[The following guest post was written by Grant Purdy, Director of Sufficient Certainty Pty Ltd.]

Firstly, a little about myself. Next year I will have been practicing the black art of risk management for 50 years; mostly I’ve helped people and their organisations make better decisions.  Risk management, when I started out, was about providing just one of many inputs to decision-making, but over the years it has become much more: a largely self-serving proliferation of artifacts and confections.

Fortunately, the risk management profession seems now to be slowly getting back to where we started: that the context for risk management should always and only be the decision being faced, and its only role to be limited to understanding the uncertainties inherent in the assumptions on which the decision rests.

One of the phenomena that has bedeviled risk management is something I call the “Pernicious Triangle”. This is where a group of well-meaning people, with an interest in a subject, get together to write a “standard” to codify their thinking. This gets taken up by a standards organisation such as ISO and is published and promulgated.  Regulators and other consultants see this, and compliance starts to become mandated as good practice.  Then, of course, the original committee is joined by those with more commercial interests, and artificial edifices and jargon are developed and extended in a new version of the standard, which of course is then taken up by regulators – and so on.

The 2009 version of ISO 31000 on the Management of Risk probably represented peak thinking on risk management.  Although even that left a major unresolved dichotomy: how can you aspire to the integration of risk management into decision-making when what is described involves standalone, separately labeled artifacts and processes – which act to discourage and prevent integration?

The definition of risk in ISO 31000 is “effect of uncertainty on objectives” and it was intended (I was there when it was developed) that “objectives” here are not just any old ones, but are those that relate organisation’s highest reason it exists, its purpose.

Risk is therefore a property of the organisation and its purpose and is neither positive nor negative.  However, it was therefore surprising that ISO 9001:2015 and now 2026 adopt a bastardised of the ISO 31000 definition of risk that omits the key, anchoring and context-setting term “objectives”. Effect of uncertainty is meaningless – it means effect arising from an absence of knowledge and just invokes the challenge: “so what?”

The authors of ISO 9001:2026 also invented a set of notes that are supposed to explain the definition (but don’t make much sense). These also don’t follow those in the ISO risk management standard.

The authors also seem to think that “risks” (NB plural) can produce undesired or negative effects while opportunities can only generate “desired effects.” In other words, that somehow, “opportunity” is the antonym of “risk” – which, of course, it is not.

“Opportunity,” as defined in dictionaries, is simply a time or set of circumstances that makes it possible to do something. What that “something” is depends entirely, of course, on the decision we then make as to how to respond.

In the clarification section of ISO 9001:2026, rather than providing clarity, the information on risk management just adds to the reader’s confusion and suggests that cut-down versions of risk management called “Risk Based Thinking” and “Opportunity Based Thinking” are quite good enough for quality management. Only when a “formal” approach is needed does the organisation have the “choice” of adopting a “more extensive” approach such as that in ISO 31000.

It will come as rather a shock to the risk management profession and indeed to all commercial enterprises and the capitalist system, that clause A.6.1.1 of the International Standard on Quality Management Systems advises that: “Risks and opportunities are distinct; they can be determined and addressed through separate processes.”

Somewhat naively, you could expect the International Organisation for Standardisation would insist that important terms like “risk” be defined and used the same way across all its standards, and to pull its technical committees into line when they deviate.  Indeed, the whole purpose of ISO 31073:2022 (was ISO Guide 73) is to standardise terms and definitions, to be applied in all ISO standards, with respect to risk and its management.

Clearly the experts on TC176 have decided they are above all that; they understand risk management better than the ISO experts on the subject! And no one at ISO has had the wherewithal or guts to insist they toe the line.

As Stephen Hawking once said: “The greatest enemy of knowledge is not ignorance, it is the illusion of knowledge!”

In 2015, TC176 decided to ignore the ISO Risk Management Standard and conjure up a shortcut risk management called “Risk-Based Thinking” or RBT.  This is not defined in ISO 9001 – but then, of course, this ambiguity means we can all make up what it is supposed to mean and never be wrong – and it cries out for advice from consultants.

This action, of course, fits neatly in the pernicious triangle phenomena I’ve described above – and, soon after RBT was invented, the market was flooded with people offering courses, software and, of course, consultancy to help people implement RBT.

Now, in the 2026 version of ISO 9001, a new confection has been invented called “Opportunity-Based Thinking.” And again, this confection is not defined, and we can expect the normal, highly lucrative flood of courses, with consultancy services and software to follow. In fact, it seems the OBT gravy train is already leaving the station. A plethora of courses is already being offered (some, a bargain at $395) and even a consultancy organisation has opened a website called opportunitybasedthinking.com!

The intriguing, and I am sure not intended, implications of OBT is that, brace yourselves, TC176 might actually be onto something here!

Fundamentally, every organisation exists for an explicit purpose, and the only way it can pursue and achieve that purpose is by recognising opportunities (as defined in a dictionary) as they arise and emerge and then exploit them by making and implementing decisions.

So, almost certainly by accident, the new confection of OBT could actually stimulate better decision-making, involving all aspects of management, across the whole organisation.  In fact, OBT could be so comprehensive and all-embracing that it makes the rest of the ISO quality management systems standard, the risk management standard and all the other ISO management system standards irrelevant, unnecessary and, in effect, obsolete.

Wow!  Maybe the next version of ISO 9001 will have just one page, and all the other ISO management system standards won’t be needed in the future.

However, somehow, I doubt it!  After all, how would ISO make money, and how would the members of its many technical committees pay for their international holidays?!

The pernicious triangle must keep turning.


Grant Purdy has worked in the risk management field for over 50 years. He was a nominated expert to the ISO working group that wrote ISO 31000 and ISO Guide 73, and provided substantial input to ISO/IEC 31010. He was a member of the Australia/New Zealand joint standards committee on risk management for fourteen years, chairing it for ten, and led the Australian delegation to the ISO technical committee that maintains the standard. Before that, he was Group Risk Manager at BHP Billiton, Managing Director of Aon Pacific Risk Management, and held senior roles at Andersen, DNV and IRCA, working across more than twenty-five countries.

For the last twelve years until he retired, Grant worked throughout the world advising major clients on projects and decisions as an Associate Director of Broadleaf Capital International.

He is the co-author of the book Deciding, which was reviewed here. 

 

 

Advertisements

ISO 14001 Implementation