ISO 9001 clause 6.1 requires organisations to “determine risks and opportunities, plan actions to address them, and evaluate their effectiveness.” Translated into engineering business language, this is asking a simpler question: what could go wrong in your operation that would affect your ability to deliver quality products and services — and what are you doing about it before it goes wrong?
Quality risk management is the structured answer. It does not require a dedicated risk team, enterprise software, or a formal governance framework. For most Australian engineering and manufacturing SMEs, it requires a clear framework, two to three hours with the right people, and the discipline to keep the output current.
This article gives you a five-step framework for building that program — starting from scratch, building something that satisfies an ISO 9001 auditor, and actually operating in your business rather than sitting in a compliance folder.
Why most engineering SMEs approach quality risk backwards
Ask any quality manager in an engineering business where their time goes and the answer is almost always the same: corrective actions. Customer complaints. Rework orders. Non-conformance reports. Addressing these is necessary — but it is, by definition, reactive.
The corrective action register is a historical record of risks that were not managed. Every entry represents a failure that could, in most cases, have been identified before it materialised. Research in quality management consistently finds that detecting and correcting a defect costs three to four times more than preventing it — and that a proactive risk management program reduces the total cost of quality significantly over time.
The businesses that manage quality risk well do not have shorter corrective action registers because they have better luck. They have shorter registers because they identified risks in their processes, suppliers, and equipment before those risks became failures — and put controls in place that addressed root causes rather than symptoms.
A quality risk register and a corrective action register should be connected, not parallel. Every significant corrective action should prompt a question: is this risk in our register? If not, add it. If it is, was the treatment effective? The risk register should shrink the CA register over time — that is how you know the program is working.
Understand your context — what is your business actually trying to protect?
Before identifying risks, you need clarity on what you are protecting. ISO 9001 clause 4.1 — understanding the organisation and its context — feeds directly into clause 6.1: the risks that matter are the ones that threaten your ability to deliver what customers depend on. You cannot identify those risks without first being clear on what that is.
In practice, answer two questions for your specific business:
- What quality outcomes do your customers rely on? For a fabrication business: dimensional accuracy, material traceability, weld quality, on-time delivery. For a product developer: design intent fidelity, specification compliance, prototype reliability. For a precision machinist: surface finish, dimensional tolerance, cleanliness.
- What conditions or events would prevent you from delivering them? Equipment failure, operator error, supplier non-conformance, inadequate specifications, process variation. The answers to this question become the categories your Step 2 risk identification explores.
A SWOT-style context analysis is the right tool here — mapping internal strengths and weaknesses (processes, equipment, people, documentation) and external opportunities and threats (supply chain, regulatory, technology, customer requirements). A structured 60-minute discussion with your senior team produces the context clarity that makes Step 2 significantly more productive and focused.
You cannot identify the risks that matter until you are clear on what you are protecting. Context clarity is not a bureaucratic exercise — it is what makes risk identification targeted rather than theoretical.
Identify your risks — using the six-category framework
Risk identification is where the QRM program is built or broken. The most common failure at this stage is generating a list that is either too short (obvious risks only) or too abstract (theoretical scenarios that have never occurred). The six-category framework below is a structured prompt list that generates a comprehensive, operationally grounded risk register for most engineering and manufacturing businesses.
Undocumented variation between operators; missing weld inspection step; no standard shift-handover procedure; process steps performed differently by different team members.
Dimensional non-conformance at machining; incorrect material grade used without approval; specification drift between design revision and production.
Supplier delivers without material certificates; single-source dependency; no incoming inspection process; undisclosed material substitutions.
Critical process knowledge held by one operator; no training record for CNC setup; quality inspection steps learned only by shadowing.
Measurement instrument out of calibration; no preventive maintenance schedule; environmental temperature affecting adhesive cure with no monitoring.
Specification ambiguity not resolved before production; undocumented verbal drawing change; no formal contract review process before acceptance.
How to run a risk identification session: Gather the people closest to the work — operators, technicians, and supervisors, not just managers. Work through each category as a prompt: ‘For this area, what has gone wrong in the last twelve months? What almost went wrong? What keeps you up at night?’ Document every item without filtering.
