Risk management

Risk is the effect of uncertainty on your objectives. Every business deals with it. The only question is whether it does so deliberately and systematically or in passing. Anyone who looks at risk systematically decides earlier, rather than under pressure.

In practice this usually ends in a spreadsheet. Once a year it is filled in, assessed and filed away. It satisfies the standard and changes nothing. A risk register that nobody uses is not worth the effort. The value is not created by writing things down. It is created when a risk turns into an action, when someone is responsible for that action, and when someone checks later whether it worked.

Who this is for

Strategic risk management

Strategic risks arise outside your own processes: in the market, in legislation, in technology. That calls for a different view than process faults do.

PESTEL

A framework for looking outwards. It covers political, economic, social, technological, environmental and legal developments. We work through the six fields with you and ask each time: what does this mean in concrete terms for your business? The result is a sound description of your context – the basis for everything that follows.

SWOT

Strengths, weaknesses, opportunities and threats on a single sheet. Strengths and weaknesses come from inside, opportunities and threats from outside. Keeping the two apart gives you the organisation's view of its environment and with it a basis for strategic decisions.

Balanced Scorecard

Strategy across four perspectives: customers, finance, internal processes, and learning and growth. For each perspective you define objectives, measures, targets and actions. That turns an intention into something measurable. And risks become visible wherever a measure stays below target for any length of time.

Operational risk management and root cause analysis

This is about what can go wrong in products, processes and equipment. And about what happens after a fault.

FMEA

Failure Mode and Effects Analysis. It identifies risks in systems, products and processes before they occur. Three variants are common: system, design and process FMEA. We facilitate the sessions and make sure that actions come out at the end, not just numbers.

HACCP

Hazard Analysis and Critical Control Points. It is the standard in the food and food supply industry. It covers production, processing and transport. The aim is effective preventive measures, critical points under control and therefore no health risk to end consumers.

Root cause analysis after incidents

After a fault, it is usually the symptom that gets fixed. The so-called correction. What matters, though, is the actual cause, so that a sensible corrective action can be determined to remove it. We work with 5 Whys and the Ishikawa cause-and-effect diagram. The fishbone diagram sorts primary and secondary causes into categories and shows the dependencies. Only once the cause is established does a corrective action hold.

What you get

How we work

  1. Review what is already there

    Usually two or three lists already exist in the business, kept in different places. We look at them and work out which of them mean the same thing.

  2. Set the context and the scale

    A workshop with the management team. First the context, via PESTEL or SWOT, then the assessment scale. Each level gets a short, binding definition. After that, nobody argues from gut feeling.

  3. Assess and prioritise the risks

    We assess together and deliberately cut back. What remains is a manageable number of risks that are genuinely talked about. The rest stays with the departments.

  4. Assign actions and connect them

    One action, one responsible person, one date per risk. The register is hooked into your management system so that it does not run alongside it. That covers clause 6.1 of ISO 9001 as well.

  5. Check effectiveness

    After the first cycle we look at what became of the actions. What worked stays. What did not is replaced.

Who handles this at our end

Marion Rammé – IRCA certified and registered QMS / EMS / OHSMS Lead Auditor #01194927

Rüdiger Rammé – IRCA certified and registered QMS / OHSMS Lead Auditor #01192806

The team in detail

How this looked in practice

Starting point: A single site, certified to ISO 9001, around 6,000 customer records in the ERP system. An internal audit raised the question of whether that customer base had ever been screened against the EU financial sanctions list. It had not. Breaching sanctions law is not a formality, it is a criminal offence.

Approach: A screening of the entire customer base against the EU consolidated financial sanctions list, which with all name variants runs to some 24,000 entries. The match runs fuzzy, because spellings differ, and first strips out legal forms and generic industry words so that not every “Trading” becomes a hit. A second, independent line of checking covers country risk: every customer based in an embargoed or high-risk country, regardless of name. The computation deliberately runs locally. The data provider's ready-made screening interface would have transmitted customer names to a third party, which opens a data protection problem of its own. This way only the download of the public list leaves the building, not a single customer record.

Result: Nine suspected matches at a deliberately low threshold, and after manual review not one of them stood up. One customer based in a high-risk country was flagged for legal clarification. Management received a report setting out the source, the method and the legal basis for each suspected match, together with instructions for checking it themselves. We also fixed the rhythm: the full base once a year, plus every new customer before the first delivery. The list changes daily, so a one-off check is worthless.

The client's name, the match list and the country analysis remain confidential.

Frequently asked questions

Can you be certified to ISO 31000?

No. ISO 31000 is a guidance standard and contains no auditable requirements. There is no accredited body that issues a company certificate for it. What is offered on the market as a certificate is either a personal qualification or a provider's own seal. The methodology is demonstrated through the management system standards that require a risk assessment.

What does it cost to set up?

Considerably less than a full management system project. Usually a workshop with the management team is enough, plus building the methodology and connecting it to your day-to-day processes. After a conversation about your business we can put a figure on it.

How many risks make sense?

Fewer than most organisations create. A medium-sized business can sensibly steer ten to twenty risks at top level. Anything beyond that is no longer discussed, only administered. Individual departments may keep more detailed views below that, such as an FMEA per process.

Who in the business needs to be involved?

Senior management, otherwise it becomes an exercise for quality management alone. Then the people responsible for the main areas, because they know the real risks. For individual topics you bring in specialists, from IT or health and safety for instance. Being involved means assessing and deciding – not just signing off a list.

How does this relate to clause 6.1 of ISO 9001?

ISO 9001 requires you to determine and address risks and opportunities. It does not say how. That is exactly the gap ISO 31000 fills, with an approach, terminology and process steps. In practice it means one methodology, one register – and clause 6.1 is covered.

Let us talk about it

The first conversation is free and without obligation. It usually takes half an hour. Afterwards you know what to expect and whether we are the right people for your project.

Prefer to write? The contact form reaches us just as well.