Risk-Based Thinking in Quality Management
Risk-Based Thinking in Quality Management
RISK BASED
THINKING
TO QUALITY
PROCESSES
SUMMARY
The new version of the ISO 9001:2015 standard was released on September
23rd, 2015. One of the new requirements is to show evidence of risk-based
thinking (RBT) in the quality management system. How do you do that? How
are auditors likely to respond to the new challenges that ISO 9001:2015
brings? How do you produce documented evidence of risk-based thinking?
Although ISO 9001:2015 does not call for formal methods of risk management, it is
likely that anyone trying to understand RBT may turn to ISO 31000 and the list of risk
assessment techniques in particular. However, this is not as easy as it sounds. There are
many techniques to choose from and many may not be applicable to the sectors that ISO
9001 serves.
This white paper has two major sections. The first part provides a primer on many of
the ISO 31000 risk assessment techniques and considers their applicability to quality
management. The second part provides a six-step methodology that you can follow to
deliver evidence of a risk-based approach to quality. It is a practical methodology that
is specific on inputs / outputs, and what you need to do in-between. Several example
templates are provided that could form the basis for your documented information.
ISO 9001:2015 incorporates what the draft version of the International Standard has
termed “Risk-based Thinking“ in its requirements for the establishment, implementation,
maintenance and continual improvement of the quality management system. If you
are already familiar with the DIS or read the many discussions on the subject that have
appeared on LinkedIn groups and elsewhere, you will already be aware that formal risk
management is not mandated. However, organisations can, in the words of the TC 176
Committee‘s draft standard (May 2014) “...choose to develop a more extensive risk-based
approach than is required by this International Standard, and ISO 31000 provides guidelines
on formal risk management which can be appropriate in certain organisational contexts“.
“Risk-based thinking“ assessment is likely to form a sizeable section of the ISO 9000
Guidance documents when they are published along with the ISO 9001:2015 Standard. The
aim is to produce (a) evidence that you could show to an assessor [HEALTH WARNING:
nobody yet knows exactly what they will be asking for], and (b) a useful way of identifying,
evaluating and treating the kind of risks that apply to the processes used in Quality
Management.
• What is acceptable?
• What is unacceptable?
Then...
However, this list presupposes that you have identified risks and opportunities.
So if you have not done so yet, how do you approach risk identification in your context?
Read on...
Will ISO 31000:2009 help in taking a ‚risk-based approach‘ to the quality management
system, component processes and activities?
The ISO 9001 DIS says that ISO 31000 provides guidelines on formal risk management,
which can be appropriate in certain organisational contexts.
Those working for large, indeed global entities understand this. They have long since
adopted risk management methodologies and have risk managers on their team who are
familiar with ISO 31000.
But what is ISO 31000 attempting to achieve, and is it relevant to the majority of
organisations that are trying to gain or transition to ISO 9001?
1
Project risk management guidelines: managing risk with ISO 31000 and IEC 62198, Dale F Cooper, et al, Wiley, 2014
Great for the Strategic aims of the senior management, but not of any great value to the
“poor bloody infantry“ of quality managers out there.
Perhaps the first (and frustrating) conclusion you will come to, having spent at least £120
($180) on your personal copy is that you also need to buy [Link] 31010:2009 – Risk
management – Risk assessment techniques.
Therefore, your boss says, “OK, buy the one you actually need but don‘t come back to
me asking for more. We‘ve got by without “risk-based thinking“ in the past [insert number
of years or decades]; surely we can do so this time?“ You thank her or him for authorising
the purchase.
The PDF arrives on your computer. You open it. There are 92 pages, 6 of which in Annex
A are a comparison of risk assessment techniques (some useful tables here) before you
arrive at Annex B, consisting of 61 pages describing the 31 risk assessment techniques.
These seem suited for the kind of people who enjoyed Mathematics (and Statistics
especially) at school, but who may not be that interested in helping you to design
effective quality processes.
Yes, there is a worthy (absorbing even?) preamble about risk assessment concepts and
processes. There‘s also a Clause describing how to select techniques for risk assessment,
this starts with the valid advice:
Risk assessment may be undertaken in varying degrees of depth and detail and using one
or many methods ranging from simple to complex. The form of assessment and its output
should be consistent with the risk criteria developed as part of establishing the context.
[Clause 6.2]
There is no point in making life more complicated than it needs to be; thus:
By now, you are probably fired up with the possibility of finding a suitable risk assessment
technique that fits the context of your organisation and its quality management system.
You cannot wait to get started on the job.
Annex A
(informative)
You quickly realize there are more risk assessment techniques than you thought existed,
and even a cursory reading suggests that some are complex. Notably the ones that are
strongly applicable to each step of the full risk assessment process; specifically:
• risk identification;
• risk analysis – consequence analysis;
• risk analysis – qualitative, semi-quantitative or quantitative probability estimation;
• risk analysis – assessing the effectiveness of any existing controls;
• risk analysis – estimation the level of risk;
• risk evaluation.
7. Hazard Analysis & Critical Control Points (HACCP) 23. Sneak circuit analysis
Not everybody will have the resources and capabilities within the organisation to attempt
some of these - e.g., Fault tree analysis, Cause / consequence analysis, Monte-Carlo
analysis, Bayesian analysis.
Quality managers working for smaller enterprises (SMEs) may only dream of conducting
analysis at the level required by some techniques in the list. The sheer complexity of some
types of risk assessment will render the tool useless in most organisations employing
between 1 and 250 people. However, that does not mean to say that ISO 31010 isn’t a
valuable reference should you ever be required to think about risk in these terms.
In our view, this does not have to be an onerous task even at the high-risk end of the
context spectrum. However, to completely ignore the risks and opportunities aspect of
planning your QMS [see 6.1], regardless of the degree of risk involved, would surely be to
risk a major non-conformity?
ISO 9001 Risk-based thinking could (and we are not saying that it should) be demonstrated
by showing the outputs from one or more of the risk assessment tools in ISO 31010 in your
“documented information“.
To give you a flavour of what these tools are intended to achieve and how they work,
we intend to describe a selection of the 31 listed in ISO 31010. At the same time, we will
attempt to link these tools to QMS processes in a meaningful way; however, we do not
anticipate our work in this respect to be in any way definitive as a reliable reference. There
is no common consensus on how best to employ risk assessment techniques in quality
management - at least none that we are aware of yet!
[That said, we are studying with interest the ICH guideline Q9 on quality risk management,
which provides principles and examples of tools for quality risk management applied to
different aspects of pharmaceutical quality. If you have experience of this guideline, I‘d
welcome your input!]
Note: the text is based on the contents of Table A.2 – Attributes of a selection of risk
assessment tools [Source: IEC/FDIS 31010:2009].
This is a simple form of risk identification and a technique that provides a list of
uncertainties that need to be considered. Users can refer to a previously developed
checklist, code or standard.
Checklists and reviews of historical data are, naturally enough, a sensible step if you are
serious about identifying the risks and opportunities in accordance with the requirements
of ISO 9001:2015 Clause 6.1 and intend to plan and implement the appropriate actions
to address them. Although you could enhance the quality of the output by following a
systematic process to identify risks by means of a structured set of prompts or questions
for the experts - see structured interview below.
Personally, we would start by making a checklist of the known issues in the environment
that can (a) affect conformity of products and services [risk] and (b) have the ability to
enhance customer satisfaction [opportunity].
No ISO 9001 assessor is likely to fault you for making this much effort whether or not you
have addressed these risks and opportunities in the design of your quality management
system and its associated processes.
However, it is also worth remembering that checklists are most useful when applied to
check that everything has been covered after a more imaginative technique that identifies
new problems has been applied.
This is a simple inductive method of analysis whose objective is to identify the hazards and
hazardous situations and events that can cause harm for a given activity, facility or system.
Note: the term “hazard“ is always used in the context of physical harm.
At first sight, not a very promising tool but it does have advantages; namely: it is able to be
used when there is limited information; and it also allows risks to be considered very early
in the system lifecycle. In some organisational contexts, preliminary hazard analysis could
be appropriate as a risk assessment tool for quality when its use helps prevent Critical
Non-conformities; which could, for example, result in hazardous or unsafe conditions for
individuals using, maintaining or depending on the product.
This is a means of collecting a broad set of ideas and evaluation, ranking them by a
team. Brainstorming may be stimulated by prompts or by one-on-one and one-on-many
interview techniques.
