SP-002-001 Process risk management
Purpose
To define the methodology for identifying, assessing, monitoring, and controlling risks related to Quality Management System (QMS) processes. This procedure ensures that process risks are systematically managed to maintain the effectiveness of the QMS and support continuous improvement.
This specific procedure addresses process risks — risks that could affect the effectiveness of QMS processes and quality management activities. Product risks related to medical device safety and performance are managed according to GP-013 Risk management, which follows ISO 14971 requirements.
Scope
All processes defined in the QMS Process Map (Annex-2 Process map), including but not limited to:
- Management processes
- Operational processes
- Support processes
Definitions
- Process risk: The possibility that a process may not achieve its intended objectives or may negatively impact other processes, product quality, or regulatory compliance.
- Risk identification: The systematic process of finding, recognizing, and describing process risks.
- Risk assessment: The overall process of risk analysis and risk evaluation for processes.
- Risk control: Actions implemented to eliminate or reduce process risks to acceptable levels.
- RPN (Risk Priority Number): A numerical value calculated as Severity × Probability × Detection, used to prioritize process risks.
Responsibilities
JD-001
To approve the process risk assessments and ensure adequate resources are allocated for risk control measures.
JD-004
To coordinate the process risk management activities, maintain the T-002-010 Process risk register, and monitor the effectiveness of risk control measures.
JD-003
To participate in the identification and assessment of process risks related to technical and design processes.
JD-005
To participate in the identification and assessment of process risks related to validation, clinical, and technical processes.
Process owners
To identify and report process risks within their areas of responsibility, implement risk control measures, and monitor their effectiveness.
Inputs
- Process validation results (
T-002-007 Process validation card) - Quality indicators data (
T-002-003 Quality indicators) - Audit findings (
GP-003 Audits) - Non-conformities and CAPAs (
GP-006 Non-conformity. Corrective and preventive actions) - Customer feedback and complaints
- Changes in regulatory requirements
- Management review outputs
Outputs
T-002-010 Process risk register- Risk control measures and action plans
- Updated process validation cards
- Input for management review
Development
Process risk identification
Process risks shall be identified considering the following sources:
-
Process validation: During the validation of each process, potential risks are identified and documented in the
T-002-007 Process validation card. -
Quality indicators: Deviations from expected indicator values may indicate process risks that need to be addressed.
-
Internal and external audits: Findings from audits may reveal process weaknesses or risks.
-
Non-conformities: Recurring non-conformities may indicate underlying process risks.
-
Changes: Any change to processes, equipment, personnel, or regulatory requirements shall trigger a risk review.
-
SWOT analysis: The annual SWOT and CAME analysis performed during the Management Review (documented in
T-002-004 Annual management review report) may identify strategic risks affecting processes.
Process risk categories
Process risks shall be categorized according to their nature:
| Category | Description | Examples |
|---|---|---|
| Operational | Risks related to day-to-day process execution | Equipment failure, human error, resource unavailability |
| Compliance | Risks related to regulatory or standard requirements | Non-compliance with ISO 13485, MDR requirements gaps |
| Strategic | Risks affecting long-term QMS objectives | Technology obsolescence, market changes |
| Resource | Risks related to human, financial, or infrastructure resources | Key personnel loss, budget constraints |
| External | Risks from external factors | Supplier failures, regulatory changes, force majeure |
Process risk assessment
Severity assessment
The severity of a process risk is assessed based on its potential impact:
| Score | Severity | Description |
|---|---|---|
| 1 | Negligible | Minor impact, easily corrected, no effect on QMS effectiveness |
| 2 | Minor | Limited impact, correctable with minor effort, minimal effect on QMS |
| 3 | Moderate | Noticeable impact, requires significant effort to correct, affects QMS effectiveness |
| 4 | Major | Significant impact on QMS, may affect product quality or compliance |
| 5 | Critical | Severe impact, regulatory non-compliance, potential product safety issues |
Probability assessment
The probability of occurrence is assessed as follows:
| Score | Probability | Description |
|---|---|---|
| 1 | Remote | Unlikely to occur (< 1% chance) |
| 2 | Low | Could occur occasionally (1-10% chance) |
| 3 | Moderate | May occur sometimes (10-30% chance) |
| 4 | High | Likely to occur (30-60% chance) |
| 5 | Very high | Expected to occur (> 60% chance) |
Detection assessment
The ability to detect the risk before it causes impact:
| Score | Detection | Description |
|---|---|---|
| 1 | Almost certain | Risk will almost always be detected before impact |
| 2 | High | High probability of detection |
| 3 | Moderate | Moderate probability of detection |
| 4 | Low | Low probability of detection |
| 5 | Remote | Risk is unlikely to be detected |
Risk Priority Number (RPN) calculation
The RPN is calculated as:
The maximum RPN is 125 (5 × 5 × 5).
Risk acceptability criteria
| RPN Range | Risk Level | Required Action |
|---|---|---|
| 1-15 | Low | Monitor, no immediate action required |
| 16-40 | Medium | Implement risk reduction measures within 6 months |
| 41-75 | High | Implement risk reduction measures within 3 months |
| 76-125 | Critical | Immediate action required, escalate to management |
Process risk control
When process risks exceed acceptable levels, risk control measures shall be implemented following this hierarchy:
- Elimination: Remove the risk source entirely (e.g., automate error-prone manual processes)
- Substitution: Replace the risky element with a safer alternative
- Engineering controls: Implement process changes or safeguards
- Administrative controls: Procedures, training, and work instructions
- Monitoring: Enhanced monitoring and detection measures
Each risk control measure shall be documented in the T-002-010 Process risk register including:
- Description of the control measure
- Responsible person
- Implementation deadline
- Verification method
- Expected residual RPN
Process risk monitoring
Process risks shall be monitored through:
-
Quarterly review: The
JD-004reviews theT-002-010 Process risk registerquarterly to assess:- Status of risk control measures
- Effectiveness of implemented controls
- New risks identified
- Changes in existing risk levels
-
Annual management review: Process risks are reviewed during the annual management review and documented in the
T-002-004 Annual management review report. -
Triggered reviews: A risk review is triggered by:
- Significant non-conformities
- Changes to processes
- Audit findings
- Changes in regulatory requirements
Documentation
All process risks and their management shall be documented in the T-002-010 Process risk register, which includes:
- Risk identification (ID, description, category)
- Risk assessment (severity, probability, detection, RPN)
- Risk acceptability determination
- Risk control measures (if applicable)
- Responsible person and deadline
- Verification of effectiveness
- Current status
- Residual risk assessment
Process flowchart
Associated documents
GP-002 Quality planningGP-006 Non-conformity. Corrective and preventive actionsGP-013 Risk management(for product risks)T-002-003 Quality indicatorsT-002-004 Annual management review reportT-002-007 Process validation cardT-002-010 Process risk register
Signature meaning
The signatures for the approval process of this document can be found in the verified commits at the repository for the QMS. As a reference, the team members who are expected to participate in this document and their roles in the approval process, as defined in Annex I Responsibility Matrix of the GP-001, are:
- Author: Team members involved
- Reviewer: JD-003 Design & Development Manager, JD-004 Quality Manager & PRRC
- Approver: JD-001 General Manager