{"id":35307,"date":"2026-10-01T17:34:37","date_gmt":"2026-10-01T21:34:37","guid":{"rendered":"https:\/\/www.oxebridge.com\/emma\/?p=35307"},"modified":"2026-10-01T17:37:24","modified_gmt":"2026-10-01T21:37:24","slug":"guest-post-opportunity-based-thinking-another-confection-or-the-solution-to-everything","status":"publish","type":"post","link":"https:\/\/www.oxebridge.com\/emma\/guest-post-opportunity-based-thinking-another-confection-or-the-solution-to-everything\/","title":{"rendered":"Guest Post: Opportunity-Based Thinking: Another Confection or the Solution to Everything?"},"content":{"rendered":"<p><em>[The following guest post was written by Grant Purdy, Director of <a href=\"https:\/\/www.sufficientcertainty.com\/\">Sufficient Certainty Pty Ltd.<\/a>]<\/em><\/p>\n<p>Firstly, a little about myself. Next year I will have been practicing the black art of risk management for 50 years; mostly I\u2019ve helped people and their organisations make better decisions.\u00a0 Risk management, when I started out, was about providing just one of many inputs to decision-making, but over the years it has become much more: a largely self-serving proliferation of artifacts and confections.<\/p>\n<p>Fortunately, the risk management profession seems now to be slowly getting back to where we started: that the context for risk management should always and only be the decision being faced, and its only role to be limited to understanding the uncertainties inherent in the assumptions on which the decision rests.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-35308\" style=\"border: 1px solid #000000;\" src=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2026\/10\/pernicioustrianble.png\" alt=\"\" width=\"400\" height=\"256\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2026\/10\/pernicioustrianble.png 541w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2026\/10\/pernicioustrianble-150x96.png 150w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2026\/10\/pernicioustrianble-200x128.png 200w\" sizes=\"(max-width: 400px) 100vw, 400px\" \/>One of the phenomena that has bedeviled risk management is something I call the &#8220;Pernicious Triangle&#8221;. This is where a group of well-meaning people, with an interest in a subject, get together to write a &#8220;standard&#8221; to codify their thinking. This gets taken up by a standards organisation such as ISO and is published and promulgated.\u00a0 Regulators and other consultants see this, and compliance starts to become mandated as good practice.\u00a0 Then, of course, the original committee is joined by those with more commercial interests, and artificial edifices and jargon are developed and extended in a new version of the standard, which of course is then taken up by regulators \u2013 and so on.<\/p>\n<p>The 2009 version of ISO 31000 on the Management of Risk probably represented peak thinking on risk management.\u00a0 Although even that left a major unresolved dichotomy: how can you aspire to the integration of risk management into decision-making when what is described involves standalone, separately labeled artifacts and processes &#8211; which act to discourage and prevent integration?<\/p>\n<p>The definition of risk in ISO 31000 is &#8220;<em>effect of uncertainty on objectives<\/em>&#8221; and it was intended (I was there when it was developed) that &#8220;objectives&#8221; here are not just any old ones, but are those that relate organisation\u2019s highest reason it exists, its purpose.<\/p>\n<p>Risk is therefore a property of the organisation and its purpose and is neither positive nor negative.\u00a0 However, it was therefore surprising that ISO 9001:2015 and now 2026 adopt a bastardised of the ISO 31000 definition of risk that omits the key, anchoring and context-setting term &#8220;objectives&#8221;. Effect of uncertainty is meaningless \u2013 it means effect arising from an absence of knowledge and just invokes the challenge: \u201cso what?\u201d<\/p>\n<p>The authors of ISO 9001:2026 also invented a set of notes that are supposed to explain the definition (but don\u2019t make much sense). These also don\u2019t follow those in the ISO risk management standard.<\/p>\n<p>The authors also seem to think that &#8220;risks&#8221; (NB plural) can produce undesired or negative effects while opportunities can only generate \u201cdesired effects.\u201d In other words, that somehow, &#8220;opportunity&#8221; is the antonym of &#8220;risk&#8221; \u2013 which, of course, it is not.<\/p>\n<p>&#8220;Opportunity,&#8221; as defined in dictionaries, is simply a time or set of circumstances that makes it possible to do <em><u>something<\/u><\/em>. What that &#8220;something&#8221; is depends entirely, of course, on the decision we then make as to how to respond.<\/p>\n<p>In the clarification section of ISO 9001:2026, rather than providing clarity, the information on risk management just adds to the reader\u2019s confusion and suggests that cut-down versions of risk management called &#8220;Risk Based Thinking&#8221; and &#8220;Opportunity Based Thinking&#8221; are quite good enough for quality management. Only when a &#8220;formal&#8221; approach is needed does the organisation have the &#8220;choice&#8221; of adopting a &#8220;more extensive&#8221; approach such as that in ISO 31000.<\/p>\n<p>It will come as rather a shock to the risk management profession and indeed to all commercial enterprises and the capitalist system, that clause A.6.1.1 of the International Standard on Quality Management Systems advises that: <em>&#8220;Risks and opportunities are distinct; they can be determined and addressed through separate processes.&#8221;<\/em><\/p>\n<p>Somewhat naively, you could expect the International Organisation for Standardisation would insist that important terms like &#8220;risk&#8221; be defined and used the same way across <em>all<\/em> its standards, and to pull its technical committees into line when they deviate.\u00a0 Indeed, the whole purpose of ISO 31073:2022 (was ISO Guide 73) is to standardise terms and definitions, to be applied in all ISO standards, with respect to risk and its management.<\/p>\n<p>Clearly the experts on TC176 have decided they are above all that; they understand risk management better than the ISO experts on the subject! And no one at ISO has had the wherewithal or guts to insist they toe the line.<\/p>\n<p>As Stephen Hawking once said: \u201c<em>The greatest enemy of knowledge is not ignorance, it is the illusion of knowledge!\u201d<\/em><\/p>\n<p>In 2015, TC176 decided to ignore the ISO Risk Management Standard and conjure up a shortcut risk management called &#8220;Risk-Based Thinking&#8221; or RBT.\u00a0 This is not defined in ISO 9001 \u2013 but then, of course, this ambiguity means we can all make up what it is supposed to mean and never be wrong \u2013 and it cries out for advice from consultants.<\/p>\n<p>This action, of course, fits neatly in the pernicious triangle phenomena I\u2019ve described above &#8211; and, soon after RBT was invented, the market was flooded with people offering courses, software and, of course, consultancy to help people implement RBT.<\/p>\n<p>Now, in the 2026 version of ISO 9001, a new confection has been invented called &#8220;Opportunity-Based Thinking.&#8221; And again, this confection is not defined, and we can expect the normal, highly lucrative flood of courses, with consultancy services and software to follow. In fact, it seems the OBT gravy train is already leaving the station. A plethora of courses is already being offered (some, a bargain at $395) and even a consultancy organisation has opened a website called opportunitybasedthinking.com!<\/p>\n<p>The intriguing, and I am sure not intended, implications of OBT is that, <em>brace yourselves<\/em>, TC176 might actually be onto something here!<\/p>\n<p>Fundamentally, every organisation exists for an explicit purpose, and the only way it can pursue and achieve that purpose is by recognising opportunities (as defined in a dictionary) as they arise and emerge and then exploit them by making and implementing decisions.<\/p>\n<p>So, almost certainly by accident, the new confection of OBT could actually stimulate better decision-making, involving all aspects of management, across the whole organisation.\u00a0 In fact, OBT could be so comprehensive and all-embracing that it makes the rest of the ISO quality management systems standard, the risk management standard and all the other ISO management system standards irrelevant, unnecessary and, in effect, obsolete.<\/p>\n<p>Wow!\u00a0 Maybe the next version of ISO 9001 will have just one page, and all the other ISO management system standards won\u2019t be needed in the future.<\/p>\n<p>However, somehow, I doubt it!\u00a0 After all, how would ISO make money, and how would the members of its many technical committees pay for their international holidays?!<\/p>\n<p>The pernicious triangle must keep turning.<\/p>\n<hr \/>\n<p><em><a href=\"https:\/\/www.sufficientcertainty.com\/about\">Grant Purdy <\/a>has worked in the risk management field for over 50 years. He was a nominated expert to the ISO working group that wrote ISO 31000 and ISO Guide 73, and provided substantial input to ISO\/IEC 31010. He was a member of the Australia\/New Zealand joint standards committee on risk management for fourteen years, chairing it for ten, and led the Australian delegation to the ISO technical committee that maintains the standard. Before that, he was Group Risk Manager at BHP Billiton, Managing Director of Aon Pacific Risk Management, and held senior roles at Andersen, DNV and IRCA, working across more than twenty-five countries.<\/em><\/p>\n<p><em>For the last twelve years until he retired, Grant worked throughout the world advising major clients on projects and decisions as an Associate Director of Broadleaf Capital International.<\/em><\/p>\n<p><em>He is the co-author of the book\u00a0<strong>Deciding<\/strong>, which was reviewed <a href=\"https:\/\/www.oxebridge.com\/emma\/book-review-deciding-dont-call-it-risk-management-2\/\">here<\/a>.\u00a0<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>","protected":false},"excerpt":{"rendered":"<p>Grant Purdy dissects ISO 9001&#8217;s latest made-up invention.<\/p>","protected":false},"author":644,"featured_media":35314,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","mc4wp_mailchimp_campaign":[],"footnotes":""},"categories":[5],"tags":[7756,186,14,8728,8628,263,240,148,42],"class_list":["post-35307","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-opinion","tag-grant-purdy","tag-iso-31000","tag-iso-9001","tag-obt","tag-opportunity-based-thinking","tag-rbt","tag-risk-based-thinking","tag-risk-management","tag-tc-176","et-has-post-format-content","et_post_format-et-post-format-standard"],"_links":{"self":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/35307","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/users\/644"}],"replies":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/comments?post=35307"}],"version-history":[{"count":3,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/35307\/revisions"}],"predecessor-version":[{"id":35313,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/35307\/revisions\/35313"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media\/35314"}],"wp:attachment":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media?parent=35307"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/categories?post=35307"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/tags?post=35307"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}