Ford just recalled 565,000 Broncos and Bronco Raptors for engine compartment fire risk. Half a million vehicles. And somewhere in a PFMEA workbook—probably on a shared drive with "FINAL_v3_REAL_FINAL" in the filename—that failure mode has a severity rating below 10.

I know this because I have been in the rooms where those numbers get debated. I have watched a cross-functional team talk themselves down from a 10 to a 7 because the RPN was "too high" and nobody wanted to trigger the action plan that would stall the launch. The math is seductive: severity 10, occurrence 4, detection 3—RPN of 120. Drop severity to 7 and you are at 84, comfortably beneath the action threshold. The workbook turns green. The meeting ends early. Three years later, half a million vehicles are recalled because engines are catching fire.

Why severity is the one rating your team should never negotiate

Severity in PFMEA describes the worst credible consequence of a failure mode on the end user. Not the likely case. Not the case-with-controls-in-place case. The worst credible case. IATF 16949 is explicit about this, and every core tools manual reinforces it.

When the failure mode is "engine compartment fire," severity is 10. There is no version of combustion that is a 7. A 7 means something like "customer perceives defect with high annoyance but no safety impact." Fire is not annoying. Fire kills people, destroys property, and generates headlines that erase billions in market capitalisation before lunch.

At SNOP, where I built the quality function for a 900-employee greenfield plant, I made one rule non-negotiable in every PFMEA session I chaired: if the failure mode involves thermal event, fire, or any catastrophic safety consequence, severity stays at 10. We do not have a conversation about it. The conversation we have is about occurrence and detection—because those are the variables you can actually engineer. Severity is physics.

At WITTE Automotive, I inherited PFMEA workbooks where severity ratings had been massaged to keep RPNs under 100. Three months of uncomfortable meetings with engineering leadership to unwind those scores. We found failure modes related to lock cylinder retention scored at severity 6. The actual consequence of a door latch failing at motorway speed is not a 6. We corrected them. QRQC and A3 discipline then drove the countermeasures—substantial failure-cost reduction followed, not because the scores changed, but because acknowledging the real severity forced the right engineering responses.

How thermal risks get systematically under-scored to keep production moving

The mechanism is not malicious. Nobody sits in a PFMEA session thinking, "I am going to under-score fire risk so we can ship defective vehicles." What happens is slower and more insidious. A dozen small compromises, each one sounding reasonable in the moment.

Someone says, "But we have a detection control that catches this in-line." Severity is not about detection. Someone says, "The probability of this happening is low." Severity is not about probability—that is what occurrence measures. Someone says, "The supplier has secondary containment." Severity describes what happens when all of that fails and the customer is doing 130 on the Autobahn.

The RPN formula—severity × occurrence × detection—is supposed to be a prioritisation tool. Instead it has become an optimisation target. Teams engineer the score, not the risk. And because severity carries the most mathematical weight, it is the rating under the most pressure. Dropping occurrence from 4 to 3 requires engineering work. Dropping severity from 10 to 7 requires consensus.

The same discipline applies at Airbus, where I lead manufacturing engineering technical authority for North America. In aerospace, we operate under AS9100 and EASA oversight, and the regulatory tolerance for severity negotiation is effectively zero. We achieved a 50% reduction in EASA audit findings in one cycle not by gaming scores but by refusing to—by treating every high-severity failure mode as an immediate stop condition. You do not calculate an RPN and then decide whether to act. You act first, and the RPN documents the prioritisation.

The arithmetic of catching a 10 at PFMEA versus catching it in a recall letter

A proper PFMEA with severity 10 on a thermal failure mode triggers mandatory action. That action might delay a launch by six weeks. It might cost €800,000 in additional engineering validation, updated tooling, or a redundant heat shield. It might require a design change that ripples through the BOM.

Now run the recall math. 565,000 vehicles. Field inspection, dealer campaigns, software reflashes or hardware replacement, regulatory penalties, litigation exposure, brand damage. The Ford recall will cost hundreds of millions—conservatively. The six-week delay would have cost a fraction of that.

The 97% reduction in internal lead time I delivered at Airbus through Routing Verification KPIs was built on the same principle: catching the high-severity failure at the engineering stage costs orders of magnitude less than catching it in the field. I have gone quarters with zero critical customer escalations—not because I am lucky, but because I refuse to compromise severity ratings under schedule pressure. When engineering pushes back, and they always do, the answer is the same: the score describes the physics, not the schedule.

If your PFMEA turns a fire into a 7, the failure mode you have actually identified is in your scoring process.

Key takeaways

  • Severity describes the worst credible consequence, full stop. Fire is a 10. There is no engineering argument that changes that.
  • RPN is a prioritisation tool, not an optimisation target. If your team is engineering the score instead of engineering the risk, your PFMEA process has already failed.
  • Occurrence and detection are the variables you control. Severity is the variable physics controls. Argue about the first two, never the third.
  • The cost of a six-week launch delay triggered by an honest severity 10 is a fraction of the cost of a 565,000-vehicle recall triggered by a dishonest severity 7.

Fire does not negotiate. It does not care about your action threshold, your launch date, or your optimised RPN. The Broncos now being recalled cleared every quality gate in Ford's system. Every gate let them through because somewhere, in a room full of competent engineers, someone decided fire was a 7. Half a million owners are living with that arithmetic. The fix is not complicated. Stop debating severity on thermal events. Treat it as a stop condition. Let the RPN do what it was designed to do—prioritise action, not prevent it.