Documentation
Tutorials
Workflows
Kebab actions
Daily Work
Dashboard & Reports
Quality Control
ISO 17025
Logs
Contacts
Billing
Analysis Setup
Settings
Initial Setup
Help & Reference
Architecture decisions
Workflows
0:000:00

Risk Assessments Workflow

This guide describes the step-by-step process for identifying and assessing risks. Per ISO 17025 §8.5, the laboratory must identify risks and opportunities that could affect impartiality, validity of results, or QMS effectiveness.


Prerequisites

Before you begin, make sure that:

#PrerequisiteWhyPage
1UsersResponsible person assignmentUsers

Step 1 — Navigation

Go to the Risk Assessments page from the main menu. A table of existing risk records is displayed.

The visible table columns are:

ColumnDescription
Risk No.Unique code (for example RISK-YYYY-0001)
DateWhen the risk was identified
Risk DescriptionBrief description
AreaWhich area/process is affected
LikelihoodLow, Medium or High
ImpactLow, Medium or High
Risk LevelCalculated from likelihood x impact
StatusOpen, Mitigated, Accepted or Closed
There are also hidden columns (Mitigation Actions, Responsible, Review Date, Notes). You can show them from the column settings.

Step 2 — Identify the Risk

Identify risks that could affect laboratory operations. Typical categories:

CategoryExamples
ImpartialityClient pressure for specific results, conflict of interest
Result validityAgeing equipment, insufficient analyst training
OperationalPower outage, HVAC failure, reagent shortage
PersonnelKey staff departure, understaffing
ExternalRegulatory changes, pandemic, supply chain issues

Step 3 — Create a Record

Click the "+" button on the toolbar to open the creation form.

Fill in the fields:

FieldDescriptionRequired
Risk No.Leave blank for auto-numbering (for example RISK-YYYY-0001)No
DateWhen the risk was identifiedYes
Risk DescriptionWhat could happenYes
AreaWhich area/process is affectedYes
LikelihoodLow, Medium or HighYes
ImpactLow, Medium or HighYes
ResponsiblePerson responsible for mitigationYes
StatusStarts as "Open"Yes
Review DateWhen the risk will be reassessedNo
NotesAdditional remarksNo
The Risk Level is calculated automatically from the combination of likelihood and impact.

Step 4 — Assess Likelihood & Impact

Use the following tables as a guide:

Likelihood

LevelDescription
LowRare — has not occurred or occurs < 1 time/year
MediumPossible — has occurred or occurs 1-3 times/year
HighFrequent — occurs > 3 times/year

Impact

LevelDescription
LowMinimal effect — does not affect results or operations
MediumSignificant effect — affects some analyses or processes
HighCritical effect — risk to result validity or accreditation
Base the assessment on historical data, audit findings, and industry benchmarks.

Step 5 — Mitigation Actions

Fill in the Mitigation Actions field with measures taken to reduce the risk.

Example: "Install UPS for uninterruptible power supply. Maintenance contract for HVAC units. Train a second analyst as backup."

Mitigation actions aim to reduce either the likelihood or the impact (or both).

Step 6 — Implement & Review

After defining actions:

  1. Implement the mitigation actions
  2. Change status to "Mitigated" once measures are in place
  3. Check effectiveness — has the risk actually decreased?
  4. Set Review Date — at least annually
If the risk is low and acceptable without measures, change the status to "Accepted" with justification in the notes.

Step 7 — Close

Close a risk when:

  • The risk no longer exists (for example, equipment replaced)
  • Mitigation measures have been verified as effective
  • The risk has been superseded by a new record due to changed conditions

Change the status to "Closed".


Step 8 — Search & Filtering

Type in the search field for quick text filtering.

Filter Panel

Click the filter icon to open the filter panel:

FilterTypeDescription
StatusSelectShow only one status
LikelihoodSelectShow only one likelihood level
ImpactSelectShow only one impact level
Date (from)DateIdentification date from
Date (to)DateIdentification date to
Max RecordsNumberRecord limit for print/export (default: 200)

FAQ

How do I determine likelihood and impact?

Use historical data, audit findings, and industry benchmarks. If no data is available, start with a conservative estimate and revise during the review.

When should risks be reassessed?

At least annually or when significant changes occur — new equipment, staff changes, new methods, regulatory changes, or after a significant event.

Can I accept a risk without mitigation measures?

Yes, if the risk is low and the cost of mitigation is not justified. Document the reasoning in the notes and change the status to "Accepted".

How does auto-numbering work?

If you leave the "Risk No." field blank during creation, the application assigns the next available code (format RISK-YYYY-NNNN). You can also enter your own code.