13.1 Risk Assessment Inputs, Monitoring, and Control Plans

Key Takeaways

  • ISO 9001:2015 clause 6.1 replaced the standalone preventive action clause with risk-based thinking, requiring organizations to determine risks and opportunities affecting conformity, plan actions to address them, and evaluate the effectiveness of those actions.
  • Risk assessment inputs include customer complaints, field and warranty returns, internal scrap and rework, SPC and capability trends, product and process monitoring reports, supplier performance, audit findings, near-misses, and change events.
  • Sorting the same defect count by where it was found -- in-process, final inspection, or the customer -- converts routine reject data into a risk signal about which control failed.
  • A control plan lists, for each operation, the characteristic and its classification, the specification, the measurement technique, the sample size and frequency, the control method, and the reaction plan; the reaction plan is what tells the operator what to contain, whom to notify, and what to stop.
  • The four mitigation strategies are avoid or eliminate, reduce or mitigate, transfer or share, and accept -- and acceptance is legitimate only when it is explicit, documented, monitored, and carries a defined review trigger.
Last updated: September 2026

13.1 Risk Assessment Inputs, Monitoring, and Control Plans

Risk-Based Thinking Replaced the Preventive Action Clause

ISO 9001:2015 clause 6.1 (Actions to Address Risks and Opportunities) requires an organization to determine the risks and opportunities that could affect conformity of products and services and the ability to enhance customer satisfaction, to plan actions to address them, and to evaluate the effectiveness of those actions. This clause replaced the standalone preventive-action clause that existed in earlier editions: risk-based thinking is preventive action, built into every process instead of sitting in its own procedure.

For a quality technician this is not a documentation detail. It changes the daily question from "did this part conform?" to "what is this data telling me is about to go wrong?"

Risk in this context is the effect of uncertainty on an expected result — an effect that may be negative (a threat) or positive (an opportunity). Risk assessment combines two dimensions:

Risk=f(Severity of the consequence, Likelihood of occurrence)\text{Risk} = f(\text{Severity of the consequence},\ \text{Likelihood of occurrence})

and, in failure-mode work, a third: how likely the organization is to detect the problem before the customer does (Section 13.2).


The Methods of Risk Assessment and Mitigation

MethodWhat it evaluatesWhere a technician meets it
Trend analysis (SPC)Whether a process is drifting toward a limit before it violates oneControl charts, capability trending, monthly PPM charts
FMEA (DFMEA and PFMEA)Which failure modes carry the highest combination of severity, occurrence, and detectionPFMEA reviews, Action Priority ratings (Section 13.2)
Root cause analysisWhy a realized failure occurred, so the same risk is eliminated5 Whys, 8D, fault tree (Section 13.3)
Product and process monitoring reportsWhether performance is holding over timeScrap and rework reports, first-pass yield, audit results, gage R&R trending
Risk matrix / risk registerRelative priority across many dissimilar risksCross-functional risk reviews, new-product launches
Control plansWhich controls are in place at each operation, and what happens when they failThe control plan posted at the operation

ISO 14971 provides the formal risk-management framework for medical devices, and IATF 16949 requires control plans and FMEAs as standing automotive requirements, but the underlying logic is identical everywhere: identify what can go wrong, rank it, control it, and monitor whether the control is working.


Inputs to Risk Assessment

Risk assessment is only as good as the data fed into it. A technician is usually the person closest to several of these inputs.

InputWhat it signalsHow a technician reads it
Customer complaintsProblems the internal system failed to catchPareto by defect type, by part number, and by customer; a rising count on one defect type is a signal even if each complaint is small
Field and warranty returnsFailures that survived all internal controls and reached serviceReturns per thousand units by build month; a rising cohort points at a change made in that period
Internal scrap and reworkWhere the process is losing money and stabilityScrap dollars by operation; rework hours by defect; both are Cost of Poor Quality (Section 2.1)
SPC and capability trendsDrift, shift, increased dispersion before a specification violationRun rules on the control chart; a declining Cpk trend across months
Product and process monitoring reportsAggregate health of an operationFirst-pass yield, downtime, tool life against plan, in-process reject rate
Supplier performanceIncoming riskSupplier PPM, on-time delivery, SCAR count, receiving inspection reject rate
Internal and external audit findingsSystemic weaknesses not yet visible in product dataRepeat findings against the same clause across areas
Near-misses and close callsFailures that were caught by luck rather than by controlCaught-at-final-inspection escapes that should have been caught in-process
Change eventsThe single largest source of new riskNew material, new supplier, new operator, new tool, engineering change, relocation

[!IMPORTANT] Escapes matter more than rejects. A defect found at in-process inspection is the system working. The same defect found at final inspection means an in-process control failed. The same defect found by the customer means every control failed. Sorting the same defect count by where it was found converts ordinary reject data into a risk signal about the control system.


