Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

asset criticality explained

Asset Criticality: 5 Essential Steps to Rank Assets (ISO 55001)

Asset criticality is the ranking of assets by the consequence of their failure — to service, safety, the environment, cost and reputation — and it is the single input that turns an ISO 55001 system from a list of assets into a set of priorities. ISO 55001:2024 never uses the phrase, but clause 6.1’s actions to address risks and opportunities, clause 4.5’s documented decision-making and clause 8.1’s life-cycle management all presuppose that the organisation knows which assets matter most; the standard’s principle of value, from ISO 55000:2024, is meaningless without a way of saying which failures destroy the most of it.

The assessment is also the input the maintenance strategy, the condition survey programme, the data-quality effort and the whole-life cost models all consume. This guide sets out a five-step asset criticality assessment, the consequence categories and scales that make it consistent, how probability is kept separate from consequence, where the result feeds the rest of the system, and the five mistakes that make criticality rankings useless.

Asset criticality assessment: five steps and five consequence categories
1 Scope and hierarchy · 2 Consequence categories and scales · 3 Score consequence per asset · 4 Combine with likelihood for risk · 5 Band, record and use — service, safety, environment, financial, reputation.

Why ISO 55001 needs asset criticality

Clause 6.1 requires the organisation to determine the risks and opportunities that need to be addressed and to plan actions proportionate to them; the 2024 edition’s foreword adds a “clear distinction between how an organization shall address ‘risk’ and how it shall address ‘opportunities'”.

Proportionate action needs a scale, and criticality is that scale for assets: it says which assets’ risks are worth a condition-based maintenance regime, a spare in stock, an annual inspection and a whole-life cost model, and which are worth run-to-failure and a reorder point. Clause 4.5’s decision-making criteria and clause 8.1’s life-cycle management then apply different rules to different criticality bands. Our guide to ISO 55001:2024 covers the clauses; the register that holds the result is covered in our guide to the asset register.

The five-step asset criticality assessment

  1. Fix the scope and the level. Criticality is assessed at a level of the asset hierarchy — usually the maintainable unit or the system — and inherited or aggregated from there. Assessing every bolt is wasted effort; assessing only whole sites hides the pump that stops the works.
  2. Define the consequence categories and scales. Typically five categories, each with a four- or five-point scale anchored in the organisation’s own terms — hours of service loss, injury severity, environmental permit breach, cost bands, media exposure — and aligned with the corporate risk criteria so that a “4” means the same in the asset register as in the risk register.
  3. Score the consequence of functional failure for each asset, assuming the failure happens, category by category, and take the highest category score or a weighted sum according to a documented rule. This is consequence only.
  4. Combine with likelihood to get risk, where the decision needs it: likelihood from failure history, condition and age, on its own scale. Criticality (consequence) is a property of the asset’s role; risk changes as condition changes.
  5. Band, record and use. Three or four criticality bands with defined treatment rules per band; the band, the scores, the method version and the date recorded in the register; a review trigger on any change of role, redundancy or service obligation.

Consequence categories and scales

Category What a high score means Anchor the scale in Typical source
Service or production Loss of service to many customers, or full production stoppage, for a long period Customers affected × hours; units lost Service level agreements; production plans
Safety Potential for fatality or multiple serious injuries on failure The organisation’s H&S risk matrix severity scale HAZOP, safety cases, incident history
Environment Permit breach, reportable release, lasting damage Regulatory reporting thresholds Environmental permits, aspects register
Financial Repair, consequential loss and penalties above a defined band Cost bands agreed with finance Whole-life cost models, contracts
Reputation and compliance Regulator intervention, public attention, contractual breach Stakeholder and regulatory exposure Stakeholder analysis under clause 4.2

Redundancy is the factor most often applied wrongly. A duty-standby pair has lower service consequence per pump than a single pump, because failure of one does not stop service — but the standby’s criticality rises the moment the duty pump is out. Handle it by assessing the system’s consequence and the units’ contribution, and by flagging assets whose criticality is conditional on redundancy being available.

Where the result feeds

System element How asset criticality is used ISO 55001 clause
Maintenance strategy Band A: condition-based or predictive; Band B: time-based; Band C: run-to-failure with spares 8.1 operational planning
Condition assessment programme Survey frequency and method by band 7.6 data; 9.1 monitoring
Data-quality effort Complete and verify register fields for high-criticality assets first 7.6 data and information
Whole-life cost and investment decisions Consequence pricing for element 6; investment priority 4.5 decision-making
Risk and opportunity actions Proportionate treatment; opportunity to reduce criticality by redundancy or redesign 6.1
Spares and contingency Stocking policy and emergency plans by band 8.1; 8.3 externally provided
Predictive action Where to look for potential nonconformities before they occur 10.3

Five mistakes that make criticality useless

  • Mixing likelihood into the consequence score. A highly reliable but catastrophic-on-failure asset ends up “medium”, and the organisation stops watching the one thing it should never stop watching.
  • Scales without anchors. “High” means something different to each assessor; the ranking is opinion.
  • Everything is critical. Sixty per cent of assets in the top band is a ranking that ranks nothing; force the distribution or refine the scales.
  • Assessed once, in 2019. Roles, redundancy and service obligations change; the register needs a date and a trigger.
  • Not used. A criticality register that does not drive the maintenance strategy or the survey programme is a spreadsheet, and the auditor will ask what it changed.

Running the assessment

  1. Workshop the scales with operations, safety, environment and finance so each category’s anchors are the organisation’s own.
  2. Assess by system with the people who run it, using failure modes to structure the consequence questions.
  3. Calibrate across sites — a sample re-scored by a second team exposes drift.
  4. Record the method as a procedure with a version number, and the results in the register with dates.
  5. Review annually and on trigger, and report the band distribution at management review.

Frequently asked questions

What is asset criticality?
A ranking of assets by the consequence of their functional failure across service, safety, environmental, financial and reputational categories, scored on anchored scales and banded so that maintenance strategy, condition assessment, data effort and investment priority can be set proportionately. It is consequence-based; risk adds likelihood.

Does ISO 55001 require it?
Not by name. Clause 6.1’s proportionate actions on risks and opportunities, clause 4.5’s decision-making criteria and clause 8.1’s life-cycle management all presuppose a way of ranking assets by what their failure would cost, and criticality is the established method.

Criticality or risk — which goes in the register?
Both, separately: criticality as a property of the asset’s role, risk as criticality combined with a likelihood that changes with condition. Recording only a combined risk score hides catastrophic-but-reliable assets.

How many bands?
Three or four is usual — enough to give each band a distinct treatment rule, few enough that the rules are actually different.

How often should it be reviewed?
Annually, and on any change of role, redundancy, service obligation or regulatory requirement; the register should carry the assessment date and method version.

Where this leaves you

Run asset criticality as a five-step assessment on anchored scales, keep consequence separate from likelihood, band the result with treatment rules that actually differ, record method and date in the register, and wire the bands into the maintenance strategy, the survey programme and the investment criteria. If the assessment changes nothing downstream, it has not been done yet.

References

More on ISO 55001

The Risk-Based Decision-Making and Criticality procedure, the Criticality Register, the Risk Register, the Condition Assessment procedure and the PPM Schedule are in the ISO 55001 Asset Management Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.