SBS - The best value in QMS software

Risk Identification and Risk Assessment for any Process - Is it necessary?

Jen Kirley

Quality and Auditing Expert
Staff member
Admin
#11
So, My question is that, is it a requirement of ISO 9001 to do risk assessment on QMS processes? I know that we usually do risk assessment in some ways.
There is a pervasive myth that formal risk analysis is required for processes. A great deal of outcry on Linked In and other sites perpetuates the myth. Some of the loudest outcry is from consultants, who naturally want to exhibit their expertise and advocacy for the user.

But 6.1 of ISO 9001:2015 does not require a formal analysis. It does not require documentation. Guidance documents suggest risk to be handled as per ISO 31000, which probably helped build the myth.

An auditor will ask about risk, and what you do in response to it. If you have a checklist to ensure all requirements are met in the packaging and shipping process, produce it and describe its intent. Checklists are very good for helping to control transaction-type process risks.

The internal audit can help determine effectiveness of actions taken to reduce risk. If your packaging area and shipping area uses a checklist, the audit can include that and compare it to complaints, if any, about problems with shipped product. If your purchasing process relies on ISO certification for suppliers and you find contamination problems with a certain raw material from a certain supplier, that is data indicating your action to address risk may not have been sufficient and you must do more. If that is the case, describe that; you can use supplier CARs and related documents to help show documentation of this analysis.

If an auditor demands you to have a formal risk analysis for processes, ask "Where is the requirement?" The regulated industries will need process FMEAs (Failure Mode Effect Analysis) but without that requirement or a customer requirement, this is not required in 9001:2015. A corrective action stating otherwise should be disputed so the auditor can be corrected.
:2cents:
 
Elsmar Forum Sponsor

Big Jim

Super Moderator
#12
All of the posts after Sydney's 1st one give credence to his comments.

In response to the OPs question:

"So, My question is that, is it a requirement of ISO 9001 to do risk assessment on QMS processes? I know that we usually do risk assessment in some ways."

I would suggest the answer is no. I would further suggest that there is a requirement there, but the requirement is that risk awareness is required for all of the quality management system, including the processes. Assessment no. Awareness yes.

I would also suggest that most organizations already do this.
 

Sidney Vianna

Post Responsibly
Staff member
Admin
#13
but the requirement is that risk awareness is required for all of the quality management system, including the processes. Assessment no. Awareness yes.
:applause: I like the term Risk Awareness much better than Risk Based Thinking. Very well said, Big Jim.

With so much confusion about RBT, especially when it comes to the conformity assessment practices, there is a risk ;) for clashes. Let me offer the following scenario, one that I bring here, now and then:

Company pays commissions to the sales force for sales volumes. Auditor interviewing a sales person finds out that orders are being accepted, despite the fact that customer expected receipt date of the product is way shorter than the typical lead (delivery) time the organization "guarantees" to customers. Auditor asks the sales person about the potential problem. Salesperson answer: My job is to sell. That's how I make my living. Orders are taken in and production is responsible for ensuring that orders are prioritized/expedited to satisfy the customer requested dates.
Auditor had already identified the fact that there had been numerous customer complaints concerning late deliveries.

Should the auditor identify the situation as a failure of the sales person to use RBT when accepting orders? Would you, as an auditor?

Please note that I am not identifying the auditor as a 3[sup]rd[/sup], 2[sup]nd[/sup] or 1[sup]st[/sup] party auditor.
 

Big Jim

Super Moderator
#14
I would write such a nonconformance. I don't think that RBT can be used as an excuse for not meeting a requirement. I would write it under 7.2.1 in the old standard or 8.2.2 in the new standard. There may be additional applications as well.

Not only would I write it, I have written them. In one such case I felt like I had thrown a grenade into the closing meeting and nearly immediately left. Their root cause was that their company was out of control. Their corrective action included establishing a means of tracking and scheduling production so that they could have better forecast lead times. It worked. They needed a wake up call.
 

dhakadmilind

Starting to get Involved
#15
Dear ,
I have the different opinion on this. In 2015 ,there is no Preventive action and it is get replaced by RBT topic. Now if we dont consider the processes in RBT then how we are going to find out the chances for improvement .
We are having the process for calibration and if we dont consider the Risk in calibration then how we are going face the audit i.e 4.1-4.2 to 6.1 for calibration process.
So as per my interpretation , We have to do the SIPOC and then remaining all clauses will be applicable to it by consider PDCA approach.
Pls need your valuable input on this.
Thanks
 

howste

Thaumaturge
Super Moderator
#16
Dear ,
I have the different opinion on this. In 2015 ,there is no Preventive action and it is get replaced by RBT topic. Now if we dont consider the processes in RBT then how we are going to find out the chances for improvement .
We are having the process for calibration and if we dont consider the Risk in calibration then how we are going face the audit i.e 4.1-4.2 to 6.1 for calibration process.
So as per my interpretation , We have to do the SIPOC and then remaining all clauses will be applicable to it by consider PDCA approach.
Pls need your valuable input on this.
Thanks
I believe that if you implement your system per your interpretation the system would meet the risk-based thinking requirements. But to say we "have to" have SIPOCs or any other tool is adding to the requirements.

