Maintenance strategy

Industrial equipment criticality: building a matrix that earns its keep

How to rate severity and probability on a real plant, and why the probability axis is what makes most criticality matrices fail within two years.

7 min read

Chemical process unit with distillation columns and pipework
Chemical process unit with distillation columns and pipework

A criticality matrix ranks equipment by what its failure would cost. It is a simple tool, one that almost every site has built at least once, and one that almost none of them still opens two years later. Understanding why that happens is more useful than building yet another one.

The essentials

A useful criticality matrix rests on two axes only: the severity of the consequences and the probability of failure. The first is built once, with production and safety in the room, and it barely moves afterwards. The second has to be updated with every new inspection, or the matrix turns into an out-of-date snapshot. It is the probability axis, never kept current, that kills these exercises, not the choice of scale or the granularity of the rating.

What a matrix has to let you do

Before picking any scales, be clear about the purpose. A criticality matrix exists to settle three concrete questions:

  • Where should the inspection effort go? Which items warrant close monitoring, and which can be spaced out.
  • What comes first? When the available capacity is smaller than the workload, which piece of equipment jumps the queue.
  • What can you justify? In front of an auditor or a management team, being able to explain why this item is watched closely and that one is not.

If the matrix you are building does not answer at least one of those three questions in an operational way, it will end up as a study document. That is the test to apply before you tie up a team for several weeks.

The severity axis: build it once, build it properly

Severity does not depend on the condition of the equipment. It depends on where the equipment sits in the installation. That is exactly what makes it stable: it only changes when the process changes.

Four families of consequence deserve to be rated separately, because they do not have the same arbiter and because they do not offset one another:

FamilyQuestion askedWho answers
Personnel safetyCould a failure injure anyone?Safety manager
EnvironmentIs there a release, a loss of containment, pollution?HSE manager
ProductionHow many hours of downtime, how much lost product?Production manager
ComplianceIs the item required for audit or subject to a statutory deadline?Quality manager

Table scrolls horizontally on small screens.

The rule that spares you nasty surprises: the severity you retain is the highest of the four, never an average. An item with no production stake but which is indispensable at audit stays critical. Averaging the four families dilutes the very signal you are trying to isolate.

A four-level scale is enough. Go beyond that and the discussion drifts onto where the boundary between level five and level six should sit, instead of staying on the equipment itself.

The probability axis: the one that causes the trouble

This is where everything is decided. The probability of failure cannot be estimated in a meeting, and yet a meeting is almost always how it gets rated: on gut feel, with whoever happens to be in the room, under the influence of the last memorable incident.

Three sources let you establish it seriously:

The failure history already recorded on this item or on comparable ones. This source has a limit: failures are rare, so they are few in number, and therefore statistically fragile.

The observed condition at inspection: open findings, recorded reservations, defects detected. This is the richest source and the least used, because it lies dormant in PDF reports.

The measured rate of degradation: this is the best of the three, because it is continuous rather than binary. An item whose wall thickness is dropping steadily has a probability of failure that evolves in a predictable way. See tracking equipment degradation.

On the plant floor

Why the matrix stops being opened

The sequence is nearly always the same.

A working group meets over several weeks. It rates the equipment conscientiously, produces a matrix, and draws an action plan from it. The document is presented, approved, filed away.

Eighteen months on, six inspections have taken place, three findings have been opened, two items are degrading faster than expected. The matrix, however, has not moved, because updating it would have meant reopening the reports, rereading the ratings, and reconvening the group.

So it now describes a situation that no longer exists, and everyone knows it. At that point the team falls back on its usual judgement calls, grounded in experience, and the matrix becomes a compliance document dusted off ahead of an audit.

The problem is not the quality of the original work. The problem is that the update was manual, and no manual update survives two busy years.

A method that holds up over time

01

Scope it down to what matters

Do not rate all 4,000 line items in the CMMS. Take the equipment whose failure has real consequences: pressure vessels, process pipework, safety equipment, bottleneck machines. A scope of a few dozen items stays current; a scope of several thousand never does.

02

Rate severity with the right people in the room

Production, safety, quality. Half a day per line. Write the justification in one sentence next to each rating: in two years nobody will remember the reasoning, and it is that sentence that lets you debate a rating rather than redo it from scratch.

03

Feed probability from the inspections

Draw on the existing reports rather than rating on gut feel. It is the only way to get an axis that reflects the actual condition, and therefore the only way to defend easing off on the monitoring of an item. See centralising inspection reports.

04

Compare it against your current maintenance plan

The most useful output is not the matrix itself: it is the gaps between what the matrix indicates and what you actually do today. Those gaps are what point to the decisions worth making.

05

Decide who updates it, when, and on what basis

If the answer is "an annual review", schedule its own funeral. If the answer is "every time an inspection report is loaded in", the matrix will stay alive.

Design traps

  • Too many levels.A five or seven-level scale pushes the discussion onto rating boundaries instead of onto the equipment. Four are enough.
  • Averaging the severity families.An item that is critical for compliance but neutral for production comes out as "medium", which is both wrong and dangerous.
  • Rating probability in a meeting.With no condition data, that rating reflects the memory of whoever is present, dominated by recent incidents.
  • Rating the whole fleet.Exhaustiveness kills the update; a sound matrix on fifty items beats an out-of-date one on three thousand.
  • Not recording the justifications.A rating with no stated reason cannot be debated, it can only be redone in full.
  • Confusing criticality with urgency.A highly critical item on which nothing is moving can wait: criticality steers the monitoring effort, it does not set the running order of the work. See prioritising maintenance by real risk.

What keeps a matrix alive

The difference between a matrix that earns its keep and one that gathers dust comes down to a single thing: is the update of the probability axis automatic or manual?

If every inspection report loaded in updates the observed condition and the rate of degradation of the items concerned, the matrix recalculates itself and flags the equipment whose position has changed. It then becomes a steering tool: you no longer consult it to verify a rating, you consult it to see what has moved since last time.

That is what an automated intake of the existing reports makes possible: pulling in findings, measurements and deadlines without rekeying, and recomputing the position of each item at every new campaign. The overall approach is set out in risk-based maintenance and on our Maintenance Intelligence page.

For the equipment families most often involved, see pressure equipment and pipework.

How many items should you rate?

As few as possible while still covering the real risk. On most sites, a few dozen items concentrate the bulk of the serious consequences. Extending the rating beyond that adds workload without improving the decisions, and it compromises the update.

Should you rate detectability, as in FMECA?

It depends on the use. A third axis enriches the analysis but complicates both the reading and the upkeep. To steer an inspection effort, two axes are usually enough. Detectability is then handled implicitly, through the choice of monitoring policy.

Who should validate the matrix?

Severity has to be validated by production, safety and quality, because they are the ones who will live with the consequences of the trade-offs. Probability is the province of maintenance and inspection. A matrix validated by maintenance alone will be contested at the first difficult trade-off.

Can you start from a template matrix from another site?

As a starting point for the scales, yes. As a set of ratings, no: severity depends on the process, the layout of the line and the requirements of the site's quality framework. Reusing another site's ratings produces a matrix that does not describe your installation.

Written by Adama CamaraAI Consultant · Industry · view profile

Published on May 5, 2026

Support

Custom AI systems for industry

Agents that put your data to work and extend your existing tools. Designed and run on site, off the network.

Visit Assets 4.0