Skip to content

Common Mode Failure Analysis

Identify shared dependencies that could cause supposedly independent backups or safeguards to fail together.

The Diagnostic Story

Symptom: The system has redundancy built in — multiple backups, alternative paths, separate vendors, parallel safeguards — but when a real failure arrives, several of them disappear at once. The resilience plan listed resources but not whether those resources were actually independent. Identical design lineage, shared upstream dependencies, or common training quietly turned many protections into one hidden point of failure.

Pivot: Make independence assumptions explicit, map shared dependencies across redundant elements, identify which failure modes could defeat multiple paths simultaneously, rate correlated exposure, and then act — through diversity, isolation, hardening, sequencing, monitoring, or explicit residual-risk governance.

Resolution: Redundancy investments become more credible because the independence claims behind them have been tested. Surprising correlated failures decrease and diversification priorities become visible. Residual shared risk is governed explicitly rather than discovered in a crisis.

Reach for this when you hear…

[data center operations] “We have two power feeds but they come out of the same transformer — that is not redundancy, that is the same failure in two colors.”

[aviation safety] “All three flight computers came from the same production batch with the same firmware defect — the redundancy was real on paper but not in the failure mode.”

[financial risk] “We thought we were diversified across six counterparties until the credit event hit and it turned out four of them had the same underlying exposure.”

Mechanisms / Implementations

  • Common-Cause FMEA: Adapts failure mode analysis to ask which single causes could defeat multiple protections.
  • Fault Tree with Common-Cause Branching: A fault tree can represent shared causal branches that lead to multiple failures.
  • Dependency Mapping Workshop: A dependency mapping workshop brings together people who see different parts of the system.
  • Backup Independence Test: A backup independence test exercises a backup under a shared dependency outage.
  • Supply-Chain Dependency Review: A supply-chain dependency review traces alternate suppliers down to shared sub-tier suppliers, shipping routes, regional exposures, labor constraints, and regulatory chokepoints.
  • Diverse Vendor Review: A diverse vendor review checks whether vendor diversity is real across infrastructure, ownership, code lineage, support, credentials, and failure response.
  • Correlated Risk Register: A correlated risk register records common-mode exposures, owners, mitigation status, test evidence, and residual-risk acceptance.
  • Tabletop Cascade Exercise: A tabletop cascade exercise simulates a shared failure cause and follows how redundant paths respond together.
  • Credential and Infrastructure Dependency Audit: This audit checks whether emergency systems, backups, and alternate teams still depend on the same identity provider, cloud control plane, network, physical access system, or infrastructure service.

Abstractions this archetype builds on — directly (a source ingredient) or as a related pattern. Links follow the typed catalog namespace.

Built directly on (3)

Also references 9 related abstractions

Variants

Narrower or domain-specific specializations that share this archetype's core structure. Recognized variants are established; candidate variants are provisional.

Common-Cause Failure Analysis · risk or failure variant · recognized

A causal form of common-mode review that asks which single cause could defeat multiple redundant paths or safeguards.

Backup Independence Analysis · implementation variant · recognized

A backup-focused variant that tests whether alternate capacity, suppliers, records, channels, or roles remain available under the same stress that disables the primary path.

Shared Dependency Review · implementation variant · candidate

A dependency-centered review that looks for upstream resources, controls, or conditions shared by multiple protections.

Correlated Risk Analysis · risk or failure variant · candidate

A quantitative or portfolio-style variant that analyzes whether risks assumed to offset or diversify one another actually fail together under stress.