Safety analysis should be derived from design. I prefer that FMEA or FTA should be derived systematically.
And what if there are nothing identified additional safety requirements from safety analysis?
It would be good news, because your design is safe even though you considered diverse failure conditions.
But what if there is no history to improve your system safety and there is nothing identified and your system is safety critical. Does it make sense?
Of course, customer will not believe what you did.
IF safety requirements are not additionally identified from safety analysis, then please consider that your mechanism to derive FMEA and FTA from design is wrong, or your design may miss what should be contained.
There are many approaches, some are useful, and the others may not. Your practice can be improved, so continually improve your design to stretch to safety.
In this sense, re-work is very common.