PJCINC

  • Home
  • About PJC
    • Why PJC
    • Our “A to Z” Approach
    • PJC Testimonials
    • PJC Clients
    • News & Events
    • Supplier Audits
    • Risk Management
    • Compliance Audit
  • Standards
    • ISO 9001
      • ISO 9000 Implementation
      • ISO 9000 Maintenance
    • AS9100
      • AS9100 Implementation
      • AS9100 Maintenance
    • TNI 2016
    • IATF 16949
      • IATF 16949 Implementation
      • IATF 16949 Maintenance
    • ISO 13485
      • Medical Device Single Audit Program
    • ISO/IEC 17025
      • Cannabis
    • ISO 14001
      • ISO 14000 Implementation
      • ISO 14000 Maintenance
    • ISO 27001
    • ISO 20000-1
    • CMMC
    • R2 – Responsible Recycling
    • RIOS
    • ISO 45001
    • HACCP
    • FSSC 22000
    • Risk Assessment
  • ISO Consulting
  • Training
    • Virtual Public Seminars
    • ISO 9001:2015 Overview Course (Online)
    • ISO 9001:2015
      Internal Auditor
    • ISO 14000
      Internal Auditor
    • IATF 16949
      Internal Auditor
    • AS9100
      Internal Auditor
    • Measurement Uncertainty
    • ISO/IEC 17025 Internal Auditor
    • ISO/IEC 17025 Overview
    • Root Cause
    • SPC
    • Core Tools
      • ISO/TS 16949:2002 Linkage to the
        Core Tools
  • Resources
    • PJC Blog
    • PJC Podcast
    • PJC Videos
    • Green Paper Library
    • Executive Overviews
    • ISO Consultation
    • Quality Manual Review
  • Contact PJC
    • Request A FREE Quote
    • Request A FREE Quick Quote
      • A to Z Implementation
      • Training
      • Internal Audits
      • Assistance/Consulting
    • Here To Answer Your Questions

Risk Management, Risk Based Thinking, Risks and Opportunities – Why the ISO took the leap with the most controversial aspect of the revisions that became ISO 9001:2015.

When the early drafts of what would eventually become ISO 9001:2015 became readily available in mid-2014 it was painfully apparent that most controversial and difficult “new idea” that was to be included in the new standard was the concept of Risk. The early work on this actually goes back to 2012 and the development of the Annex SL framework that eventually became the basis for almost all of the currently published ISO standards.

As specified in Annex SL – risk is actually treated as one half of a two part assessment. The official section in ISO 9001:2015 is titled “Actions to address risks and opportunities.” Recognizing this two part nature of the concept is key to understanding the intent of the framers when they wrote “risk” into the standard in the first place. Namely, an organization should be vigilant not just for opportunities to “prevent undesired effects” but also for opportunities to “enhance desired effects.”

PJC - What Is Risk AssessmentFurthermore, it was never the intent of the framers that every ISO 9001:2015 certified organization would suddenly have to implement a formal risk management program. Indeed, they took great pains to specifically point out that a risk management program was not mandatory in ISO 9001:2015 Annex A.4.

So – just what IS required to meet this requirement? To begin, an organization must first have a firm grasp on the concept of risk and be prepared to explain the approach that has been taken in meeting the requirement. It is acknowledged that the approach taken can (and should) vary depending on the organization’s character, management team preference, and scope of activity. The only firmly auditable record requirement pertaining to risk from ISO 9001:2015 is clause 9.3.2e, which requires that “the effectiveness of actions taken to address risks and opportunities” be included among the items discussed within the management review meeting.

Beyond management review, all other documentation that an organization chooses to maintain pertaining to risk is voluntary and should be structured in such a way to serve the organization and help it meet the risk/opportunity requirement in an effective way. The myriad of methodologies that can be deployed include the automotive FMEA, which seeks to identify potential weaknesses within the production process with targeted improvement efforts to prevent such issues from occurring. The SWOT method is also popular, giving organizations a structure for analyzing risks and opportunities side by side. Even a basic risk management checklist used during an organization’s contractual and/or production planning phase can be helpful.

The intent of ISO 9001:2015 is that (regardless of methodology) the risk/opportunity assessment leads to “integration and implementation (of) actions into (the) quality management system processes.” In other words, that the lessons your analysis uncovered show up the actual day to day processes and don’t just exist in the minutes of your management review meeting.

When properly implemented, risk analysis and risk based thinking can help an organization operate efficiently and effectively. These efforts should be viewed in much the same way as the Continual Improvement ideology that was new in ISO 9001:2000. Namely, that risk efforts are internal to an organization’s quality management system, not supplemental.

Request A FREE Quote - PJC

Request A FREE Quote - PJC

Receive News & Updates From PJC



PJC Implementation Process

Training



MORE INFO / REGISTER NOW!


PJC Blog

  • Advantages of Outsourcing your ISO implementation Project
  • Holiday Greetings from Perry Johnson Consulting, Inc.
  • Preparing for Certification Audits: Common Pitfalls to Avoid

News & Updates

  • First Step in Preparing for ISO Certification: GAP Assessment

Testimonials

Our consultant, Jim Johnson, was extremely helpful not only during the implementation process but afterwards. Kudos to Jim and the staff of PJC!
Ken SeloverQuality ManagerStructural Diagnostics, Inc.
Mahindra Automotive North America (MANA) Manufacturing challenged Perry Johnson Consulting (PJC) to help implement ISO 9001:2015 while ramping up production for our ROXOR off-road vehicle. MANAM was focused on a streamlined, high-level approach to build quality into our manufacturing processes and develop the Quality Management System. PJC was a true partner! Our consultant, Nancy, embraced our approach and kept us focused on key ISO deliverables. She guided us to a successful ISO implementation… Read more
Denise VallisProject ManagerMahindra Automotive North America
From quoting to certification, everyone at Perry Johnson Consulting has been professional and a valued partner. Their auditors demonstrate a vast knowledge of quality standards and are able to translate them to real world application.
Matt NorbergQuality Control ManagerNational Products Inc.
Steve was a wonderful auditor. He was very professional and thorough. He took time to answer my questions about different parts of the standard. I would recommend him to other companies needing an internal audit.
Kelli BradburyPrecision Die Technologies
Hiring Perry Johnson to help us get certified to ISO 9001:2015 was the right move on our part. They did an excellent job on our documentation. Perry Johnson also answered a lot of questions for me going up to the audits which helped greatly. WE passed the audit in June. Thank you for your help, it was money well spent. I will refer you to anyone I talk to about this.
Tony BriaQuality ManagerHydra-Matic/Fabrics For Industry
PJC did consulting for us for our ISO 9002:2015 system and we found them to be professional and listened to our needs. They created a system that was easy to implement and use on a daily basis.
Kraig ReichwaldVP of ManufacturingCustom Metal Products
Wayne’s expertise in ISO 9001:2015 was essential in Vonco Products attaining our ISO certification. His knowledge was a great help improving our system by eliminating waste while assisting in developing our QMS.
Mike DeleoQuality ManagerVonco Products
Michael was instrumental in helping us make this transition much less stressful than I thought it would be. His attention to detail and expertise prepared us for our recertification audit. His professional demeanor made him a pleasure to work with.
Tyler HawkOperations ManagerCross Technologies Group, Inc.
We have been using Perry Johnson Consulting for 5 years and have never had a bad experience. With their expertise and knowledge of the ISO programs they have guided and helped us achieve an outstanding QMS. Thank you to all the friendly and professional people at PJC and we hope to have a long lasting relationship.
Larry ReimersQuality ManagerCTG, Inc.
Thought I’d drop a line to you and the staff to say thank you all very much for your dedicated hard work. You helped save our company, and I’m sending you all a heartfelt thanks!
Kevin J. CoffeyPresidentAlert Tubing Fabricators Inc.

RECEIVE NEWS & UPDATES FROM PJC

Subscribe to our mailing list:


"We are proud to provide services to the U.S. Government!"

PJC Celebrates 30 Years!

PJC's 30th Anniversary
Teresa O'Donnell – President & CEO
Teresa O'Donnell
President & CEO

Perry Johnson Consulting, Inc.

200 East Big Beaver Rd.
Troy, Michigan 48083
Phone: 1-888-248-0256 or (248) 519-2602
Email: [email protected]

PJC Contact Us

  • Facebook
  • Instagram
  • LinkedIn
  • YouTube

Copyright © 2025 PERRY JOHNSON CONSULTING, INC. (PJC) • All rights reserved.