SCRM Supplier Compliance & Risk Management

Explainer · fundamentals

What risk-based thinking actually means.

The term has been in almost every management standard since 2015 and is regularly misread – sometimes as an obligation to build a matrix, sometimes as an empty phrase. Neither is right.

Risk-based thinking means directing your effort to where things can go wrong, and being able to explain why you divided it that way. No more, but no less either.

With the 2015 revision, ISO 9001 replaced preventive action with this principle. Since then it runs through the whole structure of management standards: in planning, in process control, in the depth of supplier assessment, in the audit programme and in management review.

What matters is what the standard does not require. ISO 9001 demands no risk register, no matrix and no particular method. It demands that risks and opportunities be determined and addressed and that effectiveness be evaluated. How is left to you – and that freedom is precisely what unsettles people.

What risk means here

The standards define it more broadly than everyday usage.

Effect of uncertainty on objectives
That is the definition. It contains neither “harm” nor “probability” – a risk can also turn out positively.
Opportunities are included
The standards deliberately say “risks and opportunities”. A new supplier can be a failure risk and simultaneously the chance to break a single source.
No obligation to quantify
A reasoned judgement suffices where it is traceable. Numbers without a basis are worse than a good two-sentence justification.
Tied to objectives
Without defined objectives no risk can be determined. Not knowing what should succeed makes it impossible to say what could fail.

Where it appears in the standards

PlaceWhat is requiredWhat that means in practice
PlanningDetermine risks and opportunities and plan actionsThink through once a year, in structure, what endangers your objectives – and record it.
Process controlDetermine type and extent of control on a risk basisNot every process needs the same density of control. The grading must be justified.
SuppliersExtent of assessment based on effect on conformityThe calibration service is assessed more deeply than office supplies – and the reason is on record.
Internal auditAudit programme considering the importance of processesAudit critical processes more often than others, rather than everything annually.
Management reviewEvaluate the effectiveness of actions on risksNot just “we collected risks” but “here is what it achieved”.

How an auditor tests it

They rarely ask for the register. They ask for the reasoning.

  1. The why questionWhy do you assess this supplier annually and that one every three years?“It has always been that way” is the classic finding. An answer referring to failure impact and replaceability is risk-based thinking.
  2. The consistency checkDoes the classification match the actual treatment?A supplier rated critical with no second source and no date for one is a contradiction that gets noticed.
  3. The effectiveness questionWhat did the action achieve?Collecting risks and changing nothing does not satisfy the requirement. The judgement belongs in management review.
  4. The currency questionWhen did you last look at this?A 2021 classification for a supplier who has since become a single source shows the thinking did not keep up.

Three common misreadings

“We need a risk matrix”
Not necessarily. A matrix is a way of presenting, not an ISO 9001 requirement. It becomes useful when many risks must be prioritised – not because a standard demands it.
“Risk-based means non-binding”
The opposite. The freedom concerns the method, not the duty. Being unable to justify a grading means having no risk-based system, not a flexible one.
“That is the quality function’s job”
Risks arise where the work happens. A collection without the operating functions produces a list nobody recognises – and nobody maintains.

The shortest test of whether your system is risk-based: take two suppliers treated differently and explain the difference in one sentence. If you cannot, what is missing is not the matrix but the criterion.

Risk-based means graded – and that has to be visible

In SCRM, criticality, depth of assessment and cycle are connected. Whoever is classified gets the matching treatment automatically, and the reasoning stays on the record.

Request a consultation How a risk assessment is built Scope and depth