Risk & Opportunity Assessment Flashcards
7 cards from real ISO AUDITOR practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk & Opportunity Assessment flashcards as text
Under ISO 9001:2015, which statement about documented information related to risk and opportunity assessment is accurate?
Answer: The standard does not mandate a specific documented risk register, but evidence of the process is expected
ISO 9001:2015 does not prescribe a risk register as mandatory documented information, but auditors expect to see evidence that risks and opportunities have been determined and acted upon.
A service company identifies that losing a key employee represents a significant operational risk. Under ISO 9001:2015, the appropriate response is to:
Answer: Develop a succession plan or cross-training program as an action to address the risk
People-related risks that threaten the ability to deliver conforming services are within QMS scope; actions such as cross-training or succession planning directly address Clause 6.1 requirements.
During an ISO 9001:2015 stage 1 audit, the auditor reviews the risk assessment methodology. What is the primary purpose of evaluating it at this stage?
Answer: To confirm the organization has understood its context and has a credible plan for addressing risks before the stage 2 audit
Stage 1 assesses readiness; reviewing the risk methodology ensures the organization understands its context (Clause 4) and has planned appropriate responses (Clause 6.1) before the full conformity audit.
An organization treats all risks identically regardless of their potential impact on product conformity. An auditor would most likely raise this as:
Answer: A nonconformity against Clause 6.1.2 for failing to apply proportionate actions
Clause 6.1.2 requires actions to be proportionate to the potential effect on product/service conformity; treating all risks the same demonstrates the organization has not met this requirement.
Which of the following best illustrates how risk-based thinking is embedded in Clause 8 (Operation) of ISO 9001:2015?
Answer: Control of externally provided processes (8.4) requires assessing risks from supplier performance before establishing controls
Clause 8.4 requires organizations to determine the type and extent of control over external providers based on the potential impact on product/service conformity, which is a direct application of risk-based thinking.
An organization uses a risk matrix to score risks as High, Medium, or Low and only acts on 'High' risks. An auditor's concern with this approach should be:
Answer: Medium risks may also require action if they affect conformity; the threshold must be justified
A blanket policy of ignoring Medium risks may violate Clause 6.1.2 if any of those risks have significant potential to affect product/service conformity — the organization must justify its treatment thresholds.
How should an organization communicate updated risk assessments to relevant internal parties under ISO 9001:2015?
Answer: Through the internal communication mechanisms required by Clause 7.4, tailored to what is relevant for each audience
Clause 7.4 requires the organization to determine internal communications relevant to the QMS; updated risk assessments are QMS-relevant and must be communicated to those who need the information to perform their roles.