The requirements we need to meet include considering risk throughout the system and taking appropriate actions. What an organization does to meet these requirements is left up to them. I have personal preferences in ways to do it, but none of them are mandatory.
 
Last edited:

Big Jim

Super Moderator
#17
Dear ,
I have the different opinion on this. In 2015 ,there is no Preventive action and it is get replaced by RBT topic. Now if we dont consider the processes in RBT then how we are going to find out the chances for improvement .
We are having the process for calibration and if we dont consider the Risk in calibration then how we are going face the audit i.e 4.1-4.2 to 6.1 for calibration process.
So as per my interpretation , We have to do the SIPOC and then remaining all clauses will be applicable to it by consider PDCA approach.
Pls need your valuable input on this.
Thanks
You are dramatically overthinking this. You prepare for calibration by meeting the requirements of 7.1.5. What is in 7.1.5 are requirements, not suggestions that you apply risk consideration to if you don't meet the requirements.
 

Sidney Vianna

Post Responsibly
Staff member
Admin
#18
Well, Sidney has made quite a few posts in which he for all intents and purposes has said that this version is poorly written (to say the least).
ISO and IEC standards are supposed to follow the ISO/IEC Directives Part 2 Document - Principles and rules for the structure and drafting of ISO and IEC documents. Section 5.5 stipulates:
Requirements shall be objectively verifiable. Only those requirements which can be verified shall be included.
The prolongued and numerous discussions we have on RBT can be attributed, in my estimation, to the failure in creating RBT-related text in 9001:2015 which is easily and readily verifiable.

I have been a member of the Cove for 16 years. For over 12 years, I have been providing pointers to guidance documents, interpretational papers, etc... but I have also pointed out that many of them don't offer pragmatic, actionable, conclusive and authoritative assistance. To pretend otherwise is counterproductive, in my view.
 

Jen Kirley

Quality and Auditing Expert
Staff member
Admin
#19
ISO and IEC standards are supposed to follow the ISO/IEC Directives Part 2 Document - Principles and rules for the structure and drafting of ISO and IEC documents. Section 5.5 stipulates: The prolongued and numerous discussions we have on RBT can be attributed, in my estimation, to the failure in creating RBT-related text in 9001:2015 which is easily and readily verifiable.

I have been a member of the Cove for 16 years. For over 12 years, I have been providing pointers to guidance documents, interpretational papers, etc... but I have also pointed out that many of them don't offer pragmatic, actionable, conclusive and authoritative assistance. To pretend otherwise is counterproductive, in my view.
True, that. I keep sending the links because the documentation, however wonkish, is from the technical committee and not just the opining of a consultant (who might have a questionable agenda). I do also recommend the book ISO 9001:2015 In Plain English, which I think does a very good job of explaining it.
 

Sidney Vianna

Post Responsibly
Staff member
Admin
#20
True, that. I keep sending the links because the documentation, however wonkish, is from the technical committee and not just the opining of a consultant (who might have a questionable agenda).
In my opinion, there are some decent papers offered by the TC 176, but, then, there are some useless material as the paper on ISO 9001:2015 and Risk. To use the example of crossing a road as the scenario to exemplify RBT is a huge mistake. Some of the people developing these papers are so afraid (scared actually) of being called wrong that they never develop authoritative guidance. They are always on the fence. Why not create several scenarios in the business world, scenarios typical users of the standard can relate to? Crossing a road? :mad: Gimme a break. :mad:

Let's also remember that the introduction of RBT came up as a result of the ISO TMB decision to "enforce" a common structure of the ISO Management System Standards via Appendix 2 of the Annex SL of the ISO/IEC Directives Part 1 Document.

That "mandatory template" stipulates the following:

6.1 Actions to address risks and opportunities
When planning for the XXX management system, the organization shall consider the issues referred to in 4.1 and the requirements referred to in 4.2 and determine the risks and opportunities that need to be addressed to:
— give assurance that the XXX management system can achieve its intended outcome(s);
— prevent, or reduce, undesired effects;
— achieve continual improvement.
The organization shall plan:
a) actions to address these risks and opportunities;
b) how to:
— integrate and implement the actions into its XXX management system processes;
— evaluate the effectiveness of these actions.
Nothing there about RBT. RBT was a mental construct, dreamed to replace preventive action, but it just adds to the confusion. There is NO RBT.

Let's correlate this with the ISO 14001:2015 standard that has to follow the same structure. How do organizations comply with 6.1 in ISO 14001:2015? Via assessment of relevance, significance and materiality of impacts and aspects? We should just adapt the same mindset for quality management.

When it comes to producing products that conform to requirements and satisfying customers, there are aspects of the business processes that might impact such objectives more directly than others. Manage your business process appropriately and, by definition, you are assessing and managing your Q risks.
 
