Global Community

 View Only

  • 1.  Risk Assessment in Management Systems: Tools for ISO 31000 Auditors

    Posted 13 hours ago

    Apply bow-tie analysis for quality/environmental risks.

    Tools: Risk matrices in Excel or software like BowTieXP. I've used it to prioritize EMS threats.

    Your favorite tools? How do you integrate with ISO standards?



    ------------------------------
    Francisco J. Tapia Guerrero
    ftapia@qualitascertification.com
    www.linkedin.com/in/franktapiaguerrero
    ------------------------------


  • 2.  RE: Risk Assessment in Management Systems: Tools for ISO 31000 Auditors

    Posted 6 hours ago

    Most of what I see on site is a risk matrix in a spreadsheet, and the tool is rarely the problem. The trouble is that the register lists risks in general terms and never connects to a decision, so the same scores come back year after year and nothing changes. Bow tie earns its keep for exactly that reason, because it forces you to name the barrier and who owns it rather than just scoring a hazard.

    When I audit against 9001 or 14001 I do not really ask what tool they used. I take one significant aspect or one key process, ask what could go wrong, then look for the control they said they put in and the evidence it is working. If the risk register cannot be traced into an objective, a control or a competence requirement, it is a document rather than a method.



    ------------------------------
    Dilawar Laghari
    Auditor, Consultant and Trainer
    AuditWorkshop.com
    ------------------------------



  • 3.  RE: Risk Assessment in Management Systems: Tools for ISO 31000 Auditors

    Posted 6 hours ago

    Most of what I see on site is a risk matrix in a spreadsheet, and the tool is rarely the problem. The trouble is that the register lists risks in general terms and never connects to a decision, so the same scores come back year after year and nothing changes. Bow tie earns its keep for exactly that reason, because it forces you to name the barrier and who owns it rather than just scoring a hazard.

    When I audit against 9001 or 14001 I do not really ask what tool they used. I take one significant aspect or one key process, ask what could go wrong, then look for the control they said they put in and the evidence it is working. If the risk register cannot be traced into an objective, a control or a competence requirement, it is a document rather than a method.



    ------------------------------
    Dilawar Laghari
    Auditor, Consultant and Trainer
    AuditWorkshop.com
    ------------------------------