Risk Doesn't Mean Complex Software
Risk-based thinking was introduced into ISO 9001:2015 to make prevention part of everyday management, not to require a dedicated risk-management platform. For most organizations, it's a mindset and a light planning step, not a new system to buy.
The Four Building Blocks
- Risk — something that could prevent you from meeting an objective or requirement
- Opportunity — something that could help you improve beyond the baseline
- Process controls — the point where you actually address the risk or opportunity, inside your existing processes
- Review — checking whether the actions taken were effective, typically at management review
A Simple Example Table
| Context | Risk / Opportunity | Action Taken |
|---|---|---|
| Single key supplier for a critical material | Risk: supply disruption | Qualify a second supplier as a backup |
| New automated inspection tool available | Opportunity: reduce inspection errors | Pilot the tool on one production line |
| Experienced staff nearing retirement | Risk: loss of process knowledge | Document key steps and cross-train a successor |
These examples are illustrative only — your own risks and opportunities depend entirely on your business.
Practical Consultant Note
The organizations that struggle most with risk-based thinking are usually the ones trying to build a separate, formal risk register from scratch. The ones that do it well simply add a "what could go wrong / what could go better" question into planning meetings they're already having.
Have a Risk-Based Thinking Question?
Send us your specific question and get a focused, professional read — US$19, one-time.
Start a $19 Quick CheckFrequently Asked Questions
Does ISO 9001 require a formal risk register?
A: No specific format is mandated. A simple table or log is often sufficient — what matters is that risks and opportunities are actually identified and addressed, not the format used.
Is risk-based thinking the same as ISO 31000?
A: No — ISO 31000 is a dedicated risk management standard. ISO 9001's risk-based thinking is a lighter-weight concept built into the QMS, not a requirement to implement a separate risk management standard.
How often should risks be reviewed?
A: Typically alongside your regular planning and management review cycle — see our management review guide for where this fits.