Trend Analysis: Using SPC as a Risk Tool

Control charts are usually taught as a process-control tool; the Body of Knowledge lists trend analysis (SPC) as a risk assessment method, and the difference is the time horizon.

Control useRisk use
"Is this subgroup out of control right now?""Is this process moving toward a limit over weeks?"
Reacts to a single out-of-control signalReacts to a pattern of small, consistent movement
Chart of the characteristicChart of the metric: monthly PPM, weekly scrap dollars, Cpk by month, returns per thousand

Three risk-relevant patterns (the run rules of Section 6.3 applied to management metrics):

  1. A trend — six or more consecutive points moving in one direction — on a Cpk-by-month chart means the process is deteriorating even if no part has yet been rejected. Tool wear, fixture wear, and supplier drift all look like this.
  2. A shift — nine or more consecutive points on one side of the centerline — after a known change confirms the change had an effect, whether or not anybody expected one.
  3. Increasing dispersion — a widening range chart with a stable average — is the classic precursor to a capability failure, because Cpk erodes from the spread rather than from the mean.

Charting a metric rather than a characteristic also protects against the most common management error: treating every monthly movement as a special cause. Applying control-chart logic to a scrap-rate metric tells you whether last month's increase is a signal or noise, which decides whether a corrective action is warranted at all.


Control Plans

A control plan is the document that states, operation by operation, what is controlled, how, how often, by whom, and what happens when the control detects a problem. It is the bridge between the PFMEA (what could go wrong) and the work instruction (what the operator does).

The Three Types

TypeWhen it appliesCharacteristic emphasis
PrototypeDuring prototype buildsHeavy dimensional and material measurement to learn the process
Pre-launchAfter prototype, before full production sign-offIncreased inspection frequency and additional controls until the process proves stable
ProductionOngoing mass productionNormal frequencies, SPC where appropriate, reaction plans in place

Pre-launch control plans deliberately over-inspect. Moving to the production control plan too early — before capability and stability are demonstrated — is one of the most common launch failures.

What a Control Plan Contains

ColumnContent
Part / process number and nameWhich operation
Machine, device, jig, toolWhat performs the operation
Characteristic (product and process)What is being controlled, with its classification symbol (Section 10.5)
Specification / toleranceThe requirement
Evaluation / measurement techniqueWhich gage or method, tied to a specific M&TE type
Sample size and frequencyHow many, how often
Control methodSPC chart, check sheet, error-proofing device, 100 percent automated gage
Reaction planExactly what happens when the control detects a nonconformity: contain what, notify whom, stop what

[!CAUTION] The reaction plan is the column technicians are tested on. A control plan that specifies a characteristic, a gage, and a frequency but leaves the reaction plan blank has documented detection without documenting response. When an out-of-control point appears, the operator does not know whether to stop the machine, how far back to contain, or whom to call, and the containment boundary expands with every minute of confusion.

Keeping the Three Documents Consistent

The PFMEA, the control plan, and the work instruction must agree. A PFMEA that calls for a torque check every hour, a control plan that says once per shift, and a work instruction that mentions no torque check at all is a systemic finding regardless of which document is right. When any one of them changes, the other two are reviewed — and a control plan is always reviewed after a nonconformance, a customer complaint, an engineering change, or a process change.


Ranking and Mitigating Risk

The Risk Matrix

Ranking dissimilar risks requires a common scale. A simple matrix crosses consequence against likelihood:

                        LIKELIHOOD
              Rare    Unlikely  Possible  Likely   Frequent
            +--------+--------+--------+--------+--------+
  Severe    | MEDIUM |  HIGH  |  HIGH  | EXTREME| EXTREME|
            +--------+--------+--------+--------+--------+
  Major     |  LOW   | MEDIUM |  HIGH  |  HIGH  | EXTREME|
S           +--------+--------+--------+--------+--------+
E Moderate  |  LOW   |  LOW   | MEDIUM |  HIGH  |  HIGH  |
V           +--------+--------+--------+--------+--------+
E Minor     |  LOW   |  LOW   |  LOW   | MEDIUM | MEDIUM |
R           +--------+--------+--------+--------+--------+
I Negligible|  LOW   |  LOW   |  LOW   |  LOW   | MEDIUM |
T           +--------+--------+--------+--------+--------+
Y

The matrix is a communication tool, not a calculation. Its value is forcing a cross-functional team to agree on where each risk sits, and its danger is the same arithmetic trap as the Risk Priority Number (Section 13.2): a high-severity, low-likelihood risk can be scored down into complacency. Severity is never reduced by argument — it is reduced only by changing the design or the consequence.

The Four Mitigation Strategies

StrategyMeaningManufacturing example
Avoid / eliminateRemove the source of the risk entirelyRedesign so the part cannot be assembled backwards; eliminate a hazardous solvent
Reduce / mitigateLower the likelihood or the consequenceError-proof the fixture; add an in-process automated gage; tighten the control plan frequency
Transfer / shareMove the consequence to another partyInsurance; contractual allocation; outsourcing a special process to a qualified specialist
AcceptRetain the risk deliberately, with monitoringA low-severity cosmetic risk retained with a trend chart and a review trigger

Acceptance is a legitimate decision only when it is explicit, documented, and monitored. Undocumented acceptance is just an unmanaged risk with a better name.


Worked Example: Reading the Inputs Before Anything Fails

Situation: A machining cell has shipped no nonconforming parts in six months. The technician assembles the monthly monitoring data:

MonthCpk (bore dia.)In-process rejectsFinal-inspection catchesCustomer complaints
April1.681100
May1.611400
June1.551310
July1.471920
August1.412231

Analysis:

  1. Cpk shows a five-point downward trend. No specification has been violated, but capability is eroding steadily — the signature of progressive tool, fixture, or spindle wear.
  2. The escape location is migrating downstream. Final-inspection catches rose from 0 to 3, meaning the in-process control is no longer catching what it used to. This is a risk signal about the control, not only about the process.
  3. The first customer complaint arrived in August, after eight months of data that predicted it.

Action: This is a risk-assessment finding, not a nonconformance. Raise it through the control-plan review: investigate the wear mechanism, tighten the in-process frequency as an interim control, evaluate a PFMEA update for occurrence and detection ratings, and set a monitoring trigger on the Cpk trend. Waiting for a rejected lot would have converted a preventable trend into a corrective action and a customer escape.


Common Exam Traps for CQT Candidates

[!CAUTION] Trap 1: Believing ISO 9001:2015 removed preventive action. It removed the separate clause and distributed the requirement through risk-based thinking in clause 6.1. The obligation is stronger, not weaker.

Trap 2: Treating every monthly movement in a metric as a special cause. Apply control-chart logic to the metric first; reacting to noise is tampering (Section 5.1).

Trap 3: Counting defects without sorting them by where they were found. In-process, final, and customer discovery carry completely different risk meanings for the same defect.

Trap 4: Leaving the reaction plan column blank. A control plan that detects without prescribing a response leaves containment to improvisation.

Trap 5: Scoring severity down. Likelihood and detection can be improved by controls; severity changes only when the design or the consequence changes.

Trap 6: Letting the PFMEA, control plan, and work instruction drift apart. Inconsistency among the three is a systemic finding by itself.

Trap 7: Accepting a risk silently. Acceptance must be explicit, documented, monitored, and have a defined review trigger.

Loading diagram...
Risk Inputs, Assessment, Mitigation, and the Control Plan Loop
Test Your Knowledge

A machining cell has shipped no nonconforming parts in six months, but the monthly Cpk for the controlled bore diameter has fallen from 1.68 to 1.41 across five consecutive months, and catches at final inspection have risen from zero to three per month. How should a quality technician classify and act on this?

A
B
C
D
Test Your Knowledge

A production control plan for a critical fastening operation specifies the characteristic, the tolerance, a calibrated torque transducer as the measurement technique, and a sample of five parts per hour, but the reaction plan column is blank. During the shift, one sampled fastener reads below the minimum torque. What is the practical consequence of the blank column?

A
B
C
D
Test Your Knowledge

A cross-functional team reviews a risk that would be catastrophic if it occurred but is judged extremely unlikely. A team member proposes lowering the severity rating so that the calculated risk score drops below the action threshold and no resources have to be committed. How should a quality technician respond?

A
B
C
D