logo

QA/RA Consulting, Auditing & Training

logo

Let's get started

Stop Calling It Risk Based. Start Proving It.

Most companies say that their quality management systems are risk based. FDA will ask you to prove it.

Under the FDA’s Quality Management System Regulation (QMSR), that distinction is getting harder to ignore.

As inspections evolve, the question isn’t just whether risk is documented. Instead, it’s whether your approach to risk is actually driving how your system operates – how you prioritize processes, allocate resources, and respond to problems.

That’s the danger lurking inside ISO 13485 clause 4.1.2(b): organizations are expected to apply a risk-based approach to how QMS processes are controlled.

Not describe it. Not reference it. Apply it.

 

And that’s where many systems start to break down.

What the Standard Is Actually Asking For

ISO 13485 doesn’t treat risk like a side project, but instead regards it as the thing that’s supposed to drive the system.

The process approach already assumes you:

  • Identify and manage interconnected processes
  • Monitor them
  • Improve them

That part isn’t new. What gets missed is what comes next: risk-based thinking is supposed to:

  • Shape how those processes are designed
  • Influence how tightly they’re controlled
  • And – more important than people like to admit – change how decisions get made

That last piece is where things usually fall apart, because applying a risk-based approach doesn’t mean adding another form or spreadsheet – it means your system stops behaving the same way everywhere.

A risk-based QMS isn’t just controlled. It actually treats some things like they matter more than others.

Where Systems Break Down

Most organizations don’t struggle to talk about risk. They struggle to factor it in without making the system feel uneven. Because of this, everything gets standardized:

  • Same audit cadence
  • Same training approach
  • Same supplier controls
  • Same escalation rules

Clean. Consistent. Easy to explain. Also – usually wrong. Treating everything the same isn’t control. It’s hesitation.

Because once you take risk seriously, you have to make decisions that people don’t love:

  • Some processes get more scrutiny
  • Some get less scrutiny
  • Some issues move fast
  • Others don’t need to

That’s not tidy. It doesn’t always look great in a procedure. But that friction? That unevenness? That’s usually where you can tell the system is actually thinking.

What Risk-Based Thinking Looks Like in Practice

Internal Audits: Follow Consequence, Not Habit

A risk-based audit program doesn’t run just because something is “due.” It focuses on:

  • Where failure would actually matter
  • Where change has introduced uncertainty
  • Where problems already exist

Less “we audit this every year.” More “we pay attention where it would hurt if we didn’t.”

Training: Not Everything Deserves the Same Attention

Training is one of the easiest places to spot whether risk is truly being used or just mentioned, because a lot of systems still rely on:

  • Assign
  • Read
  • Sign
  • Move on

That’s fine for low-risk work, but it’s harder to defend when:

  • Tasks are complex
  • Mistakes have downstream impact
  • Roles directly affect quality or compliance

Not all work carries the same consequence. If your training approach doesn’t reflect that, risk isn’t influencing the system. It’s just there in the background.

Supplier Controls: Same Framework, Different Reality

Some suppliers matter a lot; others really don’t. But if the controls look identical, the system isn’t showing any real judgment.


A risk-based system doesn’t treat suppliers the same. It treats them differently on purpose.

This Isn’t a Procedure Gap. It’s a Decision Gap.

Most systems already say the right things about risk. That’s rarely the issue. The problem is when those statements:

  • Don’t change priorities
  • Don’t affect how controls are applied
  • Don’t influence where time and effort go

A risk-based QMS is defined by what it does differently, such as where it:

  • Pays closer attention
  • Applies more rigor
  • Steps in earlier

Those differences are the signal the QMS is truly risk-based.

 

A Simple Test: Can You Prove It?

Want to know if your system is really risk based? Ask:

  • Can we explain why some processes get more attention than others?
  • Do our resources follow that logic?
  • Does the system actually behave differently in those areas?

If the answer is “everything looks pretty much the same” then risk probably isn’t driving much of anything.

 

And if risk doesn’t change your controls, your priorities, or your decisions… it’s not embedded in your QMS. It’s just along for the ride.

Final Thought: Risk Should Change What You Do

Clause 4.1.2(b) isn’t asking whether you can describe risk – it’s addressing whether risk actually changes how your system behaves. Because when it does:

  • Controls stop being one-size-fits-all
  • Efforts become more deliberate
  • Decisions start to line up with reality

If risk doesn’t change what you do, then you’re not applying a risk-based approach.

 

You’re just talking about one.

Learn More

ELIQUENT Life Sciences (formerly Oriel STAT A MATRIX) offers training and support in areas where risk-based thinking becomes visible in practice: internal auditing, CAPA, supplier quality, and inspection readiness.

 

Explore ways in which your organization can strengthen how risk shows up in day-to-day quality decisions.

 

 

 

Our team is here to help. Contact us online
or
Get answers right now. Call

US Office Washington DC

1.800.472.6477

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.