ISO Risk Assessment Methodology: Why 3 Registers Win

ISO RISK ASSESSMENT METHODOLOGY

Why One ISO Risk Assessment Methodology Cannot Serve Two Standards

Calibrate. Separate. Defend.

DIRECT ANSWER

An ISO risk assessment methodology is the documented way an organization scores, ranks, and accepts risk inside its management system. ISO 9001 lets you choose that method freely. ISO 13485 does not, because product-realization risk is governed by ISO 14971:2019, which requires objective acceptability criteria set in a risk management plan and measures severity as harm to a patient rather than consequence to a business. Organizations certified to both standards routinely try to run one register and one scoring scale across the pair. That single decision is the most common structural failure in ISO risk assessment methodology design, and it fails in both directions at once.

ISO risk assessment methodology

There is one sentence in ISO 14971:2019 that ends the argument before it starts. The standard states plainly that it does not apply to business risk management. Not “is less suited to.” Does not apply. Any ISO risk assessment methodology that files a supplier-insolvency risk and a patient-harm hazard into the same register, against the same severity scale, has already crossed a line the standard drew deliberately — and an FDA investigator reading that file since February 2, 2026 can see it.

This guide is not a survey of every risk technique in existence. It is a working answer to one question: what ISO risk assessment methodology can you actually defend in an audit room when you hold ISO 9001, ISO 13485, or both. It covers what each standard genuinely requires of your method, the four assessment types that belong in a quality management system, how to calibrate severity scales that will not contaminate each other, where a shared register is safe and where it is a finding, and what changes when ISO 9001:2026 publishes. It is written for quality and regulatory leaders who already hold certification and need their ISO risk assessment methodology to survive contact with a registrar.


PART 1 — THE TWO-STANDARD PROBLEM

What Your ISO Risk Assessment Methodology Must Do Under Each Standard

Choose. Prove. Document.

Most method-selection advice treats ISO 9001 and ISO 13485 as near-siblings that differ mainly in vocabulary. They do not. They were built on different structures, they impose different obligations on your method, and they hand you different amounts of freedom. Choosing an ISO risk assessment methodology without knowing which of those obligations applies to which register is how organizations end up rewriting the whole thing after their first surveillance audit.

ISO 9001 Hands You the Choice

ISO 9001 requires risk-based thinking. It does not require a risk management procedure, a risk register, a scoring scale, or a documented method. Clause 6.1 asks you to determine risks and opportunities and to plan actions to address them. It is silent on how. That silence is deliberate — a two-person service firm and a multi-site manufacturer should not be forced into the same apparatus.

The freedom is real, and it is also where most organizations get lazy. An auditor cannot fault your ISO risk assessment methodology for being simple. They can and will fault it for being undefined — for producing ratings nobody can explain, applied inconsistently across departments, with no stated basis for why a score of twelve triggers action and a score of ten does not.

Clause 4.4.1 is where that catches up with you: the QMS processes have to be determined and controlled, and a scoring method that changes depending on who is in the room is not controlled. MSI's breakdown of the risk management procedure template requirements across five standards covers exactly where ISO 9001 is the outlier and how Clause 4.4.1 closes the gap the silence opens.

ISO 13485 Carries Two Separate Risk Obligations, Not One

This is the distinction that most guidance collapses, and collapsing it is the root of a great many findings. ISO 13485:2016 imposes two different risk obligations that live in different places and answer to different rules.

Clause 4.1.2 b) — QMS process risk. The organization applies a risk-based approach to the control of the appropriate processes needed for the quality management system. This is organizational and operational: which processes get tighter control, which get more audit attention, which get validated. The method here is yours to choose, much as under ISO 9001.

Clause 7.1 — product realization risk. The organization documents one or more processes for risk management in product realization, and retains records. In practice this routes directly to ISO 14971:2019, the international standard for applying risk management to medical devices, which is where the freedom stops. Here the ISO risk assessment methodology is constrained: the risk management plan must define objective criteria for risk acceptability, the method for evaluating overall residual risk must be defined in that plan, and the results are reviewed before commercial distribution and captured in a risk management report.

One standard, two registers, two rulebooks. An ISO risk assessment methodology that acknowledges only the second one leaves Clause 4.1.2 b) unevidenced. One that acknowledges only the first leaves the device file naked. MSI's guide to ISO 13485 risk management under FDA inspection covers what happens when an investigator pulls records against the second obligation.

The Sentence in ISO 14971 That Settles It

ISO 14971:2019 states its own scope exclusions explicitly, and one of them is business risk management. The standard governs risks of harm — to the patient, the user, other persons, property, and the environment — across the full device life cycle, from conception through decommissioning and disposal. It does not govern whether your largest customer might not renew, whether a currency movement threatens margin, or whether a key engineer is a single point of failure. Those are real risks. They belong in the quality register. They do not belong in the risk management file, and an ISO risk assessment methodology that puts them there has misread the standard's own boundary.

The risk management file has a regulator reading it. The quality risk register has management reading it. They have different audiences, different purposes, and different consequences when they are wrong. Merging them does not save work — it creates a document that serves neither reader well and invites a question you cannot answer cleanly.

DIRECT ANSWER

A compliant ISO risk assessment methodology for a dual-certified organization defines three things separately: the method and criteria for ISO 9001 Clause 6.1 quality risks and opportunities, the method for ISO 13485 Clause 4.1.2 b) QMS process risk, and the ISO 14971-governed method for Clause 7.1 product realization risk. The first two can share a scale. The third cannot share one with either, because its severity dimension measures harm and its acceptability criteria are fixed in the risk management plan.


PART 2 — THE METHODS THAT BELONG

Four ISO Risk Assessment Methodology Types That Belong in a QMS

Qualitative. Scored. Structured.

Generic risk literature lists a dozen or more assessment types. Most of them were built for information security, insurance, or capital markets, and importing them into a quality management system adds vocabulary without adding defensibility. Four types do real work inside ISO 9001 and ISO 13485. A mature ISO risk assessment methodology usually runs two or three of them side by side, matched to register rather than applied uniformly.

1. Qualitative Assessment — Fast, Honest About Its Own Limits

Descriptive scales — high, medium, low — supported by structured expert judgment. Tools are risk matrices, heat maps, and facilitated workshops. A qualitative ISO risk assessment methodology is the right starting point for a Clause 6.1 quality register, for context and interested-party risks under Clauses 4.1 and 4.2, and for any organization whose historical data will not support arithmetic.

Its structural weakness is band compression. Three buckets cannot distinguish a nuisance from an existential threat when both land in “high,” and evaluator-to-evaluator variance is real. The fix is not to abandon it but to anchor it: write a one-line definition of what each band means in your business, and require the assessor to name which definition they applied. That single discipline converts a subjective matrix into something an auditor can follow.

2. Semi-Quantitative and FMEA — The Workhorse

Numerical scores assigned to qualitative categories. Failure Modes and Effects Analysis is the dominant form in both quality and device environments: rate Severity, Occurrence, and Detection, and use the result to prioritise. For most manufacturers this is the practical centre of the entire ISO risk assessment methodology, because it produces a defensible ranking without demanding statistical infrastructure the organization does not have.

One point of currency worth getting right: the Risk Priority Number is legacy practice. The 2019 AIAG-VDA harmonised FMEA handbook replaced RPN thresholds with Action Priority tables, precisely because multiplying three ordinal scales produces a number with no defensible meaning — an RPN of 100 built from severity 10 is not the same animal as an RPN of 100 built from detection 10, yet the arithmetic treats them identically.

Organizations still running RPN cut-offs are not non-conformant, but they are carrying a known analytical flaw, and an auditor who knows the handbook will ask about it. The ASQ FMEA reference is a reasonable orientation; the handbook itself is the operative document. Organizations feeding FMEA output into internal audit planning build the strongest process risk discipline, and the internal audit risk matrix shows how audit depth should follow the scoring.

3. Quantitative Assessment — Narrow but Decisive

True probability and impact modelling from historical data. Inside a quality management system the honest use cases are narrow: process capability and defect-rate modelling where the data genuinely exists, reliability and failure-rate estimation for components with population history, and post-market complaint frequency where volume supports it. A quantitative ISO risk assessment methodology is powerful exactly where the data is real and dangerous everywhere else, because false precision short-circuits the challenge that an obviously rough estimate would have invited.

The test is simple. If you cannot name the dataset and its size, the number is decoration. Most organizations reaching for quantitative methods are reaching past their data, and the resulting register looks authoritative while resting on assumptions nobody has tested.

4. Scenario and Bow-Tie Analysis — For Risks With No History

Structured narratives of how an event unfolds, including cascade and response. Bow-tie analysis is the most useful form for regulated organizations because it makes controls visible on both sides of the event — preventive controls on the cause side, mitigative on the consequence side — which maps cleanly onto how a registrar thinks about control adequacy. A scenario-based ISO risk assessment methodology is the right tool for field-action and recall decisions, supply disruption, emerging regulatory change, and any risk where historical frequency data is thin by definition.

What About NIST RMF, FAIR, and the Security Frameworks?

They are competent frameworks solving a different problem. NIST RMF and FAIR were built for information security risk, where the object is an asset or a threat actor and the output is a control selection or a dollar-value loss exposure. Neither concept maps onto the object an ISO risk assessment methodology has to address, which is a process, a product characteristic, or a hazard leading to harm.

Device organizations with connected products do need cybersecurity risk work — ISO 14971:2019 explicitly brings data and systems security within its own scope — but that work belongs in a security programme feeding the device risk file, not substituting for it. Importing a security framework into a QMS register is the most common way a well-resourced quality function ends up with documentation nobody can defend clause by clause.

Where ISO 31000 Fits

ISO 31000 is not a certifiable standard and it does not prescribe a technique. What it provides is governance architecture — principles, framework, and process — that an organization can use to hold several methods together coherently. That is genuinely useful for a multi-site or multi-standard group that needs one set of principles across diverse operations.

Its companion, IEC 31010, catalogues assessment techniques and their applicability, which is the more practical document when you are actually choosing. Neither one satisfies an ISO 9001 or ISO 13485 requirement on its own; they inform the ISO risk assessment methodology, they do not replace it. Organizations running an integrated system should read MSI's guide to the ISO 9001 and ISO 14001 transition as one plan, since a shared risk architecture is one of the main efficiencies integration actually buys.


SIDE BY SIDE

Matching ISO Risk Assessment Methodology to Register

Scan. Match. Choose.

Register Governing Requirement Method That Fits Severity Measures
Quality risks and opportunities ISO 9001 Clause 6.1; method controlled via Clause 4.4.1 Qualitative matrix with anchored band definitions, or light semi-quantitative scoring Consequence to the organization and its objectives
QMS process risk ISO 13485 Clause 4.1.2 b) Semi-quantitative process scoring; drives control tightness and audit depth Consequence to QMS effectiveness and conformity
Product realization risk ISO 13485 Clause 7.1, governed by ISO 14971:2019 Design and process FMEA plus hazard analysis, criteria fixed in the risk management plan Harm to patient, user, others, property, environment
Supplier and purchasing ISO 9001 Clause 8.4; ISO 13485 Clause 7.4 with risk proportionality Weighted scoring across quality history, capability, and single-source exposure Effect on conforming product and on continuity
Post-market and field action ISO 13485 Clauses 8.2.1 and 8.5; ISO 14971 production and post-production Scenario and bow-tie analysis; feeds back into the risk file Harm, evaluated against the original acceptability criteria
Opportunities ISO 9001 Clause 6.1.1 b) only — ISO 13485 has no opportunity concept Qualitative, in the quality register exclusively Benefit to objectives — never enters the risk management file

PART 3 — SCALE CALIBRATION

Severity Scales: Where ISO Risk Assessment Methodology Actually Breaks

Harm. Impact. Separate.

Everything above is preamble to this section. Method selection gets the attention, but in MSI's experience the failure that actually produces findings is almost never the choice of qualitative versus semi-quantitative. It is the severity scale — one scale, quietly reused across registers that measure fundamentally different things.

The Quality Severity Scale Measures Consequence to the Business

On the ISO 9001 side, a severity of 10 typically means something like: customer contract lost, regulatory sanction, production halted across sites. The scale is anchored in organizational consequence, which is exactly what Clause 6.1 is asking about — the ability to achieve intended results. A well-built quality ISO risk assessment methodology writes those anchors down so the rating is reproducible.

The ISO 14971 Severity Scale Measures Harm to a Person

On the device side, severity of 10 means death or permanent impairment. Not lost revenue. Not a customer escalation. Harm. And crucially, ISO 14971:2019 requires the acceptability criteria to be objective and set in advance, in the risk management plan — you do not get to decide after scoring that a particular residual risk is tolerable because commercially it would be inconvenient not to be. The published scope of ISO 14971:2019 confirms both points: criteria are required, acceptable levels are not specified by the standard, and business risk is outside the document entirely.

What Happens When You Merge Them

The contamination runs both ways, and neither direction is benign.

