[ STAGE 2 OF 5 · RISK-BASED QMS JOURNEY ]

Compliance-Driven

Risk management is done because a regulation requires it. The assessments exist, but they are filed, not used.

What a stage is not

The stages are SPEQ’s organising device for building a risk-based quality system, not a regulator’s mandated sequence. Real programmes overlap and revisit them, and no inspection asks which stage you are in.

The assessments exist. They are complete, they are signed, and they are filed — and no decision changes because of them. A reader at this stage recognises the specific fatigue of producing a document whose only consumer is an auditor, and the quiet knowledge that the same template gets applied to a critical process and a trivial one because the procedure asks for one either way.

[ ARE YOU HERE? THE DIAGNOSTIC SIGNS ]
  • ·Risk assessments are produced for the file and rarely reopened
  • ·The same depth of assessment is applied to everything, regardless of impact
  • ·QRM is a document deliverable, not an input to decisions

WHY ORGANISATIONS STOP HERE

This stage is stable because it satisfies the auditable question. An inspector asks whether risk management is documented, and it demonstrably is; the requirement, read literally, is met. Moving on means accepting that the real test is whether an assessment ever changed anything — a harder standard to pass and one nobody outside the organisation is currently applying.

[ YOUR FIRST MOVES TO ADVANCE ]
  • Make one real decision from a risk assessment — change a control, a frequency, or a scope because of it
  • Introduce proportionality: let risk decide how much assessment a change or deviation warrants
  • Connect risk output to CAPA and change control so it drives action
[ HOW IT OPERATES AT THIS STAGE ]
  • ·Risk assessments are triggered by procedure, then shelved
  • ·Effort is uniform because "that’s the template"
  • ·Success is measured by documents completed, not risk reduced