Introduction
Since the release of the 2015 version of ISO 9001, risk-based thinking has become one of the most important concepts within quality management systems.
Unfortunately, it has also become one of the most misunderstood.
Many organizations responded by creating:
- Risk registers
- Risk matrices
- Risk scoring spreadsheets
Yet during audits, it often becomes clear that risk-based thinking is not actually influencing how decisions are made.
The intent of ISO 9001 was never to create additional paperwork.
Instead, risk-based thinking was introduced to encourage organizations to proactively identify uncertainty, prevent problems, and improve decision-making throughout their operations.
Why Risk-Based Thinking Was Introduced
Previous versions of ISO 9001 relied heavily on preventive action requirements.
The challenge was that preventive action often became a reactive process.
Organizations would wait until something happened and then determine how to prevent it from occurring again.
Risk-based thinking shifts the focus:
Instead of asking:
“What should we do after something goes wrong?”
Organizations ask:
“What could go wrong, and what should we do now?”
This creates a more proactive management system.
What Risk-Based Thinking Actually Looks Like
Many organizations expect risk-based thinking to exist in a separate procedure.
In reality, auditors often look for evidence of risk-based thinking throughout normal business activities.
Contract Review
Before accepting work, organizations evaluate:
- Technical capability
- Staffing availability
- Equipment capacity
- Customer requirements
- Regulatory obligations
That is risk-based thinking.
Supplier Evaluation
When organizations select suppliers based on:
- Quality history
- Delivery performance
- Competence
they are applying risk-based thinking.
Training Programs
When management identifies:
- Critical competencies
- Potential knowledge gaps
- Succession concerns
they are managing risk.
Laboratory Operations
Laboratories routinely manage risks involving:
- Sample integrity
- Equipment failure
- Data integrity
- Method limitations
- Environmental conditions
Again, this is risk-based thinking in practice.
Common Mistakes I See During Audits
Mistake #1: Creating a Risk Register and Forgetting About It
Many organizations build extensive risk registers during implementation.
Years later:
- Nobody reviews them
- Nobody updates them
- Nobody uses them
The document exists, but the process does not.
Mistake #2: Treating Risk as a Quality Department Responsibility
Risk management belongs to the entire organization.
The people performing the work often understand operational risks better than management.
Mistake #3: Focusing Only on Negative Risks
ISO 9001 discusses both:
- Risks
- Opportunities
Organizations frequently ignore opportunities entirely.
Mistake #4: Overcomplicating the Process
Some systems become so complicated that employees avoid using them.
Simple systems are often more effective.
A Practical Approach for Small and Medium Organizations
Step 1: Identify Key Processes
Focus on activities that affect:
- Customers
- Compliance
- Performance
Step 2: Ask Three Questions
For each process:
- What could go wrong?
- What are we doing to prevent it?
- How would we know if controls failed?
Step 3: Identify Opportunities
Ask:
- What could improve efficiency?
- What could improve quality?
- What could improve customer satisfaction?
Step 4: Review Regularly
Risk-based thinking should become part of:
- Management review
- Internal audits
- Planning meetings
Advanced Insight
The most mature organizations rarely talk about “risk-based thinking.”
Instead, they naturally incorporate risk considerations into every decision.
Employees:
- Think ahead
- Anticipate problems
- Evaluate alternatives
- Learn from experience
Risk management becomes part of the culture.
Key Insight
Risk-based thinking is not a document, a spreadsheet, or a risk register. It is a mindset that influences daily decisions.
Conclusion
Organizations that successfully implement risk-based thinking move beyond compliance and build more resilient, adaptable, and effective management systems.
The goal is not to eliminate risk.
The goal is to understand it well enough to make better decisions.