Quality Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Quality Magazine logo
  • NEWS
  • PRODUCTS
    • FEATURED PRODUCTS
    • SUBMIT YOUR PRODUCT
  • CHANNELS
    • AUTOMATION
    • MANAGEMENT
    • MEASUREMENT
    • NDT
    • QUALITY 101
    • SOFTWARE
    • TEST & INSPECTION
    • VISION & SENSORS
  • MARKETS
    • AEROSPACE
    • AUTOMOTIVE
    • ENERGY
    • GREEN MANUFACTURING
    • MEDICAL
  • MEDIA
    • A WORD ON QUALITY PUZZLE
    • EBOOK
    • PODCASTS
    • VIDEOS
    • WEBINARS
  • EVENTS
    • EVENT CALENDAR
    • IMTS
  • DIRECTORIES
    • BUYERS GUIDE >
      • Supplier Insights
    • NDT SOURCEBOOK
    • VISION & SENSORS
    • TAKE A TOUR
  • INFOCENTERS
    • Digital Quality Management Systems
    • NEXT GENERATION SPC & QUALITY ANALYTICS
  • AWARDS
    • ROOKIE OF THE YEAR
    • PLANT OF THE YEAR
    • PROFESSIONAL OF THE YEAR
  • MORE
    • Expert Columns
    • NEWSLETTERS
    • QUALITY STORE
    • INDUSTRY LINKS
    • SPONSOR INSIGHTS
  • EMAG
    • eMAGAZINE
    • ARCHIVES
    • CONTACT
    • ADVERTISE
  • SIGN UP!
SoftwareManagement

Management

The Modified Fink Risk Analysis Method for Conformity Assessment Bodies

Risk assessment is not a one-time exercise but a continuous cycle that must adapt to changes in organizational context, industry regulations, and emerging threats.

By Dr. George Anastasopoulos
Cropped visual graph of Fink Risk Analysis Method for Conformity Assessment Bodies (CABs). Risk lines are shown in green, blue, and red.

Image Source: PJLA

May 10, 2025

✕
Image in modal.

This article explores the significance of risk management in Conformity Assessment Bodies, examining the key principles, strategies, and tools that can help CABs identify, assess, and mitigate risks. By understanding the potential risks they face and implementing appropriate risk management measures, CABs can enhance their resilience, improve the accuracy of their assessments, and ensure their long-term success in an increasingly competitive and dynamic global marketplace. Through a practical approach, this article provides insights into integrating risk management practices into the core operations of CABs, offering guidance to both new and seasoned professionals in the field.

Methodology

The modified Fink Risk Analysis Method is particularly well-suited for Conformity Assessment Bodies (CABs) due to its systematic, structured approach to identifying, evaluating, and managing risks within complex environments. The Fink method provides a clear framework for addressing these risks by integrating both qualitative and quantitative factors, enabling CABs to assess risks from multiple perspectives.

Application of the proposed modified Fink Risk Analysis Method

The following key steps outline the process involved in the modified Fink Risk Analysis Method for Conformity Assessment Bodies (CABs):

Step 1: Risk Identification

A crucial first step in Risk Assessment (hereafter, "risk(s)" is used interchangeably for risk/opportunity) is gaining a thorough understanding of the business and its associated interested parties. Practitioners should consider key aspects such as:

  • What defines the business?
  • Is it product-based, service-based, or both?
  • What level of public scrutiny does it face? Is it a regulated industry?
  • Does it involve hazardous activities?
  • Does it rely on contract workers?
  • What are the associated liabilities?
  • Who are the relevant interested parties?

This may include CAB staff and contractors, customers, the public, regulators, industry groups, and government entities.

Once these interested parties are identified, they should be engaged in discussions about potential risks within the business. If necessary, a brief overview of the business—derived from the considerations in question one—can be provided. Gathering input can be as simple as an email outreach or performing brainstorming sessions and does not require a complex or highly technical process. Involving individuals from various levels within the organization (e.g., administration, technical, management, finance) as well as external stakeholders (e.g., contractors, regulators, subject matter experts) ensures a diverse range of perspectives. This broad participation increases the likelihood of identifying and capturing relevant risks effectively.

Step 2: Risk Categorization

After gathering responses, the next step is to organize the identified risks into broad categories. This helps streamline the assessment process by grouping similar risks, reducing redundancy, and minimizing duplicate analyses. The categories should be relevant to the business, with examples including Regulatory Risks, IT Systems Risks, Conflict of Interest/Impartiality Risks, Resource Risks, Domestic Business Risks, International Business Risks, and Policy, Procedure, or Process Risks.

Once the categories are established, risks can be assigned accordingly. During this process, similar risks—those with overlapping subjects—can be merged to simplify the overall list. For instance, "Loss of power supply while testing" and "power supply breakage" can be consolidated into "Loss of power supply while testing."

Step 3: Risk Assessment

With the risks now categorized and consolidated where appropriate, the next step is to gather input from interested parties regarding the Impact (1-10) and Likelihood of Occurrence (1-100%) for each risk. Like the initial step, this process can be efficiently conducted via email and does not need to be complex or highly technical.

To proceed, organize the risks by category, identify the most relevant interested parties for each, and request their assessment by asking:

  1. What they believe the impact of each risk is on a scale of 1 to 10.
  2. What they believe is the likelihood of occurrence is on a scale of 1 to 100%.

Step 4: Risk Evaluation

Although the responses may initially suggest a clear prioritization of risks, it is essential to validate the preliminary findings by plotting the risks and calculating their respective values. Once all responses have been collected, determine the average Impact and Likelihood values for each risk. After compiling the risks into a single list, with one Impact value and one Likelihood value per risk, they can be visualized on a graph like the example below:

Figure 1: one Impact value and one Likelihood value per risk
Figure 1 Source: PJLA

As shown, the X-axis represents the Impact, while the Y-axis represents the Likelihood. For example, you can compare the table below with the corresponding graph:

Risk Identifier

Category

Risk

Impact 

(1-10)

Likelihood 

(1 to 100%)

A

Process control - Inspection

Loss of internet connectivity while performing an inspection

5.9

71

B

National Lockdown in response to pandemic

7.1

79

C

Service Completion

Complicated inspection report requires too much time while on the jobsite which prevents project completion

7.9

20

D

Administrative

Inspectors do not submit their reports on time

2.8

32

Figure 2: Four Risk Value Zones – Low Risk, Medium Risk, High-Medium Risk, High Risk
Figure 2 Source: PJLA

The graph above highlights the four risk level zones. Once the two values are plotted, each risk falls into a specific zone. For example, Risk A is categorized as high-medium risk, Risk B is high risk, Risk C is medium risk, and Risk D is low risk. These risks are clearly placed on the graph; however, what happens when the impact and likelihood values are much closer to each other?

Consider the graph and table below:

Figure 3: Risks with very similar Impact and Liklihood values.
Figure 3 Source: PJLA

The risks above have impact and likelihood values that are so similar, making it challenging to determine which is more critical. In this case, you can calculate the exact Impact Value (IV) for each risk. To do so, multiply the Impact by the Likelihood; the calculated IVs are shown in the far-right column of the table below.

Risk Identifier

Category

Risk

Impact (1-10)

Likelihood (1 to 100%)

Impact Value

(Impact x Likelihood = IV)

A

Process control - Inspection

Loss of internet connectivity while performing an inspection

6.5

70

455

B

National Lockdown in response to pandemic

6.7

69

462.3

 

C

Service Completion

Complicated inspection report requires too much time while on the jobsite which prevents project completion

7.0

66

462

D

Administrative

Inspectors do not submit their reports on time

7.2

67

482.4

After calculating the IV for each risk, reorder them to reflect their ranked positions. Based on the results above, Risk C has the highest value, indicating that it is the most critical of the four example risks. Below is the reorganized ranked list based on the IV:

Ranked Order

Risk Identifier

IV

1

D

482.4

2

B

462.3

3

C

462

4

A

455

Step 5: Identify Acceptable Risk Level (ARL) and Risks Exceeding ARL

Once a hierarchical list of risks is established and plotted on a graph to determine their positions within the four risk zones, organizations should define an Acceptable Risk Level (ARL). This level can be broadly determined based on the four risk zones, for example, considering all risks within the medium and low risk zones as acceptable, or more specifically based on a particular IV, such as classifying all risks with an IV less than 400 as acceptable. Once the ARL is determined, identify the risks that exceed the ARL. These are the risks that require treatment.

Below is an example for:

ARL = Risks with IV < 400

ARL = Risks < IV=400

Ranked Order

Risk Identifier

Calculated Impact Value (IV)

Treatment Required?

1

C

483

Yes

2

D

473.6

Yes

3

A

465

Yes

4

B

453.6

Yes

5

E

419

Yes

6

H

400.2

Yes

7

F

398

No

8

G

350.4

No

9

I

343

No

10

J

320.5

No

Step 6: Mitigation and Contingency Planning

The list of risks that require treatment are shared again with the interested parties, asking them to suggest mitigation and contingency plans for each risk. As with the previous steps, this process should not be overly time-consuming or technical, but it may require further clarification to ensure that the interested parties understand what is expected from the plans.

A mitigation plan is a plan designed to:
A. Reduce the Likelihood of Occurrence of the risk
Or
B. Reduce the Impact of the risk
Or
C. Reduce both the Likelihood of Occurrence and Impact of the risk

A mitigation plan is implemented immediately and aims to address A through C before a risk escalates into a crisis.

A contingency plan, on the other hand, is put in place if a specific risk develops into a crisis. It typically works to minimize the impact or duration of the crisis, as it is no longer possible to reduce the likelihood of occurrence at this stage.

In terms familiar to the conformity assessment industry, a mitigation plan can be viewed as preventive action, while a contingency plan can be considered corrective action or correction.

Once responses to the latest query have been received, similar to what was done with the risks in step 2, the mitigation and contingency plans should be reviewed, analyzed, and consolidated where applicable. For instance, two similar mitigation plans may be proposed for the same risk:

Risk

Party A proposed mitigation

Party B proposed mitigation

Loss of power supply during testing

Implement backup generators with automatic transfer switches to ensure continuous operation.

Install UPS systems for critical equipment to provide temporary power during outages.

Top management should be involved in deciding which mitigation and contingency plans to implement for addressing each risk. This is typically done through a risk discussion during a scheduled management review meeting, though in some cases, it may require a separate meeting.

Step 7. Ongoing Monitoring and Review

Once management has selected the plans they wish to implement, the organization proceeds with the execution. As mentioned earlier, mitigation plans rarely eliminate a risk completely; instead, they reduce either the Impact or Likelihood of Occurrence. This means that residual risk will still remain even after the plans are implemented. Depending on the success of the implementation, the level of residual risk may remain the same or decrease.

To calculate residual risk, follow a process similar to the one used in the initial information-gathering phase:

  • Circulate the list of risks along with a brief description of the mitigation measures implemented.
  • Ask interested parties to review the mitigation and provide updated values for Impact and Likelihood of Occurrence.
  • Replot the risks and recalculate the IV for each one to determine the residual risk level.

If the residual risk is acceptable, document the justification for its acceptability.

If the residual risk is unacceptable, repeat the process and consider alternative mitigation measures until the residual risk is deemed acceptable.

When replotted after mitigation, there should be noticeable movement of the risks on the graph. For example, recall the graph with Risks A, B, C, and D shown in Step 4:

Figure 4: Replotted after mitigation with noticeable movement of the risks.
Figure 4 Source: PJLA

Now, let’s assume that mitigation measures have been applied to each risk as follows:

Risk A: Mitigation measure successfully implemented to reduce the Likelihood of Occurrence.

Risk B: Mitigation measure successfully implemented to reduce the Impact.

Risk C: Mitigation measure successfully implemented to reduce both the Likelihood of Occurrence and Impact.

Risk D: Mitigation measures are not successfully implemented to reduce either factor.

The movement of the risks on the graph would then appear as shown below:

Figure 5: A2, B2, C2 represent newly calculated IVs after mitigation. Impact and Likelihood of Occurrence are reduced.
Figure 5 Source: PJLA

Where A2, B2, and C2 represent the newly calculated IVs after implementing the mitigation plans: Reducing the Likelihood of Occurrence moves the risks vertically (A), reducing the Impact moves the risks horizontally (B), and reducing both the Impact and Likelihood of Occurrence moves the risks diagonally (C). For Risk D, since the mitigation plan failed to address either the Impact or the Likelihood of Occurrence, the risk plot remains unchanged. This can also be observed mathematically by comparing the IVs calculated before and after the mitigation.

After recalculating the numbers and confirming that the residual risk is acceptable, document the justification for this acceptability. If the residual risk remains unacceptable, repeat the process until an acceptable level of residual risk is achieved.

Epilogue

The Modified Fink Risk Analysis Method provides a structured yet flexible approach to identifying, assessing, and mitigating risks in a way that aligns with the unique needs of CABs. By incorporating stakeholder input, categorizing risks effectively, and leveraging both qualitative and quantitative evaluation techniques, this method enables CABs to make informed decisions about risk treatment.

Ultimately, risk assessment is not a one-time exercise but a continuous cycle that must adapt to changes in organizational context, industry regulations, and emerging threats. The Modified Fink Risk Analysis Method empowers CABs to systematically navigate uncertainties, maintain impartiality, and uphold the highest standards of compliance and operational integrity. By integrating this method into routine management practices, CABs can reinforce their resilience, sustain trust among stakeholders, and confidently fulfill their mission of ensuring quality and conformity in their respective fields.

References:

Steven Fink, "Crisis Management: Planning for the Inevitable", Universe, 2000

Steven Fink, "Crisis Communications: The Definitive Guide to Managing the Message", McGraw Hill, 2013

Dr. George Anastasopoulos, Patrick McCullen, Harry Makam, "Risky Business: A Comprehensive Risk Analysis of an Accreditation Body", International Journal of Conformity Assessment, Volume 2, Issue 1, 2023.

READ MORE

  • Is Risk the Future of Quality?
  • The Application of AI in Conformity Assessments: Pros, Cons, and the Human Touch
  • Recognize a Payback for Collecting Test and Metrology Data
KEYWORDS: manufacturing metrology risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Dr. George Anastasopoulos is the Technical and International Business Development Manager at PJLA.

Recommended Content

JOIN TODAY
to unlock your recommendations.

Already have an account? Sign In

  • 2024 Quality Rookie of the Year Justin Wise 1440x750px banner with "Quality Rookie of the Year" logo inset

    Meet the 2024 Quality Rookie of the Year: Justin Wise

    Justin Wise is an exceptional individual who has been...
    Aerospace
    By: Michelle Bangert
  • Man with umbrella and coat stands outside while it rains at night looking at a building.

    Nondestructive Testing: Is there an ethics problem?

    I was a whistleblower who exposed fraudulent activities...
    NDT
    By: Dale Norwood
  • Unraveling Deflategate: Football stadium with closeup of football on field

    Unraveling the Tom Brady Deflategate

    The Deflategate scandal erupted following the 2014 AFC...
    Measurement
    By: Greg Cenker and Henry Zumbrun
Manage My Account
  • eMagazine Subscriptions
  • Newsletters
  • Online Registration
  • Subscription Customer Service
  • Manage My Preferences

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Quality audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Quality or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Key Takeaways for Quality Leaders
    Sponsored byComplianceQuest

    Key Takeaways for Quality Leaders from the 2026 Gartner Magic Quadrant™ for QMS

  • This image shows a person seated next to a Bobcat T66 compact track loader.
    Sponsored byPolyWorks by InnovMetric

    Supercharging Digital Gauging at Bobcat North America

  • Dorsey Calibration Lab photo by Tom LaBarbera Picture this Studios
    Sponsored byDorsey Metrology International

    Ensuring Product Quality in a Competitive Manufacturing Landscape

Popular Stories

This image shows a person seated next to a Bobcat T66 compact track loader.

Supercharging Digital Gauging at Bobcat North America

Dorsey Calibration Lab photo by Tom LaBarbera Picture this Studios

Ensuring Product Quality in a Competitive Manufacturing Landscape

a professional in the aviation field performing maintenance, repair, and overhaul (MRO) work

Manufacturing Retention: Strategies for Improving Company Culture, Engagement and Skill Development

2026 Quality Professional of the Year!

Events

June 22, 2026

Automate 2026

Automate is North America's largest robotics and automation event — and the best place to take your ideas from insight to impact.
 
Our show floor features the world’s leading automation solutions, from AI and robotics to motion control, vision systems, and more. Plus, our educational conference is second to none, led by the brightest minds in automation today.
 
Ready to transform the way you work? Take the next step at Automate.
July 14, 2026

Quality Leaders Forum: Better Communication, Better Quality Data

The Quality Leaders Forum is a quarterly, editor-moderated fireside chat series hosted by Quality Magazine, featuring candid conversations with senior manufacturing and operations executives shaping enterprise-level quality.

View All Submit An Event

Products

Lean Manufacturing and Service Fundamentals, Applications, and Case Studies

Lean Manufacturing and Service Fundamentals, Applications, and Case Studies

See More Products
Quality Podcast Channel Custom Content

Related Articles

  • Phase-Analysis

    Selecting the Correct Analysis Method for Your Materials Sample

    See More
  • The image highlights the importance of policies and procedures in a business environment, specifically focusing on regulatory compliance and financial controls.

    Governing Artificial Intelligence in Conformity Assessment: The ISO/CASCO Perspective

    See More
  • Key to Quality: The Risk Analysis Approach

    See More

Related Products

See More Products
  • A Primer on the Taguchi Method, 2nd Edition

  • 118631.jpg

    The Art of Integrating Strategic Planning, Process Metrics, Risk Mitigation, and Auditing

  • Six Sigma for Sustainability

See More Products

Related Directories

  • FloorSciences | Forensic Failure Analysis + Testing

    FloorSciences provides forensic inspection, testing, and measurement services for commercial and industrial floors, concrete slabs, and protective coatings. We perform failure analysis, materials testing, environmental exposure assessment, and surface‑condition evaluation using ASTM based methods and metrology grade documentation to support quality, compliance, and performance assurance in manufacturing, food processing, and commercial facilities.
  • Paradigm 3 Software

    Paradigm 3 provides cost-effective QMS software contained in four modules. We provide a comprehensive system for document control, training & competency testing, corrective action, non-conformance, risk analysis, calibration and much more. Paradigm uses targeted action items to appropriate personnel to enable your organization to have complete confidence in the integrity of your system.
×

Stay in the know with Quality’s comprehensive coverage of
the manufacturing and metrology industries.

Newsletters | Website | eMagazine

JOIN TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Directories
    • Manufacturing Division
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletters
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Market Research
    • Reprints
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing