risk items.
A Practical Example of RPN in a Process FMEA
Consider a packaging line where labels can be applied to the wrong product variant. The effect is serious because customers may receive the wrong dosage instruction or product information.
Severity: 8, because the customer impact may be significant.
Occurrence: 3, because changeover errors happen occasionally, not daily.
Detection: 6, because the current visual check catches some errors but misses issues when two labels look similar.
RPN = 8 × 3 × 6 = 144
A first-time team may jump straight to adding another inspection step. That is usually the weaker fix. A better action is to reduce occurrence through barcode verification at changeover, or to prevent the wrong label roll from being loaded at all. In real operations, detection-only fixes often look good in the FMEA but fail during a rushed shift handover.
How to Interpret RPN Scores
There is no universal cutoff that works for every business. A medical device manufacturer, a software team, and a customer service center will not share the same risk appetite.
Many teams create internal rules such as:
Review the top 10 RPN items in every FMEA.
Require action for any RPN above a defined threshold.
Escalate any Severity score of 8 or higher, regardless of RPN.
Track pre-action and post-action RPN to confirm risk reduction.
The third rule matters. A failure mode with S = 10, O = 2, and D = 2 has an RPN of only 40. But if the effect involves injury, regulatory breach, or major customer harm, it should not be buried below less severe issues.
Common RPN Mistakes to Avoid
Using vague rating scales
If one engineer reads Occurrence 5 as monthly and another reads it as annual, your FMEA is already in trouble. Define each rating in plain operational terms.
Multiplying ordinal scores without judgment
Severity, Occurrence, and Detection are usually ranked categories, not true measurements. Multiplication creates a useful priority signal, but it can imply more precision than exists.
Updating RPN before proof
Do not lower Occurrence because someone wrote a new work instruction yesterday. Wait for evidence: audit results, defect data, process capability, field returns, or verified control performance. When that evidence lives across disconnected systems, such as warranty claims in one database and audit results in another that will not reconcile, a Deep Tech Certification from Blockchain Council can help teams understand how integrated, traceable data systems close that gap, since an RPN update is only as credible as the evidence behind it.
Ignoring better prioritization methods
The AIAG and VDA FMEA Handbook shifted automotive FMEA practice toward Action Priority rather than relying only on RPN. Some software and systems teams also use weighted scoring when Severity should dominate the decision. RPN is useful. It is not sacred.
Best Practices for Using Risk Priority Number
Use evidence first. Pull defect history, warranty claims, support tickets, nonconformance reports, and process data before scoring.
Separate prevention from detection. Reducing the chance of failure is usually stronger than catching failure later.
Run FMEA with the right people. Include operators, quality engineers, process owners, maintenance, customer-facing staff, and design experts where relevant.
Document the action owner and due date. An FMEA without ownership becomes a risk register nobody reads.
Recalculate after validation. Show original RPN, action taken, evidence reviewed, revised S, O, D, and residual RPN.
Where RPN Fits in Six Sigma Training
If you are building Six Sigma capability, learn RPN alongside DMAIC, root cause analysis, control plans, process capability, and mistake-proofing. Universal Business Council learners can connect this topic with related Six Sigma certification study, quality management training, and process improvement courses.
For exam preparation, watch the wording. Candidates often know the formula but reverse the Detection scale. In most FMEA rating tables, a higher Detection score means poorer detection, not better detection. That one detail costs easy marks.
Next Step
Take one active process and build a short FMEA with five failure modes. Score Severity, Occurrence, and Detection with your team, calculate the Risk Priority Number, then challenge the highest-severity item even if its RPN looks modest. If you want a structured path, pair this exercise with Universal Business Council Six Sigma certification study and practice it until the scoring discussion feels evidence-based, not opinion-based. If your evidence keeps scattering across systems that will not talk to each other, a Tech Certification from Global Tech Council is worth adding to your plan, since some FMEA evidence problems need better systems integration, not another rating scale.
FAQs
1. What is Risk Priority Number (RPN) in Six Sigma?
Risk Priority Number (RPN) is a numerical risk-ranking measure commonly used in Failure Mode and Effects Analysis (FMEA). It helps teams compare potential failure modes and decide where risk-reduction efforts may deserve attention.
Traditional RPN uses three ratings:
Severity (S) × Occurrence (O) × Detection (D)
So:
RPN = S × O × D
If Severity = 8, Occurrence = 5, and Detection = 4:
RPN = 8 × 5 × 4 = 160
Higher RPN values generally indicate greater priority for investigation, although RPN should never be the only basis for deciding which risks matter.
2. What does RPN stand for in FMEA?
RPN stands for Risk Priority Number. It combines three dimensions of a potential failure:
Severity: How serious would the effect be?
Occurrence: How likely is the cause or failure to occur?
Detection: How likely are existing controls to detect the problem before the effect reaches the customer or next process stage?
These ratings are multiplied to produce a single ranking number.
The appeal is obvious: three messy dimensions become one tidy integer. Naturally, reality remains somewhat less cooperative.
