In short: Risk-based thinking replaced “preventive action” in ISO 9001:2015. Here is how to apply it without creating unnecessary paperwork.
When ISO 9001:2015 was published, the separate requirement for “preventive action” disappeared. In its place came risk-based thinking — the idea that planning for risks and opportunities should be built into the whole quality management system.
What risk-based thinking is — and isn’t
ISO 9001 does not require a formal risk management process or a risk register. It requires organizations to determine the risks and opportunities that need to be addressed to ensure the QMS achieves its intended results, and to plan actions proportionate to their potential impact.
Five practical steps
- Understand your context — internal and external issues and interested-party requirements.
- Identify risks and opportunities for each key process.
- Prioritize using a simple likelihood and consequence scale.
- Plan actions — avoid, reduce, accept or exploit — and integrate them into processes.
- Review effectiveness during internal audits and management review.
Common pitfalls
- Creating a risk register that is never used
- Listing risks without linking them to processes or objectives
- Ignoring opportunities
Risk-based thinking is a core competence in the Certified Quality Manager (CQM) body of knowledge.