HAZOP vs FMEA vs What-If Analysis: Choosing the Right Lens for a Process Change
HAZOP, FMEA, and What-If Analysis answer different risk questions. This comparison helps EHS managers and process leaders choose the method that fits the change instead of selecting the most familiar workshop format.

Key takeaways
- 01HAZOP is strongest when deviations from design intent need systematic examination across a process node or operating step.
- 02FMEA is strongest when the team must understand how component or function failures affect a system and which failure modes deserve treatment.
- 03What-If Analysis is strongest when an experienced team needs a fast, structured challenge to a defined change or activity before work begins.
- 04The best method is determined by the decision, the available process information, the consequence profile, and the evidence required after the workshop.
- 05A completed worksheet is not proof of control. Leaders still need owners, actions, assumptions, and field verification that survive the change.
A process change can look small on a project schedule and still alter the way people, equipment, and safeguards interact. Replacing a pump, changing a chemical feed, adding a bypass, or moving a maintenance boundary may create a risk question that a familiar workshop format cannot answer well.
The choice between HAZOP, FMEA, and What-If Analysis should therefore begin with the decision the organization needs to make. HAZOP asks how a process can deviate from its design intent. FMEA asks how a component or function can fail and what the effect will be. What-If Analysis asks what could go wrong in a defined situation and whether the proposed controls are adequate.
The right risk-analysis method is the one whose structure matches the change, the consequence profile, the information available, and the evidence leaders need before authorizing work.
Why does method selection matter more than workshop familiarity?
Teams often select the method they have used most recently because the template, facilitator, and meeting rhythm are already available. That is convenient, although convenience can hide a mismatch. A component-level failure review may not expose a process deviation caused by interactions between operating steps, while an expansive HAZOP may consume time without improving a narrow equipment decision.
OSHA 29 CFR 1910.119 requires an appropriate process hazard analysis methodology for covered processes and identifies several acceptable approaches, including What-If, HAZOP, and FMEA. The standard does not turn one method into a universal answer. It places the responsibility on the organization to match the analysis to the process complexity and the hazards involved.
That distinction supports a broader point in Andreza Araujo's work. In Safety Culture: From Theory to Practice, the declared management system matters less than the decisions that remain reliable when work changes. A report is useful only when its findings influence design, authorization, ownership, and verification.
What does HAZOP examine best?
HAZOP examines deviations from an intended process design. A multidisciplinary team works through defined nodes or operating steps, combines guide words with process parameters, identifies credible causes and consequences, and records safeguards, recommendations, and unresolved assumptions.
Its strength is interaction. A valve position, flow change, pressure increase, control failure, or loss of utility may create a different exposure when it occurs alongside another condition. HAZOP gives the team a disciplined way to test those relationships instead of reviewing each item in isolation.
HAZOP is usually the strongest fit when a project involves a new or materially modified process, when design intent is documented, and when multiple engineering and operating interfaces can alter the scenario. Its weakness appears when the team lacks current drawings, operating limits, or people who understand how the process is actually run.
What does FMEA examine best?
FMEA examines how an item, function, or process step can fail, what effect that failure may have, how the failure might be detected, and which treatment is justified. IEC 60812:2018 describes FMEA as a planned method for identifying failure modes, effects, and treatments, including the FMECA variant when criticality is assessed.
FMEA is particularly useful when the decision concerns equipment reliability, a safety function, a maintenance strategy, or the failure behavior of a subsystem. The analysis can make hidden dependencies visible, such as a sensor that fails without a diagnostic alarm or a backup component that is not truly independent.
Its main trap is false precision. Ranking failure modes does not make the underlying assumptions true, and a high score does not automatically identify the most important process scenario. The team should connect each important failure mode to a function, a consequence, a detection path, an owner, and a verification activity.
What does What-If Analysis examine best?
What-If Analysis uses structured questions to challenge a defined activity, process, or change. The team asks what could happen if a condition occurs, then evaluates causes, consequences, safeguards, and actions. The method can be efficient when the scope is clear and the participants have relevant operating experience.
Its value comes from proportionality. A plant may not need a full node-by-node HAZOP to review a temporary connection, a short-duration operating change, or a well-bounded maintenance activity. A focused What-If review can expose weak assumptions before authorization, provided the team does not confuse speed with completeness.
