Risk Ranking and Filtering — Comparing Risks That Don't Share a Scale
The one idea
FMEA scores risks within one process on one shared scale. Risk ranking and filtering compares risks across processes, products, or sites that have no natural shared scale at all, by explicitly defining and weighting the criteria that make one risk matter more than another.
Mechanics
- Define criteria that matter across every risk being compared — typically patient impact, regulatory exposure, likelihood, and detectability, though a portfolio-level exercise might add business impact or timeline pressure.
- Weight the criteria to reflect what actually matters most in this decision (patient impact usually carries the most weight; timeline pressure usually carries the least, if it’s included at all).
- Score each risk against every criterion, using whatever scale is practical (often 1–5, sometimes qualitative bands converted to numbers).
- Compute a weighted score and rank — then filter: set a threshold or a headcount/budget cutoff and act on what clears it, explicitly documenting why anything below the line is being deferred.
The “filtering” half is as important as the ranking half — the exercise exists to produce a short, defensible action list, not just a long sorted table nobody acts on.
Worked example — a site quality council’s quarterly resourcing decision
Five unrelated findings are competing for the same limited investigation and remediation budget this quarter:
| Risk | Patient impact (×3) | Regulatory exposure (×2) | Likelihood (×1) | Weighted score |
|---|---|---|---|---|
| Stability OOS trend, Product A | 5 | 4 | 3 | 5×3 + 4×2 + 3×1 = 26 |
| Method-transfer gap, Product B (new receiving lab) | 3 | 3 | 4 | 3×3 + 3×2 + 4×1 = 19 |
| Aging HPLC fleet (increasing downtime) | 2 | 1 | 5 | 2×3 + 1×2 + 5×1 = 13 |
| Recurring documentation deviation (data-integrity adjacent) | 3 | 5 | 4 | 3×3 + 5×2 + 4×1 = 23 |
| Pending inspection commitment (due date approaching) | 2 | 4 | 5 | 2×3 + 4×2 + 5×1 = 19 |
Ranked and filtered against a “fund the top three this quarter” cutoff: the stability OOS trend (26) and the documentation deviation (23) fund first regardless of tiebreaks; the method-transfer gap and the inspection commitment tie at 19 and need a secondary criterion (e.g., regulatory due date) to break the tie for the third slot. The aging-fleet risk (13) is explicitly deferred — not ignored, documented as deferred, with the reasoning on record for the next review cycle.
When to reach for it vs. FMEA
Use risk ranking and filtering when the decision spans multiple unrelated risks competing for the same finite resource — funding, staffing, audit time — not when you’re working through the failure modes of a single process or method, which is FMEA’s job. It’s the tool for “which of these five different problems do we fix first,” not “what could go wrong in this one method.”
Known weaknesses
- The weighting scheme is itself a subjective judgment call — this is the same criticism Q9(R1) raises about FMEA’s Severity/Occurrence/Detection scoring; risk ranking and filtering doesn’t remove that subjectivity, it just moves it up a level, from scoring individual failure modes to weighting the criteria that compare them.
- Different stakeholders (quality, manufacturing, regulatory affairs) often disagree on the weights themselves — reaching agreement on the weighting is frequently the harder part of the exercise, not the scoring.
- A weighted score can create false precision — a 26 vs. a 23 looks decisive, but both numbers rest on the same soft inputs as any other risk score, and the ranking should be sanity-checked qualitatively before being treated as a tiebreaker.