Doc. No.
: GTF/SOP/06
STANDARD OPERATING PROCEDURE
Revision: 01
RISK MANAGEMENT
Date: 15-07-2019 Page 1 of 2
REVISION HISTORY
Date of Current
[Link]. Sections Details of Revision
Revision Rev
01 10-01-2019 New release 00
02 15-07-2019 All Revised to customer & GTFIPL current requirements 01
1.1 PURPOSE
The purpose of this document is to address risks and opportunities when
(I) Planning for Quality Management System. (Organizational)
(II) Risks and Opportunities arising during the provision of products/services (i.e.
the operational risks)
1.2 SCOPE
All processes where potential non-conformities and any undesirable situation likely to
happen and result in negative consequences.
1.3 PROCEDURE
a. Organizational risk management are done by all process owners in co-ordination with
Management Representative when planning/establishing the QMS, or when there are
changes to the QMS.
b. Operational level, risk management are carried out by Operations Heads /Project
Manager for all new projects or when there are any major (impacting schedules, quality,
budgets, technical challenges, etc,).
c. When conducting organizational/operational risk management, internal, external issues
and the needs and expectation of interested parties will be considered as inputs to
determine the risk and opportunities. The identified risks and opportunities will be
addressed to give assurance that the QMS can achieve its intended results, enhance
desirable effects, prevent/reduce undesired effects and achieve improvement.
d. All opportunities are identified and implemented thru continual improvement
initiatives.
Prepared By: Santhosh Approved By: Bhaskara Rao
Doc. No.: GTF/SOP/06
STANDARD OPERATING PROCEDURE
Revision: 01
RISK MANAGEMENT
Date: 15-07-2019 Page 2 of 2
e. risk assessment criteria:
• likelihood/Probability on a scale of 1 to 5, 5 being the highest and 1 being the lowest
• consequences/Severity on a scale of 1 to 5, 5 being the highest and 1 being the
lowest
f. Acceptable Risk Levels
• Risk acceptance known as the Risk Exposure Level is determined as 3x3=9 and below
as the Original Risk. Any level above 9 is considered as high-risk level and that
needs to be mitigated.
g. Identification, assessment, implementation of mitigation and communication of risks
throughout operations:
Any risk exposure above 9 is not acceptable and planned actions are taken to mitigate the
risk with a planned date for completion of actions. This is communicated to the team for
their cooperation and actions as needed. On completion of actions as described, date of
completion is noted down in the Risk Register
h. Acceptance of risks remaining after implementation of mitigating actions: On
completion of mitigation actions, the Residual/ Current risk is re-assessed during review
using the same criteria for assessment as original risk. The risk exposure obtained is
indicated as the Residual/ Current risk and accepted.
i. There is a one Risk and Opportunity Register, MR/F/07 which may have risks and
opportunities both at the organizational level and at the operational process level which
is reviewed once in six months and the information is maintained. The register can be
reviewed and updated whenever there is a new/additional risk and opportunities
identified
j. This Register to be reviewed in Management Reviews where new/additional risks and
opportunities may be identified and action may be taken.
1.4 RECORDS
Risk and Opportunity Register MR/F/07
Prepared By: Santhosh Approved By: Bhaskara Rao