ISO Standards
Summary: Reference page for ISO management system standards encountered in the library. Starting point: ISO 9001:2015 (quality management) and ISO 45001:2018 (occupational health and safety), specifically their joint risk and opportunity management procedure. Will expand as additional ISO standards enter the library.
Sources: Academia/ISO9001+ISO45001-risk-and-opportunity-procedure-sample.pdf
Last updated: 2026-05-06
ISO 9001:2015 — Quality Management Systems
ISO 9001 sets requirements for a quality management system (QMS). Organizations use it to demonstrate consistent ability to provide products and services that meet customer and regulatory requirements. The 2015 version introduced risk-based thinking as a core structural principle — shifting ISO 9001 from a process-documentation standard to a risk-management standard.
Key clause: Clause 6 — Planning: organizations must determine risks and opportunities, then plan actions to address them. This is not a separate risk department function; it is embedded in strategic planning.
ISO 45001:2018 — Occupational Health and Safety
ISO 45001 is the international standard for occupational health and safety (OH&S) management systems. Aligned structurally with ISO 9001 (both use the Annex SL framework), allowing integrated implementation.
The risk and opportunity procedure (joint template)
The sample procedure covers both standards. Core elements:
Risk management process
1. Identification
Risks are identified at multiple levels: strategic (organizational context, stakeholder expectations), operational (process risks, resource constraints), and project/task level. Input methods include SWOT analysis, PESTLE analysis, process mapping, and incident review.
2. Assessment and prioritization
A two-dimensional risk matrix: Likelihood (1–5) × Impact (1–5) = Risk Score (1–25).
Risk evaluation categories:
- 1–4: Acceptable / monitor
- 5–9: Tolerable / mitigate
- 10–16: Significant / treat as priority
- 17–25: Critical / immediate action required
3. Risk appetite
Organizations define a threshold above which risks must be formally treated. Risks below the threshold are accepted; above it, treatment is mandatory and documented.
4. Treatment options
- Avoid: eliminate the activity generating the risk
- Reduce: implement controls to lower likelihood or impact
- Transfer: insurance, contractual transfer, outsourcing
- Accept: conscious decision to live with the risk (documented)
5. Review and escalation
Risk registers are reviewed at defined intervals (quarterly minimum for significant risks). Escalation paths: Line Manager → HSQ Manager → Top Management → Board.
Opportunity management process
Opportunities are defined as circumstances that, if pursued, could improve performance, reduce costs, or enhance stakeholder value. The procedure requires:
- Identification alongside risk identification (same review cycles)
- Assessment of feasibility and strategic fit
- Documentation of planned actions and resource requirements
- Review of outcomes
Roles and responsibilities
| Role | Responsibility |
|---|---|
| Top Management | Set risk appetite; approve critical risk treatments; provide resources |
| HSQ Manager | Maintain risk register; coordinate assessments; report to Top Management |
| Line Managers & Supervisors | Identify risks in their area; implement controls; escalate as required |
Connections to other library themes
Systems thinking (systems-thinking): the ISO risk framework is an applied systems model — it maps inputs (hazards, opportunities), processes (assessment, treatment), outputs (risk registers, action plans), and feedback loops (review cycles). The procedure’s escalation structure is a governance hierarchy for managing system disturbances.
Trust (trust): ISO certification functions as an institutional trust signal — the QMS is a documented bet by the organization that it will behave consistently. Third-party certification converts internal process claims into externally verifiable commitments.