This guide describes the step-by-step process for identifying and assessing risks. Per ISO 17025 §8.5, the laboratory must identify risks and opportunities that could affect impartiality, validity of results, or QMS effectiveness.
Before you begin, make sure that:
| # | Prerequisite | Why | Page |
|---|---|---|---|
| 1 | Users | Responsible person assignment | Users |
Go to the Risk Assessments page from the main menu. A table of existing risk records is displayed.
The visible table columns (by default) are:
| Column | Description |
|---|---|
| Code | Unique code (for example RISK-YYYY-0001) |
| Title | Short title of the risk |
| Score | Risk level, calculated from likelihood x impact |
| Status | Open, In Mitigation, Mitigated or Closed |
| Responsible | Person responsible for mitigation |
There are also many hidden columns (Category, Priority, Identified Date, Due Date, Identified By, Likelihood, Impact, Completion Date, Review Date, Control Effectiveness, Risk Description, Mitigation Strategy, Notes). You can show them from the column settings.
Identify risks that could affect laboratory operations. The form's Category field accepts one of the following values:
| Category | Examples |
|---|---|
| Technical | Method error, test procedure deviation |
| Equipment | Ageing equipment, instrument failure, overdue calibration |
| Personnel | Key staff departure, insufficient training/understaffing |
| Sample Handling | Incorrect preservation, loss of sample identification |
| Environmental | Power outage, HVAC failure |
| Procedure | Unclear or outdated SOP |
| Compliance | Regulatory changes, pending accreditation issue |
| Data Integrity | Unauthorized access, data loss |
Click the "+" button on the toolbar to open the creation form.
Fill in the fields:
| Field | Description | Required |
|---|---|---|
| Code | Leave blank for auto-numbering (for example RISK-YYYY-0001) | No |
| Risk Title | Short title | Yes |
| Category | See the category table in Step 2 | Yes |
| Status | Starts as "Open" | Yes |
| Likelihood | Low, Medium, High or Critical | Yes |
| Impact | Low, Medium, High or Critical | Yes |
| Priority | Low, Medium, High or Critical | No |
| Control Effectiveness | Effective, Partially Effective or Ineffective | No |
| Treatment Type | Accept, Avoid, Mitigate or Transfer — see the note in Step 5 | No |
| Identified Date | When the risk was identified | Yes |
| Identified By | The user who identified the risk | Yes |
| Due Date | Deadline for implementing mitigation measures | No |
| Responsible | Person responsible for mitigation | No |
| Completion Date | When the measures were completed | No |
| Review Date | When the risk will be reassessed | No |
| Risk Description | What could happen | No |
| Mitigation Strategy | See Step 5 | No |
| Notes | Additional remarks | No |
The Risk Score is calculated automatically from the combination of likelihood and impact.
Use the following tables as a guide. Both fields have four levels:
| Level | Description |
|---|---|
| Low | Rare — has not occurred or occurs < 1 time/year |
| Medium | Possible — has occurred or occurs 1-3 times/year |
| High | Frequent — occurs > 3 times/year |
| Critical | Near-certain — occurs on an ongoing basis or > 1 time/month |
| Level | Description |
|---|---|
| Low | Minimal effect — does not affect results or operations |
| Medium | Significant effect — affects some analyses or processes |
| High | Critical effect — risk to result validity or accreditation |
| Critical | Catastrophic effect — laboratory shutdown or loss of accreditation |
Base the assessment on historical data, audit findings, and industry benchmarks.
Fill in the Mitigation Strategy field with measures taken to reduce the risk.
Example: "Install UPS for uninterruptible power supply. Maintenance contract for HVAC units. Train a second analyst as backup."
Measures aim to reduce either the likelihood or the impact (or both).
Also select a Treatment Type (Accept, Avoid, Mitigate or Transfer):
If you select "Avoid" or "Mitigate", the application automatically creates an entry in the Improvement Backlog with an owner (the Responsible person, or if not set, the user who identified the risk) and a due date, so the treatment plan is tracked. "Accept" and "Transfer" do not create an Improvement Backlog entry.
After defining actions:
If you decide to accept the risk without mitigation measures, select "Accept" in the Treatment Type field and document the justification in the notes. There is no separate "Accepted" status — the status remains "Open" until you close the record (Step 7).
Close a risk when:
Closing is not done from the edit form by changing the Status — it is a dedicated action:
Closing a risk assessment is only permitted for the Lab Director, Quality Manager, or Reviewer roles (ISO 17025 §8.5). Other roles get a permission error and the record does not close.The "Close" action is disabled once the record is already "Closed". After closing, the form displays a banner with the closure date, user, and reason.
Type in the search field for quick text filtering.
Click the filter icon to open the filter panel:
| Filter | Type | Description |
|---|---|---|
| Category | Select | Show only one category |
| Status | Select | Show only one status |
| Priority | Select | Show only one priority |
| Date (from) | Date | Identification date from |
| Date (to) | Date | Identification date to |
| Max Records | Number | Record limit for print/export (default: 200) |
How do I determine likelihood and impact?
Use historical data, audit findings, and industry benchmarks. If no data is available, start with a conservative estimate and revise during the review.
When should risks be reassessed?
At least annually or when significant changes occur — new equipment, staff changes, new methods, regulatory changes, or after a significant event.
Can I accept a risk without mitigation measures?
Yes, if the risk is low and the cost of mitigation is not justified. Select "Accept" in the Treatment Type field and document the reasoning in the notes. You don't need to change the status — there is no "Accepted" status.
How does auto-numbering work?
If you leave the "Code" field blank during creation, the application assigns the next available code (format RISK-YYYY-NNNN). You can also enter your own code.