3. How do you calculate Risk Priority Number?
The traditional calculation is:
RPN = Severity × Occurrence × Detection
Suppose an FMEA identifies a failure mode with:
Severity = 9
Occurrence = 4
Detection = 6
Then:
RPN = 9 × 4 × 6
RPN = 216
The team can compare this value with other failure modes, while also reviewing the individual Severity, Occurrence, and Detection ratings.
4. What is Severity in an RPN calculation?
Severity (S) represents the seriousness of the consequences if a failure occurs.
Many FMEA systems use a 1-to-10 scale, where a low rating represents minimal impact and a high rating represents very serious consequences.
Potential effects could involve:
Customer dissatisfaction
Product failure
Safety hazards
Regulatory violations
Production shutdown
Financial loss
Severity focuses on the effect of the failure, not simply how frequently the problem occurs.
5. What is Occurrence in an RPN calculation?
Occurrence (O) estimates how likely a failure cause is to occur.
A typical FMEA uses a defined rating scale where:
Low Occurrence → infrequent failure
High Occurrence → frequent failure
The rating should ideally be supported by evidence such as defect history, warranty data, process capability, maintenance records, field failures, or comparable process experience.
Assigning occurrence scores based on collective facial expressions in a meeting is less rigorous than some teams seem to hope.
6. What is Detection in an RPN calculation?
Detection (D) represents the ability of existing controls to detect a failure or its cause before the undesirable effect occurs or escapes, according to the specific FMEA methodology being used.
In traditional scoring systems:
Low Detection rating → strong likelihood of detection
High Detection rating → poor likelihood of detection
This direction sometimes confuses beginners because a higher Detection score means greater detection risk, not better detection capability.
A failure that is difficult to detect can therefore receive a high D score.
7. What is an example of an RPN calculation?
Suppose a manufacturing process has a potential failure mode:
Failure Mode: Incorrect hole diameter
The team assigns:
Severity = 7
because the part may fail assembly.
Occurrence = 5
because the problem occurs occasionally.
Detection = 6
because current inspection may miss some defective parts.
The calculation is:
RPN = 7 × 5 × 6 = 210
The team can then evaluate actions to reduce occurrence or improve detection.
8. What is the highest possible RPN score?
If Severity, Occurrence, and Detection are each rated from 1 to 10, the maximum traditional RPN is:
10 × 10 × 10 = 1,000
The minimum is:
1 × 1 × 1 = 1
Therefore:
RPN range = 1 to 1,000
However, the numerical range should not be interpreted as a precise probability or financial-risk scale. An RPN of 400 is not mathematically “twice as risky” as an RPN of 200.
RPN is primarily a prioritization tool.
9. What is considered a high RPN in Six Sigma?
There is no universal RPN threshold that applies to every organization or industry.
Some organizations establish internal categories such as:
Low → Monitor
Medium → Review
High → Corrective action
However, thresholds should reflect:
Industry requirements
Customer expectations
Safety implications
Regulatory requirements
Product complexity
Organizational risk tolerance
A high-severity failure should not be ignored merely because its total RPN falls below an arbitrary cutoff.
10. Why can using only RPN be misleading?
Different combinations of Severity, Occurrence, and Detection can produce identical RPN values.
For example:
10 × 2 × 3 = 60
and:
3 × 5 × 4 = 60
Both produce an RPN of 60, but the first includes maximum severity while the second does not.
Treating them as equivalent could hide a critical safety or regulatory risk.
This is one of RPN's major limitations: multiplication compresses different risk profiles into the same number.
11. Should high Severity risks be prioritized even when RPN is low?
Often, yes.
High-severity risks involving safety, regulatory compliance, critical product functions, or severe customer consequences may require action regardless of their total RPN.
For example:
Severity = 10
Occurrence = 2
Detection = 2
RPN = 40
The RPN looks relatively modest, but a Severity rating of 10 may demand immediate attention.
Teams should therefore examine the individual ratings alongside the total RPN.
12. How is RPN used in a Six Sigma FMEA?
During FMEA, teams typically:
1. Identify process or product functions
↓
2. Identify potential failure modes
↓
3. Determine failure effects
↓
4. Identify potential causes
↓
5. Review existing controls
↓
6. Assign S, O, and D ratings
↓
7. Calculate or otherwise prioritize risk
↓
8. Define improvement actions
↓
9. Reassess risk after implementation
RPN can help focus limited improvement resources on important failure modes.
13. How can a Six Sigma team reduce RPN?
Since:
RPN = S × O × D
teams traditionally seek to reduce one or more components.
Reduce Occurrence: Eliminate root causes, redesign processes, mistake-proof operations, improve capability, or strengthen preventive maintenance.
Improve Detection: Introduce better controls, automated monitoring, sensors, inspections, or error detection.
Reduce Severity: This often requires changing the product, process, system, or design so that the consequence of failure becomes less serious.
Simply changing the score in the spreadsheet remains disappointingly ineffective.
14. Can Severity be reduced in an FMEA?
Yes, but reducing Severity is usually harder than reducing Occurrence or improving Detection.
Severity represents the consequence of failure. To reduce it, the team generally needs to change the design or process so that the failure has a less serious effect.
For example, adding a redundant safety mechanism could prevent a component failure from creating a dangerous system-level consequence.
Additional inspection normally improves Detection rather than reducing Severity.
15. How does Poka Yoke help reduce RPN?
Poka Yoke, or mistake-proofing, can reduce risk by preventing errors from occurring or detecting them immediately.
For example:
Before improvement:
Operator can install component backward.
After Poka Yoke:
Fixture physically allows only correct orientation.
This may substantially reduce the Occurrence rating because the error becomes much less likely or impossible under normal conditions.
Well-designed prevention is generally stronger than relying solely on downstream inspection.
16. What is the difference between RPN and risk matrix scoring?
RPN traditionally combines:
Severity × Occurrence × Detection
A conventional risk matrix more commonly compares:
Impact × Likelihood
Risk matrices may classify risks into categories such as low, medium, high, or critical.
RPN adds the detection dimension, making it useful for FMEA where existing controls matter.
Neither method provides perfect mathematical measurement of risk. Both are structured decision aids rather than tiny numerical oracles.
17. What is the difference between RPN and FMEA Action Priority?
Modern AIAG-VDA FMEA methodology uses Action Priority (AP) rather than relying on RPN as the primary prioritization method.
Action Priority evaluates combinations of:
Severity + Occurrence + Detection
and categorizes action priority as:
High (H)
Medium (M)
Low (L)
This approach gives stronger consideration to high-severity situations and avoids some weaknesses created by simply multiplying three ordinal ratings.
Organizations should therefore follow the FMEA standard or customer-specific methodology applicable to their work.
18. When should RPN be recalculated?
RPN should be reassessed after meaningful risk-reduction actions are implemented.
The process is:
Initial S, O, D → Initial RPN
↓
Implement corrective/preventive action
↓
Evaluate new controls and evidence
↓
Assign revised S, O, D
↓
Calculate revised RPN
For example:
Before improvement:
8 × 6 × 5 = 240
After improvement:
8 × 2 × 3 = 48
The revised score provides evidence of how the assessed risk profile changed, assuming the new ratings are justified.
19. What are common mistakes when using RPN?
Common mistakes include:
Treating RPN as an exact quantitative risk measure
Ignoring high Severity because total RPN is low
Using arbitrary universal cutoff values
Assigning ratings without evidence
Confusing a high Detection score with good detection
Reducing scores without changing the process
Focusing on inspection instead of prevention
Failing to reassess risks after improvements
Using outdated FMEA documents
The FMEA should be a living risk-management tool, not a spreadsheet excavated immediately before an audit.
20. How should Six Sigma teams use RPN effectively?
RPN works best when used as one part of a broader risk-based decision process rather than as an automatic ranking formula.
A practical approach is:
Identify Failure Mode
↓
Evaluate Severity
↓
Estimate Occurrence
↓
Assess Detection Controls
↓
Calculate RPN
↓
Review High-Severity Risks Separately
↓
Prioritize Actions
↓
Prevent or Reduce Failure Causes
↓
Improve Detection Where Necessary
↓
Verify Effectiveness
↓
Recalculate and Document Residual Risk
For example:
Failure Mode | S | O | D | RPN |
|---|---|---|---|---|
Incorrect assembly | 8 | 6 | 5 | 240 |
Missing label | 4 | 7 | 3 | 84 |
Safety-system failure | 10 | 2 | 3 | 60 |
If the team blindly ranks only by RPN, the safety-system failure appears least important. That illustrates exactly why RPN should support professional judgment rather than replace it.
The most useful principle is:
RPN identifies where to look. Risk analysis determines what to do.
Six Sigma teams should combine RPN with FMEA analysis, customer requirements, safety considerations, regulatory obligations, process data, root-cause analysis, and the effectiveness of existing controls.
The arithmetic takes seconds. Understanding whether a failure deserves action is the part humans are still expected to contribute.
Related Articles
View AllSix Sigma
Design for Six Sigma Explained: When to Use DFSS Instead of DMAIC
Design for Six Sigma helps teams design new products, services, and processes to meet quality targets from launch instead of fixing defects later.
Six Sigma
Six Sigma Probability Explained: Using Chance to Understand Risk
Six Sigma probability turns uncertainty into measurable defect, failure, and risk estimates so teams can make better quality decisions.
Six Sigma
Six Sigma in Banking: Reducing Errors, Delays, and Compliance Risk
Learn how Six Sigma in banking reduces errors, cycle time, rework, and compliance risk across onboarding, credit, reconciliation, and approvals.
Trending Articles
The Role of Blockchain in Ethical AI Development
How blockchain technology is being used to promote transparency and accountability in artificial intelligence systems.
AWS Career Roadmap
A step-by-step guide to building a successful career in Amazon Web Services cloud computing.
Top 5 DeFi Platforms
Explore the leading decentralized finance platforms and what makes each one unique in the evolving DeFi landscape.