Risk Assessment (Quality)
Quick facts
| Category | Proactive risk identification and mitigation |
|---|---|
| Used by | Manufacturing, medical devices, pharmaceuticals, aerospace, automotive and other regulated industries |
| Also called | RBT (risk-based thinking) |
| Related standards | ISO 9001, ISO 13485, ISO 14971, AS9100, IATF 16949 |
| Related processes | FMEA, preventive action, management review, supplier evaluation, change control |
| Semantic match | quality risk assessment, ISO 9001 risk-based thinking, risks and opportunities, risk management process |
What is Risk Assessment (Quality)?
Quality risk assessment is the structured process of identifying things that could go wrong in a product, process or quality management system, evaluating how likely and how severe each risk is, and deciding what action, if any, is warranted to address it. It also considers opportunities, since a risk-based approach recognizes that uncertainty can create positive outcomes as well as negative ones.
ISO 9001:2015 introduced risk-based thinking as a mindset that runs throughout the entire standard, replacing the standalone preventive action clause found in earlier versions. Rather than requiring one specific risk management procedure, the standard expects risk to be considered when planning the QMS, running processes and evaluating performance.
In practice, organizations use a range of tools to conduct quality risk assessments, from simple qualitative risk matrices to more formal, quantitative methods such as FMEA, depending on the complexity and regulatory expectations of their industry.
Why is Risk Assessment (Quality) important?
Risk assessment shifts an organization's posture from reactive, where problems are addressed only after they occur, to proactive, where potential failures are identified and mitigated before they affect customers or compliance status.
Because ISO 9001 does not prescribe a single risk methodology, organizations have flexibility to scale their approach, using simple tools for lower-risk processes and more rigorous methods, such as FMEA, for higher-risk products or processes, particularly in regulated industries.
Risk assessment also supports better resource allocation, helping organizations prioritize attention and investment toward the areas most likely to affect product quality, customer satisfaction or regulatory compliance.
How does Risk Assessment (Quality) work?
A typical quality risk assessment process includes:
- Context. Identify the process, product or issue being assessed.
- Risk identification. Determine what could go wrong and what opportunities exist.
- Analysis. Estimate the likelihood and severity of each identified risk.
- Evaluation. Compare risk levels against acceptance criteria to prioritize action.
- Action planning. Define controls or actions to reduce unacceptable risks.
- Implementation. Put the planned actions in place with assigned ownership.
- Monitoring and review. Reassess risks periodically or when conditions change.
Risk Assessment vs. FMEA
| Comparison | Risk Assessment (General) | FMEA |
|---|---|---|
| Scope | Any risk or opportunity affecting the QMS | Specific failure modes in a product or process |
| Structure | Flexible; method chosen by the organization | Formal, structured method with defined scoring |
| Typical use | Supplier decisions, management review, planning | Product design and process design activities |
| ISO 9001 reference | Clause 6.1, risk-based thinking | Not a required tool; commonly used to satisfy Clause 6.1 |
Real-world examples of Risk Assessment (Quality)
A medical device manufacturer conducts a risk assessment on a new supplier before qualification, evaluating the likelihood of component variability and the potential impact on product performance, and sets incoming inspection criteria based on the results.
An automotive supplier uses an FMEA-based risk assessment during process design to identify a step with a high risk priority number and adds a poka-yoke control before the process is released to production.
A pharmaceutical company performs a periodic risk assessment of its facility's environmental monitoring program, adjusting sampling frequency in areas where the assessment indicates elevated contamination risk.
Regulations and standards related to Risk Assessment (Quality)
ISO 9001 Clause 6.1 requires organizations to determine the risks and opportunities that need to be addressed to give assurance the QMS can achieve its intended results, enhance desirable effects, prevent or reduce undesired effects, and achieve improvement, with actions proportionate to their potential impact.
ISO 13485 places strong emphasis on risk management throughout the product lifecycle, often referencing ISO 14971 for medical device risk management specifically. AS9100 and IATF 16949 build risk assessment into product and process design activities, commonly using FMEA as a required or expected tool.
Unlike some clauses, ISO 9001's risk-based thinking does not mandate a specific technique, giving organizations flexibility to select a method appropriate to their size, complexity and industry, while sector-specific standards may impose more rigorous methodology requirements.
Required by
How QT9 helps with Risk Assessment (Quality)
QT9 QMS risk management capabilities
- Document and score risks with configurable risk assessment criteria.
- Assign risk owners, tasks, priorities and approvals in one workflow.
- Link risk assessments to FMEA, CAPA, supplier evaluation and change control records.
- Track mitigation actions to completion with automated alerts.
- Monitor open risks and trends with real-time dashboards.
- Maintain a complete, audit-ready record of every risk assessment performed.
See QT9 Software in Action
Discover how QT9 Software helps manufacturers improve efficiency, strengthen compliance and connect quality management and ERP processes within one integrated platform.
Common mistakes with Risk Assessment (Quality)
Common mistakes include treating risk assessment as a one-time exercise rather than revisiting it when processes, products or suppliers change, and using an overly generic risk matrix that does not reflect the specific severity or likelihood factors relevant to the organization.
Other problems include identifying risks without following through on mitigation actions, and failing to consider opportunities alongside threats, which is an explicit part of ISO 9001's risk-based thinking approach.
Frequently asked questions
Related quality management terms
Related content
Ready to Transform Your Business?
See how QT9 Software helps manufacturers simplify operations, improve traceability and drive continuous improvement with integrated quality management and ERP software.