The Risk Assessments page is the laboratory's register of risks and opportunities: what could go wrong or be improved, how heavy it is, what is being done about it, and when it may close (EN ISO/IEC 17025:2017 §8.5).
Found under: ISO 17025 → CAPA & Findings → Risk Assessments.
| Button | Action |
|---|---|
| Add — Create a new record | |
| Columns — Show/hide table columns | |
| Filters — Open/close the filter panel. A red dot indicates active filters | |
| Export CSV — Download table data as a CSV file | |
| Orientation — Toggle between portrait and landscape printing | |
| Print — Generate a PDF of the current view | |
| Help — Open the help dialog | |
| Search — Quick search through table data |
Clicking the icon on each row shows:
| Field | Description |
|---|---|
| Code | Unique risk code. Leave blank for auto-numbering. |
| Title | Brief description of the risk |
| Category | Technical, Equipment, Personnel, Sample Handling, Environmental, Process, Compliance or Data Integrity (hidden column) |
| Likelihood | Likelihood score: Low (1), Medium (2), High (3), Critical (4) (hidden column) |
| Impact | Impact severity score: Low (1), Medium (2), High (3), Critical (4) (hidden column) |
| Score | Auto-calculated: Likelihood × Impact (1–16) — colour-coded by level |
| Status | Open, Being Mitigated, Mitigated or Closed — colour-coded |
| Priority | Critical, High, Medium or Low (hidden column) |
| Responsible | Person responsible for risk mitigation |
| Detection Date | Date of detection (hidden column) |
| Detected By | The user who identified the risk (hidden column) |
| Mitigation Strategy | Proposed mitigation measures (hidden column) |
| Control Effectiveness | Effective, Partially Effective or Ineffective (hidden column) |
| Risk Description | Detailed risk description (hidden column) |
| Deadline | Mitigation completion deadline (hidden column) |
| Completion Date | Actual completion date (hidden column) |
| Review Date | Risk reassessment date (hidden column) |
| Notes | Additional remarks (hidden column) |
The edit form additionally holds:
| Field | Description |
|---|---|
| Kind (§8.5.1) | Risk or Opportunity — the standard asks for both, not only the bad news |
| Expected Benefit (§8.5.1b) | Shown only on an Opportunity: what the laboratory gains by taking it |
| Validity Impact (§8.5.3) | How far it touches the validity of results — it decides how strictly the row closes, see below |
| Treatment Type | Accept, Avoid, Mitigate or Transfer |
The register is not a list of problems. The standard wants the laboratory to consider opportunities for improvement too, which is what Kind separates. On an Opportunity the question changes: instead of "what do we lose if it happens", the Expected Benefit field asks what we gain by taking it.
The Score is computed on the server as Probability × Impact, so it cannot be written by hand to say something other than the two fields do.
When Treatment Type is Avoid or Mitigate — that is, when something actually has to be done — an entry is created automatically in the Improvement Backlog, owned by the Responsible person (or, if unset, whoever identified the risk), with the risk's deadline as its due date.
That entry is shown inside the risk's form with its title and status, but it is managed in the Improvement Backlog — here it is only an indicator.
Closing is a separate action, not a choice in the Status menu: an ordinary edit cannot write "Closed". Three checks run, and they are proportional to the severity.
Closing is reserved for the Lab Director, Quality Manager or Reviewer. Deleting a register row is likewise a quality act, with the same roles.
On each row, the icon that means Delete on other pages appears here as Close. An already-closed assessment will not close again — the button is disabled. After closing, the form shows who closed it, when, and with what reason.
See also: Improvement Backlog, Corrective Actions, Deviations.
Points at — this page does not stand without these: