← All ISO AUDITOR Flashcard Decks

Risk & Opportunity Assessment Flashcards

7 cards from real ISO AUDITOR practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk & Opportunity Assessment flashcards as text
  1. An organization decides to 'avoid' a risk by discontinuing a product line that consistently causes nonconformities. Under ISO 9001:2015, this is:

    Answer: A valid risk treatment option that eliminates the risk source

    Risk avoidance by eliminating the risk source (e.g., discontinuing a problematic product) is a legitimate treatment strategy consistent with the flexible approach required by Clause 6.1.

  2. During an audit, you find that the organization shares risk information with suppliers. Under ISO 9001:2015, this practice best reflects:

    Answer: Risk transfer or sharing as a treatment strategy for externally dependent processes

    Sharing risk information with suppliers is a form of risk transfer or sharing, a valid treatment under Clause 6.1 for risks arising from externally provided processes.

  3. ISO 9001:2015 Annex A.4 clarifies that risk-based thinking is used to achieve a QMS that is a 'preventive tool.' What is the primary implication for auditors?

    Answer: Auditors should look for proactive, embedded risk controls in processes, not just reactive responses

    Annex A.4 explains that risk-based thinking makes prevention habitual and systemic; auditors should therefore assess whether risk controls are genuinely built into process design and execution.

  4. A company identifies a risk but decides to accept it without any mitigation because the cost of action exceeds the potential loss. Under ISO 9001:2015, this decision is:

    Answer: Acceptable if the decision is deliberate, documented, and proportionate to the potential impact on conformity

    Risk acceptance is a recognized treatment; ISO 9001:2015 requires only that actions be proportionate and that the decision to accept be informed and deliberate.

  5. Which management review input, specified in Clause 9.3.2, directly reflects the effectiveness of risk and opportunity actions?

    Answer: Effectiveness of actions taken to address risks and opportunities

    Clause 9.3.2(e) explicitly lists 'effectiveness of actions taken to address risks and opportunities' as a required management review input, closing the Plan-Do-Check-Act loop.

  6. An auditor notices that an organization's risk assessment focuses exclusively on product quality risks and ignores QMS process risks. This approach is:

    Answer: Insufficient — Clause 6.1 requires addressing risks to achieving QMS results, which includes process performance

    Clause 6.1 requires addressing risks that affect the ability to achieve intended results of the QMS, which encompasses process performance, not just end-product quality.

  7. An interested party (e.g., a major customer) introduces new quality requirements. How should this feed into the organization's risk and opportunity assessment?

    Answer: As a new external issue that may create both risks (nonconformity if unmet) and opportunities (competitive advantage if met)

    New interested party requirements are an external issue (Clause 4.2) that the organization must determine, and they can create both risk (failing to meet them) and opportunity (meeting them better than competitors).