Let us remind ourselves first of what ISO 9001:2015 says we should do.
When planning for the quality management system, ISO 9001:2015 requires organisations
to consider the issues referred to in 4.1 [Understanding the organisation and its context]
and the requirements referred to in 4.2 [Understanding the needs and expectations of
interested parties] and determine the risks and opportunities that need to be addressed, in
order to:
a) give assurance that the quality management system can achieve its intended result(s)
b) prevent, or reduce, undesired effects
c) achieve continual improvement.
We should integrate and implement the actions into the organisation‘s quality management
system processes (see clause 4.4) and evaluate their effectiveness.
[Note: in the section “Supporting Methods“, Human reliability analysis (HRA), which deals
with the impact of humans on system performance and can be used to evaluate human
error influences on the system, is able to provide quantitative output and is “strongly
applicable“ to risk analysis and “applicable“ to risk evaluation - see Table A.1 in ISO 31010.]
However, before we get bogged down in too much detail with regard to the other
Supporting Methods, Scenario Analysis, Function Analysis, Controls Assessment and
Statistical Methods, we should ask what are we trying to achieve here, and how will any of
these assessment tools help?
If we were considering risks in relation to a quality management system and its associated
processes, we would be asking the following questions:
What are the risks associated with the organisation‘s context and objectives - and why
1.
does each risk occur? [identifying the risk and the reason for its occurrence].
How likely is it that the organisation will deliver nonconforming products and services in
3.
relation to the risks we have identified? [probability of the risk occurring].
There are other possible questions worth considering at this stage - for example,
“How effective are our existing controls?“ - in order to identify factors that reduce the
consequences or probability of the risk; however, in terms of what we actually need to
know, these will make a good start.
ISO 31000 states that risk assessment attempts to answer the following fundamental
questions:
Providing that you adhere to this basic structure, you are following the framework that is set
out in the International Standard ISO 31000:2009.
Rather than spending several days reading the Standard and having long meetings with
colleagues to see how it might be applicable, why not look for methods that would help
you to meet the requirements of ISO 9001?
Even if it is clear from the design of your processes that you have taken account of Clause
6.1 and determined the risks and opportunities that need to be addressed, having a record
of your risk assessment processes might prove useful, if only as a reminder to keep matters
under review!
Then, evaluate the risk assessment tools (numbering 31 in total) in ISO 31010 to see if they
are applicable to your organisational context.
It‘s probably not the time to use them in anger yet (see below), but at least you will know
they exist and that some tools could help to identify risks and opportunities and be useful
in carrying out risk analysis (if you consider consequences, probability and level of risk) and
risk evaluation.
No, absolutely not. Although if you don‘t currently use risk assessment tools to identify
the typical uncertainties that need to be considered, and there is no previously developed
list available of hazards, risks or control failures, either resulting from a previous risk
assessment or past failures - where do you begin? This is likely to be an especially vexing
question for organisations that are new to ISO 9001 quality management and have to
develop appropriate documented information for their quality processes.
Before you despair and start writing out check-lists based on your own observations in an
effort to tick the box, remember that your colleagues in other departments and business
units may already be using some of the formal techniques of risk assessment and risk
management process (in a ‚silo-centric‘ way of course), without you even knowing about
this.
It follows therefore that it is worth interviewing them (in a structured or unstructured way)
or bringing them together for a brainstorming session - if only to find out what qualitative
and quantitative risk assessments have been made that could help you to address the
requirements of ISO 9001!
Whether or not though anyone is carrying out risk assessments, with or without the use
of the tools in ISO 31010, ISO 9001:2015 expects the organisation to understand its context
(see clause 4.1) and determine the risks and opportunities that need to be addressed (see
clause 6.1).
For example:
The ISO assume that one of the key purposes of a quality management system is to act as
a preventive tool, taking account of identified risks. Consequently, ISO 9001:2015 does not
have a separate clause or sub-clause titled ‚Preventive action’. Rather, the wording states
unequivocally:
2
ISO 31000:2009 - Principles and Guidelines on Implementation
Although there are undoubtedly a number of quality professionals who feel uncomfortable
talking about risk in relation to preventive actions, assessing risk is something that
managers in most (all?) organisations do already in one form or another. They may not
always use the term risk to describe their activities, - which could include for example
conducting a sensitivity analysis of a financial projection, or scenario planning for a project
appraisal, assessing the contingency allowance in a cost estimate, negotiating contract
conditions, or developing contingency plans - ; but even so, thinking about risks and
opportunities is central to their work. 4
IF it can reasonably be argued that managing risk is an integral part of good management
(and we think that it can) and that risk-based thinking is fundamental to achieving good
business and project outcomes and the effective procurement of goods and services,
THEN identifying, analysing and evaluating risk should be processes familiar to all quality
managers.
Not everyone agrees with this statement, of course, but understanding the context (see
clause 4.1) and determining the risks and opportunities that need to be addressed (clause
6.1) are requirements of ISO 9001:2015. Therefore, before you reject the idea of using risk
assessment tools because they are too complicated and “not part of your job“, it is worth
pondering this quote from the Introduction to the ISO 31000:2009:
“The generic approach described in this International Standard provides the principles and
guidelines for managing any form of risk in a systematic, transparent and credible manner
and within any scope and context“. 5
3
Draft BS EN ISO 9001 Quality Management Systems - Requirements, Date: 14 May 2014, A.4 Risk-based approach
4
Project risk management guidelines: managing risk with ISO 31000 and IEC 62198, Dale F Cooper, et al, Wiley, 2014.
5
ISO 31000:2009 - Principles and Guidelines on Implementation, Introduction, p.V
• Check-lists
• Brainstorming
• Structured or semi-structured interviews
Delphi can be used to estimate probability of adverse and positive outcomes: In the words
of ISO 31010:
“Expert opinion can be used in a systematic and structured process to estimate probability.
Expert judgements should draw upon all relevant available information including historical,
system-specific, organisational-specific, experimental, design, etc. There are a number
of formal methods for eliciting expert judgement which provide an aid to the formulation
of appropriate questions. The methods available include the Delphi approach, paired
comparisons, category rating and absolute probability judgements.“ 6
Despite the mention of probability above, Table A.1 – Applicability of tools used for risk
assessment, the Delphi method is marked ‚NA‘ [NA = Not Applicable] for Risk Analysis to
assess Consequence, Probability and Level of risk - although personally we would agree
with the commentary on page 29 [Clause B.3.2 Use] which states:
“The Delphi technique can be applied at any stage of the risk management process or at
any phase of a system life cycle, wherever a consensus of views of experts is needed.“ 7
A true consensus approach that avoids the bias of dominant members of the team can be
the wake-up call that management needs to assess risk.
6
ISO/IEC 31010:2009 – Risk management –
Risk assessment techniques, p.15.
7
Ibid., page 29.
SWIFT is a system for prompting a team to identify risks, normally used within a facilitated
workshop and linked to a risk analysis and evaluation technique.
The first thing to understand about SWIFT is that it was originally developed as a simpler
alternative to HAZOP (Hazard and Operability Studies), a qualitative risk identification
technique. HAZOP aims to stimulate the imagination of participants to identify potential
hazards and operability problems; structure and completeness are given by using
guideword prompts. The HAZOP technique was developed to analyse chemical process
systems and mining operation process but has later been extended to other types of
systems and also to complex operations such as nuclear power plant operation and to
use software to record the deviation and consequence. 8 HAZOP is intended for high-risk
organisational contexts where appropriate levels of resourcing are available to support
its use. SWIFT, on the other hand, has been purposely-design as a sort of ‚HAZOP-Lite‘
needing fewer resources. ISO 31010 regards the ‚Resources and capability‘ requirement
as “Medium“, so this may be a viable risk identification technique for use by most small to
medium as well as larger quality conscious organisations.
The system, procedure, plant item and/or change has to be carefully defined before the
study can commence. Both the external and internal contexts are established through
interviews and through the study of documents, plans and drawings by the facilitator.
Discussion is facilitated by creating a question using a “what-if” phrase and a prompt word
or subject. The “what-if” phrases to be used are “what if…”, “what would happen if…”, “could
someone or something…”, “has anyone or anything ever….” The intent is to stimulate the study
team into exploring potential scenarios, their causes and consequences and impacts. 10
8
ritish Standard BS: IEC61882:2002 Hazard and operability studies (HAZOP studies)- Application Guide,
B
published by BSI Group.
9
ISO/IEC 31010:2009, B.9.3 Inputs, p.39.
10
Ibid.
What we particularly like about the SWIFT concept approach is the inherent discipline
which forces the team members to consider the effectiveness of the controls. Assessing
risk is one thing, but treating it is another entirely. They have to agree a statement of risk
control effectiveness, which, if it proves to be less than satisfactory, triggers the task of
further considering risk treatment tasks and potential controls.
The application of this team-based model does not have to be complex. ISO 31010 simply
rates the Complexity of the technique as “Any“. 11
11
Ibid., Table A.2 - Attributes of a selection of risk assessment tools.
Human reliability assessment (HRA) deals with the impact of humans on system
performance and can be used to evaluate human error influences on the system.
At the risk of stating the obvious, human reliability is very important due to the contributions
of humans to the resilience of systems and to possible adverse consequences of human
errors or oversights, especially when the human is a crucial part of today‘s large socio-
technical systems.
Contrary to the impression that you might receive by reading the relevant section in ISO
31010 - specifically B.20 Human reliability assessment (HRA) - a variety of methods exist for
human reliability analysis. These break down into two basic classes of assessment method:
In 2009, the Health and Safety Laboratory compiled a report 12 for the Health and Safety
Executive (HSE) outlining HRA methods for review.
They identified 35 tools that constituted true HRA techniques and that could be used
effectively in the context of health and safety management.
Obviously, it is well beyond the scope of this article to define the merits and demits of all
these methods. However, the HRA tools in the table below illustrates that there are a large
number of risk assessment techniques in the Health & Safety arena that could be applied
elsewhere. It is also worth reflecting that Risk Management is usually associated with
the financial risk; however, risk assessment techniques have other well-established uses
including helping to maintain safe working environments.
Without being specific at this time, we think that it is possible that some of these tools
could be adapted (if they haven‘t been?) to identify, analyse and evaluate risks and
opportunities in the design of quality processes. After all, corrective and preventive actions
usually involve human beings!
12
eview of human reliability assessment methods, Prepared by the Health and Safety Laboratory for the Health
R
and Safety Executive 2009, PR679 Research Report, Julie Bell & Justin Holroyd, Health and Safety Laboratory;
First published 2009.
CM Confusion Matrix
As ISO 31010 points out in the section on the “Limitations” of HRA, many activities of
humans do not have a simple pass/fail mode. HRA has difficulty dealing with partial
failures or failure in quality or poor decision-making. 13
13
ISO/IEC 31010:2009, B.20.6 Strengths and limitations, p.63.
Root Cause Analysis (RCA) uses a specific set of steps, with associated tools, to help find
the primary cause of the problem; so that you can:
Figure out what to do to reduce the likelihood that it will happen again. RCA assumes that
systems and events are interrelated. An action in one area triggers an action in another, and
another, and so on. By tracing back these actions, you can discover where the problem
started and how it grew into the symptom you are now facing. 14
The technique can be used to identify risks by considering sets of scenarios that reflect
(for example) ‘best case’, ‘worst case’ and ‘expected case’, in order to analyse potential
consequences and their probabilities for each scenario as a form of sensitivity analysis
when analysing risk.
“...through imagination or extrapolation from the present and different risks considered
assuming [that] each of these scenarios might occur. This can be done formally or
informally, qualitatively or quantitatively.“ 16
14
Root Cause Analysis, Tracing a Problem to its Root Origins, Mind Tools website:
[Link]
15
Scenario Analysis, Wikipedia: [Link]
16
ISO/IEC 31010:2009, Table A.2 - Attributes of a selection of risk assessment tools.
An ecological risk assessment tells what happens to a bird, fish, plant or other non-human
organism when it is exposed to a stressor, such as a pesticide. 17
Aspects of the methodology, such as pathway analysis which explore different routes by
which a target might be exposed to a source of risk, can be adapted and used across a
very wide range of different risk areas, outside human health and the environment, and is
useful in identifying treatments to reduce risk. 18
The strength of this analysis is that it provides a very detailed understanding of the nature
of the problem and the factors that increase risk. However, it needs good data that is
often not available or has a high level of uncertainty associated with it. Likewise, it is also
resource intensive as is unlikely to find many uses in quality management systems.
Pathway analysis, though, is a useful tool, generally, for all areas of risk and permits the
identification of how and where it may be possible to improve controls or introduce new ones.
If you are interested in following the steps of this type of environmental risk assessment
process, we recommend that you read “Basic Information about Risk Assessment
Guidelines Development”, published by the United States Environmental Protection
Agency. See the web page link below:
[Link]
development
17
cological Risk Assessment: Technical Overview, Ecological Risk Assessment Process, U.S. Environmental
E
Protection Agency website: [Link]
18
ISO/IEC 31010:2009, B.8.2 Use, p.37.
If your organisation already has a business continuity management (BCM) system based
on the ISO 22301 Standard and since a BIA is a mandatory document, seeking out your
Business Continuity Manager to obtain the BIA report could be a sound move at this point.
You will then have a valuable item of documented information to show risk-based thinking
because you will have assessed (by means of the BIA) how key disruption risks could
affect an organisation’s operations and identified/quantified the capabilities that would be
required to manage it.
If not, well ... you could consider conducting a BIA; although we would strongly recommend
calling in a qualified business continuity consultant.
19
Elliot, D.; Swartz, E.; Herbane, B. (1999) Just waiting for the next big bang: business continuity planning in
the UK finance sector. Journal of Applied Management Studies, Vol. 8, No, pp. 43–60. Here: p. 48
A technique used in safety engineering and reliability engineering, mostly in the aerospace,
nuclear power, chemical and process, pharmaceutical, petrochemical and other high-
hazard industries. Fault tree analysis (FTA) can be used to understand how systems can fail,
to identify the best ways to reduce risk or to determine or “get a feel for” event rates of a
safety accident or a particular system level (functional) failure. It sounds more complicated
than it actually is; however, it is a resource hungry method.
If you are a Quality Manager in one of the above industries, you will probably already be
familiar with fault tree diagrams produced from this type of analysis and you may well use
the fault trees developed by the organisation to reduce or eliminate potential causes of
non-conformities. They start with the undesired event (top event) and determine all the
ways in which it could occur, shown graphically in a logical tree diagram.
Fault tree analysis is a time-consuming and costly exercise although it can be invaluable in
determining the probability of (undesirable) outcomes.
20
Fault tree analysis, Wikipedia: [Link]
A forward, bottom up, logical modelling technique for both success and failure that
explores responses through a single initiating event and lays a path for assessing
probabilities of the outcomes and overall system analysis. Using inductive reasoning, ETA
translates probabilities of different initiating events into possible outcomes. It is arguably
less resource intensive than fault tree analysis (see Table A.2 in ISO 31010).
ETA can be applied to a wide range of systems including: nuclear power plants, spacecraft,
and chemical plants. 21
Once again, if you are managing the quality system of a small enterprise in a relatively “low
risk” context, this technique is unlikely to be for you.
ISO 31010 describes the Cause and consequence analysis method as:
“A combination of fault and event tree analysis that allows inclusion of time delays. Both
causes and consequences of an initiating event are considered.“
21
Event Tree Analysis, Wikipedia: [Link]
An effect can have a number of contributory factors that can be grouped in Ishikawa
diagrams. Contributory factors are identified often through a brainstorming process (see
Part II of this article for more information).
Kaoru Ishikawa popularized these diagrams in the 1960s, when he pioneered quality
management processes in the Kawasaki shipyards. The basic concept was first used in the
1920s and is considered one of the seven basic tools of quality control. Ishikawa diagrams
are known as fishbone diagrams because their shape is like the side view of a fish skeleton.
establish the effect to be analysed and place it in a box. The effect may be positive (an
1.
objective) or negative (a problem) depending on the circumstances;
fill in the possible causes for each major category with branches and sub-branches to
3.
describe the relationship between them;
review all branches to verify consistency and completeness and ensure that the causes
5.
apply to the main effect;
identify the most likely causes based on the opinion of the team and available evidence.
6.
22
ISO/IEC 31010:2009, B.17.4 Process, p.57.
This section covers FMEA (Failure modes and effects analysis) and FMECA (Failure modes
and effects and criticality analysis).
FMEA/FMECA identifies:
•
all potential failure modes of the various parts of a system (a failure mode is what is
observed to fail or to perform incorrectly);
• the effects these failures may have on the system;
• the mechanisms of failure;
• how to avoid the failures, and/or mitigate the effects of the failures on the system.
FMEA/FMECA is a systematic analysis technique that can be used to identify the ways in
which components, systems or processes can fail to fulfil their design intent, highlighting:
•
design alternatives with high dependability;
•
failure modes of systems and processes, and their effects on operational success have
been considered;
• human error modes and effects;
• a basis for planning testing and maintenance of physical systems;
• improvements in the design of procedures and processes.
23
Failure mode and effects analysis, Wikipedia: [Link]
A technique that is used to achieve the required safety, availability and economy of
operation (safe minimum levels of maintenance), so that assets continue to do what their
users require in their operating context.
RCM allows you to identify applicable and effective preventive maintenance requirements
for equipment “...in accordance with the safety, operational and economic consequences of
identifiable failures, and the degradation mechanism responsible for those failures“. 24
RCM uses a failure mode, effect and criticality analysis (FMECA) type of risk assessment
that requires a specific approach to analysis in this context. From a quality management
standpoint, it‘s worth being aware that RCM identifies required functions and performance
standards and failures of equipment and components that can interrupt those functions.
For more information, see IEC 60300-3-11, Dependability management – Part 3-11:
Application guide – Reliability
Sneak analysis is aimed at uncovering design flaws that allow for “sneak conditions”, i.e.
those that may cause unwanted actions or may inhibit a desired function and are not
caused by component failure to develop.
Sneak analysis can locate problems in both hardware and software using any technology.
The sneak analysis tools can integrate several analyses such as fault trees, failure mode
and effects analysis (FMEA), reliability estimates, etc. into a single analysis saving time and
project expenses. 25 The technique helps in identifying design errors and works best when
applied in conjunction with HAZOP. It is very good for dealing with systems which have
multiple states such as batch and semi-batch plant.
Sneak Circuit Analysis (SCA) is used in safety-critical systems to identify sneak (or hidden)
paths in electronic and electro-mechanical systems that may cause unwanted action or
inhibit desired functions. The analysis is based on identification of designed-in inadvertent
modes of operation and is not based on failed equipment or software. SCA is most
applicable to circuits that can cause irreversible events. These include:
24
ISO/IEC 31010:2009, B.22.1 Overview, p.66
25
Ibid., B.23.2 Use, p.68.
26
Sneak circuit analysis, Wikipedia: [Link]
wiki/Sneak_circuit_analysis
HACCP is focused only on the health safety issues of a product ensuring that risks are
minimized by controls throughout the process rather than through inspection of the
end product. The seven HACCP principles are the basis of most food quality and safety
assurance systems, and the United States, HACCP compliance is regulated by 21 CFR
part 120 and 123. The HACCP principles are also included in the international standard
ISO 22000 FSMS 2005. This standard is a complete food safety and quality management
system incorporating the elements of prerequisite programmes (GMP & SSOP), HACCP
and the quality management system, which together form an organisation‘s Total Quality
Management system.
Table A.1 – Applicability of tools used for risk assessment [see page 22 of ISO 31010], lists
the HACCP technique as “Not Applicable“ for analysis of probability or levels of risk. 29
However, the principle of identifying the factors [risks] that can influence product quality,
and defining process points where critical parameters can be monitored and hazards
controlled, can be generalized for use other technical systems. 30
27
Hazard analysis and critical control points, Wikipedia:
[Link]
28
Ibid.
29
ISO/IEC 31010:2009, Table A.1 – Applicability of tools used for risk assessment, p.22
30
Ibid., B.7.2 Use, p.35.
A technique for analysing whether there are sufficient measures to control or mitigate the
risk of an undesired outcome.
•
A cause-consequence pair is selected, and the layers of protection that prevent the
cause leading to the undesired consequence are identified.
• An order of magnitude calculation is then carried out to determine whether the
protection is adequate to reduce risk to a tolerable level. 31
LOPA is a less resource-intensive process than a fault tree analysis or a quantitative form
of risk assessment but is more rigorous than qualitative subjective judgements alone. It
focuses efforts on the most critical layers of protection, identifying operations, systems
and processes for which there are insufficient safeguards and where failure will have
serious consequences. However, this technique looks at one cause-consequence pair and
one scenario at a time and, therefore, does not apply to complex scenarios where there
are many cause consequence pairs or where a variety of consequences affects different
stakeholders.
IEC 61511, Functional safety – Safety instrumented systems for the process
industry sector.
Bow-tie analysis is a simple diagrammatic way to display the pathways of a risk showing a
range of possible causes and consequences. It is used in situations when a complex fault
tree analysis is not justified or to ensure that there is a barrier or control for each of the
possible failure pathways.
To understand how this works we recommend viewing a short video entitled “The Bow Tie
Method in 5 Minutes“ by CGE Risk Management Solutions, 32 which explains the basics of
the method for risk assessment of hazards.
YouTube: [Link]
•
Markov analysis
•
Monte-Carlo analysis
•
Bayesian analysis
A method named after a Russian mathematician, best known for his work on stochastic
processes, where a collection of random variables represents the evolution of some
system of random values over time.
The nature of the Markov analysis techniques lends itself to the use of software. There are
several to choose from on the market.
The Markov analysis process is a quantitative technique and can be discrete (using
probabilities of change between the states) or continuous (using rates of change across
the states).
“The Markov analysis technique is centred around the concept of “states”, e.g. “available”
and “failed”, and the transition between these two states over time based on a constant
probability of change. A stochastic transitional probability matrix is used to describe the
transition between each of the states to allow the calculation of the various outputs.“ 34
33
ISO/IEC 31010:2009, Table A.2 - Attributes of a selection of risk assessment tools.
34
Ibid. B.24.4 Process, p.70.
•
list of various states that the system, sub-system or component can be in (e.g. fully
operational, partially operation (i.e. a degraded state), failed state, etc);
• a clear understanding of the possible transitions that are necessary to be modelled. For
example, failure of a car tyre needs to consider the state of the spare wheel and hence
the frequency of inspection;
• rate of change from one state to another, typically represented by either a probability
of change between states for discrete events, or failure rate (λ) and/or repair rate (ì) for
continuous events. 35
The output from a Markov analysis is the various probabilities of being in the various states,
and therefore an estimate of the failure probabilities and/or availability, one of the essential
components of a system.
35
Ibid. B.24.3 Input, p.70.
Markov diagrams for large systems are often too large and complicated to be of value in
most business contexts and inherently difficult to construct. Markov models are more suited
to analysing smaller systems with strong dependencies requiring accurate evaluation. Other
techniques, such as Fault Tree analysis (see Part IV of this blog post series), may be used to
evaluate large systems using simpler probabilistic calculation techniques.
States depend on current state probabilities and the constant transition rates between
states - see the state transition diagram in Figure 1 below:
2λ λ
-(2λ) S1 S2 S3 -(µ)
µ µ
-(2+µ)
Apart from this obvious drawback (complexity), a true Markovian process would only consider
constant transition rates, which may not be the case in real-world systems. Events are
statistically independent since future states are treated as independent of all past states,
except for the state immediately prior. In this way the Markov model does not need to know
about the history of how the state probabilities have evolved in time in order to calculate
future state probabilities. However, computer programs are being marketed that allow time-
varying transition rates to be defined.
Markov analysis requires knowledge of matrix operations and the results are - unsurprisingly!
- hard to communicate with non-technical personnel.
If you would like to perform Markov analysis, you are advised to consult IEC 61165,
Application of Markov techniques.
Monte Carlo analysis consists of a broad class of computational algorithms that rely on
repeated random sampling to obtain numerical results. This method can address complex
situations that would be very difficult to understand and solve by an analytical method.
Whenever there is significant uncertainty in a system and you need to make an estimate,
forecast or decision, a Monte Carlo simulation could be the answer.
[Link] How does Monte Carlo analysis model the effects of uncertainty?
Systems are sometimes too complex for the effects of uncertainty on them to be modelled
using analytical techniques. However, they can be evaluated by considering the inputs
as random variables and running a number N of calculations (so-called simulations) by
sampling the input in order to obtain N possible outcomes of the wanted result.
Monte-Carlo analysis can be developed using spreadsheets, but software tools are readily
available to assist with more complex requirements, many of which are now relatively
inexpensive.
Monte-Carlo analysis can be developed using spreadsheets, but software tools are readily
available to assist with more complex requirements, many of which are now relatively
inexpensive.
Monte Carlo simulations require you to build a quantitative model of your business activity,
plan or process. This is often done by using Microsoft Excel with a simulation tool plug-in -
a relatively inexpensive set of tools.
To deal with uncertainties using Monte Carlo analysis in your model, you‘ll replace certain
fixed numbers - for example in spreadsheet cells - with functions that draw random
samples from probability distributions. And to analyze the results of a simulation run, you‘ll
use statistics such as the mean, standard deviation, and percentiles, as well as charts and
graphs.
For risk assessment using the Monte Carlo simulation, triangular distributions or beta
distributions are commonly used.
Note that ISO 31010 Table A.1 – Applicability of tools used for risk assessment states this
is tool is strongly applicable for the Evaluation stage of risk assessment but not applicable
(NA) for risk identification or risk analysis.
Referring again to Table A.1 from ISO 31010, Bayesian analysis is used in the risk analysis
and risk evaluation stages in risk assessment. 37
In a nutshell, it is a statistical procedure which utilizes prior distribution data to assess the
probability of the result. These are often called conditional probabilities. 38
There are many places that explain the mathematics behind Bayes‘ theorem, including
Wikipedia, the Stanford Encyclopedia of Philosophy, and the wonderful blog LessWrong.
The definition that explains it best for me comes from the last of these - it is:
“The probability of a hypothesis C given some evidence E equals our initial estimate of the
probability times the probability of the evidence given the hypothesis C divided by the sum
of the probabilities of the data in all possible hypotheses.“
Bayesian inference is used in a wide range of fields from medical diagnosis to checking
your inbox for likely spam emails. However, is it any good for risk assessment?
Although it can appear to be objective, this is typically not the case. A Bayesian probability
is really a person’s degree of belief in a certain event rather than one based upon physical
evidence.
Because the Bayesian analysis approach is based upon the subjective interpretation
of probability, it provides a ready basis for decision thinking and the development of
Bayesian nets (or Belief Nets, belief networks or Bayesian networks).39 The availability
of software computing tools and what ISO 31010 terms “intuitive appeal“ has led to the
widespread adoption of Bayesian nets. However, they can be valuable wherever there is
the requirement for finding out about unknown variables by using structural relationships
and data.
37
ISO/IEC 31010:2009, Table A.1 – Applicability of tools used for risk assessment, p.22.
38
ISO/IEC 31010:2009, p.26
39
ISO/IEC 31010:2009, B.26.1 Overview, p.26.
•
define system variables;
•
define causal links between variables;
•
specify conditional and prior probabilities;
•
add evidence to net;
•
perform belief updating;
•
extract posterior beliefs. 40
Bayesian analysis can provide an easily understood model and the data readily modified to
consider correlations and sensitivity of parameters.
Lower error rates would therefore require larger sample sizes to make valid inferences
because of the properties of the binomial distribution.
Even so, we would be very interested to hear from Quality Managers who have applied
Bayesian analysis in this way to predict likely error rates in processes!
40
Ibid. B.26.3 Input, p.77.
ISO 9001 Risk-based thinking could (and we are not saying that it should) be demonstrated
by one or more of the risk assessment tools in ISO 31010:2010. However, that still leaves you
with the dilemma of selecting the most appropriate tools to help you to identify, analyse
and evaluate risk in your organisational context and with the resources at your disposal.
In ISO 9001:2015 there is no requirement for risk management. However, organisations can
choose to develop a more extensive risk-based approach, and the Standard refers to ISO
31000, which provides guidelines that can be appropriate in “certain organisational contexts“.
It remains to seen whether assessors for the various Certification Bodies will expect you to
produce documented evidence of risk-based thinking.
The short answer is we do not know at present. However, as we have postulated, there are
three possibilities:
Option 1: They will ignore the risk-based thinking requirements of Clause 6 in the same
way that some claim preventive actions were ignored in the past. The counter to this is
that Clause 6 in the DIS requires “Processes for planning and consideration of risks and
opportunities“.
Option 2: They will regard the failure to show evidence of risk-based thinking in an
organisation’s quality processes as a non-conformity (perhaps even a major non-
conformity) and will judge the quality system to be ineffective because it has failed to
reduce or eliminate the risks to process outputs.
You may decide differently, but in our view, Option 3 is more likely in the majority of cases.
Ergo, it cannot hurt your case to show documented evidence of RBT, regardless of whether
documented information is a requirement or not.
Regarding Option 3 above, it is also worth reflecting upon the number uses of the words
“continual improvement“ in the clauses of the new Standard.
Aside from the definition that appears in Normative References, the term “continual
improvement“ is used in Clause 5: Leadership, Clause 6: Planning, Clause 7: Support, Clause
9: Performance Evaluation, and - unsurprisingly - in Clause 10: Continual Improvement;
which states that:
“...the organisation shall consider the outputs of analysis and evaluation, and the
outputs from management review, to confirm if there are areas of underperformance or
opportunities that shall be addressed as part of continual improvement.“ 41
There is doubt about which of the three options above best describes the likely future
response of external auditors/assessors, but you can help put your organisation in a
position where Option 3 is the more likely outcome, because your quality processes reflect
the fact that you have taken account of the risk and opportunities in your context.
Notwithstanding the concerns about what ISO 9001 assessors may or may not be looking for
with regard to applying risk-based thinking (RBT), there are good reasons to put in place...
There is already a significant precedent in the ISO family of management system standards
that explains the need for the risk-based approach.
41
ISO/DIS 9001:2014, 10.3 Continual improvement, p.63.
“ISO/IEC 27001 takes a risk-based approach to the planning and implementation of your
ISMS, resulting in an appropriate and affordable level of organisational security. In this way,
it ensures that the right people, processes, procedures and technologies are in place to
secure your organisation’s information assets.“ 42
We suggest that we could readily substitute “ISO 9001:2015“ for “ISO/IEC 27001“; “ISMS“ for
“QMS“; “quality“ for “organisational security“; and “achieve the intended results of the quality
management system“ for “secure your organisation‘s information assets“ to arrive at the
following:
“ISO 9001:2015 takes a risk-based approach to the planning and implementation of your
QMS, resulting in an appropriate and affordable level of quality. In this way, it ensures that
the right people, processes, procedures and technologies are in place to achieve the
intended results of the quality management system.“
It is also worth bearing in mind that one of the key influences on the development of ISO
27001:2013 was the decision by the ISO to align ISO/IEC 27001 with the principles and
guidance given in ISO 31000 (risk management). This was deemed to be, in the words of
BSI, “good news for integrated management systems as now an organisation may apply
the same risk assessment methodology across several disciplines“. 43
Earlier posts in this series have examined the different risk assessment techniques aligned
to ISO 31000 and described fully in ISO 31010:2009.
3.1.2 What actions are required to plan for risks and opportunities?
Clause 6 of ISO 9001:2015 is likely to be explicit about the need for planned actions to
address risks and opportunities in quality systems:
Actions taken to address risks and opportunities shall be proportionate to the potential
impact on the conformity of products and services. 44
43
Moving from ISO/IEC 27001:2005 to ISO/IEC 27001:2013: The new international standard for information security
management systems, Transition Guide, BSI Group.
44
Ibid., p.28, lines 1054 to 1060.
So how do you go about identifying, considering and planning for risks to quality - and
how could risk analysis help you to achieve your objectives?
The simple answer is that before you can plan processes that address risk, you need
to analyze the relative importance of risks in your system. In a world where risk factors
determine the organisation‘s success or failure, we need a detailed understanding of
each of the specific risks posed to successful outcomes at the various stages of quality
processes. With this knowledge, we can determine appropriate priorities for actions.
This full understanding should result in fewer unpleasant surprises arising and will enable
managers to determine where the greatest effort should be focused in treating identified
risks and for quality assurance purposes.
The following section of this blog post contains the first part of a Proposal for a formal
methodology for making risk-based decisions when planning and considering quality
processes. we have based some of the ideas on work by Dale F. Cooper et al in the
book ‚Project management guidelines: managing risk with ISO 31000 and IEC 62198‘
(John Wiley and Sons); however, we have simplified the approach therein as applied to
international, large-scale project management. Furthermore, we have re-engineered
these ideas into a method of risk assessment and continual process improvement for ISO
9001 quality management systems, based on the process improvement model from ITIL,
which itself uses methods from quality management.
A key feature of our design for the R&O Register would be outputs from a simple
risk assessment process, following a six-step risk assessment and continual process
improvement model, which are:
These ideas are for DISCUSSION ONLY and are not recommendations for actions needed to
comply with the wording of ISO 9001:2015 in its published form (September 2015). However,
we offer them as a way to combine quality management systems and risk management
processes in order to achieve continual process improvement in a way that takes full account
of the risks and opportunities in any given context.
2. Risk identification
This step involves selecting a suitable process for risk identification (see below) and for
each quality process, identifying and numbering the risks. The activity is designed to be
carried out in a group situation where each risk is described in terms of what could happen
and what that could lead to, the causes of the risk - both external and internal to the
organisation - and the existing controls that could prevent, transfer or mitigate risks. This
process records the risks in a Risk and Opportunities Register (R&O Register) that would
form an integral part of the Quality Management System.
1.
Establish A six step Risk Assessment Methodology
the context
2.
Identify
the risks
3.
Qualitative
assessment 4.
Semi-
Qualitative
assessment 5.
Risk
treatment
plan 6.
Monitor
& review
That is to say, context is a term that is used to describe a combination of internal and
external factors and conditions that can have an effect on an organisation‘s (3.01) approach
to its products (3.47), services (3.48), investments, and interested parties (3.02). 45
An organisation needs to demonstrate its ability to provide products and services that
consistently meet customer and applicable statutory and regulatory requirements and
aims to enhance customer satisfaction. 46 Therefore, it is necessary to determine both the
external and internal context before designing and implementing quality processes that
take account of the risks and opportunities that apply in a particular context.
The risk-based approach of ISO 9000:2015 requires the organisation to understand its context
(see clause 4.1) and determine the risks and opportunities that need to be addressed (see
clause 6.1). When applying risk-based thinking to the planning and consideration of quality
processes, we should take into account the organisation‘s understanding of the...
•
external context; which can be facilitated by considering issues arising from legal,
technological, competitive, market, cultural, social, and economic environments,
whether international, national, regional or local.
• internal context; which can be facilitated by considering issues related to values, culture
knowledge and performance of the organisation. 47
The Standard also requires that “...the organisation shall maintain documented information
to the extent necessary to support the operation of processes and retain documented
information to the extent necessary to have confidence that the processes are being
carried out as planned“. 48
45
Moving from ISO/IEC 27001:2005 to ISO/IEC 27001:2013: The new international standard for
information security management systems, Transition Guide, BSI Group. 3.24, p.17.
46
Ibid. A.3, p.45.
47
Ibid. 4.1. p.25.
48
Ibid. 4.4 Quality management system and its processes, p.26
The scope and responsibilities of persons responsible for risk management and the risk
assessment methods employed will need to be documented.
49
ISO 31000, 2 Terms and definitions, 2.1 risk, p.1
50
Project management guidelines: managing risk with ISO 31000 and IEC 62198, Dale F Cooper, et al,
John Wiley & Sons Inc, March 2014.
The context of an organisation can include internal factors such as organisational culture,
and external factors such as the socio-economic conditions under which it operates;
consequently, all the requirements of ISO 9001:2015 are generic but the ways in which they
are applied can differ from one organisation to another. 51
Taking the above definitions into account, we would suggest that it would be appropriate
for a ISO 9001-compliant organisation - and especially one adopting a more formal risk
management approach based on ISO 31000 - to document the context in what we am
terming a Statement of Context.
•
Establish the external and internal organisational context in which the risk assessment
is taking place (see ISO 9001:2015 Clause 4.1);
• Specify the main objectives and outcomes that are uncertain and, therefore,
represent a risk;
• Develop criteria against which the consequences and likelihoods of identified risks can
be measured; and
• Define the key elements for structuring the risk assessment process.
Process inputs
Key process documents, scope definitions, pre-existing analyses and other relevant
documented information such as organisational policies, processes and structures.
Method
51
ISO/DIS 9001:2004, Clause 0.1 Introduction, p.6.
52
Ibid. Clause 0.5, p.9.
Establishing the context will provide information that is essential to risk identification,
analysis, and evaluation activities if they are to efficient and effective. Components of the
context could be summarised as follows:
1. organisational objectives;
2. process objectives;
3. the internal environment;
4. the external environment;
5. the context of the risk management process;
6. risk criteria.53
The risk criteria should reflect the objectives and context for the risk assessment.
Consideration should be given to stakeholder views and risk perceptions, the legal and
regulatory framework that applies in the organisation‘s context, and the time and resources
that are available.
Categories for which risks in a quality management system and associated processes
will be evaluated need to be defined and documented, taking account of all associated
activities from which risks could arise that would adversely affect the organisation or any of
its stakeholders. These could include:
•
human health and safety;
•
environmental protection;
•
legal and regulatory compliance;
•
cost;
•
production schedule / deadlines;
•
reputation;
•
performance.
However, this list will depend on context and the risks being evaluated.
53
Ibid. Clause 0.1 Introduction, p.6.
•
the nature and type of causes;
•
the consequences that can occur;
•
how consequences will be measured;
•
how likelihood will be defined (for example qualitatively or as a quantitative probability);
•
the timeframe;
•
how the level of risk is to be determined;
•
what is an acceptable (or tolerable) level of risk.
For the risk criteria to be adequate to support the decisions made at the risk treatment
stage, they should:
•
assist in decision-making leading to actions that reduce risk to levels that are as low as
reasonably practicable;
• be capable of being communicated, understood and applied within the organisation
and to an external organisation (ISO 9001:2013, 3.01) where it performs part of an
organisation‘s function (Ibid. 3.25) or process (Ibid. 3.12);
• be unambiguous in their formulation;
• not evidence any bias towards particular risk treatment options in the way in which risk
is expressed.
Documented information
Statement of organisation context - including its size and complexity, a general outline
of the external and internal risks and opportunities that it needs to address, and how that
knowledge is to be made accessible.
Process inputs
•
historical data;
•
theoretical analysis;
•
empirical data and analysis;
•
informed opinion of the project team and other experts;
•
the concerns of stakeholders. 55
Method
Use one or more of the Look-up and/or Supporting Methods described in ISO/IEC
1.
31010 designed for Risk identification.
•
Structured interviews
•
Brainstorming
•
Examination of similar quality processes
•
Delphi technique
•
SWIFT technique
[See our previous blog post about ISO/IEC 31010 for more information: ISO 31000 Risk
management techniques Attributes of a selection of risk assessment tools.
55
Adapted from assessing risks to quality from Project management guidelines: managing risk with
ISO 31000 and IEC 62198, Dale F Cooper, et al, John Wiley & Sons Inc, March 2014
Steps 3 - 5 will analyse and evaluate these risks and prioritise treatment.
Documented information
Risks and opportunities register (R&O register) - recording identified risks, controls, and
1.
ratings.
Risk description worksheet - (for recording risk at process level) listing risk description
2.
process, existing controls, key assumptions, sources of information, document
attachments.
The International Standard, ISO/IEC 31010 describes the techniques for risk identification
that could be used in Quality Management Systems.
Along with examining any check-lists that identify the causes of risk that have led to
preventive actions, and the experience of other quality managers in similar contexts,
you should also consider conducting structured interviews with individuals, focus and
discussion groups, scenario analysis, and surveys and questionnaires to help identify risks.
The quality manager/lead writes the initial risk list on a whiteboard without comments
from the other participants, who then make their contributions. The team reviews the list,
classifying and grouping the similar risks where appropriate and adding new ones as ideas
are generated. The aim is usually to generate a list of 10 risks associated with each quality
process being assessed, although this number will vary depending on the organisational
context and complexity of processes.
A structured workshop is the most effective format and adequate time should be allocated
by key participants for all the risks to be considered.
Experience and knowledge will always form a valuable part of the process, however,
historical information should not be allowed to block a creative assessment of the future
where the situations that have never arisen before affect the balance between familiar risks
may shift dramatically. 57
56
Ibid.
57
Ibid.
Qualitative analysis is based on ordinal and ranking scales for describing the
consequences and likelihoods of risk. This method helps managers to understand risks
and prioritise them for treatment, taking account of activities, processes and plans that
act as controls. It is a useful approach in situations where there is insufficient reliable
statistical data available, or where time and cost constraints prevent managers from
undertaking a more resource-intensive semi-quantitative or quantitative analysis of risk.
In comparison:
Quantitative analysis uses numerical (ratio) scales for consequences and likelihoods,
rather than descriptive or nominal scales, and requires more advanced skills.
ISO 9001:2015 requires that we consider risk qualitatively (and, depending on the
organisation‘s context, quantitatively) when defining the rigour and degree of formality
needed to plan and control the quality management system, as well as its component
processes and activities. Qualitative risk analysis is the systematic use of available
information - including documented information from the risk identification process in
Step 2 - to develop an understanding of the risks to quality objectives. 58
This includes:
58
Ibid. Chapter 8: Qualitative Risk Analysis and Risk Evaluation.
The quality management team is often the best source of information for assessing risks
to quality in terms of their causes and consequences.
• historical records;
• process records; either specific to the kind of process being assessed, or where
comparisons and inferences can be drawn regarding risk scenarios;
• industry best practice;
• user experience (from quality records and other sources - e.g. customer service
records, social media discussions, consumer satisfaction surveys);
• published literature and research reports that contain theory and/or examples
relating to failure modes or equipment reliability;
• product brochures and technical manuals;
• audit reports.
Process inputs
•
historical data;
•
theoretical analysis;
•
empirical data and analysis;
•
informed opinion of the project team and other experts;
•
the concerns of stakeholders. 59
Note: This simple list is intended to be identical to the list for risk identification in Step 1,
although you can probably add further types of information based on your organisation‘s
experience of risks to outputs.
59
Adapted from assessing risks to quality from Project management guidelines: managing risk with
ISO 31000 and IEC 62198, Dale F Cooper, et al, John Wiley & Sons Inc, March 2014
List process controls that are already in place and act to modify each risk and assess
1.
their effectiveness.
Determine the kind and level of consequences that characterise each risk.
2.
Assess the likelihood of the consequences occurring, given the controls in place.
3.
Combine levels of consequences and likelihoods to determine the level of risk.
4.
Evaluate the potential exposure for each risk identified to desired quality outcomes.
5.
Agree the management priorities for:
6.
• risk treatment;
• control assurance; and
• ensure top management oversight.60
In conjunction with Step 5 (Risk Treatment): use risk criteria to determine a) the risk
7.
treatment options available and b) whether any residual risk level in your quality
processes will be tolerable.
Process outputs
•
quality process objectives
•
organisational objectives
•
control effectiveness;
•
consequence;
•
likelihood;
•
level of risk; and
•
potential exposure.
Documented information
Risks and opportunities register (R&O register) - recording identified risks, controls,
and ratings.
Risk description worksheet - (for recording risk at process level) listing risk description
process, existing controls, key assumptions, sources of information, document attachments.
60
ISO/DIS 9001:2014, Clause 5.1.1 Leadership and commitment for the quality management system, pp.26-27.
In the first three Steps of this risk management process for quality systems, we have
addressed three fundamental requirements of ISO 9001:2015; namely:
Understanding the context of the organisation, its quality management system and
1.
processes (Clause 4).
Processes for planning and consideration of risks and opportunities (Clause 6)
2.
Processes for support, including resources, people and information (Clause 7)
3.
As ISO 9001:2015 states, the process for considering and controlling past, existing and
additional knowledge needs to take account of the organisation‘s context, including its
size and complexity, the risks and opportunities it needs to address, and the need for
accessibility of knowledge. 61 We propose documented information in the form of (1)
Statement of Context, and (2) Risks and Opportunities Register (R&O register) used to
record identified risks, controls, and ratings.
61
ISO/DIS 9001:2014, A.7 Organisational knowledge, p.46.
Agreed priorities are used to determine those processes where the highest level of
planning and consideration of risk should be focussed.
Process inputs
Method
Process outputs
Consequence and likelihood ratings and agreed priorities for each risk.
Risk contour diagrams (see example below) to plot risk factors and iso-contours; i.e.,
points of equal RF value, to give an indication of priorities.
Risk factors may be calculated as the product of the likelihood (probability) and
consequence scores:
RF = P x C
There is a very good reason for being very cautious with this method. It is that risks
with high consequence scores and low probabilities are allocated low risk factors. The
product formula may result in the risk being downgraded in terms of priorities. This is
an important concern in quality management when considering possible critical non-
conformities (i.e. any nonconformity which may result in hazardous or unsafe conditions
for individuals using, maintaining or depending upon the product or prevent performance
of a vital agency mission) and major non-conformities (any nonconformity other than
critical, which may result in failure or materially reduce the usability of the product for the
intended purpose). However unlikely the undesired outcome, the purpose of the quality
system will be undermined and the organisation‘s reputation badly damaged in the event
of this type of non-conformity ever arising.
By using score from 0 (low) to 1 (high), it is possible to assess whether the risk factor is
high if the consequence is high, or if the likelihood is high by using the following method
described in work by Dale F Cooper. 62
Where:
RF = risk factor
= P + C - (P x C)
62
Project management guidelines: managing risk with ISO 31000 and IEC 62198; Dale F Cooper, et al, John Wiley
& Sons Inc, March 2014.
0.8
Consequence (C)
0.6
0.4
0.2
0
0 0.2 0.4 0.6 0.8 1
Likelihood (L)
Iso-contours are curves on a graph connecting points of a constant value, which is the
function of two variables. A common example is map contours, which use points of
equal height separated by distance. The curve in this example is the Risk Factor (RF),
the two variables are L and C, and the constant values are e.g. RF = 0.20, RF=0.4, RF=0.6,
RF=0.8, RF=0.9.
This semi-quantitative approach to assessing risks in a Quality System has the advantage
of allowing comparison of the various risks of non-conformities (minor, major and critical)
on one or more risk attributes by one or more evaluators, resulting in a consensus view of
what are the ‚real‘ risks as measured by risk factors which are plotted on one graph.
Project management guidelines: managing risk with ISO 31000 and IEC 62198;
Dale F Cooper, John Wiley & Sons Inc, March 2014.
Documented information
Diagrammatic representations of risk - e.g., a risk factor and iso-contour graph used to
plot data from a semi-quantitative risk analysis.
63
Comparative risk assessments: concepts, problems and applications; Holger Schutz, Peter M. Wiedemann,
Wilfried Hennings, Johannes Mertens, Martin Clauberg; John Wiley & Sons, July 2006; ISBN: 978-3-527-31667-0.
64
Ibid. p.192, Appendix 4
ISO 9001:2015 states that one of the key purposes of a quality management system
is to act as a preventive tool. There is no longer a separate clause or sub-clause titled
‚Preventive action’, since the concept of preventive action is expressed through a risk-
based approach to formulating quality management system requirements. 65
• Risks and their priorities from the risk analysis and evaluation step.
• Resources, including budget, which can be applied to treating risks.
Method
Risk action plan summaries for each proposed risk treatment action.
65
ISO/DIS 9001:2014, A.4 Risk based approach, p.45.
66
Project management guidelines: managing risk with ISO 31000 and IEC 62198;
Dale F Cooper, et al, John Wiley & Sons Inc, March 2014, p.363.
67
Ibid., p.363.
68
Ibid. Chapter 10 Risk Treatment.
Identify options for addressing the risks. Let‘s say that the anticipated problem is a
backlog in production indicated by the following RF values:
Which risks should take priority? And what options are available to the organisation to
treat one or more of the risks using available resources? The highest-level risk is number
1. Speed and feed rates are likely to be too slow at present to meet the delivery schedule
of a customer order. The quality management team working with the operations team
has identified, analysed and evaluated this risk as having a Risk Factor of 0.8 (on a scale
of 0-1). Through brainstorming, they have identified and analysed a problem with the
production operatives‘ familiarity with new materials. There is a secondary factor in terms
of unfamiliarity with new machines (RF = 0.6). Absence and tardiness are also potentially
an issue as the operatives are reluctant to operate the new machines without proper
training. However, the third anticipated risk: ‚high absence and tardiness rate‘ has been
assessed as a lower risk at RF = 0.4 than the risk factors for risks 1 or 2, so it is decided to
prioritise treatment of 1 and 2.
The rationale:
Although lack of familiarity with new materials is thought a higher risk than machine
breakdowns or high absence/tardiness rates, risks 1 & 2 taken together represent an
unacceptably high risk within the context. Machine breakdowns due to poor maintenance
by the supplier and/or operator error are known to have been a problem recently in a
competing production facility, and are likely to reduce output rates at a critical time.
Strengthening the Operations team with an operator who is familiar with both the new
materials and the machine is one possibility to consider.
•
Instigating a training programme to familiarise operatives with the new materials and
improve their output performance using the new machines.
• Increasing production hours through over-time to compensate for low output until the
operatives are more familiar with the new materials, etc.
• Outsourcing the manufacturing of the component made with the new material (either
on a temporary or permanent basis) to avoid the risk.
Obviously, there could be other options available, but let‘s stick with these for now. The
next action is to determine the potential benefits and costs of the options; and then
select the best options to treat the risks.
The team next look at the possibility of hiring a skilled operative with experience of
working with the materials in question and the machines. Although it is an attractive idea,
they cannot be sure that they can hire the right person given the tight timescales they
are working to; and although urgent enquiries could be made through Human Resources
with specialist recruitment agencies, the expectation is that the only two viable options
in the short-term are increasing production hours and outsourcing on a temporary
basis. This is because a training programme will take longer to organise and will require
a specialist trainer who has experience of the material and the machines. The trainer
will not be available until over half way through the production of the customer‘s order.
Therefore, the only options are to increase production hours, accepting a high proportion
of scrap that will be generated while operatives learn to work the material, or outsource
to a manufacturer that has been using the material for two years and has successfully
overcome their machine reliability problems.
The decision is made to avoid the risk by outsourcing in this instance; however, actions
to design and implement a training course are agreed, so that the anticipated production
problem will not re-occur in the future.
This risk treatment plan has removed the risk. It may of course have introduced a new
potential risk: i.e. that the chosen outsourcing company proves to be unreliable and fails
to deliver on time, and/or within budget?
This identified risk will then be duly analysed, evaluated and, if it is thought necessary,
treated as part of a continual review of the risks.
Process outputs
Risk action plan summaries for each proposed risk treatment action.
Documented information
•
risk (risk owners);
•
control (control owners);
•
treatment plan (risk owners)
It will be necessary to decide how risks and controls will be periodically reviewed,
including how often and when these will take place; who will conduct the reviews, and
what is the most appropriate approach to adopt.
•
reporting process for risk and control monitoring and review;
•
reporting process for progress with risk treatment plans;
•
process to derive lessons from successes and failures within the quality processes
and for communicating this information to the organisation. 69
The Standard will expect you to plan and consider the risks and opportunities in
accordance with the requirements of 6.1 (Steps 1-4 above), and plan and implement
the appropriate actions to address them (Step 5 above. This includes the methods for
monitoring, measuring, as appropriate, and evaluation of processes and, if needed, the
changes to processes to ensure that they achieve their intended results (Step 6). 71
ISO 9001:2015 also mandates that the organisation shall maintain documented
information to the extent necessary to support the operation of processes and retain
documented information to the extent necessary to have confidence that the processes
are being carried out as planned.
With the help of a Risk Management Method similar to the one described above and
using QMS documented information templates controlled in the Cognidox Document
Management System, you will be in a strong position to show an assessor that you
are taking appropriate actions to address risks and opportunities, in line with the
requirements of ISO 9001:2015!
69
Ibid., adapted from Monitoring and Review section summarised on pp.363-364.
70
ISO/DIS 9001:2014, 4.4 Quality management system and its processes, p.26.
71
Ibid., p.26.
One approach could be to look to the ISO 31000 family of standards for guidance. If you do,
then ISO/IEC 31010:2009 – Risk management – Risk assessment techniques would be a
key input.
We began by saying that identifying risk, analysing the consequences, probability and
level of risk (i.e. risk analysis), and evaluating risk using formal techniques, are becoming
increasingly important in the global business world.
Formal risk management is not mandated by ISO 9001:2015 (at least not in the draft
published in 2014). However, organisations can, in the words of the TC 176 Committee’s
draft standard (May 2014) “…choose to develop a more extensive risk-based approach than
is required by this International Standard, and ISO 31000 provides guidelines on formal risk
management which can be appropriate in certain organisational contexts“.
So what will actually be required by ISO 9001 assessors as evidence of risk-based thinking?
At this point in time (June 2015), we do not really know. You could read the DIS to suggest
that the outputs from your processes to consider risk will need to be shown as evidence of
RBT. Whether this is the case when the ISO 9001:2015 Standard is published in September,
risk-based thinking is likely to be required to plan and control the quality management
system (QMS) and component processes and activities, and unlikely to be ignored in
certification audits.
Apart from the obvious answer that most ISO 9001:2008-registered organisations would
like to continue to comply with the Standard, there are several good reasons for analysing
and prioritising the risks and opportunities and planning the actions necessary to address
the risks.
To achieve that often complex task, ISO 31000:2009 can help in taking a ‘risk-based
approach’ to the quality management system, component processes and activities -
although the ISO 9001:2015 standard will not (or is unlikely to) mandate the use of formal
risk management processes.
Risk assessment in ISO 31000 may be undertaken in varying degrees of depth and detail
and using one or many methods ranging from simple to complex. When applying these
ideas to quality systems, it would surely be appropriate to select a form of risk assessment
method with an output that is consistent with the risk criteria developed as part of
establishing the context? [Clause 6.2]. Assuming that you do not have a method in place
already: which one should you choose from the bewildering array?
• risk identification;
• risk analysis – consequence analysis;
• risk analysis – qualitative, semi-quantitative or quantitative probability estimation;
• risk analysis – assessing the effectiveness of any existing controls;
• risk analysis – estimation of the level of risk;
• risk evaluation.
The tools necessary to achieve these steps are listed in ISO 31010:2009; especially Table
A.1 – Tools used for risk assessment. However, it has to be said that the list is daunting to
many quality professionals who are unfamiliar with risk management processes.
The sheer complexity of some types of risk assessment will render the tool useless in most
organisations employing between 1 and 250 people. However, that does not mean to say
that ISO 31010 is not a valuable reference should you ever be required to think about risk in
these terms.
We have described a selection of the 31 techniques listed in ISO 31010. We have attempted
to link these tools to QMS processes in a meaningful way; however, our approach is not
intended as a reference, since a great deal will depend on the organisation‘s context and
there are a considerable number of possibilities (potentially many thousands for different
types and/or sizes of organisation). There is also no common consensus as yet regarding
which ISO 31010 risk assessment techniques are the most appropriate to apply to ISO
9001:2015 quality processes; although this is certain to be covered in future books and
journal articles on how to comply with the standard.
To close, we look at the 6-step process we are recommending and provide links to
templates for documenting the outputs that we hope you will find useful. Click on
the document icon to download the PDF, or visit the Free Templates page in our
Documents Library.
This step determines the issues and requirements that can impact on the planning of
the quality management system; including: (a) the main objectives and outcomes that
are uncertain / subject to risk; and (b) the needs and expectations of the organisation’s
customers and other relevant interested parties; the products and services it provides;
the complexity of processes it employs and their interactions; the competence of persons
within or working on behalf of the organisation; and its size and organisational structure.
Download Now
This step involves selecting a suitable process for risk identification and for each quality
process, identifying and numbering the risks. This process records the risks in a Risk and
Opportunities Register (R&O Register) that would form an integral part of the Quality
Management System.
We offer two supporting templates – a Risk Description Brainstorming Sheet and a Risks
& Opportunities Register.
This step considers (for each risk) the effectiveness of the existing controls using a
suitable effectiveness scale; the consequences (impact) for each risk; the likelihood of
these consequences occurring; and the potential exposure were the controls in place
to fail.
Download Now
This step considers options for either avoiding or seeking the risk; changing the
likelihood; changing the consequences; sharing the risk; or explicitly accepting the risk
without further treatment.
We offer two supporting templates – a Risk Treatment Plan Template and a Risk
Treatment Options Worksheet.
Periodically, the team will re-assess risks and decide whether new risks are affecting or
could affect quality processes and systems as part of the cycle of continuous quality
process improvement.
We believe that it is in your interests to maximise the likelihood of what we term Option
3 – that your ISO auditor will positively note evidence that you have applied RBT.
To do this, you might look to ISO 31000 and its list of risk assessment techniques. This is
not as easy as it sounds.
We have therefore put together a ‘best practices’ guideline in the form of a proposed
six-step methodology.
COMPANY INFORMATION
Registered Office:
Cognidox Limited
St John’s Innovation Centre
Cowley Road
Cambridge CB4 0WS
UK
[Link]









