Section 1.3: Process Approach, Risk-Based Thinking, and the PDCA Cycle
Key Takeaways
- Clause 4.4 requires the organization to define and manage its processes, including inputs, outputs, sequence, interactions, resources, and KPIs.
- SIPOC maps and Turtle Diagrams are key visual tools used by Lead Auditors to plan process-based audits and trace audit trails.
- The Plan-Do-Check-Act (PDCA) cycle is the operating logic of the standard, mapping directly to Clauses 4-6 (Plan), 7-8 (Do), 9 (Check), and 10 (Act).
- Risk-based thinking is integrated throughout the QMS to prevent failures, replacing the old standalone preventive action clause.
- ISO 9001 does not mandate a formal risk register or compliance with ISO 31000; the auditor must evaluate risk compliance without prescribing specific tools.
Process Approach, Risk-Based Thinking, and the PDCA Cycle
The modern ISO 9001:2015 standard is structured around three core concepts: the process approach, risk-based thinking, and the Plan-Do-Check-Act (PDCA) cycle. Together, these concepts form a single, integrated methodology for designing, implementing, and auditing a Quality Management System. A Lead Auditor must understand how these concepts interact, as they determine the audit methodology (process-based auditing) and how the auditor evaluates risk compliance without forcing prescriptive solutions on the auditee.
The Process Approach and Clause 4.4
The process approach requires an organization to manage its activities as a system of interrelated processes rather than isolated departmental silos. Historically, organizations were audited by department: the auditor visited the Sales Department, then the Design Department, and then the Production Department. This approach often missed the gaps, communication breakdowns, and failures that occur at the handoffs between departments.
Clause 4.4 of ISO 9001:2015 establishes the requirements for the process approach. The organization must determine:
- The inputs required and the outputs expected from each process.
- The sequence and interaction of these processes.
- The resources needed and their availability.
- The assignment of responsibilities and authorities.
- The risks and opportunities associated with the process (linking to Clause 6.1).
- The methods, criteria, and performance indicators (KPIs) needed to ensure effective operation and control.
Visual Audit Planning Tools: SIPOC and the Turtle Diagram
Lead Auditors use visual tools to plan process-based audits:
- SIPOC (Suppliers, Inputs, Process, Outputs, Customers): This tool helps map a process at a high level. It identifies who supplies the inputs, what those inputs are, the core steps of the process, the outputs generated, and who receives those outputs.
- The Turtle Diagram: This tool analyzes a single process in detail by looking at its interfaces:
- Body (The Process): The core steps/activities.
- Head (Inputs): What raw materials, information, or requirements enter the process.
- Tail (Outputs): What products, services, or data leave the process.
- Leg 1 (With What - Resources): Equipment, machinery, software, and infrastructure.
- Leg 2 (With Whom - Competence): Personnel, training, skills, and qualifications.
- Leg 3 (How - Methods): Procedures, instructions, specifications, and guidelines.
- Leg 4 (How Many - Measures): KPIs, metrics, performance indicators, and quality objectives.
By mapping a process with a Turtle Diagram, an auditor can systematically plan which questions to ask and which records to sample.
The Plan-Do-Check-Act (PDCA) Cycle
The PDCA cycle is a four-step iterative management method used for the control and continuous improvement of processes and products. ISO 9001:2015 is structured around the PDCA cycle, mapping its clauses directly to this loop:
- Plan (Clauses 4, 5, and 6): Establish the objectives of the system and its processes, and the resources needed to deliver results in accordance with customer requirements and the organization's policies. It includes understanding the context of the organization (Clause 4), leadership commitment (Clause 5), and quality planning and risk management (Clause 6).
- Do (Clauses 7 and 8): Implement what was planned. This covers support activities and resource management (Clause 7) and operational execution, including design, production, and release of products and services (Clause 8).
- Check (Clause 9): Monitor and measure processes, products, and services against policies, objectives, requirements, and planned activities, and report the results. This is the performance evaluation phase, including customer satisfaction feedback, data analysis, internal audits, and management reviews.
- Act (Clause 10): Take actions to improve performance, address nonconformities, and implement corrective actions to prevent recurrence.
During an audit, the Lead Auditor uses the PDCA cycle to verify the QMS is functional and self-correcting. If an auditor finds that an organization plans objectives (Plan) and manufactures products (Do), but does not analyze customer complaints or run internal audits (Check) or take corrective action (Act), the QMS is not functioning as a cycle, resulting in systemic nonconformity.
Risk-Based Thinking: Concepts and Auditor Guidelines
One of the most significant changes in the ISO 9001:2015 revision was the formal introduction of risk-based thinking, which replaced the standalone 'preventive action' clause of the 2008 edition. The rationale was that prevention should be integrated into all aspects of the QMS, rather than being treated as a separate, reactive process.
Tracing Risk-Based Thinking in ISO 9001:2015
Risk-based thinking is integrated throughout the clauses:
- Clause 4.4: Determine risks and opportunities for QMS processes.
- Clause 5.1.2: Top management must promote risk-based thinking.
- Clause 6.1 (Actions to address risks and opportunities): The primary planning requirements where the organization must plan actions to address identified risks and integrate them into QMS processes.
- Clause 9.1.3: Analyze and evaluate the effectiveness of actions taken to address risks.
- Clause 9.3: Management review must review the effectiveness of risk actions.
- Clause 10.2: Corrective actions must be appropriate to the effects of the nonconformities encountered (risk-proportionate response).
The Auditor's Rule of Non-Prescription
A critical concept tested on Lead Auditor exams is that ISO 9001:2015 does not require a formal risk management process, a risk register, or compliance with ISO 31000. The standard requires that risks and opportunities are determined and addressed, but the method is up to the organization. For a low-risk, small service business, risk-based thinking might be demonstrated through SWOT analysis documented in management meeting minutes. For a high-risk medical device manufacturer, it may require formal FMEA (Failure Mode and Effects Analysis) and a quantitative risk register. Both approaches can conform. An auditor must never write a nonconformity citing a 'lack of a formal risk register' or a 'failure to use risk matrices' unless the organization's own documented procedures mandate it. The auditor's role is to verify that risks and opportunities have been determined, actions have been planned and implemented, and the effectiveness of these actions has been evaluated. If the organization has done this through informal but verified means, they are in conformity.
An organization uses SWOT analysis, operational meetings, and customer feedback logs to determine risks and opportunities. However, they do not have a formal risk register or a written risk management procedure. An auditor wants to write a nonconformity for a lack of a formal risk register. How should this be evaluated?
An auditor wants to plan a process audit of the shipping department. They want to check the inputs, equipment resources, personnel competency, procedures followed, metrics monitored, and outputs. Which tool is best suited for this?
An organization has documented its processes and quality objectives, allocated resources, and executed production as planned. However, they do not run internal audits, monitor process KPIs, or perform management reviews. Which phase of the PDCA cycle has failed?