Documentation
Tutorials
Workflows
Kebab actions
Daily Work
Dashboard & Reports
Quality Control
ISO 17025
Reagents & Storage
Logs
Contacts
Billing
Analysis Setup
Settings
Initial Setup
Help & Reference
Architecture decisions
ISO 17025
0:000:00

Risk Assessments

The Risk Assessments page is the laboratory's register of risks and opportunities: what could go wrong or be improved, how heavy it is, what is being done about it, and when it may close (EN ISO/IEC 17025:2017 §8.5).

Found under: ISO 17025 → CAPA & Findings → Risk Assessments.

Toolbar

ButtonAction
Add — Create a new record
Columns — Show/hide table columns
Filters — Open/close the filter panel. A red dot indicates active filters
Export CSV — Download table data as a CSV file
Orientation — Toggle between portrait and landscape printing
Print — Generate a PDF of the current view
Help — Open the help dialog
Search — Quick search through table data

Record Actions

Clicking the icon on each row shows:

  • Edit — Open the edit form
  • Preview — View record as PDF
  • Download PDF — Download the record as a PDF file
  • Send Email — Send the record as a PDF attachment via email
  • Delete — Delete the record (with confirmation)

Fields

FieldDescription
CodeUnique risk code. Leave blank for auto-numbering.
TitleBrief description of the risk
CategoryTechnical, Equipment, Personnel, Sample Handling, Environmental, Process, Compliance or Data Integrity (hidden column)
LikelihoodLikelihood score: Low (1), Medium (2), High (3), Critical (4) (hidden column)
ImpactImpact severity score: Low (1), Medium (2), High (3), Critical (4) (hidden column)
ScoreAuto-calculated: Likelihood × Impact (1–16) — colour-coded by level
StatusOpen, Being Mitigated, Mitigated or Closed — colour-coded
PriorityCritical, High, Medium or Low (hidden column)
ResponsiblePerson responsible for risk mitigation
Detection DateDate of detection (hidden column)
Detected ByThe user who identified the risk (hidden column)
Mitigation StrategyProposed mitigation measures (hidden column)
Control EffectivenessEffective, Partially Effective or Ineffective (hidden column)
Risk DescriptionDetailed risk description (hidden column)
DeadlineMitigation completion deadline (hidden column)
Completion DateActual completion date (hidden column)
Review DateRisk reassessment date (hidden column)
NotesAdditional remarks (hidden column)

The edit form additionally holds:

FieldDescription
Kind (§8.5.1)Risk or Opportunity — the standard asks for both, not only the bad news
Expected Benefit (§8.5.1b)Shown only on an Opportunity: what the laboratory gains by taking it
Validity Impact (§8.5.3)How far it touches the validity of results — it decides how strictly the row closes, see below
Treatment TypeAccept, Avoid, Mitigate or Transfer

Risk and opportunity (§8.5.1)

The register is not a list of problems. The standard wants the laboratory to consider opportunities for improvement too, which is what Kind separates. On an Opportunity the question changes: instead of "what do we lose if it happens", the Expected Benefit field asks what we gain by taking it.

The Score is computed on the server as Probability × Impact, so it cannot be written by hand to say something other than the two fields do.

Treatment: the item that gets created (§8.5.2)

When Treatment Type is Avoid or Mitigate — that is, when something actually has to be done — an entry is created automatically in the Improvement Backlog, owned by the Responsible person (or, if unset, whoever identified the risk), with the risk's deadline as its due date.

That entry is shown inside the risk's form with its title and status, but it is managed in the Improvement Backlog — here it is only an indicator.

When it may close (§8.5.3)

Closing is a separate action, not a choice in the Status menu: an ordinary edit cannot write "Closed". Three checks run, and they are proportional to the severity.

  1. A closure reason is always required.
  2. Treatment evidence for heavy risks. A Risk with a High or Critical Validity Impact — or a Score of 8 or more — will not close without all three of: Mitigation Strategy, Treatment Type, and Control Effectiveness. This check cannot be overridden: the whole point of the class is that big risks get real treatment evidence. Opportunities are exempt.
  3. The treatment item must be finished. While the linked Improvement Backlog entry is Proposed, Accepted or In Progress, the risk will not close — otherwise the register would say "handled" while the action is still running. This check is overridable with a written reason by a role holding the override permission, and the override is recorded.

Closing is reserved for the Lab Director, Quality Manager or Reviewer. Deleting a register row is likewise a quality act, with the same roles.

The closing button

On each row, the icon that means Delete on other pages appears here as Close. An already-closed assessment will not close again — the button is disabled. After closing, the form shows who closed it, when, and with what reason.

See also: Improvement Backlog, Corrective Actions, Deviations.

Connects to

Points at — this page does not stand without these: