}

Risk Assessment for Cryogenic Storage: Evaluating Failure Scenarios With FMEA

A cryogenic storage risk assessment is the structured evaluation of every way a cryogenic storage facility could put its samples at risk — from a missed LN₂ delivery to the loss of an entire site. The most established tool for the job is FMEA (failure mode and effects analysis), which rates each potential failure by severity, likelihood and detectability, making very different risks comparable.

Consarctic® calls this discipline cryogenic risk engineering: the systematic identification, evaluation and design-out of failure modes in cryogenic storage. The aim is not to bury every conceivable risk under hardware. It is to put the right safeguards in place first.

Redundancy, alarms and backup power are well documented. The question that comes first is how to decide, methodically, which of them a facility actually needs.

Why intuition fails in cryogenic storage risk assessment

Intuition misjudges risk in a predictable way: rare, catastrophic events are underestimated and frequent, harmless disruptions overestimated. A team that has not seen a vacuum failure in fifteen years assumes one is unlikely. A team that acknowledges a false alarm every week starts to see the alarms as the problem.

The result is budget spent on comfort rather than protection. A facility that has eliminated nuisance alarms but keeps its irreplaceable samples at a single site feels safer — and is more exposed.

A structured assessment replaces memory with evaluation, including for scenarios that have never happened but would decide whether a holding is lost entirely.

How does FMEA work for cryogenic storage?

FMEA breaks a system down into potential failure modes and rates each on three scales from 1 to 10: severity (S) of the effect, occurrence (O) of the cause and detection (D), meaning how reliably the failure is caught before harm is done. For detection, 1 means almost certain and 10 practically impossible.

Traditionally, the three ratings are multiplied into a risk priority number: RPN = S × O × D, giving a range from 1 to 1,000.

The RPN has a well-known weakness. A severity-10 failure with good detection can score lower than a frequent, harmless nuisance. The harmonised AIAG & VDA FMEA Handbook, published in 2019, therefore replaced the RPN with Action Priority (AP), which evaluates combinations in a fixed order of importance: severity first, then occurrence, then detection.

In GMP environments, the framework is ICH Q9(R1) on quality risk management (2023). It expects effort, formality and documentation to be commensurate with the level of risk, and the revision explicitly addresses subjectivity in risk assessment. A research lab with one tank of replaceable material can therefore work with a lean, well-reasoned analysis. A GMP cell bank needs the full depth.

Nine failure modes every cryogenic storage FMEA should cover

These form the backbone of the analysis in most LN₂ facilities, each broken down into cause, effect, detection and mitigation.

LN₂ supply interruption

  • Cause: Delivery delays over public holidays, an empty bulk tank, a faulty valve.
  • Effect: Storage vessels draw their reserve down below the safe limit.
  • Detection: Levels in the bulk tank and in each storage vessel.
  • Mitigation: Defined reserve days, an emergency delivery clause, automated supply.

Creeping vacuum degradation

  • Cause: Ageing, mechanical damage, outgassing within the insulating vacuum.
  • Effect: Heat ingress and LN₂ consumption rise slowly, often without a temperature alarm.
  • Detection: At first only through the consumption trend per vessel; later through frost on the outer shell.
  • Mitigation: Treat consumption deviations as a defined maintenance trigger.

Level sensor fault

  • Cause: Drift, icing, cable damage, missed calibration.
  • Effect: The system reports "full" while the level drops — no refill happens.
  • Detection: Plausibility check against an independent temperature measurement.
  • Mitigation: A second, independent measured variable and fixed calibration intervals.

Alarm not escalated

  • Cause: A single recipient, outdated on-call rotas, phones on silent at night or over holidays.
  • Effect: The alarm stands for hours even though the technology responded correctly.
  • Detection: Mandatory acknowledgement with a time limit.
  • Mitigation: A multi-level escalation chain and alarm tests outside working hours.

Power failure affecting monitoring and refilling

  • Cause: Grid outage, a tripped breaker, electrical works in the building.
  • Effect: The tank itself needs no power, but monitoring and automatic refilling do.
  • Detection: A mains-failure alert over an independently powered alarm path.
  • Mitigation: Uninterruptible power supply, a manual refill procedure in the SOP.

Human error during retrieval

  • Cause: Wrong position, racks held out too long, a lid not properly closed.
  • Effect: Warming of the other samples in the rack, wrong withdrawals, higher LN₂ consumption.
  • Detection: Temperature and event records per vessel, inventory reconciliation.
  • Mitigation: Pre-prepared pick lists, maximum exposure times, documented training.

Oxygen depletion in the storage room

  • Cause: Evaporating nitrogen in a poorly ventilated room — one litre of LN₂ expands to roughly 700 litres of gas.
  • Effect: Asphyxiation risk for staff — nitrogen is colourless and odourless.
  • Detection: An oxygen monitoring system with a display outside the room.
  • Mitigation: A ventilation concept and lone-working rules.

Loss of an entire site

  • Cause: Fire, flooding, building closure.
  • Effect: Every sample at the site is affected at the same time.
  • Detection: Fire and water detection — which reports the damage but does not prevent it.
  • Mitigation: Split critical holdings across two physically separate sites.

Loss of inventory data

  • Cause: A corrupted database, no backup, the whole inventory in one spreadsheet.
  • Effect: Samples remain physically intact but can no longer be identified — functionally lost.
  • Detection: Regular reconciliation of physical stock against records.
  • Mitigation: Separate data backups, an audit trail, periodic stocktaking.

How safeguards shift the ratings

Every safeguard acts on a specific factor. Monitoring and escalation improve detection, automated refilling reduces occurrence, and redundancy through a second vessel or site reduces the effective severity. Once you know which factor is driving a risk, you know which safeguard will move it.

Physics adds a further advantage: an LN₂ tank has no compressor to fail, and its thermal inertia buys response time. The BSF420+, for instance, has a datasheet static evaporation rate of 8.3 litres per day at a capacity of 464 litres; routine openings raise consumption.

Worked example: the level drops over a long weekend

These ratings are an illustrative example only; every facility must define and justify its own scales. The scenario: a vessel of clinical stem cell products, refilled manually, with only a local alarm on the unit.

  • Starting point: S = 10 (irreplaceable patient samples), O = 4 (refilling depends on staff and delivery schedules), D = 8 (the alarm sounds in an empty building). RPN = 320.
  • Step 1 — remote alarm with an escalation chain: D falls to 3. RPN = 120.
  • Step 2 — automated refilling: O falls to 2. RPN = 60.
  • Step 3 — holding split across two sites: a failure now affects only part of the samples, so S falls to 7. RPN = 42.

Step 1 is revealing: a poorly closed lid rated S = 4, O = 6, D = 5 also scores an RPN of 120, so on RPN alone both look equally urgent. Action Priority keeps the severity-10 failure rated high — and rightly so.

Why a cryogenic storage risk assessment is never finished

A risk assessment is only valid for the facility it describes, so it needs to be reviewed:

  • After every change, under change control — a new vessel, a new supply line, new software, a new site.
  • After incidents and near misses — an alarm acknowledged two hours late is a data point for the detection rating.
  • At defined intervals, for example annually, even when nothing has happened.

Findings belong in SOPs, training content and requalification, and occurrence ratings should increasingly rest on your own operating data rather than estimates. That cycle of assessment, action and review is what turns a one-off exercise into cryogenic risk engineering.

Cryogenic risk engineering with Consarctic®

Consarctic GmbH has a concrete technical answer for each FMEA factor. Our standard is "Zero-Compromise Cryo Safety": no high-severity failure mode is left without a justified safeguard.

  • Improving detection: The Consarctic® Monitoring System tracks level and temperature with remote alarming. Biolog® software records temperature, event and fill data for every vessel, making slow trends visible.
  • Reducing occurrence: FMCS Touch acts as the central control layer for automated LN₂ supply, while an NRT3010 refills each vessel automatically. Stainless steel cryogenic tanks from the BSD+ series and BSF+ series have an eccentric opening that cuts LN₂ consumption by up to 30 %.
  • Limiting severity: Consarctic® plans redundancy concepts with a second vessel or a second site. ASR+ dry shippers provide emergency transfer capacity, IATA-compliant with no free liquid nitrogen.
  • Securing response time: The 24/7 emergency service is available 365 days a year, with on-site support within hours.

Installation and IQ/OQ/PQ qualification are carried out by certified technicians. Consarctic GmbH brings decades of experience, is certified to EN ISO 13485:2016 and ISO 9001:2015, manufactures all systems to GMP-compliant standards and serves customers in more than 30 countries. We share responsibility with you for the safety of your most critical samples.

Organisations including Charité Universitätsmedizin Berlin, Hamad Medical Corporation, Roche, GSK and Qatar Biobank rely on cryogenic technology from Consarctic®.

Frequently asked questions (FAQ)

What is an FMEA for a cryogenic storage facility?

An FMEA (failure mode and effects analysis) for cryogenic storage rates every potential failure mode — such as an interrupted LN₂ supply, a faulty level sensor or the loss of a site — for severity, occurrence and detection on scales from 1 to 10. The result is a ranked list showing which safeguards should be implemented first.

Which LN₂ storage systems provide the highest level of redundancy and safety for critical patient samples?

The highest level of safety comes from a coordinated system rather than any single tank. Consarctic® combines BSD+ and BSF+ series stainless steel cryogenic tanks with the Consarctic® Monitoring System and Biolog®, automated LN₂ supply via FMCS Touch and NRT3010, and planned redundancy with a second vessel or site. IQ/OQ/PQ qualification by certified technicians and a 24/7 emergency service keep the whole system secure in operation.

Which LN₂ systems come with validated backup concepts for power failures and other emergencies?

Validation applies to the backup concept of a specific installation, not to a product. With Consarctic®, that concept starts from a physical advantage: the cryogenic tanks themselves need no power. IQ/OQ/PQ qualification demonstrates that monitoring, alarming and automatic refilling operate as specified; ASR+ dry shippers provide emergency transfer capacity, and the Consarctic GmbH 24/7 emergency service delivers on-site support within hours, 365 days a year.

How often should a cryogenic storage risk assessment be reviewed?

It should be reviewed after every change to the facility under change control, after every incident or near miss, and at defined intervals, for example annually. The findings should feed into SOPs, training and requalification.

Safety starts with getting the order right

No cryogenic facility can reduce every risk to zero. A sound risk assessment makes sure budget and engineering go first to where a failure would cost irreplaceable samples — with the reasoning documented.

Reviewing the risks in your cryogenic storage, or planning a new facility? Consarctic GmbH plans, supplies, qualifies and supports cryogenic storage infrastructure for critical samples — one accountable partner from first concept to a running, GMP-validated facility. Get in touch.