ISO 9001 clause 6.1 requires organisations to “determine risks and opportunities, plan actions to address them, and evaluate their effectiveness.” Translated into engineering business language, this is asking a simpler question: what could go wrong in your operation that would affect your ability to deliver quality products and services — and what are you doing about it before it goes wrong?

Quality risk management is the structured answer. It does not require a dedicated risk team, enterprise software, or a formal governance framework. For most Australian engineering and manufacturing SMEs, it requires a clear framework, two to three hours with the right people, and the discipline to keep the output current.

This article gives you a five-step framework for building that program — starting from scratch, building something that satisfies an ISO 9001 auditor, and actually operating in your business rather than sitting in a compliance folder.

Why most engineering SMEs approach quality risk backwards

Ask any quality manager in an engineering business where their time goes and the answer is almost always the same: corrective actions. Customer complaints. Rework orders. Non-conformance reports. Addressing these is necessary — but it is, by definition, reactive.

The corrective action register is a historical record of risks that were not managed. Every entry represents a failure that could, in most cases, have been identified before it materialised. Research in quality management consistently finds that detecting and correcting a defect costs three to four times more than preventing it — and that a proactive risk management program reduces the total cost of quality significantly over time.

The businesses that manage quality risk well do not have shorter corrective action registers because they have better luck. They have shorter registers because they identified risks in their processes, suppliers, and equipment before those risks became failures — and put controls in place that addressed root causes rather than symptoms.

A quality risk register and a corrective action register should be connected, not parallel. Every significant corrective action should prompt a question: is this risk in our register? If not, add it. If it is, was the treatment effective? The risk register should shrink the CA register over time — that is how you know the program is working.

01

Understand your context — what is your business actually trying to protect?

Before identifying risks, you need clarity on what you are protecting. ISO 9001 clause 4.1 — understanding the organisation and its context — feeds directly into clause 6.1: the risks that matter are the ones that threaten your ability to deliver what customers depend on. You cannot identify those risks without first being clear on what that is.

In practice, answer two questions for your specific business:

A SWOT-style context analysis is the right tool here — mapping internal strengths and weaknesses (processes, equipment, people, documentation) and external opportunities and threats (supply chain, regulatory, technology, customer requirements). A structured 60-minute discussion with your senior team produces the context clarity that makes Step 2 significantly more productive and focused.

You cannot identify the risks that matter until you are clear on what you are protecting. Context clarity is not a bureaucratic exercise — it is what makes risk identification targeted rather than theoretical.

02

Identify your risks — using the six-category framework

Risk identification is where the QRM program is built or broken. The most common failure at this stage is generating a list that is either too short (obvious risks only) or too abstract (theoretical scenarios that have never occurred). The six-category framework below is a structured prompt list that generates a comprehensive, operationally grounded risk register for most engineering and manufacturing businesses.

01 · Process Risks

Undocumented variation between operators; missing weld inspection step; no standard shift-handover procedure; process steps performed differently by different team members.

02 · Product / Output Risks

Dimensional non-conformance at machining; incorrect material grade used without approval; specification drift between design revision and production.

03 · Supplier / Input Risks

Supplier delivers without material certificates; single-source dependency; no incoming inspection process; undisclosed material substitutions.

04 · People / Knowledge Risks

Critical process knowledge held by one operator; no training record for CNC setup; quality inspection steps learned only by shadowing.

05 · Equipment / Infrastructure Risks

Measurement instrument out of calibration; no preventive maintenance schedule; environmental temperature affecting adhesive cure with no monitoring.

06 · Customer / Contract Risks

Specification ambiguity not resolved before production; undocumented verbal drawing change; no formal contract review process before acceptance.

How to run a risk identification session: Gather the people closest to the work — operators, technicians, and supervisors, not just managers. Work through each category as a prompt: ‘For this area, what has gone wrong in the last twelve months? What almost went wrong? What keeps you up at night?’ Document every item without filtering.

The goal is a risk register with 15 to 30 identified risks across the six categories. Describe each risk specifically: not ‘supplier risk’ but ‘supplier delivers non-conforming material without a certificate of conformance.’ A new team member should be able to read the risk description and understand exactly what failure looks like.

The people closest to the work know the risks better than anyone else in the organisation. A risk identification session without operators produces a register full of management assumptions — and management assumptions have a well-established track record of missing the important ones.

03

Assess and prioritise — likelihood × consequence

With a populated register, the next task is prioritisation. Not every identified risk requires the same response — attempting to address all risks equally is both impractical and counterproductive. The standard prioritisation tool is the risk matrix: each risk is scored on likelihood and consequence, and the product of those scores determines priority.

Likelihood ↓ / Consequence →1 Negligible2 Minor3 Moderate4 Major5 Severe
5 Almost Certain510152025
4 Likely48121620
3 Possible3691215
2 Unlikely246810
1 Rare12345
1–3 Low (monitor) 4–7 Medium (plan and schedule) 8–14 High (immediate treatment) 15–25 Critical (urgent, escalate)

Likelihood: 1 = Rare (less than once in 5 years) | 5 = Almost certain (weekly or more). Consequence: 1 = Negligible (no customer impact) | 5 = Severe (regulatory breach, recall, contract termination).

Worked Example

Risk identified: Supplier delivers non-conforming steel plate without material certificate
Likelihood: 3 — Possible (occurred twice in the last 18 months)
Consequence: 4 — Major (non-conforming material in fabricated structure creates safety and contractual risk)
Risk rating: 3 × 4 = 12 — HIGH PRIORITY
Treatment: Implement incoming inspection procedure + supplier quality agreement requiring certificates on delivery

For product and process risks in regulated industries — medical devices, pressure vessels, structural fabrication — Failure Mode and Effects Analysis (FMEA) provides a more structured alternative, adding a detectability dimension. For most engineering SMEs building their first QRM framework, the 5×5 matrix is the right starting point. FMEA is a second-step tool for once the basic register is established and maintained.

The risk matrix exists for prioritisation, not mathematical precision. A score of 12 does not need a more elaborate response than a score of 10 — it needs to be addressed before a score of 6. Treat the numbers as relative, not absolute.

Free Download

Quality Risk Register Template — Pre-Built for Engineering SMEs

A ready-to-use spreadsheet including the six-category framework, 5×5 risk matrix, sample entries for common engineering risks, and a treatment planning column.

Download the Free Template →
04

Plan your response — the four risk treatment options

For every risk rated medium or above, a documented treatment plan is needed — a specific action, an owner, and a timeline. ISO 9001 clause 6.1.2 requires that actions are determined, implemented, and evaluated for effectiveness. There are four standard treatment options:

TreatmentApproachEngineering Example
EliminateRemove the risk sourceRedesign the machining sequence to eliminate a step that consistently produces dimensional variation — removing the failure mode rather than inspecting downstream.
ReduceLower likelihood or consequenceAdd a mandatory first-article inspection checkpoint after setup — reducing the likelihood that a tooling error propagates through a full production batch.
TransferShift risk to another partyRequire suppliers to provide a certificate of conformance with every delivery, with quality performance obligations in the supplier agreement.
AcceptAcknowledge and monitorA rare, low-consequence risk where the cost of implementing a control exceeds the expected cost of the risk event. Document the decision and set a review trigger.

The treatment plan does not need to be elaborate. For a medium-rated risk, a single control measure with a documented owner and implementation date is sufficient. For a high-rated risk, a more comprehensive response may be needed — but the principle is constant: a specific action, a named person responsible, and a measurable outcome that tells you whether the treatment worked.

On the ‘accept’ option: acceptance is legitimate for genuine low-risk scenarios, but it must be a conscious, documented decision — not the default when nobody gets around to addressing a risk. An accepted risk should have a review trigger so the decision is re-evaluated if circumstances change.

Every risk treatment plan should answer three questions: What specific action are we taking? Who owns it? How will we know it worked? A treatment that cannot answer all three is not a plan — it is a good intention.

05

Monitor, review, and update — making QRM a living system

A risk register completed once and filed is not a risk management system — it is a historical document. Effective QRM requires a review rhythm that keeps the register current as the business changes and new risks emerge.

The standard review cadence:

The most important connection to maintain: every significant corrective action should prompt a risk register review. If a supplier delivers non-conforming material and that risk is not in the register, add it immediately. If it is in the register but rated low, reassess the rating. The CA log and the risk register should inform each other continuously — that connection is what transforms reactive quality management into a genuinely proactive system over time.

A risk register reviewed quarterly is a management system. A risk register reviewed never is evidence that risk management was treated as a certification requirement rather than an operational discipline — and ISO auditors can tell the difference.

What you actually need to get started

You do not need enterprise software or a dedicated risk team. The toolset for a functioning QRM program in an engineering SME is straightforward:

FMEA is worth the investment for regulated industries, new product development, and processes where failure consequence is severe and detectability is low. For most engineering SMEs building their first QRM framework, the risk register and 5×5 matrix are the right starting tools.

The connection to ISO 9001: what the auditor will check

For businesses pursuing or maintaining ISO 9001 certification, the five-step framework above maps directly to the standard’s requirements. Here is how each step connects to specific clauses — and what the auditor will ask to see as evidence.

ISO 9001 ClauseRequirementQRM Connection
Clause 4.1Understanding organisational contextDefines what you are protecting — feeds directly into risk identification scope.
Clause 4.2Needs of interested partiesIdentifies stakeholder requirements that become quality risk drivers.
Clause 6.1Risks and opportunitiesCore QRM requirement — risk identification, assessment, and planning.
Clause 6.1.2Actions to address risksSpecific treatment actions, owners, and timelines for each prioritised risk.
Clause 9.1Monitoring and measurementTracks whether risk controls are achieving their intended effect.
Clause 10.2Nonconformity and corrective actionFeedback loop — every significant CA should trigger a risk register review.

What the auditor will specifically ask to see: a populated risk register with identified risks and scores; evidence it has been reviewed recently (meeting minutes, revision history, updated dates); examples of treatment actions implemented; and evidence those actions were evaluated. An auditor who finds a register created during the certification process and never updated since will raise a non-conformance against clause 9.1.

Building the risk register before the certification process — rather than as part of it — gives you months of evidence history by Stage 2. That history is one of the strongest signals an auditor can see that your management system is genuinely operational. A register with six months of review history and visible treatment actions says something a freshly-built register cannot: that quality risk management happens here every day, not just before audits.

Start with one category, not the whole register.

The most common mistake in quality risk management is waiting until conditions are perfect. Start with process risks. Identify the five highest-rated risks in that one category. That is your QRM program — started. Innovengg’s quality team can facilitate your risk identification workshop, score your register, and build your treatment plan in a single structured session.

Book Your Free Quality Consultation →

Fahmy Hanin

CEO & Founder, Innovengg

Fahmy founded Innovengg on the belief that engineering excellence, delivered with integrity and purpose, creates lasting value for clients and communities across Australia and APAC.

Related Articles & Resources