The goal is a risk register with 15 to 30 identified risks across the six categories. Describe each risk specifically: not ‘supplier risk’ but ‘supplier delivers non-conforming material without a certificate of conformance.’ A new team member should be able to read the risk description and understand exactly what failure looks like.
The people closest to the work know the risks better than anyone else in the organisation. A risk identification session without operators produces a register full of management assumptions — and management assumptions have a well-established track record of missing the important ones.
Assess and prioritise — likelihood × consequence
With a populated register, the next task is prioritisation. Not every identified risk requires the same response — attempting to address all risks equally is both impractical and counterproductive. The standard prioritisation tool is the risk matrix: each risk is scored on likelihood and consequence, and the product of those scores determines priority.
| Likelihood ↓ / Consequence → | 1 Negligible | 2 Minor | 3 Moderate | 4 Major | 5 Severe |
|---|---|---|---|---|---|
| 5 Almost Certain | 5 | 10 | 15 | 20 | 25 |
| 4 Likely | 4 | 8 | 12 | 16 | 20 |
| 3 Possible | 3 | 6 | 9 | 12 | 15 |
| 2 Unlikely | 2 | 4 | 6 | 8 | 10 |
| 1 Rare | 1 | 2 | 3 | 4 | 5 |
Likelihood: 1 = Rare (less than once in 5 years) | 5 = Almost certain (weekly or more). Consequence: 1 = Negligible (no customer impact) | 5 = Severe (regulatory breach, recall, contract termination).
Risk identified: Supplier delivers non-conforming steel plate without material certificate
Likelihood: 3 — Possible (occurred twice in the last 18 months)
Consequence: 4 — Major (non-conforming material in fabricated structure creates safety and contractual risk)
Risk rating: 3 × 4 = 12 — HIGH PRIORITY
Treatment: Implement incoming inspection procedure + supplier quality agreement requiring certificates on delivery
For product and process risks in regulated industries — medical devices, pressure vessels, structural fabrication — Failure Mode and Effects Analysis (FMEA) provides a more structured alternative, adding a detectability dimension. For most engineering SMEs building their first QRM framework, the 5×5 matrix is the right starting point. FMEA is a second-step tool for once the basic register is established and maintained.
The risk matrix exists for prioritisation, not mathematical precision. A score of 12 does not need a more elaborate response than a score of 10 — it needs to be addressed before a score of 6. Treat the numbers as relative, not absolute.
Quality Risk Register Template — Pre-Built for Engineering SMEs
A ready-to-use spreadsheet including the six-category framework, 5×5 risk matrix, sample entries for common engineering risks, and a treatment planning column.
Download the Free Template →Plan your response — the four risk treatment options
For every risk rated medium or above, a documented treatment plan is needed — a specific action, an owner, and a timeline. ISO 9001 clause 6.1.2 requires that actions are determined, implemented, and evaluated for effectiveness. There are four standard treatment options:
| Treatment | Approach | Engineering Example |
|---|---|---|
| Eliminate | Remove the risk source | Redesign the machining sequence to eliminate a step that consistently produces dimensional variation — removing the failure mode rather than inspecting downstream. |
| Reduce | Lower likelihood or consequence | Add a mandatory first-article inspection checkpoint after setup — reducing the likelihood that a tooling error propagates through a full production batch. |
| Transfer | Shift risk to another party | Require suppliers to provide a certificate of conformance with every delivery, with quality performance obligations in the supplier agreement. |
| Accept | Acknowledge and monitor | A rare, low-consequence risk where the cost of implementing a control exceeds the expected cost of the risk event. Document the decision and set a review trigger. |
The treatment plan does not need to be elaborate. For a medium-rated risk, a single control measure with a documented owner and implementation date is sufficient. For a high-rated risk, a more comprehensive response may be needed — but the principle is constant: a specific action, a named person responsible, and a measurable outcome that tells you whether the treatment worked.
On the ‘accept’ option: acceptance is legitimate for genuine low-risk scenarios, but it must be a conscious, documented decision — not the default when nobody gets around to addressing a risk. An accepted risk should have a review trigger so the decision is re-evaluated if circumstances change.
Every risk treatment plan should answer three questions: What specific action are we taking? Who owns it? How will we know it worked? A treatment that cannot answer all three is not a plan — it is a good intention.
Monitor, review, and update — making QRM a living system
A risk register completed once and filed is not a risk management system — it is a historical document. Effective QRM requires a review rhythm that keeps the register current as the business changes and new risks emerge.
The standard review cadence:
- Quarterly: Review the top ten highest-rated risks. Check whether treatment actions have been implemented and whether they have reduced the risk rating as expected. Update where circumstances have changed.
- Annually: Full register review — add risks identified during the year, close out eliminated risks, and refresh the context analysis to reflect business changes.
- Triggered: An unscheduled review when a significant corrective action is raised, a new customer or contract is accepted, a key supplier changes, a process is significantly modified, or a near miss occurs.
The most important connection to maintain: every significant corrective action should prompt a risk register review. If a supplier delivers non-conforming material and that risk is not in the register, add it immediately. If it is in the register but rated low, reassess the rating. The CA log and the risk register should inform each other continuously — that connection is what transforms reactive quality management into a genuinely proactive system over time.
A risk register reviewed quarterly is a management system. A risk register reviewed never is evidence that risk management was treated as a certification requirement rather than an operational discipline — and ISO auditors can tell the difference.
What you actually need to get started
You do not need enterprise software or a dedicated risk team. The toolset for a functioning QRM program in an engineering SME is straightforward:
- A risk register. A well-structured spreadsheet: risk description, category, likelihood score, consequence score, risk rating, treatment option, specific action, owner, target date, and review status.
- The 5×5 risk matrix. The scoring tool above — printable, placed in your quality management folder, with consistent scoring criteria.
- The six-category prompt list. Used in risk identification sessions to ensure all relevant risk domains are covered, not just the ones management is already aware of.
- A review schedule. Quarterly reviews booked in the calendar at the start of each year. Annual management review with risk register update as a standing agenda item.
FMEA is worth the investment for regulated industries, new product development, and processes where failure consequence is severe and detectability is low. For most engineering SMEs building their first QRM framework, the risk register and 5×5 matrix are the right starting tools.
The connection to ISO 9001: what the auditor will check
For businesses pursuing or maintaining ISO 9001 certification, the five-step framework above maps directly to the standard’s requirements. Here is how each step connects to specific clauses — and what the auditor will ask to see as evidence.
| ISO 9001 Clause | Requirement | QRM Connection |
|---|---|---|
| Clause 4.1 | Understanding organisational context | Defines what you are protecting — feeds directly into risk identification scope. |
| Clause 4.2 | Needs of interested parties | Identifies stakeholder requirements that become quality risk drivers. |
| Clause 6.1 | Risks and opportunities | Core QRM requirement — risk identification, assessment, and planning. |
| Clause 6.1.2 | Actions to address risks | Specific treatment actions, owners, and timelines for each prioritised risk. |
| Clause 9.1 | Monitoring and measurement | Tracks whether risk controls are achieving their intended effect. |
| Clause 10.2 | Nonconformity and corrective action | Feedback loop — every significant CA should trigger a risk register review. |
What the auditor will specifically ask to see: a populated risk register with identified risks and scores; evidence it has been reviewed recently (meeting minutes, revision history, updated dates); examples of treatment actions implemented; and evidence those actions were evaluated. An auditor who finds a register created during the certification process and never updated since will raise a non-conformance against clause 9.1.
Building the risk register before the certification process — rather than as part of it — gives you months of evidence history by Stage 2. That history is one of the strongest signals an auditor can see that your management system is genuinely operational. A register with six months of review history and visible treatment actions says something a freshly-built register cannot: that quality risk management happens here every day, not just before audits.
Start with one category, not the whole register.
The most common mistake in quality risk management is waiting until conditions are perfect. Start with process risks. Identify the five highest-rated risks in that one category. That is your QRM program — started. Innovengg’s quality team can facilitate your risk identification workshop, score your register, and build your treatment plan in a single structured session.
Book Your Free Quality Consultation →