Most of what I see on site is a risk matrix in a spreadsheet, and the tool is rarely the problem. The trouble is that the register lists risks in general terms and never connects to a decision, so the same scores come back year after year and nothing changes. Bow tie earns its keep for exactly that reason, because it forces you to name the barrier and who owns it rather than just scoring a hazard.
When I audit against 9001 or 14001 I do not really ask what tool they used. I take one significant aspect or one key process, ask what could go wrong, then look for the control they said they put in and the evidence it is working. If the risk register cannot be traced into an objective, a control or a competence requirement, it is a document rather than a method.
------------------------------
Dilawar Laghari
Auditor, Consultant and Trainer
AuditWorkshop.com
------------------------------
Original Message:
Sent: 08-03-2026 11:49 PM
From: Dilawar Laghari
Subject: Risk Assessment in Management Systems: Tools for ISO 31000 Auditors
Most of what I see on site is a risk matrix in a spreadsheet, and the tool is rarely the problem. The trouble is that the register lists risks in general terms and never connects to a decision, so the same scores come back year after year and nothing changes. Bow tie earns its keep for exactly that reason, because it forces you to name the barrier and who owns it rather than just scoring a hazard.
When I audit against 9001 or 14001 I do not really ask what tool they used. I take one significant aspect or one key process, ask what could go wrong, then look for the control they said they put in and the evidence it is working. If the risk register cannot be traced into an objective, a control or a competence requirement, it is a document rather than a method.
------------------------------
Dilawar Laghari
Auditor, Consultant and Trainer
AuditWorkshop.com
------------------------------