Harm scale imposed on the quality register. Business risks are systematically under-rated, because almost nothing in a commercial register reaches “permanent impairment.” A supplier concentration exposure that could stop production for a quarter scores a 3 against a harm anchor and disappears below the action threshold. Leadership then reads a register in which nothing looks urgent, which is precisely the condition under which the next disruption arrives unflagged.

Business scale imposed on the device file. This is the dangerous direction. A hazard whose commercial consequence is modest — a rarely used feature, a small installed base — gets rated low even though the harm if it occurs is severe. The ISO risk assessment methodology has now quietly traded patient safety against revenue, in a document a regulator reads.

And since February 2, 2026, when the FDA's Quality Management System Regulation took effect and incorporated ISO 13485:2016 by reference into 21 CFR Part 820, that document sits inside a federal requirement. The removal of the old §820.180(c) exemption compounds it: management review records and internal audit reports are no longer shielded from routine review, so the meeting where the scale was rationalised is now readable too.

DIRECT ANSWER

Keep the severity scales separate and build one bridge. A defensible ISO risk assessment methodology runs a harm-anchored scale in the ISO 14971 risk management file and a consequence-anchored scale in the quality register, then defines a single translation rule stating what organizational response each band triggers. That rule — not a shared scale — is what lets leadership prioritise across registers without letting either scale corrupt the other.

The Bridge: Common Response Tiers, Not Common Scores

The integrating layer that makes a multi-register ISO risk assessment methodology work is a response tier map. Rather than forcing both registers onto one number, define three or four organizational response levels — for example: monitor at review cadence, action plan with named owner and date, escalate to management review, stop and remediate before proceeding — and state which band in each scale maps to which tier. A device hazard at harm level 9 and a supply exposure at business consequence level 9 may both land in “escalate to management review,” and that is the comparison leadership actually needs. They do not need the two nines to mean the same thing, because they do not.

Organizations typically report that defining these tiers is the hardest conceptual work in the whole exercise and the piece that delivers most of the value. It is also the piece that survives an audit best, because it gives you a written answer to the question every capable auditor eventually asks: show me how you decided this one mattered more than that one.


PART 4 — SHARED OR SEPARATE

When a Shared Register Is Safe and When It Is a Finding

Share. Split. Prove.

Separation does not mean duplication of everything. Plenty of the apparatus can and should be shared, and an ISO risk assessment methodology that duplicates unnecessarily will not be maintained. The line runs through the acceptability decision, not the paperwork.

Element Share It? Why
Governing procedure document Yes One procedure can describe both processes, provided it names them separately and states which applies where
Identification and workshop technique Yes How you surface risks is method, not acceptance; the same facilitation works for both
Review cadence and governance Yes Both feed management review; a single cadence is more likely to actually happen
Response tier definitions Yes — deliberately This is the bridge that makes cross-register prioritisation possible
Severity scale and anchors No Harm and business consequence are different dimensions; sharing corrupts both
Acceptability criteria No ISO 14971 fixes device criteria in the risk management plan; quality criteria are yours to set
The register itself No The risk management file has a defined content and a regulator reading it; do not dilute it
Opportunity entries Never ISO 13485 has no opportunity concept; an opportunity in a device risk file is an unforced error

PART 5 — WHAT CHANGES IN 2026

How ISO 9001:2026 Reshapes ISO Risk Assessment Methodology Choice

Sharper. Stricter. Sooner.

ISO 9001:2026 is scheduled to publish on 16 September 2026, the Final Draft ballot having closed in July with technical content frozen. Reporting through the revision cycle has pointed consistently toward a sharpened distinction between risks and opportunities, alongside strengthened treatment of resilience, supply chain, change management, and organizational knowledge.

The standard will not mandate a particular ISO risk assessment methodology. It never has, and there is no indication it is starting. What changes is the standard of evidence your existing method will be read against. A register that files risks and opportunities into one undifferentiated list, scored on one scale, has always been weak practice; against a sharpened distinction it becomes harder to defend as a considered approach rather than an inherited one.

DIRECT ANSWER

Do not rebuild your ISO risk assessment methodology for ISO 9001:2026 before the published text is in hand. Do three things now that will hold regardless: separate opportunity entries from risk entries so they can be evaluated on their own terms, write down the anchors behind each severity band, and confirm that risk output demonstrably reaches management review and changes something. Every one of those is defensible under the 2015 edition and will be needed under the 2026 one.

One dependency worth planning around: certification body accreditation lags publication, so the first certificates against the new edition are not expected before the middle of 2027. That is scheduling relief, not permission to wait — the organizations that transition calmly are the ones that used the gap. MSI's guides to the ISO 2026 transition deadline and the ISO 9001 gap analysis turn the window into a work list. Device organizations should note a separate point of currency: ISO 19011:2026 published in May 2026 and withdrew the 2018 edition immediately with no transition period, so any risk-based audit programme still citing ISO 19011:2018 references a withdrawn document. MSI's breakdown of the six edits ISO 19011:2026 requires covers the specific changes.


PART 6 — SELECTION CRITERIA

Five Questions That Settle Your ISO Risk Assessment Methodology

Ask. Answer. Decide.

Selecting an ISO risk assessment methodology is not about finding the best method in the abstract. It is about finding the defensible fit for a specific set of registers and obligations. Five questions, answered honestly, settle it in most organizations.

Question 1 — Which Registers Do You Actually Have?

Before anything else, enumerate them. ISO 9001 only means one quality register with an opportunity dimension. ISO 13485 only means two — process risk under Clause 4.1.2 b) and product risk under Clause 7.1, with no opportunities anywhere. Both means three. Organizations that skip this step build one register, discover the gap at audit, and rebuild. Get the count right and the rest of the ISO risk assessment methodology follows more or less mechanically.

Question 2 — Can You Name the Data Behind Your Numbers?

If you cannot name the dataset and roughly its size, you are running a semi-quantitative ISO risk assessment methodology wearing quantitative clothing. That is not a violation, but calling it what it is prevents the false-authority problem. MSI client experience suggests that organizations adopting methods beyond their data envelope tend to abandon them within about eighteen months, leaving a documentation residue that reads as compliant and provides no live protection.

Question 3 — Where Is the Regulatory Floor?

Check what is mandated before considering what is preferable. For device organizations the floor moved on 2 February 2026 and is now federal in the United States. For ISO 13485 holders the acceptability criteria requirement is not negotiable. For ISO 9001-only organizations there is effectively no floor on method, which shifts the question from what is required to what you can evidence. Sector standards from bodies such as AAMI may add further expectations, and accreditation oversight now sits with Global ACI following its replacement of the previous arrangements on 1 January 2026.

Question 4 — What Decision Does the Output Have to Support?

Match the method to the decision. Audit programme scoping needs a clear ranking, so semi-quantitative scoring works and pure high-medium-low does not differentiate enough. Design release needs a documented acceptability determination against pre-set criteria, which is ISO 14971 territory and nothing else will do. Management review needs comparability across registers, which is what the response tier bridge provides. Strategic conversation needs scenarios. An ISO risk assessment methodology chosen without reference to the decision it feeds will produce output nobody uses.

Question 5 — Can You Sustain It Through Two Surveillance Cycles?

The honest maintenance test. A simple ISO risk assessment methodology that is actually run beats a sophisticated one that is reconstructed the week before the audit. Registers that go stale between surveillance visits are visible — the dates cluster, the entries have not changed, and the reviewer notices. Choose for the cadence you will genuinely keep, and build capability upward from there rather than starting at the top and decaying.


PART 7 — PATTERNS FROM PRACTICE

ISO Risk Assessment Methodology Patterns From MSI Client Experience

Composite. Anonymized. Instructive.

The patterns below are composite anonymizations drawn from across MSI's 200+ audits attended. They illustrate how organizations that hold more than one standard arrive at a workable ISO risk assessment methodology — and what they had to unlearn first.

Pattern 1 — Dual-Certified Device Manufacturer: Three Registers, One Bridge

A manufacturer holding both ISO 9001 and ISO 13485 typically arrives carrying a single register built years earlier on the quality side, with the device hazard analysis grafted on. The unwinding follows a predictable order: split the product realization entries into a proper ISO 14971 file with criteria stated in the risk management plan, stand up a distinct process-risk view for Clause 4.1.2 b) that drives control tightness and audit depth, leave the quality register holding business and opportunity entries, then build response tiers as the bridge. The ISO risk assessment methodology that results is not more complex to run — it is three narrower jobs instead of one impossible one.

Organizations typically report that the QMSR transition is what finally forced the split, because an investigator reading from the standard does not accept a harm determination made on a commercial scale. The work was overdue in every case; the regulation supplied the deadline.

Pattern 2 — Multi-Site Healthcare Network: Standardising Without Flattening

Regional networks reliably present the same problem: every facility built its own ISO risk assessment methodology, so nothing is comparable at group level. The instinct is to impose one scale everywhere, which fails because clinical process risk and facility operational risk are not the same object. What works better is standardising the method for clinical patient-safety risk — usually a facilitated FMEA with common anchors — while allowing operational risk to stay locally scored, with group-level response tiers providing the comparability leadership actually needed.

Phased rollout beats comprehensive coverage; start with the highest-priority clinical processes, demonstrate the value, then extend. MSI's work on operational efficiency under pressure applies directly to how that rollout is staged, and the expanding ISO 7101 healthcare quality work is where much of this now lands.

Pattern 3 — Manufacturer After a Supply Disruption

Manufacturers with international supplier networks frequently discover, after one disruption, that their supplier matrix was scoring the wrong dimensions entirely. A strong rating on contract terms and delivery history says nothing about geographic concentration, single-point-of-failure dependency, or cascade exposure. The rebuild that holds adds those dimensions explicitly to the weighted score rather than adding a new method, and maps the complete value chain to surface dependencies that never felt like risks because nothing had gone wrong yet.

Organizations typically report that the mapping — not the scoring change — produced most of the value. MSI's alliance with CAQ AG Factory Systems supports organizations needing software-supported integration of that data into the wider QMS, and ISO compliance automation covers where tooling helps and where it does not.


PART 8 — COMMON MISTAKES

Five ISO Risk Assessment Methodology Mistakes That Waste the Work

Spot. Stop. Strengthen.

Mistake 1 — One Scale Across Every Register

The central error, covered above, and worth restating because it is so common. Harm and business consequence are different dimensions. An ISO risk assessment methodology that scores them identically is not simpler — it is producing two wrong answers instead of two right ones. The fix is separate scales joined by response tiers.

Mistake 2 — Opportunities Filed Into the Device Risk File

A direct consequence of building the device system on an ISO 9001 base. ISO 13485 contains no opportunity concept, and ISO 14971 governs harm. An opportunity entry sitting in a risk management file signals to a reviewer that the boundary is not understood, which invites scrutiny of everything else in the file. Keep opportunities in the quality register where Clause 6.1.1 b) put them.

Mistake 3 — Unwritten Band Anchors

Ratings that cannot be reproduced because nothing states what a 7 means. This is the single easiest defect to fix and the one most often left. Write one line per band. The ISO risk assessment methodology becomes auditable the moment the anchors exist, and inter-assessor variance drops immediately.

Mistake 4 — Importing a Framework Verbatim

Adopting a published framework without adapting the criteria to the organization's actual processes and context. The generic artifact becomes disconnected from operations, producing output that is technically correct and practically ignored. Customization is not optional, and it is the part consultants are genuinely useful for. MSI's guide on tailoring management system standards covers the principle across the wider QMS.

Mistake 5 — Assessment That Changes Nothing

The register grows; the audit plan, the capital plan, and the supplier qualification process do not move. If no decision changed, the ISO risk assessment methodology is theatre, and a capable auditor will find that out by asking what the last high-rated risk actually caused to happen. Build the link explicitly: risk output into audit programme scope, into management review inputs, into resource decisions. MSI's guide on risk mitigation through internal audit and the work on internal audit risk mitigation strategies both cover how that linkage is evidenced.

Four of these five are documentation failures wearing a methodology costume — the approach was defensible, the procedure behind it was not. The MSI risk management procedure template and the wider library of ISO procedure templates and guides close that gap directly, and ISO procedure order covers where risk sits in the writing sequence.


PART 9 — IMPLEMENTATION

Your ISO Risk Assessment Methodology Implementation Plan

Separate. Anchor. Bridge. Prove.

Phase 1 — Register Inventory (Weeks 1-2)

List every place risk is currently recorded, including the spreadsheets that are not officially registers. Map each to the clause it is meant to satisfy. Identify entries sitting in the wrong file — business risks in the device file, hazards in the quality register, opportunities anywhere they should not be. Most organizations find their ISO risk assessment methodology is already three methods operating without acknowledgment, which makes the next phase a formalisation rather than a rebuild.

