Quality Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Quality Magazine logo
  • NEWS
  • PRODUCTS
    • FEATURED PRODUCTS
    • SUBMIT YOUR PRODUCT
  • CHANNELS
    • AUTOMATION
    • MANAGEMENT
    • MEASUREMENT
    • NDT
    • QUALITY 101
    • SOFTWARE
    • TEST & INSPECTION
    • VISION & SENSORS
  • MARKETS
    • AEROSPACE
    • AUTOMOTIVE
    • ENERGY
    • GREEN MANUFACTURING
    • MEDICAL
  • MEDIA
    • A WORD ON QUALITY PUZZLE
    • EBOOK
    • PODCASTS
    • VIDEOS
    • WEBINARS
  • EVENTS
    • EVENT CALENDAR
    • IMTS
  • DIRECTORIES
    • BUYERS GUIDE >
      • Supplier Insights
    • NDT SOURCEBOOK
    • VISION & SENSORS
    • TAKE A TOUR
  • INFOCENTERS
    • Digital Quality Management Systems
    • NEXT GENERATION SPC & QUALITY ANALYTICS
  • AWARDS
    • ROOKIE OF THE YEAR
    • PLANT OF THE YEAR
    • PROFESSIONAL OF THE YEAR
  • MORE
    • Expert Columns
    • NEWSLETTERS
    • QUALITY STORE
    • INDUSTRY LINKS
    • SPONSOR INSIGHTS
  • EMAG
    • eMAGAZINE
    • ARCHIVES
    • CONTACT
    • ADVERTISE
  • SIGN UP!
Management

Management

Is Risk the Future of Quality?

As a quality professional, risk is going to be in your future. Get ready. It’s going to be a bumpy ride.

By Greg Hutchins, Margaux Hutchins
Risk of investment strategy concept. Knob positioned on maximum risk.

Image Source: Bet_Noire / iStock / Getty Images Plus

August 29, 2024
✕
Image in modal.

I’ve been in quality a long time and seen its ups and downs. I believe there is now a resurgence or as some say quality renaissance. We think the glory days of quality are starting in 2024 driven by risk.  

Hopefully, this piece describes what’s up. And, most importantly how you can position yourself and make money. We call this opportunity risk or upside risk.

The Glory Years

Face of Quality | Organizations Need to Assess Risk Level and Take Appropriate Actions

Face of Quality | Jim L. Smith

Organizations Need to Assess Risk Level and Take Appropriate Actions

Let’s start at the beginning. Years ago, I was the project manager (PM) building tank farms, high pressure gas lines, and oil terminals. Only one problem in my last job. Problem was our stainless 304 valve flanges were cracking and the project was not making its objectives. Not good. As the PM, I took the hit. Quit. Get fired. Or, take a demotion and fix the problem: start a quality program in the company. My marching orders were get good parts. Up to that time, we bought strictly ‘Made in the USA.’ This was the beginning of my quality journey.

For the next year or so, I started one of the first quality programs in oil/gas in the U.S. using Mil Q 9858 (predecessor to ISO 9001).  The year was 1987, start of ISO 9001, Baldrige, and Six Sigma. I started teaching management system auditing to AGA Labs, one of the first U.S. Certification Bodies. Saw the quality opportunity and took the jump to full time quality consulting. In the 1990’s, we did a lot of TQM, Six Sigma, and ISO. Had the best-selling quality books. These were the glory years. Then, quality seemed to go sideways.

Start of ISO Interest in Risk

In 2000, ISO 9001 had just come up with process based compliance. Lots of other things were going on. Relatively low barrier to entry. Certifications were decreasing in North America. Lots of entrants into ISO. Our quality consulting was flattening.

So, we asked what’s the next big thing? In 2000, we wrote several pieces for ASQ premising the future of quality was risk. We started evangelizing risk. We were so fervent that we rebranded our products and engineering to risk.

ISO was similarly challenged. ISO was searching for a new revenue model. What to do? ISO saw its future and started its journey of harmonization of its standards. ISO was prescient and started adding risk to standards.

ISO Risk

There are many definitions of risk. Each definition is acceptable largely based on context and use case. Let’s look at a few definitions based on context. Conversationally, risk is something bad or consequential occurring. This is an OK definition. But, how do you operationalize the definition to make it useful and measurable?

In 2009, ISO recognized this problem. In ISO 31000 risk was defined as the “effect on uncertainty on objectives.” You can now see that uncertainty can impact an organization and how it affects business in terms of meeting its objectives. The challenge is some companies had problems operationalizing this definition. To simplify, we suggested using the risk definition of ‘effect on uncertainty on achieving objectives.’ This little change makes it clear that uncertainty impacts reaching or attaining a business objective.

Another challenge is that ISO defined risk as an upside risk (opportunity risk) and downside risk (harsh consequences). Opportunity risk is often hard to measure and audit against (check adherence).

ISO 9001:2015 Risk Based Thinking

In 2015, ISO 9001 was updated with the concept of Risk-Based Thinking (RBT). This was significant because it impacted more than 1 million certified companies. Great idea. Great timing. However, RBT again challenged companies. How does a company operationalize and audit its thinking? Hard if you haven’t taken Mind Reading 101.

Risk-Based diagram
Source: Quality Plus Engineering

Let’s look at this a little deeper. To plan, conduct, and report an independent audit, the auditor and CB’s needed an audit trail of evidence including artifacts, flowcharts, supporting documentation, interviews, logical decisions, and findings. To some companies RBT was a little vague. This is hugely important since consistency is the hallmark of quality, where definitions are clear and processes are stable, capable and improving. To operationalize RBT, we suggested to our clients thinking of RBT as risk based, problem solving and risk based, decision making. Both of which can provide a certifiable audit trail.

ISO 31000 Risk Management Framework

In 2009, ISO 31000 developed their flagship risk standard. The standard explains the basics of risk assessments. It is a risk framework which provides a useful risk taxonomy in different contexts. The standard became the basis of ISO’s risk based approach to all of their standards.

The framework consists of the following:

Risk framework
Source: Quality Plus Engineering
  • Communication and consultation: Define stakeholder requirements and the level and type of risk the organization is willing to accept.
  • Establish context: Define the strategic, operational, and quality objectives the organization wants to achieve.
  • Risk identification: Identify the critical risks impeding the organization to achieve its objectives.
  • Risk Analysis: Analyze risk in terms of likelihood and consequence.
  • Risk evaluation: Evaluate risk in terms of risk appetite or tolerance.
  • Risk treatment. Avoid, accept, transfer, or reduce risk to acceptable levels.
  • Monitoring and review: Incorporate risk into the company’s governance, assurance, and compliance systems.
  • Recording and reporting: Report on the state of reducing risk to meet business objectives.

ISO 31000 is a guideline standard NOT for certification. The challenge is that companies want a risk certification. So what are Certification Bodies doing? CB’s are offering ISO 31000 Certificates of Conformance to their clients.

ISO 19011 Risk Based Audits

In ISO certification, three questions have to be addressed: 1. What management system standard will be used for certification, compliance, or adherence? 2. How will the standard be audited or assured? And 3. Who will conduct the audits?  

ISO 19011:2018 answers the second question. ISO 19011 introduced risk based auditing for managing, planning, conducting, and reporting ALL management system audits.

ISO 42001:2024 AI Management System

ISO now wants to become the global voice of risk standardization. In the World Economic Forum (WEF) 2023, ISO evangelized climate risk standardization. In WEF 2024, ISO advocated for AI harmonization, conformity assessment and risk standardization. ISO is also developing an ecosystem of AI standards around ISO 42001, a certifiable risk based AI Management System standard.

So, what’s going on? Risk is the lens for looking at AI. It is also the future of our profession and ISO. Why? Autonomous risk based problem solving and decision making have become prevalent in healthcare access, tenant screening, criminal justice, facial recognition, employment screening, incarceration, insurance and homelessness. AI seems to be omnipresent and omniscient. The challenge is that we often don’t understand how these autonomous decisions are made.

Is Risk the Future of Quality?

The EU is taking the lead on AI risk based regulations which we believe will kickstart the quality renaissance driven by risk. The EU AI Act will vastly increase ISO Quality Management System and Risk Management System certifications. Why? Let’s look at the EU AI Act regulations:

EU AI Act, according to Article 17 (February 6, 2024) requires:

“Providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation. That system shall be documented in a systematic and orderly manner in the form of written policies, procedures and instructions .. ”

EU AI Act according to Article 9 (February 6, 2024) requires:

 “A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems.…  The risk management system shall be understood as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, requiring regular systematic review and updating.” 

In the U.S., the Office of Management and Budget requires AI risk analysis and is considering ISO 42001 compliance. Colorado and New York have also mandated risk based auditing of high risk AI systems calling out ISO 42001.

AI has to be fair and safe. As quality professionals, it is our duty and opportunity to be the risk assurance in the middle of humans and machines working and making decisions together.

As a quality professional, risk is going to be in your future. Get ready. It’s going to be a bumpy ride. So, what do you think? Have we made the case that the future of quality is risk? What do YOU think is the future of our profession? We would love to hear from you.  

KEYWORDS: manufacturing metrology risk management risk management software

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Greg Hutchins, PE CERM  is Principal Engineer at Quality Plus Engineering. For more information, please email him at [email protected] or visit www.CERMAcademy.com.

Margaux Hutchins, CERM is Product Manager at Quality Plus Engineering. For more information, please email her at  [email protected] or visit www.CERMAcademy.com.

Recommended Content

JOIN TODAY
to unlock your recommendations.

Already have an account? Sign In

  • 2024 Quality Rookie of the Year Justin Wise 1440x750px banner with "Quality Rookie of the Year" logo inset

    Meet the 2024 Quality Rookie of the Year: Justin Wise

    Justin Wise is an exceptional individual who has been...
    Aerospace
    By: Michelle Bangert
  • Man with umbrella and coat stands outside while it rains at night looking at a building.

    Nondestructive Testing: Is there an ethics problem?

    I was a whistleblower who exposed fraudulent activities...
    NDT
    By: Dale Norwood
  • Unraveling Deflategate: Football stadium with closeup of football on field

    Unraveling the Tom Brady Deflategate

    The Deflategate scandal erupted following the 2014 AFC...
    Measurement
    By: Greg Cenker and Henry Zumbrun
Manage My Account
  • eMagazine Subscriptions
  • Newsletters
  • Online Registration
  • Subscription Customer Service
  • Manage My Preferences

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Quality audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Quality or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Key Takeaways for Quality Leaders
    Sponsored byComplianceQuest

    Key Takeaways for Quality Leaders from the 2026 Gartner Magic Quadrant™ for QMS

  • This image shows a person seated next to a Bobcat T66 compact track loader.
    Sponsored byPolyWorks by InnovMetric

    Supercharging Digital Gauging at Bobcat North America

  • Dorsey Calibration Lab photo by Tom LaBarbera Picture this Studios
    Sponsored byDorsey Metrology International

    Ensuring Product Quality in a Competitive Manufacturing Landscape

Popular Stories

This image shows a person seated next to a Bobcat T66 compact track loader.

Supercharging Digital Gauging at Bobcat North America

a professional in the aviation field performing maintenance, repair, and overhaul (MRO) work

Manufacturing Retention: Strategies for Improving Company Culture, Engagement and Skill Development

Dorsey Calibration Lab photo by Tom LaBarbera Picture this Studios

Ensuring Product Quality in a Competitive Manufacturing Landscape

2026 Quality Professional of the Year!

Events

June 22, 2026

Automate 2026

Automate is North America's largest robotics and automation event — and the best place to take your ideas from insight to impact.
 
Our show floor features the world’s leading automation solutions, from AI and robotics to motion control, vision systems, and more. Plus, our educational conference is second to none, led by the brightest minds in automation today.
 
Ready to transform the way you work? Take the next step at Automate.
July 14, 2026

Quality Leaders Forum: Better Communication, Better Quality Data

The Quality Leaders Forum is a quarterly, editor-moderated fireside chat series hosted by Quality Magazine, featuring candid conversations with senior manufacturing and operations executives shaping enterprise-level quality.

View All Submit An Event

Products

Lean Manufacturing and Service Fundamentals, Applications, and Case Studies

Lean Manufacturing and Service Fundamentals, Applications, and Case Studies

See More Products
Quality Podcast Channel Custom Content

Related Articles

  • Face of Quality: The Future of Quality

    See More
  • QM 0522 Management Future of Quality

    The Future of Quality

    See More
  • Management: The Future of Quality ISO Standards

    See More

Related Products

See More Products
  • certified.jpg

    The Certified Manager of Quality / Organizational Excellence Handbook, 4th Edition

  • principles of quality costs.jpg

    Principles of Quality Costs, Fourth Edition

See More Products

Related Directories

  • Quality Liaison Services of North America Inc.

    QLS provides a unique working arrangement for both equipment OEMs and their suppliers. For OEMs, we are directed at suppliers who have quality problems in the plant then we act as a supplier's representative on special projects requiring investigation, engineering or other types of repairs. For suppliers, QLS is an extension of their company on-site at the OEM's facility.
×

Stay in the know with Quality’s comprehensive coverage of
the manufacturing and metrology industries.

Newsletters | Website | eMagazine

JOIN TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Directories
    • Manufacturing Division
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletters
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Market Research
    • Reprints
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing