ISO AUDITOR Risk & Opportunity Assessment 3 — Questions and Answers
Question 1: A SWOT analysis is conducted during strategic planning. Under ISO 9001:2015, how does this relate to risk and opportunity assessment?
- Weaknesses and threats map to risks; strengths and opportunities map to opportunities (Correct answer)
- SWOT is not an acceptable tool under ISO 9001:2015
- Only the threat quadrant is relevant to Clause 6.1
- SWOT results must be documented as mandatory records
Correct answer: Weaknesses and threats map to risks; strengths and opportunities map to opportunities
SWOT analysis is a recognized tool for identifying context (Clause 4.1); weaknesses/threats inform risk identification and strengths/opportunities inform opportunity exploitation under Clause 6.1.
Question 2: ISO 9001:2015 does not require a formal risk management process such as ISO 31000. This means:
- Organizations have flexibility in choosing their risk assessment methodology (Correct answer)
- No risk assessment is required at all
- Risk must be addressed only at the strategic level
- A documented risk register is always mandatory
Correct answer: Organizations have flexibility in choosing their risk assessment methodology
ISO 9001:2015 intentionally does not mandate a specific methodology, allowing organizations to use any proportionate approach — from simple checklists to full ISO 31000 frameworks.
Question 3: During surveillance audit, an auditor finds that the organization updated its risk assessment two years ago and has not reviewed it since. Which ISO 9001:2015 principle is most directly violated?
- Risk assessments must be reviewed at planned intervals or when significant changes occur (Correct answer)
- All risk assessments must be reviewed annually
- Risk assessment review is only triggered by customer complaints
- The standard does not require review of risk assessments
Correct answer: Risk assessments must be reviewed at planned intervals or when significant changes occur
Clause 6.1 requires risks to be determined in the context of the organization; Clause 9.3 management review must include information on risks, implying ongoing review when context changes.
Question 4: A quality manager states that risk-based thinking eliminates the need for preventive action in ISO 9001:2015. This statement is:
- Correct — risk-based thinking replaced the formal preventive action clause from ISO 9001:2008 (Correct answer)
- Incorrect — preventive action is still required under Clause 10.2
- Incorrect — preventive action was moved to Clause 8.5
- Correct — only corrective action is required under the 2015 version
Correct answer: Correct — risk-based thinking replaced the formal preventive action clause from ISO 9001:2008
ISO 9001:2015 deliberately replaced the standalone preventive action clause (8.5.3 in 2008) with risk-based thinking embedded throughout the standard, making proactive risk management systemic rather than reactive.
Question 5: Which of the following scenarios represents an opportunity that an ISO 9001:2015 auditor would expect to see formally addressed?
- Adopting automation to reduce defect rates and improve delivery times (Correct answer)
- Responding to a customer complaint about delayed shipment
- Closing out a nonconformity from a previous audit
- Updating the quality manual to reflect organizational changes
Correct answer: Adopting automation to reduce defect rates and improve delivery times
Exploiting automation as a means to improve quality performance and achieve objectives is a classic opportunity that should be captured, evaluated, and acted upon under Clause 6.1.
Question 6: When auditing Clause 6.1, an auditor should expect to find linkage between risk/opportunity actions and which other clause?
- Clause 6.2 — quality objectives (Correct answer)
- Clause 7.1 — resources
- Clause 8.3 — design and development
- Clause 9.2 — internal audit
Correct answer: Clause 6.2 — quality objectives
Risk and opportunity actions should directly inform quality objectives (Clause 6.2) because objectives represent planned outcomes that address identified risks and exploit opportunities.
Question 7: A company operates in a highly regulated medical device sector and uses a full FMEA process for risk assessment. An auditor reviewing their ISO 9001:2015 compliance should:
- Accept the FMEA as a valid and proportionate method for addressing Clause 6.1 requirements (Correct answer)
- Raise a nonconformity because ISO 9001 does not reference FMEA
- Require the company to also complete a separate, simpler risk register
- Note that FMEA only addresses product risks, not QMS risks
Correct answer: Accept the FMEA as a valid and proportionate method for addressing Clause 6.1 requirements
ISO 9001:2015 allows any suitable methodology; an FMEA is a rigorous, well-recognized risk tool that satisfies the intent of Clause 6.1 for a regulated organization.
A SWOT analysis is conducted during strategic planning.
Under ISO 9001:2015, how does this relate to risk and opportunity assessment?