When we talk about risks, most of the time we refer to events, whether something will happen or not, but there are other circumstances to which we are exposed and that could influence our success and, to help us, the scholars of the subject have identified four types of uncertainties.
There are different types of risk and not all of them can be managed by the quality system but they should always be considered when the potential losses suffered could affect the performance of the QMS. Let's see which categories the risks fall into:
Strategic risks – are those that derive directly from operating within a specific sector at a specific time and may include:
- risks related to the market and those inherent to the sector or deriving from consumer preferences or emerging technologies that could make a product line obsolete;
- reputation risks such as the loss of credibility of the organization due to problems related to products or services, legal actions or negative publicity;
- risks related to the IT sector or technologies in general that could create a loss of business continuity;
- environmental risks that concern those organizations that operate or depend on suppliers located in regions of the world prone to natural environmental disasters;
- risks related to human capital that can arise in organizations that depend on a particular source or type of work that may be exposed to recruitment risks by the competition;
- health and safety risks that can be found in organizations that operate in hazardous environments or that provide products or services that could expose customers to possible hazards.
Financial risks - are those associated with how an organization manages financial activities, including:
- debts and credits, interest rates and exchange rates;
- customer liquidity;
- the ability to raise the capital necessary to finance improvements
Operational risks - are present in every company and derive from internal malfunctions of processes such as:
- risks related to products and services (for example, when it is not possible to translate into a product or service the concept that one has in mind);
- technological risks;
- risks related to business development (for example, when it is not possible to reach agreements with other companies that are fundamental for a certain type of business);
- risks related to synchronization (for example, arriving too early or too late on a market, delays in transport, suppliers who are unable to deliver a product on time, etc.);
- risks related to margin (when it is possible to produce something that the market wants but the margins are too tight);
- risks related to the execution of work (for example, when plans and procedures are not implemented as expected);
- risks related to system errors
Compliance risks – are those associated with regulatory requirements and any violations of the rules.
The inclusion of risk in ISO 9001:2015 is a good thing because, for too long, the requirements have been treated by those who adopted the standard as something that had to be dealt with, regardless of the need. The only exceptions allowed were the requirements contained in section 7.
With the new version of the document we are authorized to assess the risk and produce evidence to demonstrate that the actions taken to address the risks and opportunities are proportional to the potential impact on the conformity of products and services.
There are several requirements related to risk management scattered throughout ISO 9001:2015, some of which are duplicated under different headings:
- when planning the quality management system, the risks and opportunities arising from an assessment of the organization's context and stakeholder requirements must be determined and addressed, in order to ensure that the QMS can achieve the expected results;
- when determining the processes necessary for the management system, the organization must consider the risks and opportunities it has previously determined;
- top management must promote a way of thinking based on risk management;
- top management must ensure that the risks and opportunities that may affect the conformity of products and services and the ability to improve customer satisfaction are determined and managed;
- the organization must plan actions to address these risks and opportunities, including how to integrate and implement the decided actions within the QMS processes and evaluate the effectiveness of these actions;
- the actions taken to address the risks and opportunities must be proportional to the potential impact on the conformity of products and services;
- the results of the analysis of data and information deriving from monitoring and measurements must be used to evaluate the effectiveness of the actions taken to address the risks and opportunities;
- management reviews must be planned and carried out, taking into account the effectiveness of the actions taken to address risks and opportunities;
- when a non-conformity occurs, the risks and opportunities determined during planning must be updated, if necessary.