Last edited:
Thread starter Similar threads Forum Replies Date
K Identification of hazards and Risk file IEC 62366 - Medical Device Usability Engineering 7
S ISO 14971 Risk Management - Questions for Hazard identification ISO 14971 - Medical Device Risk Management 2
A Is Risk Identification and Treatment a Process? ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 25
R Risk Analysis and Hazard Identification concerning Clinical Decision Support Systems ISO 14971 - Medical Device Risk Management 1
Uriel Alejandro Risk Identification Methods and Risk Management Procedure AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 24
S Hazard Identification and Risk Assessment - Can Risk Assessment be "Grandfathered"? Occupational Health & Safety Management Standards 4
K Do you have to use RPN in Medical Device Risk Analysis? Identification of Hazards ISO 14971 - Medical Device Risk Management 6
K Behaviour Assessment for Hazard Identification & Risk Assessment Occupational Health & Safety Management Standards 25
G Hazard Identification and Risk Assessment 4.3.1 Occupational Health & Safety Management Standards 14
T Biological Evaluation (10993) & Risk Management ISO 14971 - Medical Device Risk Management 7
D Cybersecurity and Risk Management: Loss of confidentiality IEC 62304 - Medical Device Software Life Cycle Processes 4
Q FMEA and Risk assessment in Microsoft Access FMEA and Control Plans 6
I Realization processes input into overall risk ISO 14971 - Medical Device Risk Management 2
M Need Help With Information Security Asset Risk Register IEC 27001 - Information Security Management Systems (ISMS) 2
thisby_ Post Market/Production Risk Assessment ISO 14971 - Medical Device Risk Management 0
S Risk Management Review ISO 14971 - Medical Device Risk Management 4
D Low risk IVD study in the UK, do I need MHRA approval? UK Medical Device Regulations 1
S Risk Management and other Files ISO 14971 - Medical Device Risk Management 8
silentmonkey Overall Benefit/Risk Analysis - Risk Management VS Clinical Evaluation ISO 14971 - Medical Device Risk Management 3
N ISO 27001 for Jumb Burger - Risk Assessment sheet IEC 27001 - Information Security Management Systems (ISMS) 11
C Risk Assessment Tools ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 3
qualprod Examples to mitigate risk from Covid ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 5
G Risk of stopping your customer's line IATF 16949 - Automotive Quality Systems Standard 4
C Risk Matrix vs FMEAs ISO 14971 - Medical Device Risk Management 11
S IVD risk class II devices for Brazil and MDSAP Other Medical Device Regulations World-Wide 0
M ISO 14971:2019: Criteria for overall residual risk ISO 14971 - Medical Device Risk Management 6
M ISO14971:2019 - Verification of implementation and effectiveness of risk control ISO 14971 - Medical Device Risk Management 3
Aymaneh Medical Device Cybersecurity Risk Management IEC 27001 - Information Security Management Systems (ISMS) 2
S Traceability of requirements to design and risk Design and Development of Products and Processes 3
R Risk control measures as per ISO 14971 ISO 14971 - Medical Device Risk Management 6
D Deciding whether or not pre-market clinical investigation is required for low risk device EU Medical Device Regulations 5
R The term "Benefit Risk Ratio" in EU MDR, do I need to present benefit risk analysis as a RATIO Risk Management Principles and Generic Guidelines 4
_robinsingh Security Risk Assessment Tool IEC 27001 - Information Security Management Systems (ISMS) 0
A 21 CFR 820 - Risk Management - Looking for some guidance US Food and Drug Administration (FDA) 3
bryan willemot Contract Review and risk managment AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 2
D Risk Analysis using Monte Carlo Simulation instead of Scoring and Heat Map Risk Management Principles and Generic Guidelines 2
Sravan Manchikanti Software Risk Management & probability of occurrence as per IEC 62304 IEC 62304 - Medical Device Software Life Cycle Processes 8
E Normal Condition Hazards in Risk Analysis ISO 14971 - Medical Device Risk Management 3
silentmonkey Rationalising the level of effort and depth of software validation based on risk ISO 13485:2016 - Medical Device Quality Management Systems 10
R Risk assessment on IT containers and the information they contain IEC 27001 - Information Security Management Systems (ISMS) 4
B Threat/Vulnerability Catalogue for risk assessment IEC 27001 - Information Security Management Systems (ISMS) 4
R Opportunity For Improvement vs Opportunity (Positive Risk) ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 18
R FOD Risk Assessment - What tools would you recommend for assessing FOD risk? AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 1
R Identify Medical Device characterstics as Annex C of ISO 14971 Risk Management ISO 14971 - Medical Device Risk Management 5
A ISO 14971 PFMEA Manufacturing Risk ISO 14971 - Medical Device Risk Management 2
Q Example of the Risk Template Document Control Systems, Procedures, Forms and Templates 1
K Overall residual risk according to ISO 14971:2019 ISO 14971 - Medical Device Risk Management 5
A Risk Number for each software requirement IEC 62304 - Medical Device Software Life Cycle Processes 7
A IEC 60601 11.2.2.1 Risk of Fire in an Oxygen Rich Environment, Source of Ignition IEC 60601 - Medical Electrical Equipment Safety Standards Series 0
D Importing a general wellness low risk product Other US Medical Device Regulations 3

Similar threads

Top Bottom