Actions to address risks and opportunities
Based on the context and interested parties, you need to identify which risks should be mitigated and which opportunities pursued, with actions proportionate to the potential impact. The standard does not mandate a specific risk-management method: it requires that the analysis exists and has consequences.
Quality objectives and planning to achieve them
Objectives must be consistent with the policy, measurable, monitored, communicated and updated. For each one you need to define what will be done, with what resources, who is responsible, by when, and how results will be evaluated.
Planning of changes
When the system needs to change —a new process, a new line, a critical supplier change— it must be done in a planned way: considering the purpose of the change, its potential consequences, the resources available and who is responsible for each part.
What an auditor usually asks for
- A risk-and-opportunity register or matrix linked to concrete actions
- Quality objectives with an indicator, an owner and a date, not just a generic phrase
- Regular monitoring of those objectives with real data, not just at year-end
- A record of how the last relevant change to the system was planned
How to cover planning in Kimobox
- 1Log risks and opportunities in a matrix with an owner, likelihood, impact and a linked action.
- 2Define quality objectives with an indicator, an owner and a date, and let the system calculate the indicator itself.
- 3When you plan a change (supplier, line, process), document the reason, the impact and the resources before you carry it out.
Objectives stop living in a separate spreadsheet: the indicator calculates itself from data the process already generates.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- ISO 9001:2015 — Quality management systems. Requirements ISO · 2015 ed., with Amd 1:2024
- ISO 9000:2015 — Fundamentals and vocabulary ISO · 2015 ed.
- ISO 19011:2018 — Guidelines for auditing management systems ISO · 2018 ed.