Phase 2 — Scale Anchoring (Weeks 3-4)

Write the band definitions for each scale, separately. Harm anchors for the ISO 14971 file, consequence anchors for the quality register, process-impact anchors for QMS process risk. Then define the response tiers and map each band to a tier. This is the conceptual core of the ISO risk assessment methodology and it deserves the calendar time; rushing it produces anchors nobody uses.

Phase 3 — Rescore and Pilot (Weeks 5-10)

Rescore one register against the new anchors before touching the others. Watch what moves. Entries that jump bands are telling you where the old scale was distorting, and those movements are the evidence that justifies the rest of the project internally. Document the rationale for significant changes, because a reviewer comparing this year's register to last year's will ask.

Phase 4 — Wire It Into Governance (Months 3-6)

Connect the output to the decisions. Risk ratings drive internal audit programme scope. Response tiers determine what escalates to management review under ISO 9001 Clause 9.3 and ISO 13485 Clause 5.6. Post-market signals route back into the risk file. Set the review cadence and hold it. A well-wired ISO risk assessment methodology stops being a document you maintain and becomes the mechanism that decides where attention goes, which is the only version that survives long term.


READY TO MOVE

Stop Writing the Risk Procedure From Scratch at 11pm

You have picked the method. Now it has to become a procedure that says how risk gets identified, scored, escalated, accepted, and reviewed — with the criteria worksheet attached and the registers already formatted. MSI's ISO procedure templates cover ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001 and ISO 7101, every procedure written to one architecture so the set interlocks the day you open it. Editable Word. Judgment calls already made by consultants who sit in certification audits. Twenty-eight years of practice, written down.

Browse the ISO Procedure Templates and Guides →

Not sure which registers you are actually required to run, or whether your severity scales are contaminating each other? Talk it through before you rebuild anything. Plan a session with MSI: 760-434-9141

WHERE RISK OUTPUT HAS TO LAND

Your Risk Ratings Are Only Real If Management Review Acts on Them

Every response tier that escalates has to land somewhere, and that somewhere is management review — required under ISO 9001 Clause 9.3, ISO 13485 Clause 5.6, ISO 14001, ISO 45001 and ISO 7101. Since the QMSR took effect, those minutes are FDA-readable for device organizations, which means the meeting where you discussed your risk profile is now part of the inspection surface. MSI's Management Review Toolkits give you the agenda, the input checklist, the deck, and the minutes format that shows a decision was actually made.

See the ISO Management Review Toolkits →

If the rebuild is bigger than a procedure — a full certification project, or a system that needs year-round attention — SurePath handles turnkey ISO certification with risk-based thinking built in from the start, and SureResults keeps the system current between surveillance visits. For organizations that want the register pressure-tested by someone who sits on the other side of the table, MSI's contracted internal audit work does exactly that.


FREQUENTLY ASKED

ISO Risk Assessment Methodology Questions Auditors Actually Ask

Ask. Answer. Apply.

Does ISO 9001 require a documented risk assessment methodology?

DIRECT ANSWER

No. ISO 9001 requires risk-based thinking under Clause 6.1 but does not require a documented risk management process, a register, or a specific ISO risk assessment methodology. However, Clause 4.4.1 requires QMS processes to be determined and controlled, and a scoring approach that cannot be reproduced consistently is not controlled. In practice most certified organizations document the method because it is easier to defend than to explain.

The distinction matters when an auditor challenges your approach. You are not obliged to produce a procedure, but you are obliged to show the process is controlled. Written band anchors and a stated action threshold satisfy that in a page. MSI's guide to ISO 9001 benefits covers how smaller organizations build this maturity without overbuilding documentation.

Can I use one risk register for ISO 9001 and ISO 13485?

DIRECT ANSWER

Not for product realization risk. ISO 14971:2019 governs the device risk management file, requires acceptability criteria set in the risk management plan, and explicitly excludes business risk management from its scope. A single register merging quality risks with device hazards puts entries in a file where the standard says they do not belong. A dual-standard ISO risk assessment methodology can share the governing procedure, the identification technique, and the review cadence; the register, the severity scale, and the acceptability criteria cannot be shared.

Does ISO 13485 require FMEA?

DIRECT ANSWER

No. Neither ISO 13485 nor ISO 14971 names FMEA as a required technique. Clause 7.1 requires a documented process for risk management in product realization, and ISO 14971 requires objective acceptability criteria — but the specific ISO risk assessment methodology is yours to select and justify. FMEA is near-universal in the sector because it fits design and process hazards well, not because it is mandated. Hazard analysis, fault tree analysis, and bow-tie approaches are all defensible where they suit the object being assessed.

Where do opportunities go if ISO 13485 has no opportunity concept?

DIRECT ANSWER

In the ISO 9001 quality register, and only there. Clause 6.1.1 b) makes determining opportunities an ISO 9001 obligation. ISO 13485 contains no opportunity requirement anywhere, and an opportunity entry inside an ISO 14971 risk management file signals to a reviewer that the scope boundary is not understood. Dual-certified organizations should keep an explicit rule in the ISO risk assessment methodology stating that opportunities never enter the device file.

MSI's risk management procedure template guide works through where each of the five standards sits on opportunities and criteria, including the three that require documented criteria explicitly.

Is the Risk Priority Number still acceptable?

DIRECT ANSWER

Acceptable but dated. No ISO standard requires or forbids RPN, so an ISO risk assessment methodology using RPN thresholds is not non-conformant. The 2019 AIAG-VDA harmonised FMEA handbook replaced RPN with Action Priority tables because multiplying three ordinal scales yields a figure with no stable meaning — a high score driven by severity is a different problem from the same score driven by detection. Organizations still on RPN should at minimum add a severity override rule so high-severity items cannot be filtered out by a low product.

How often should the risk assessment methodology be reviewed?

DIRECT ANSWER

Review the ISO risk assessment methodology itself annually through management review, and review the registers on a cadence matched to their volatility — device hazard files on design change and post-market signal, quality registers quarterly in most organizations. Trigger an off-cycle methodology review after a merger, a new product line, a regulatory change, or any instance where a material risk materialised that the method should structurally have surfaced.

The last trigger is the most informative and the least used. When something goes wrong, the useful question is not only what the risk was but whether the method was capable of finding it. MSI's ISO 13485 management review playbook covers how that discussion should read in the minutes now those records are inspectable.

Should small organizations use a formal methodology at all?

DIRECT ANSWER

Yes, but scaled honestly. A one-page ISO risk assessment methodology with written band anchors, a stated action threshold, and a quarterly review beats an elaborate framework nobody maintains. Small device organizations still need the ISO 14971 file done properly — that obligation does not scale down — but the quality register can be a spreadsheet with defined columns. Start where you can sustain it and add rigour as the operation grows.

Do we need ISO 31000 to satisfy ISO 9001 or ISO 13485?

DIRECT ANSWER

No. ISO 31000 is guidance, not a certifiable requirement, and neither ISO 9001 nor ISO 13485 references it normatively. It is useful as governance architecture for a group running several standards or sites that wants one set of risk principles, and its companion IEC 31010 is genuinely helpful when choosing techniques. Neither one discharges a clause obligation on its own, so an ISO risk assessment methodology built purely on ISO 31000 will still need the clause-level criteria written down.


THE BOTTOM LINE

A Defensible ISO Risk Assessment Methodology Is a Calibration Problem

See. Separate. Defend.

Most of the energy spent on risk method selection goes into the wrong question. Qualitative or semi-quantitative, matrix or FMEA — these are real choices, but they are rarely what fails. What fails is a single severity scale quietly doing two incompatible jobs, and acceptability criteria that were never written down because nobody realised one standard required them and the other did not.

Get the register count right. Anchor each scale in the dimension its standard actually measures. Build one bridge of shared response tiers so leadership can still prioritise across the whole picture. That is the entire architecture, and an ISO risk assessment methodology built that way survives a registrar, an FDA investigator, and the more difficult test of still being used two years later.

If your current register produces the same ratings year over year, or the last real surprise was something the method should structurally have caught, that is the signal to revisit the calibration rather than the technique. A planning session moves that forward faster than internal debate, and organizations working with an ISO consulting partner most often cite audit-room calibration as the reason they engaged one. MSI's guide to risk culture transformation covers the organizational half of the work, and AI risk management under ISO discipline covers where the newest category of risk lands in this architecture.

RELATED READING

More on ISO Risk Assessment Methodology and Related Standards

Read. Reference. Refine.

Standards and primary sources

Related MSI guides, products and services


About Management Systems International (MSI)

Management Systems International (MSI) is a veteran-owned, female-owned ISO consulting firm founded in 1998. With 28 years of experience — including extensive AS9100 work in MSI's early years — MSI has supported 80+ certifications, attended 200+ audits, and trained 600+ professionals across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101.

Phone: 760-434-9141 · Web: msi-international.com

Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 15 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply