ISO9001 System Document Package (6) | Risk and Opportunity Management Procedure (6.1)
Document Description: This procedure corresponds to clause 6.1 "Actions to address risks and opportunities" of ISO 9001:2015. It is a core procedure document at the planning level of the quality management system (QMS) and is classified as a second-level document. It operationalizes the concept of "risk-based thinking" into a daily mechanism: by systematically identifying risks and opportunities that affect the expected outcomes of the system, formulating response measures according to risk levels, and tracking and evaluating their effectiveness, it aims to reduce adverse impacts, maximize favorable opportunities, and support the realization of quality objectives and continuous improvement of the system. This procedure is applicable to all enterprises that need ISO 9001 certification or have established a QMS, especially small and medium-sized manufacturing and service enterprises that lack systematic management methods for process risks. It can be directly adopted and revised according to the actual situation of the enterprise.
1. Purpose
To establish a mechanism for identifying, assessing, responding to, and monitoring risks and opportunities, ensuring that the company can fully identify risks and opportunities that may affect the expected outcomes of the QMS (including product and service conformity, customer satisfaction, and goal achievement) during the planning of the QMS and its processes. Appropriate response measures should be taken to control risks to an acceptable level, while seizing opportunities to promote continuous improvement and enhance the effectiveness of the QMS.
2. Scope of Application
This procedure applies to the management of risks and opportunities in all processes within the scope of the company's QMS, including but not limited to:
- Risks and opportunities identified in the analysis of the organizational environment (4.1) and stakeholder requirements (4.2);
- Risks and opportunities in the planning of the QMS (6.1) and the setting of quality objectives (6.2);
- Risks and opportunities in the entire product realization process (8.1-8.7), including design and development, procurement, production, inspection, and delivery;
- Risks and opportunities identified in monitoring and measurement, analysis and evaluation (9.1), internal audit (9.2), and management review (9.3);
- Risks and opportunities triggered by nonconforming products and corrective actions (10.2), and change management (6.3/8.5.6).
This procedure does not apply to the management of specialized risks such as personal safety, environment, and occupational health. Such risks should be managed according to relevant laws, regulations, and specialized system requirements.
3. Responsibilities
- General Manager: Approves the "Risk and Opportunity List" and major risk response measures; chairs management reviews and makes decisions on significant risks and opportunities at the system level; provides resource support for risk management activities.
- Management Representative (System Responsible Person): Organizes the establishment, implementation, and maintenance of the risk and opportunity management mechanism; reviews the results of risk identification and assessment and the response measures; supervises the implementation and effectiveness evaluation of risk response measures by various departments; reports the overall status of risk management to the General Manager.
- Department Heads: Organizes department personnel to identify risks and opportunities related to their processes; fills out the "Risk and Opportunity Identification and Assessment Form" as required; implements risk response measures within their department's scope of responsibility; regularly provides feedback on the implementation status to the Management Representative.
- Quality Department (System Focal Department): Compiles and revises this procedure; aggregates risk and opportunity information from various departments, compiles, and maintains the "Risk and Opportunity List"; organizes risk level assessments and effectiveness evaluations of response measures; retains relevant records.
- All Employees: Timely reports new risks or opportunities identified in their daily work to their department head or the Quality Department.
4. Work Procedures
(1) Identification of Risks and Opportunities
Identification Timing:
- At least once during the initial establishment of the system and before each annual management review;
- When there are significant changes in the organizational environment or stakeholder requirements;
- When new processes, products, equipment, or technologies are introduced (in conjunction with change management);
- When major nonconformities, significant customer complaints, or serious nonconformities are found in internal or external audits;
- When laws, regulations, or industry standards are updated and may impact the system.
Identification Inputs:
- Results of organizational environment analysis (internal: corporate culture, resources, capabilities, performance data; external: laws and regulations, technology, market, supply chain);
- Stakeholder (customers, suppliers, employees, regulatory bodies, etc.) needs and expectations;
- Results of process analysis (turtle diagrams, process performance indicators);
- Historical data on nonconformities, complaints, audit findings, and corrective actions;
- Outputs from management reviews and continuous improvement projects.
Identification Methods:
- Methods such as brainstorming, questionnaires, process flowchart analysis, SWOT analysis (strengths/weaknesses/opportunities/threats), and process failure mode analysis (FMEA) can be used;
- Departments should conduct a thorough review of each process dimension to ensure coverage of the entire product realization process and support processes;
- Risk descriptions should be specific and understandable, clearly stating "risk event + potential consequences," for example, "Key position employee turnover leading to insufficient inspection capability, potentially causing missed inspections to reach customers"; opportunity descriptions should clearly state "opportunity content + potential benefits," for example, "Growth in new energy market demand, can expand new customer groups, and increase order volume."
(2) Assessment of Risks and Opportunities
For each identified risk and opportunity, the responsible department fills out the "Risk and Opportunity Identification and Assessment Form," evaluating the risk from two dimensions: occurrence (O) and severity (S). The evaluation criteria are as follows:
Risk Occurrence (O) Scoring Criteria:
Score Level Occurrence Description 1 Very Low Almost impossible (occurs once in more than 5 years) 2 Low Rare (occurs once every 2-5 years) 3 Medium Occasional (occurs once every 1-2 years) 4 High Frequent (occurs once every 6 months to 1 year) 5 Very High Very frequent (occurs multiple times within 6 months) Risk Severity (S) Scoring Criteria:
Score Level Impact Description 1 Minor Minimal impact, can be self-corrected, does not affect delivery or customer satisfaction 2 Low Partial impact, requires minor rework, customer has complaints but can be resolved through negotiation 3 Medium Process performance decline, affects delivery time or cost, customer dissatisfaction 4 Severe Impacts the realization of system objectives, causes batch nonconformities, customer complaints, or customer loss 5 Very Severe Threatens the operation of the system or the survival of the company, causes major quality incidents or legal disputes Risk Level (R) = Occurrence (O) × Severity (S), categorized into three levels based on the score:
Risk Level Score Range Response Requirements Low Risk 1-4 Maintain existing controls, incorporate into routine monitoring, acceptable Medium Risk 5-12 Develop response measures, specify responsible persons and completion deadlines, track implementation High Risk 13-25 Must immediately develop specialized response measures, approved by the General Manager, prioritize resource allocation, monthly tracking until risk is downgraded Opportunity Assessment: Evaluate opportunities based on "graspability" and "potential benefits." Prioritize opportunities with high graspability and significant potential benefits, incorporating them into the annual business plan or improvement projects.
(3) Response to Risks and Opportunities
Based on the risk assessment results, select appropriate response methods, including but not limited to:
- Avoiding risks: Terminating or adjusting activities that may generate risks (e.g., abandoning high-risk, low-benefit new projects);
- Accepting risks to pursue opportunities: Actively investing within the assessed tolerance (e.g., expanding into new markets);
- Eliminating risk sources: Eradicating the conditions that generate risks through design, process, or equipment improvements (e.g., adding poka-yoke devices);
- Changing the likelihood or consequences of risks: Reducing likelihood or mitigating impact through training, stricter inspections, backup suppliers, etc.;
- Sharing risks: Transferring part of the risk through insurance, outsourcing, or quality agreements with suppliers;
- Retaining risks: Making decisions based on sufficient information, accepting residual risks, and maintaining monitoring.
Response measures should specify: measure content, responsible department/person, completion deadline, required resources, and verification method. Measures for medium and high risks should be filled into the "Risk and Opportunity Response Measures and Effectiveness Evaluation Form."
Risk response measures should be integrated into process control measures, prioritizing their inclusion in relevant procedure documents, work instructions, or control plans to avoid a disconnect between the measures and the system.
For major risks, the responsible department should develop a specialized response plan, which must be reviewed by the Management Representative and approved by the General Manager before implementation.
(4) Flowchart (Text Version)
Start
│
▼
Collect Inputs: Organizational environment, stakeholder requirements, process analysis, historical data
│
▼
Departments Identify Risks and Opportunities (Brainstorming/SWOT/FMEA, etc.)
│
▼
Fill out the "Risk and Opportunity Identification and Assessment Form"
│
▼
Quality Department Aggregates, Evaluates Risk Level (L×S) (Low/Medium/High)
│
├─────── Low Risk ───────► Maintain existing controls, incorporate into routine monitoring
│
├─────── Medium Risk ───────► Develop response measures, specify responsible persons/deadlines, track implementation
│
└─────── High Risk ───────► Specialized response plan, General Manager approval, monthly tracking
│
▼
Implement Measures (Integrate into procedure documents/work instructions/control plans)
│
▼
Management Representative Organizes Effectiveness Evaluation (At least once a year, in conjunction with management review)
│
▼
Risk Downgrade/Closure or Update Measures → Update the "Risk and Opportunity List"
│
▼
Management Review Inputs and Outputs → Continuous Improvement
│
▼
End
(5) Monitoring, Evaluation, and Update
- Department heads should provide feedback on the implementation status to the Quality Department within the specified completion deadlines. The Quality Department conducts quarterly follow-up checks on the implementation progress of medium and high-risk response measures and records the results.
- Before each annual management review, the Management Representative organizes the evaluation of the effectiveness of risk and opportunity response measures:
- Whether the risk has been downgraded or eliminated after the implementation of measures;
- Whether new risks or secondary risks have emerged;
- Whether opportunities have been effectively seized and benefits achieved.
- The evaluation results are included as inputs for the management review and incorporated into the management review report. For measures with insufficient effectiveness, a new response plan should be developed according to this procedure.
- The Quality Department updates the "Risk and Opportunity List" dynamically based on the results of identification, assessment, response, and evaluation, ensuring that the list reflects the current actual situation.
5. Related Records
| No. | Record Name | Number | Retaining Department | Retention Period |
|---|---|---|---|---|
| 1 | Risk and Opportunity Identification and Assessment Form | QR-6.1-01 | Quality Department/Various Departments | 3 years |
| 2 | Risk and Opportunity Response Measures and Effectiveness Evaluation Form | QR-6.1-02 | Quality Department | 3 years |
| 3 | Risk and Opportunity List | QR-6.1-03 | Quality Department | 3 years (current effective version retained indefinitely) |
| 4 | Risk Management Training Record | QR-6.1-04 | Human Resources Department | 3 years |
Form Filling Instructions:
- Risk and Opportunity Identification and Assessment Form: Each risk/opportunity is listed on a separate line, including the identification date, identification department, risk/opportunity description, category (strategic/market/process/supply chain/compliance, etc.), occurrence score, severity score, risk level, and proposed response method. The form is reviewed by the department head and confirmed by the Quality Department.
- Risk and Opportunity Response Measures and Effectiveness Evaluation Form: For medium and high risks, specify the measure content, responsible person, completion deadline, resource requirements, and fill in the verification results, residual risk level, and evaluation conclusion (effective/needs improvement) after implementation.
- Risk and Opportunity List: Sorted by risk level from high to low, updated in real-time, and used as a mandatory input for management reviews.
6. Related Documents
- Quality Manual (QM-01) Chapters 4, 6, 9, 10;
- Organizational Environment and Stakeholder Management Procedure (QP-5);
- Quality Policy and Quality Objectives Management Procedure (QP-7);
- Change Management Procedure (QP-29);
- Nonconforming Product and Corrective Action Procedure (QP-27);
- Management Review Procedure (QP-26);
- Internal Audit Procedure (QP-25).
Usage Instructions
1. How to Modify According to the Actual Situation of the Enterprise
- Organizational Structure Adaptation: Replace "Management Representative" with the actual quality responsible position in the enterprise (e.g., Quality Director, System Engineer). For smaller enterprises, the General Manager can directly assume the responsibilities of the Management Representative, merging the review/approval levels in the procedure, but the complete closed loop of "identification—assessment—response—evaluation" must be retained.
- Product Type Adaptation: Manufacturing enterprises can add PFMEA/DFMEA references in the "identification methods." Service enterprises can change "batch nonconformities" to "service errors/customer complaints" and adjust risk categories to service delivery, information security, personnel turnover, etc. Project-based enterprises can add "project schedule risk" categories.
- Assessment Criteria Adaptation: The score descriptions in the table are general examples. It is recommended to revise them according to the enterprise's quality objectives, customer requirements, and industry characteristics (e.g., medical and food industries can increase the severity scores for compliance risks). Alternatively, a qualitative evaluation using "high/medium/low" levels can replace the scoring system, but consistency in evaluation results must be ensured.
- Frequency Adaptation: It is suggested to conduct a comprehensive identification at least once a year (synchronized with management reviews). For industries with significant fluctuations and rapid order changes, the frequency can be adjusted to every six months or combined with quarterly business analysis.
2. Audit Focus Points (Typically Checked by Certification Auditors)
- Whether there is evidence of risk and opportunity identification (forms, meeting records) rather than just the procedure document;
- Whether risk identification covers the organizational environment (4.1) and stakeholder requirements (4.2) (auditors often ask, "How do you know the customer requirements have changed?");
- Whether there are response measures and effectiveness evaluation records for high risks, and whether there are any items that are identified but not managed;
- Whether the risk list is dynamically updated and can be cross-verified with records of corrective actions, change management, and management reviews;
- Whether response measures are truly integrated into process control (e.g., written into work instructions, control plans) rather than remaining on the list.
3. Common Errors
- Identification Without Assessment: Listing dozens of risks without scoring and categorizing them, making it impossible to determine management priorities, and likely to be judged as nonconformities during audits;
- Vague Measures: Writing measures like "strengthen training" or "improve awareness" without specifying responsible persons, deadlines, and verification methods, making it impossible to track the closed loop;
- Disconnection from the System: The risk list is not associated with management reviews and corrective actions, forming a "two-skin" situation. The correct approach is to use risk information as input for management reviews and to treat the closure of major risks as evidence of continuous improvement;
- Omission of Opportunities: Writing only risks and not opportunities, which contradicts the intent of clause 6.1—this clause requires addressing both risks and opportunities. Focusing only on risks may result in observation items;
- One-Time Effort: Conducting identification only before certification and not updating it afterward, turning the risk list into a review material and losing its daily management value.
Identification, assessment, response, and evaluation form a closed loop, making risks controllable and opportunities graspable.
Knowledge code: 2.3.1
Version: v20260809
Author: Quality Think Tank Quality Think Tank is dedicated to providing systematic professional knowledge, methodologies, and practical tools for quality management practitioners, helping enterprises continuously improve their quality capabilities.