← All ISO AUDITOR Flashcard Decks

Risk & Opportunity Assessment Flashcards

7 cards from real ISO AUDITOR practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk & Opportunity Assessment flashcards as text
  1. A SWOT analysis is conducted during strategic planning. Under ISO 9001:2015, how does this relate to risk and opportunity assessment?

    Answer: Weaknesses and threats map to risks; strengths and opportunities map to opportunities

    SWOT analysis is a recognized tool for identifying context (Clause 4.1); weaknesses/threats inform risk identification and strengths/opportunities inform opportunity exploitation under Clause 6.1.

  2. ISO 9001:2015 does not require a formal risk management process such as ISO 31000. This means:

    Answer: Organizations have flexibility in choosing their risk assessment methodology

    ISO 9001:2015 intentionally does not mandate a specific methodology, allowing organizations to use any proportionate approach — from simple checklists to full ISO 31000 frameworks.

  3. During surveillance audit, an auditor finds that the organization updated its risk assessment two years ago and has not reviewed it since. Which ISO 9001:2015 principle is most directly violated?

    Answer: Risk assessments must be reviewed at planned intervals or when significant changes occur

    Clause 6.1 requires risks to be determined in the context of the organization; Clause 9.3 management review must include information on risks, implying ongoing review when context changes.

  4. A quality manager states that risk-based thinking eliminates the need for preventive action in ISO 9001:2015. This statement is:

    Answer: Correct — risk-based thinking replaced the formal preventive action clause from ISO 9001:2008

    ISO 9001:2015 deliberately replaced the standalone preventive action clause (8.5.3 in 2008) with risk-based thinking embedded throughout the standard, making proactive risk management systemic rather than reactive.

  5. Which of the following scenarios represents an opportunity that an ISO 9001:2015 auditor would expect to see formally addressed?

    Answer: Adopting automation to reduce defect rates and improve delivery times

    Exploiting automation as a means to improve quality performance and achieve objectives is a classic opportunity that should be captured, evaluated, and acted upon under Clause 6.1.

  6. When auditing Clause 6.1, an auditor should expect to find linkage between risk/opportunity actions and which other clause?

    Answer: Clause 6.2 — quality objectives

    Risk and opportunity actions should directly inform quality objectives (Clause 6.2) because objectives represent planned outcomes that address identified risks and exploit opportunities.

  7. A company operates in a highly regulated medical device sector and uses a full FMEA process for risk assessment. An auditor reviewing their ISO 9001:2015 compliance should:

    Answer: Accept the FMEA as a valid and proportionate method for addressing Clause 6.1 requirements

    ISO 9001:2015 allows any suitable methodology; an FMEA is a rigorous, well-recognized risk tool that satisfies the intent of Clause 6.1 for a regulated organization.