SQC
ISO 9001:2015
RISK-BASED THINKING
Presented By STARK INDUSTRIES
SQC
Contents
Section A • Risk-Based Thinking
Section B • Risk Identification
Section C • Risk Analysis
Section D • Risk Evaluation
Section E • Risk Treatment
Section F • Risk Monitor & Review
Section G • Communication & Consultation
SQC
Objectives
• Understand Risk and Risk Based Thinking.
• Understand what’s Risk Based Thinking on what does it required
based on the ISO 9001:2015 requirements.
• Understand the simple Risk tool, and how it integrates into the
process approach.
• Understand on how to establish, implement, maintain Risk Based
Thinking a Continual Process Improvement activity.
SQC
Why Risk?
• Risk-based thinking enables an organization to determine the factors
that could cause its processes and its quality management system to
deviate from the planned results, to put in place preventive controls
• to minimize negative effects and to make maximum use of
opportunities as they arise
SQC
Risk Define
• An effect which is potentially happens that may hinder the
organization to achieve the intended results.
• It may deviate the process from the expected flow - positive or
negative.
• Risk can be defined by two (2) parameters
• Severity = Seriousness of the harm
• Probability = Probability that the harm will occur
SQC
Section A
Risk-Based Thinking
SQC
What is “Risk-based Thinking”?
• Risk based thinking – we do sub-consciously in daily life.
• Risk often thought in negative sense, which is not correct
• Risk-based thinking also help to identify opportunities (positive side of
risk)
• The concept of risk has always been implicit in ISO 9001:2015
revision makes it more explicit and builds it into the QMS
• Risk-based thinking makes preventive action part of the routine.
SQC
ISO 9001:2015
REQUIREME
ISO 9001:2015 requires for the NTS
organization to determine the risks and
opportunities based on the knowledge
of the organization’s context (4.1 & 4.2)
SQC
6.1.1 When planning for the quality ISO 9001:2015
management system, the
organization shall consider the
issues referred to in 4.1 and the
REQUIREME
requirements referred to in 4.2 and
determine the risks and
NTS
opportunities that need to be
addressed to:
a) give assurance that the quality
management system can achieve
its intended result(s);
b) enhance desirable effects;
c) prevent, or reduce, undesired
effects;
d) achieve improvement.
SQC
Identifying Risks
• Risks are determined to prevent or reduce undesired effects, and to
give assurance that quality management system can achieve its
intended results.
• ISO 9001 does not define specific types of risks that need to be
determined and addressed
Types and categories of risks are commonly used:
Processes risks of nonconforming output, process breakdown, process inefficiency,
excessive variability, etc.
Quality risk of defects and non-attainment of specified requirements
Suppliers risk of defects and non-attainment of specified requirements
Operation risks to business continuity, data loss, public relations, etc
SQC
What about Opportunity?
• Apart from the risks, the organization has to also identify the
opportunities that may come in its way.
• Opportunities can be in form of adoption of new practices, launching
of new products or services, opening new markets, addressing new
clients, building partnerships, using new technology and other
desirable and viable possibilities to address the organization’s or its
customers’ needs.
SQC
Why Risks are considered?
• Risk : Effect of uncertainties
• Risk Level: Likelihood x
consequences
• Risks and opportunities can affect
conformity of products and services
and the ability to enhance customer
satisfaction are determined and
addressed
SQC
Managing Risks
SQC
SQC
Identify Risk
Causes of Risk
Risk
Consequence /
Impact
SQC
Basis of Risk Assessment
Compliance Obligations
Environmental Aspects Other Issues
& Other Requirements
Adapt existing
Interested parties Context Review
evaluation criteria
Requirements Issues
Risks & Opportunities Risks & Opportunities
Compliance Obligations
Register Those to be addressed
SQC
Risk Assessment Process
Environmental
Aspects • Achieve
intended
Risks & outcomes
Compliance Opportunities Actions to • Prevent
Obligations that need to Address undesired
be addressed effects
• Continual
Other Issues & Improvement
Requirements
SQC
Framework of Risk Management
SQC
Section B
Risk Identification
SQC
Step 1: Risk Identification
Internal External
issues issues
Requirements of Compliance
interested parties obligation
Identify
Risk
/Opportunity
which can affect the organization’s ability to achieve the
intended outcomes of its quality management system
SQC
SQC
Who is Interested Parties?
Person/ organization that can affect, be affected by, or perceive themselves to be affected
by a decision or activity
Determine interested
EXAMPLE
party
Owner,
Determine their Business Employee Regulator Customer Supplier Government
requirements Partner
Monitor and review
SQC
Understand Context
What
• What internal and external issues will stop or help you achieve your
intended outcomes?
• Include environmental conditions capable of affecting or being
affected by your organization
• What are the risks and opportunities?
• Which need to be addressed?
SQC
External SQC
Issues
SQC
Section C
Risk Analysis
SQC
Existing controls and their effectiveness
SQC
Section D
Risk Evaluation
SQC
Step 3: Risk Evaluation
STEP 3a: Determine Probability/likelihood of occurrence
Probability Criteria – 3 level scale
Probability Rating Description
Low 1 May be once a year
Medium 2 Probably can happen
quarterly
High 3 Almost every month
SQC
Step 3: Risk Evaluation
STEP 3b: Determine severity
Severity Criteria – 3 level scale
Severity Rating Description
Low 1 No significance
Performance of product/services is
Medium 2 still acceptable, impact is
manageable
Seriously affects the performance of
High 3
process/services
SQC
STEP 3c: Determine the
risk rating (3x3 scale)
STEP 3d: Determine control requirement SQC
(3x3 scale)
• A Low Risk that does not require any action plan. However, the management
Low Risk may trigger the action plan if finds it is important.
Medium • Medium chance of risk, the management may trigger the action plan if finds
it is critical to control
Risk
• A HIGH risk requires action to control the risk. Action plan must be
documented on the risk assessment form including date of implementation
High Risk • Corrective action within 1 months
• Notify QMR and assess activity
STEP 3a: Determine Probability/likelihoodSQC
of
occurrence
Probability Criteria – 5 level scale
Level Probability Description
1 Rare Will probably never happen / recur / extra
ordinary case
2 Unlikely Do not expect it to happen/ recur but it is
possible it may do so
3 Possible Might happen or recur occasionally
4 Likely Will probably happen/recur but it is not a
persisting issue
5 Almost Certain Will undoubtedly happen / recur, possibly
frequently
SQC
STEP 3b: Determine severity – 5 level scale
Level
Description
1 (insignificant) 2 (minor) 3 (moderate) 4 (major) 5 (catastrophic)
Minor loss of function Temporary major loss of a Major loss of a building. Temporary major loss of Permanent loss or
within a building. building. a major building or damage to entire asset.
permanent loss. Permanent loss of
Breakdowns of essential
Property / Asset Breakdown of minor Unavailability of minor capital equipment. Temporary loss of essential capital
equipment. equipment. essential capital equipment.
equipment
Rumors. Local media coverage – Local media coverage – National media coverage National media
Potential for public short-term reduction in long-term reduction in with <3 days service well coverage with >3 days
concern. No media public confidence public confidence below reasonable public service well below
coverage. expectation. reasonable public
Reputation expectation.
Total loss of public
confidence.
No interruption in Operational interruption 3 Operational interruption Operational Interruption Permanent loss of
Operational operation days or less between 3 days to 1 between 1 – 12 months service or facility
disturbance month
No or minimal impact or Breach of statutory Single breach in statutory Enforcement action. Multiple breaches in
Statutory duty / breech of guidance / legislation duty Multiple breaches in statutory duty.
inspections statutory duty statutory duty. Prosecution.
STEP 3c: Determine the risk rating (5x5 SQC
scale)
Severity
1 2 3 4 5
Likelihood
Insignificant Minor Moderate Major Catastrophic
5 Almost 5 10 15 20 25
Certain
4 Likely 4 8 12 16 20
3 Possible 3 6 9 12 15
2 Unlikely 2 4 6 8 10
1 Rare 1 2 3 4 5
STEP 3d: Determine control requirement SQC
(5x5 scale)
• Risk Matrix Priority Guideline
Low Risk. May be accepted but should be monitored periodically to
Low risk 1-3 ensure the rating does not change.
Moderate Risk. May require corrective action through planning and
Moderate risk 4-6 budgeting process. Control may be adequate with some risk.
High Risk. Unacceptable level of risk exposure which requires constant
High risk 8-12 monitoring and controls. May requires immediate corrective action.
Extreme Risk. May required prohibition of work and process. Significant
Extreme risk 15-25 probability that major harm will occur if control measures are not
implemented and URGENT action is required.
SQC
Section E
Risk Treatment
SQC
STEP 4: RISK TREATMENT
Avoid Risk will be able to be avoided by not proceeding
with the activity likely to generate the Risk.
Accept Accept the risk or increasing the risk in order to
pursue an opportunity.
Reduce Reduce by changing the likelihood or changing
consequence.
Transfer / Transfer the risk involves another party bearing or
Share sharing some part of the Risk.
SQC
Section F
Risk Monitor & Review
SQC
SQC
Section G
Communication & Consultation
SQC
SQC
Risk Registers
The importance of Risk Register
The risk register becomes essential of it records identified risks, their
severity, and actions steps to be taken
Risk Register (by Department) built from
a) Organization SWOT
b) List of Internal /External Issues
c) Needs and Expectations of Interested Parties
Integrating Risk Based Thinking with the SQC
Process Approach
The purpose of the process approach is to
a) Enhance an organization’s effectiveness and efficiency in achieving
its defined objectives.
b) Enhancing customer satisfaction by meeting customer
requirements.
Integrating Risk Based
Thinking with Process
Approach & PDCA
SQC
SQC
Process + Risk + PDCA Model
ACT PLAN the process
Interaction with the
Interaction with the
Incorporate Improvement (Extend of planning
as necessary Depends on risk)
processes
processes
INPUTS DO Carry out the OUTPUTS
Process and action
CHECK monitor/review effective
of action to reduce risk
SQC
Summary
• ISO 9001:2015 - Risk-based thinking standard
• Intent - To ensure organizations consider risks and opportunities that
could affect the results of their plan.
• Objective Evidence:
• Risk & Opportunity Analysis on External and Internal Factors
• Risk Profile/Register
• Risk & Opportunity Action Plan
• Action Plans have been carried out
SQC
SQC