methodatlas
RunsheetEngineering

Failure Scenario Analysis

ComplexityMedium
Time1-3 h
Participants3-8
FormatWorkshop
MaturityEstablished
01

Prerequisite

What needs to be finished first

Complete firstIncident datanot in catalog

Symptoms, relevant timing, logs, alerts, or observations are available in raw form.

Without: Without a clear scope, the team gathers material but cannot derive a robust structure or decision.
02

Preparation

What needs to be ready before start

Materials

Workboard or document for Failure Scenarios; existing notes, data, decisions, and assumptions; markers for uncertainty, owner, and next steps.

People / roles

Facilitator; domain experts from affected area; one owner for outcome and follow-up; named decider when decisions are made.

Pre-read

Scope, occasion, known facts, relevant constraints, prior options or events, and desired workshop outcome.

Time needed

60-180 min

Setup

Prepare an empty Failure Scenarios template. Make scope and working question visible at the top. Mark each assumption as an assumption, not a fact.

03

Core question

The one question this method answers

How could the system plausibly fail, what would that impact be, and which controls are missing?

04

Flow

Marker: Phase

StepDurationActionHint
1Fix scope
10-20 minDefine occasion, goal, and boundaries of analysis. Put off all off-topic themes in a parking lot.A narrow scope yields better results than a full but diffuse sweep.
2Gather raw material
20-40 minCollect and make visible facts, events, options, constraints, and assumptions.Keep facts and interpretations separate. Mark uncertain points instead of smoothing them.
3Build structure
30-60 minFill Failure Scenarios step by step, clarify relationships between elements, and reveal contradictions.Do not evaluate too early. Stabilize structure first, then draw conclusions.
4Check and condense
20-40 minMark gaps, weak assumptions, counterexamples, and critical paths. Check the output for readability.If nobody can explain the logic in two minutes, the artifact is not ready.
5Define next steps
15-20 minDocument decision, experiment, test, measure, or follow-up with owner and date.A good artifact without a next action stays knowledge work without impact.
05

Artifact

What comes out at the end

Form

Failure Scenarios with occasion, scope, key elements, assumptions, flagged gaps, result interpretation, and next step with owner and date.

Versioning / ownership

Save artifact with date, scope, and participants. On new evidence, create new version or change note to keep decision logic traceable.

Tool alternatives
  • Miro or FigJam
  • Lucidchart or draw.io
  • Confluence or Notion
  • Google Docs or Sheets
  • Markdown in repository

failure-scenario-analysis-working-template.md

Compact working template for Failure Scenario Analysis with context, input, output artifacts, and next step.

Failure Scenario Analysis Working Template

Goal

Analyzes plausible failure scenarios to prepare weak points, controls, and response options.

Context

When and for what do we use this method?

Input

Which data, observations, decisions, or materials are available?

Execution

Short notes along the runsheet.

Output artifacts

  • Failure Scenarios:
  • Risk Notes:
  • Control Gaps:
  • Test and Response Actions:

Assumptions and open questions

  • ...

Decision / Next step

Owner, date, and success signal.

06

Example output

Concrete filled scenario, fictional example

failure-scenario-analysis-beispiel.md

Concrete filled scenario, fictional example

Failure Scenario Analysis - Checkout outage on sale day

Scope: A specific project area is analyzed, not the whole company. Working question: How could the system plausibly fail, what would that impact be, and which controls are missing?

Excerpt from artifact:

  • Fact 1: current observation is documented with source.
  • Assumption 1: the key causal chain is plausible but not yet proven.
  • Critical point: one open condition decides whether the favored path is viable.

Result: The team chooses a focused next step with owner and date. Signal: Move from risk awareness to response plan.

07

Pitfalls

Recognize symptoms and steer against them

Trap

Scope drifts

Symptom

New topics are added continuously and artifact loses focus.

What to do

Keep scope visible and park new topics.

Trap

Assumptions treated as facts

Symptom

Discussion sounds certain despite weak evidence.

What to do

Mark every uncertain statement and set a check-point.

Trap

Too early actioning

Symptom

Team jumps to actions after only a few minutes.

What to do

Complete the structure first, then derive options and actions.

Trap

No counter-check

Symptom

Artifact only confirms favorite hypothesis.

What to do

Ask explicitly for counterexamples, negative branches, or excluded options.

Trap

No owner

Symptom

Result is understandable but nobody carries it forward.

What to do

Document next step with owner, date, and success signal.

08

Stop criteria

Done signals checkable in under a minute

No clear trigger or scope.
No raw material or no participants with contextual knowledge.
Method is used to justify an already-failed decision.
Important assumptions cannot be discussed openly.
No owner for outcome or follow-up is available.

Finished the runsheet?

Go to the profile for purpose, similar methods, and sources or continue to the next method in the catalog.