A bad actor is any asset that disproportionately drives unplanned downtime, repair cost, or production loss, and CMMS work order data is the raw material for separating these chronic offenders from sporadic one-off failures [S3][S6].
The working definition in current reliability practice is that the top 5-10% of assets account for more than 50% of total maintenance spend, and the top 10% of power-plant assets can consume 60% of the maintenance budget [S3][S7]. The minimum dataset is a 12-24 month export of unplanned corrective work orders, keyed to equipment tag, failure mode, labor hours, parts cost, and downtime hours [S3][S5][S9].
Work Order Data Fields Required to Build a Bad Actor List
Every corrective work order used for bad actor analysis must carry the equipment tag, order type, failure mode, maintenance cost, and associated downtime cost, otherwise the Pareto sort collapses into noise [S5][S9]. Reliabilityweb's published bad actor program steps explicitly require these five fields as the minimum schema before any ranking is attempted [S5].
Practitioners also require a problem description, a functional-failure flag, and an "actions performed" log so that recurring failure modes can be classified, not just counted [S1]. Without a functional-failure flag, painting, calibrations, and other non-failure work orders inflate the failure count and bias the ranking [S1].
For instrument-heavy plants, the same logic applies to flow meter and pressure transmitter populations, where chronic zero-shift or impulse-line blockages on a small subset of measurement loops drive most calibration cost: the flow meter and pressure transmitter encyclopedia pages outline the data fields a CMMS should capture to feed that ranking. Bad actor ranking at equipment-class level is also a standard reliability move: one SMRP case study uses object-type Pareto on low-criticality groups such as gas detectors and temperature probes to flag entire equipment families as chronic offenders [S4].
Pareto Sort and the 80/20 Rule Applied to Work Orders
Bad actor programs are built on the Pareto principle, and the working assumption is that 80% of failure impact comes from 20% of causes, so the top 20% of assets are selected for further review after the initial cost or downtime sort [S3][S5]. The published four-step framework is: aggregate 12-24 months of corrective work orders, Pareto rank by failure frequency and total cost or downtime, calculate MTBF and MTTR per asset, then cross-reference against an Asset Criticality Ranking matrix to focus engineering on the high-criticality quadrant [S3].
Frequency and cost are two distinct variables, and a chronic "death by a thousand cuts" failure pattern (a labeling machine failing 15 times a month for 10 minutes each) ranks as a bad actor on frequency even though no single event is large [S3]. On the other end, a single 40-hour gearbox tear-down will dominate the cost Pareto without ever appearing on a frequency Pareto, so reliability engineers run both rankings in parallel [S3][S5].
MTBF, MTTR, and the 3-Failure-in-12-Months Threshold

MTBF identifies assets whose failure cycle is shorter than the PM interval, which is a hard signal that the preventive program is misaligned with the physics of failure, while MTTR surfaces assets that are difficult to service and point to design or training gaps [S3]. A gearbox failing every 6 months on a 12-month PM cycle is a textbook MTBF-violation bad actor, irrespective of its total cost [S3].
One oil-and-gas reliability manager formalises the trigger as: any equipment with more than 3 functional failures inside a rolling 12-month window is a potential bad actor, and a quarterly CMMS corrective-notification dump feeds the count [S4]. That same manager then applies a risk and impact assessment with operations to convert the candidate list into "active" bad actors, which become the working backlog for 5-Why, simple RCA, or discipline-engineering review [S4].
Chronic vs. Sporadic Failures: Sorting the Noise
Chronic failures are frequent, often normalised by operators, and usually carry multiple contributing factors such as poor lubrication, improper start-up, or sanitation-induced breakdown, while sporadic failures are sudden, dramatic events with a single root cause like a lightning strike or a forklift impact [S3]. The SMRP-cited estimate is that eliminating chronic failures can reduce overall maintenance cost by up to 60% because chronic failures are the bulk of "hidden" factory waste [S3].
This is the reason reliability engineering treats bad actor analysis as the entry point to failure-elimination work, not as a stand-alone report: the output is a ranked list of chronic failure modes on critical assets, and the next step is a Pareto of failure modes within the bad-actor subset to select the most repetitive mode for RCA [S5].
Asset Criticality Ranking: Where the Engineering Hours Should Go

A bad actor on a non-critical run-to-fail asset is a nuisance, but a bad actor on a bottleneck machine is a systemic threat, so the engineering response is gated by an Asset Criticality Ranking matrix before any RCA is opened [S3]. SMRP members running this workflow report filtering their candidate list on unplanned repair orders affecting OEE, annual cost of operating and repair, age, and demand or utilisation, which mirrors the four standard reliability dimensions of cost, downtime, probability, and consequence [S4].
For instrumented processes, the same logic extends to data logger fleets, where a small subset of channels or units generates the bulk of calibration, memory-card, and battery replacement work orders; ranking that fleet by work-order count per channel is a direct analogue of the equipment-tag bad actor sort. The CMMS work order is the common substrate: the cost code, labour hours, and failure description are identical whether the asset is a pump, a transmitter, or a flow computer.
From Bad Actor List to Engineering Action and Tracked Value
Once the active bad actor list is agreed with operations, the reliability team reports progress in fortnightly site reliability meetings and tracks each item through to elimination, after which the value delivered is quantified against the original risk score to justify the program [S4]. Treatment options documented in the field are 5-Whys, simple RCA, discipline-engineering review, hardware redesign with management-of-change, procedural change, component upgrade, and OEM service-bulletin feedback [S4].
For the program to survive, the workflow must be an approved company procedure or guideline, with every stakeholder from operator to reliability manager aligned on data fields, ranking criteria, and the elimination loop, otherwise the CMMS work order history degrades into an underused archive [S4][S1]. The published end-state is a closed loop: cost-down Pareto plus failure-mode Pareto plus criticality gate plus RCA plus tracked value, all driven by the same CMMS work order rows that the maintenance team has been writing for years.
Trackable signals to watch through the rest of 2026: vendor releases of automated CMMS-to-bad-actor modules that pre-tag functional failures and pre-compute MTBF, and updates to SMRP best-practice documents on bad actor calculation, since the September 2026 forum thread shows the definition is still being standardised across pharma, chemicals, and upstream oil and gas [S2][S4].
Background reading: Ex d enclosure vs native ATEX light curtain: spec-by-spec.