Quality Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Quality Magazine logo
  • NEWS
  • PRODUCTS
    • FEATURED PRODUCTS
    • SUBMIT YOUR PRODUCT
  • CHANNELS
    • AUTOMATION
    • MANAGEMENT
    • MEASUREMENT
    • NDT
    • QUALITY 101
    • SOFTWARE
    • TEST & INSPECTION
    • VISION & SENSORS
  • MARKETS
    • AEROSPACE
    • AUTOMOTIVE
    • ENERGY
    • GREEN MANUFACTURING
    • MEDICAL
  • MEDIA
    • A WORD ON QUALITY PUZZLE
    • EBOOK
    • PODCASTS
    • VIDEOS
    • WEBINARS
  • EVENTS
    • EVENT CALENDAR
    • IMTS
  • DIRECTORIES
    • BUYERS GUIDE >
      • Supplier Insights
    • NDT SOURCEBOOK
    • VISION & SENSORS
    • TAKE A TOUR
  • INFOCENTERS
    • Digital Quality Management Systems
    • NEXT GENERATION SPC & QUALITY ANALYTICS
  • AWARDS
    • ROOKIE OF THE YEAR
    • PLANT OF THE YEAR
    • PROFESSIONAL OF THE YEAR
  • MORE
    • Expert Columns
    • NEWSLETTERS
    • QUALITY STORE
    • INDUSTRY LINKS
    • SPONSOR INSIGHTS
  • EMAG
    • eMAGAZINE
    • ARCHIVES
    • CONTACT
    • ADVERTISE
  • SIGN UP!
Test & InspectionManagement

Risk and ISO 9001: 2015

Risk-based thinking and the process approach.

By Walt Murray
Risk and ISO 9001
February 1, 2016

In September, the International Organization for Standardization (ISO) published ISO 9001:2015, the updated high-level system (HLS) quality management system standard that includes some fundamental changes in how organizations are expected to operate to remain in conformance.

The most noticeable change in the revised standard is that it follows the Annex SL structure that ISO management system standards are now required to adopt. ISO developed the 10-clause, high-level structure to ensure that management system standards are aligned with a set of common requirements.

Additional key changes include enhanced leadership engagement in the management system, increased emphasis on organizational context, greater focus on risk-based thinking, more flexibility regarding documentation and fewer prescriptive requirements. This means more planning documentation and the application of appropriate risk measures at the management level as part of that documentation.

Compared with earlier versions of ISO 9001, the 2000 and 2008 editions focused less on documentation and more on managing processes. ISO 9001:2015 is even less prescriptive than its predecessors and focuses more on performance. This creates challenges for auditing the system by the evaluation of such components as metrics/key performance indicators for quality objectives.

ISO has combined the process approach—the systematic management of processes and their interactions to achieve intended results—with risk-based thinking (risk and opportunity analysis), and by employing the four-step Plan-Do-Check-Act (PDCA) method at all levels in the organization. This combination of risk-based thinking, process approach and PDCA forms an integral part of the ISO 9001:2015 standard.

Risk-Based Thinking, the Process Approach and PDCA

Chief among the changes in ISO 9001:2015 is that risk is no longer implicit or limited to specific elements of the quality management process. Risk is now addressed throughout the standard and built into the whole management system. The revised standard also has explicit requirements for risk-based thinking to support and improve the understanding and application of the process approach.

In ISO 9001:2105, risk-based thinking makes preventive action part of strategic and operational planning, so reference to “preventive action” has been replaced with “actions to address risks and opportunities.” Companies are now expected to identify risks and opportunities, and execute S.M.A.R.T. driven quality objectives and planning of changes. Organizations’ consideration of risk becomes proactive rather than reactive to factors that may affect their QMS. Essentially, risk-based thinking turns the entire management system into a preventive planning tool.

Risk-based thinking is a major part of the process approach, ensuring risk is considered from beginning to end. A key point of the process approach is to have an organization’s processes operate as a single, integrated system. Understanding activities as linked processes that function as a complete system helps achieve more consistent results. This means organizations must consider activity inputs and outputs; a set of activities in a process; a process working within a system; the objectives for which the system should operate; and the direction the system should go.

The process approach is meant to help organizations achieve defined objectives by planning processes, performing them according to the plan, assessing performance and improving the processes. ISO 9001:2015’s new structure is built around the PDCA sequence, commonly used to manage processes and systems. Operating as a closed-looped approach for continual improvement, with risk‐based thinking at each stage, PDCA can help organizations define, implement and control active measures toward improvements—both in individual processes and the QMS as a whole.

In the 2015 edition, ISO 9001’s primary objective remains the same: to continually improve quality and ensure that products and services consistently meet customers’ requirements. By integrating risk-based thinking with the process approach and PDCA, organizations are better able to achieve their stated objectives, ensure consistency of output quality and create value for the customers and the organization as a proactive posture.

As of September 2015, companies with or seeking ISO 9001 certification have three years to meet the QMS requirements in the new edition. For organizations with a culture of risk-based thinking, the updates may mean business as usual. For others, introducing a risk-based approach to their entire QMS could be challenging, mainly in shifting the way that they think about risk. Pushing risk-based thinking to its simplest level of understanding is the most effective way to accomplish this strategy.

KEYWORDS: High level system International Organization for Standardization ISO standards plan-do-check-act (PDCA)

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Qm1016 clmn isoupdate p1 author murray

Walt Murray, CLA, CSSMBB, is CEO of ARC Experts and a valuable part of MasterControl’s Quality and Compliance Consulting (QCC) services team. He has 32 years of quality, environmental and health and safety experience, and has conducted more than 300 audits for regulated Fortune 500 companies.

Recommended Content

JOIN TODAY
to unlock your recommendations.

Already have an account? Sign In

  • 2024 Quality Rookie of the Year Justin Wise 1440x750px banner with "Quality Rookie of the Year" logo inset

    Meet the 2024 Quality Rookie of the Year: Justin Wise

    Justin Wise is an exceptional individual who has been...
    Aerospace
    By: Michelle Bangert
  • Man with umbrella and coat stands outside while it rains at night looking at a building.

    Nondestructive Testing: Is there an ethics problem?

    I was a whistleblower who exposed fraudulent activities...
    NDT
    By: Dale Norwood
  • Unraveling Deflategate: Football stadium with closeup of football on field

    Unraveling the Tom Brady Deflategate

    The Deflategate scandal erupted following the 2014 AFC...
    Measurement
    By: Greg Cenker and Henry Zumbrun
Manage My Account
  • eMagazine Subscriptions
  • Newsletters
  • Online Registration
  • Subscription Customer Service
  • Manage My Preferences

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Quality audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Quality or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Key Takeaways for Quality Leaders
    Sponsored byComplianceQuest

    Key Takeaways for Quality Leaders from the 2026 Gartner Magic Quadrant™ for QMS

  • This image shows a person seated next to a Bobcat T66 compact track loader.
    Sponsored byPolyWorks by InnovMetric

    Supercharging Digital Gauging at Bobcat North America

  • Dorsey Calibration Lab photo by Tom LaBarbera Picture this Studios
    Sponsored byDorsey Metrology International

    Ensuring Product Quality in a Competitive Manufacturing Landscape

Popular Stories

a titanium diaphragm speaker driver

The One Thing Elon Gets Right Is Designed to Scare You

This image shows a person seated next to a Bobcat T66 compact track loader.

Supercharging Digital Gauging at Bobcat North America

Dorsey Calibration Lab photo by Tom LaBarbera Picture this Studios

Ensuring Product Quality in a Competitive Manufacturing Landscape

2026 Quality Professional of the Year!

Events

June 9, 2026

Future-Proof your Quality Processes with Advanced 3D Optical CMM Technology

Discover how to effortlessly capture complex data, leverage true multi-sensor automation, and ensure continuous operation without creating inspection delays.

June 22, 2026

Automate 2026

Automate is North America's largest robotics and automation event — and the best place to take your ideas from insight to impact.
 
Our show floor features the world’s leading automation solutions, from AI and robotics to motion control, vision systems, and more. Plus, our educational conference is second to none, led by the brightest minds in automation today.
 
Ready to transform the way you work? Take the next step at Automate.
View All Submit An Event

Products

Lean Manufacturing and Service Fundamentals, Applications, and Case Studies

Lean Manufacturing and Service Fundamentals, Applications, and Case Studies

See More Products
Quality Podcast Channel Custom Content

Related Articles

  • ISO Standards

    ISO 9001:2015 Implementation: The Good, the Bad and the Trending

    See More
  • M-Files Receives ISO 9001:2015 Certification

    See More

Related Products

See More Products
  • H1517.jpg

    A Practical Field Guide For ISO 9001:2015

  • 118877.jpg

    How to Audit ISO 9001 2015 A Handbook for Auditors

  • louis hannigan.jpg

    The Non-Idiot's Guide to ISO 9001:2015: Understanding and Using the Quality Management System Standard to your benefit

See More Products

Related Directories

  • isoTracker Solutions Ltd.

    Popular cloud-based QMS software with a global customer base. Ideal for small to medium-sized businesses, with no set-up cost and proactive support. Designed for easy compliance with ISO 9001, ISO 14001, ISO 17025, ISO 13485, ISO 45001, ISO 22000 and other QM standards. Pay only for the features you need and add to them as your business grows.
  • Q-Mark Manufacturing Inc.

    SAME-DAY STYLI. Q-Mark Manufacturing Inc. offers same-day order fulfillment on machine tool & CMM probe styli. Proudly made in the USA and unconditionally guaranteed since 1992. The Q in Q-Mark stands for quality. We are ISO 9001:2015 certified. Custom designs welcome. Fits all probes.
×

Stay in the know with Quality’s comprehensive coverage of
the manufacturing and metrology industries.

Newsletters | Website | eMagazine

JOIN TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Directories
    • Manufacturing Division
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletters
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Market Research
    • Reprints
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing