Documentation
Tutorials
Workflows
Kebab actions
Daily Work
Dashboard & Reports
Quality Control
ISO 17025
Reagents & Storage
Logs
Contacts
Billing
Analysis Setup
Settings
Initial Setup
Help & Reference
Architecture decisions
Workflows
0:000:00

Risk Assessments Workflow

This guide describes the step-by-step process for identifying and assessing risks. Per ISO 17025 §8.5, the laboratory must identify risks and opportunities that could affect impartiality, validity of results, or QMS effectiveness.


Prerequisites

Before you begin, make sure that:

#PrerequisiteWhyPage
1UsersResponsible person assignmentUsers

Step 1 — Navigation

Go to the Risk Assessments page from the main menu. A table of existing risk records is displayed.

The visible table columns (by default) are:

ColumnDescription
CodeUnique code (for example RISK-YYYY-0001)
TitleShort title of the risk
ScoreRisk level, calculated from likelihood x impact
StatusOpen, In Mitigation, Mitigated or Closed
ResponsiblePerson responsible for mitigation
There are also many hidden columns (Category, Priority, Identified Date, Due Date, Identified By, Likelihood, Impact, Completion Date, Review Date, Control Effectiveness, Risk Description, Mitigation Strategy, Notes). You can show them from the column settings.

Step 2 — Identify the Risk

Identify risks that could affect laboratory operations. The form's Category field accepts one of the following values:

CategoryExamples
TechnicalMethod error, test procedure deviation
EquipmentAgeing equipment, instrument failure, overdue calibration
PersonnelKey staff departure, insufficient training/understaffing
Sample HandlingIncorrect preservation, loss of sample identification
EnvironmentalPower outage, HVAC failure
ProcedureUnclear or outdated SOP
ComplianceRegulatory changes, pending accreditation issue
Data IntegrityUnauthorized access, data loss

Step 3 — Create a Record

Click the "+" button on the toolbar to open the creation form.

Fill in the fields:

FieldDescriptionRequired
CodeLeave blank for auto-numbering (for example RISK-YYYY-0001)No
Risk TitleShort titleYes
CategorySee the category table in Step 2Yes
StatusStarts as "Open"Yes
LikelihoodLow, Medium, High or CriticalYes
ImpactLow, Medium, High or CriticalYes
PriorityLow, Medium, High or CriticalNo
Control EffectivenessEffective, Partially Effective or IneffectiveNo
Treatment TypeAccept, Avoid, Mitigate or Transfer — see the note in Step 5No
Identified DateWhen the risk was identifiedYes
Identified ByThe user who identified the riskYes
Due DateDeadline for implementing mitigation measuresNo
ResponsiblePerson responsible for mitigationNo
Completion DateWhen the measures were completedNo
Review DateWhen the risk will be reassessedNo
Risk DescriptionWhat could happenNo
Mitigation StrategySee Step 5No
NotesAdditional remarksNo
The Risk Score is calculated automatically from the combination of likelihood and impact.

Step 4 — Assess Likelihood & Impact

Use the following tables as a guide. Both fields have four levels:

Likelihood

LevelDescription
LowRare — has not occurred or occurs < 1 time/year
MediumPossible — has occurred or occurs 1-3 times/year
HighFrequent — occurs > 3 times/year
CriticalNear-certain — occurs on an ongoing basis or > 1 time/month

Impact

LevelDescription
LowMinimal effect — does not affect results or operations
MediumSignificant effect — affects some analyses or processes
HighCritical effect — risk to result validity or accreditation
CriticalCatastrophic effect — laboratory shutdown or loss of accreditation
Base the assessment on historical data, audit findings, and industry benchmarks.

Step 5 — Mitigation Strategy

Fill in the Mitigation Strategy field with measures taken to reduce the risk.

Example: "Install UPS for uninterruptible power supply. Maintenance contract for HVAC units. Train a second analyst as backup."

Measures aim to reduce either the likelihood or the impact (or both).

Also select a Treatment Type (Accept, Avoid, Mitigate or Transfer):

If you select "Avoid" or "Mitigate", the application automatically creates an entry in the Improvement Backlog with an owner (the Responsible person, or if not set, the user who identified the risk) and a due date, so the treatment plan is tracked. "Accept" and "Transfer" do not create an Improvement Backlog entry.

Step 6 — Implement & Review

After defining actions:

  1. Change status to "In Mitigation" while implementing the mitigation measures
  2. Change status to "Mitigated" once the measures are in place and verified
  3. Record Control Effectiveness — Effective, Partially Effective or Ineffective
  4. Set Review Date — at least annually
If you decide to accept the risk without mitigation measures, select "Accept" in the Treatment Type field and document the justification in the notes. There is no separate "Accepted" status — the status remains "Open" until you close the record (Step 7).

Step 7 — Close

Close a risk when:

  • The risk no longer exists (for example, equipment replaced)
  • Mitigation measures have been verified as effective
  • The risk has been superseded by a new record due to changed conditions

Closing is not done from the edit form by changing the Status — it is a dedicated action:

  1. On the record's row, open the actions menu and click "Close".
  2. In the dialog that opens, you must fill in the Closure Reason — the action cannot be completed without it.
  3. Confirm. The action is irreversible.
Closing a risk assessment is only permitted for the Lab Director, Quality Manager, or Reviewer roles (ISO 17025 §8.5). Other roles get a permission error and the record does not close.

The "Close" action is disabled once the record is already "Closed". After closing, the form displays a banner with the closure date, user, and reason.


Step 8 — Search & Filtering

Type in the search field for quick text filtering.

Filter Panel

Click the filter icon to open the filter panel:

FilterTypeDescription
CategorySelectShow only one category
StatusSelectShow only one status
PrioritySelectShow only one priority
Date (from)DateIdentification date from
Date (to)DateIdentification date to
Max RecordsNumberRecord limit for print/export (default: 200)

FAQ

How do I determine likelihood and impact?

Use historical data, audit findings, and industry benchmarks. If no data is available, start with a conservative estimate and revise during the review.

When should risks be reassessed?

At least annually or when significant changes occur — new equipment, staff changes, new methods, regulatory changes, or after a significant event.

Can I accept a risk without mitigation measures?

Yes, if the risk is low and the cost of mitigation is not justified. Select "Accept" in the Treatment Type field and document the reasoning in the notes. You don't need to change the status — there is no "Accepted" status.

How does auto-numbering work?

If you leave the "Code" field blank during creation, the application assigns the next available code (format RISK-YYYY-NNNN). You can also enter your own code.