Hi all,
In clause 8.3.2.3 IATF 16949 states:
Using prioritization based on risk and potential impact to the customer, the organization shall retain documented information of a software development capability self-assessment.
My questions are:
1- Is “potential impact to the customer” anything else rather than “risk”? I think that potential impact to the customer = risk to the customer.
2- Suppose that risk and potential impact are two different things. Does this requirement ask the organization to determine the retention time of self-assessment records based on risk and potential impact to the customer? I.e. such as following table:
thanks all
In clause 8.3.2.3 IATF 16949 states:
Using prioritization based on risk and potential impact to the customer, the organization shall retain documented information of a software development capability self-assessment.
My questions are:
1- Is “potential impact to the customer” anything else rather than “risk”? I think that potential impact to the customer = risk to the customer.
2- Suppose that risk and potential impact are two different things. Does this requirement ask the organization to determine the retention time of self-assessment records based on risk and potential impact to the customer? I.e. such as following table:

thanks all