The risk is dependence on participant memory. If the process is novel, the consequences are severe, or the team cannot describe the operating envelope, an informal list of questions is too weak. In that situation, the method should be expanded or replaced with a more systematic analysis.
How do the three methods differ by decision?
| Decision need | HAZOP | FMEA | What-If Analysis |
|---|---|---|---|
| Primary lens | Process deviations from design intent | Failure modes of items or functions | Credible scenarios in a defined situation |
| Best fit | New or materially changed process design | Equipment, safety function, or maintenance reliability | Bounded change, task, or operating condition |
| Team demand | Multidisciplinary and process-specific | Function and equipment knowledge | Experienced participants with clear scope |
| Main evidence | Nodes, parameters, deviations, safeguards | Failure modes, effects, detection, treatment | Scenario questions, controls, action owners |
| Common weakness | Becomes paperwork when design information is weak | Creates ranking theater when effects are vague | Misses scenarios when experience is narrow |
This comparison is not a scoring contest. The method should produce the evidence needed for the next authorization decision. When a change affects both process behavior and equipment reliability, the organization may need more than one lens, with one accountable owner integrating the findings.
Which method fits a typical process change?
Consider a hypothetical plant that changes the concentration and dosing rate of a corrosive chemical. The first question is whether the change affects process nodes, operating limits, relief assumptions, control logic, exposure routes, and emergency response. If it does, HAZOP is likely to provide the clearest primary structure.
The team may then use FMEA for a dosing pump, sensor, interlock, or shutdown function whose failure could defeat a safeguard. A focused What-If review can challenge the startup, maintenance, or temporary operating condition that will exist while the change is introduced. Each method answers a different part of the decision.
The practical mistake is to run three workshops and leave three separate action lists. The accountable process owner should maintain one decision record that shows which scenario or failure mode each action addresses, what evidence closes it, and who verifies the control in the field.
What should an EHS manager use as selection criteria?
An EHS manager can make the selection explicit before the meeting is scheduled. The following questions are more useful than asking which method is most popular.
- Is the change primarily altering process behavior, equipment function, or a bounded work situation?
- Do we have current design information, failure data, operating limits, and people who understand the real work?
- Could interaction between deviations create a consequence that an item-by-item review would miss?
- What decision must be authorized after the analysis, and what evidence will prove that the decision remains valid?
These questions also reveal when the analysis must be strengthened. If the consequence is severe, the process is unfamiliar, or the information is incomplete, a short workshop should not be presented as proportional simply because it finished quickly.
What traps make any method look more complete than it is?
The first trap is treating attendance as competence. A room full of representatives does not guarantee that the people who operate, maintain, engineer, and authorize the change have challenged the same assumptions.
The second trap is closing recommendations by document status. A procedure can be revised while the field control remains unavailable, bypassed, poorly understood, or impossible to verify during the shift in which the change occurs.
The third trap is using the analysis to defend a decision already made. When schedule pressure determines the answer before the workshop begins, the method becomes a record of approval rather than a test of risk.
Across 25+ years leading EHS work in multinational operations, Andreza Araujo has built her safety leadership around the gap between declared control and operated control. That experience supports a simple discipline. Ask what changed, identify who owns the decision, and verify the barrier where work actually occurs.
How should leaders decide between HAZOP, FMEA, and What-If Analysis?
Use HAZOP when the main uncertainty concerns process deviations and interactions across nodes. Use FMEA when the main uncertainty concerns how an item or function can fail. Use What-If Analysis when the scope is bounded, the team is experienced, and a proportionate challenge is sufficient.
Use a combined approach when the change crosses those boundaries, but do not multiply workshops without integrating their evidence. The final decision should state the method used, the assumptions accepted, the controls required, the accountable owner, and the date of field verification.
Andreza Araujo's book Make The Difference: Be a Leader in Health & Safety treats leadership as an operating responsibility, not a meeting role. That principle applies here. The analysis is complete only when the leader can explain why the selected method fits the change and can show that the resulting controls work under the conditions people will face.
For more practical guidance on safety culture, risk ownership, and leadership decisions, visit Andreza Araujo.
Frequently asked questions
Is HAZOP better than FMEA for every process change?
When should a team use What-If Analysis?
Can HAZOP and FMEA be used together?
What does OSHA require for process hazard analysis?
What should leaders verify after the risk-analysis workshop?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.