Example: Waking up
Failure mode
The alarm does not sound, I continue sleeping
Failure pathway
The alarm runs out of battery
“non-detectability”= 2
What could go wrong?
How bad would it be?
How this could happen?
How likely is this to happen?
How unlike are we to
prevent it from happening?
FMEA terminology