ISO 17025 risks and opportunities are handled in clause 8.5 of ISO/IEC 17025:2017, and the requirement is smaller than many laboratories fear. The standard asks you to consider the risks and opportunities linked to your laboratory activities, plan actions, build them into your management system and check that they work. It does not ask for a formal risk management process. Assessors still expect objective evidence, so the practical task is to show that risk-based thinking is part of how you work.
This guide explains the requirement, what evidence is enough, and how to run a lightweight process. It builds on our guides to ISO 17025, laboratory impartiality and ISO 17025 versus ISO 9001.
Free gap assessment
Are you ready for the 2026 edition of ISO 9001?
Score yourself against the new edition, free, including the risk and opportunity split and the clause 10 renumbering that breaks converted checklists.
Run the free ISO 9001 gap assessment → or View premium report sample
What ISO 17025 risks and opportunities require
Guidance from the Canadian Association for Laboratory Accreditation, CALA, summarises the structure of clause 8.5. Subclause 8.5.1 says the laboratory shall consider the risks and opportunities associated with its activities. Subclause 8.5.2 says it shall plan actions to address them, integrate the actions into the management system and evaluate their effectiveness. A note in the standard clarifies that there is no requirement for formal methods of risk management or a documented risk management process.
| Question | Answer from the standard as summarised |
|---|---|
| Must we consider risks and opportunities? | Yes, for laboratory activities |
| Must we plan actions? | Yes, and integrate them into the management system |
| Must we evaluate effectiveness? | Yes |
| Is a formal risk process mandatory? | No, according to the standard’s note |
| Do we still need evidence? | Yes, objective evidence that risks are considered |
Read the clause in your licensed copy of the standard. Your accreditation body may add expectations, so check its guidance too.
Where risk appears elsewhere in the standard
Risk thinking is not confined to clause 8.5. The standard also links risk to impartiality, to the validity of results and to how nonconforming work is handled. Consider these connections when you build your process, because an assessor may follow the thread from a complaint or a failed proficiency test back to your risk records. Our guide to proficiency testing explains how external comparison results feed into assessing the validity of your results, and method validation covers a key source of technical risk.
What counts as objective evidence
Because no documented process is required, evidence can take many forms. CALA’s guidance suggests laboratories gather existing records that show risk is considered, such as inter-analyst comparisons, and keep them together. Useful evidence includes:
- A simple risk and opportunity register.
- Management review minutes that discuss risks and actions.
- Change control records that record the risk assessment of new equipment, methods or staff.
- Internal audit results and corrective actions.
- Proficiency test outcomes and the actions taken.
- Records of quality control trends and responses.
The point is to show that you look for problems before they affect results, and that you act on what you find.
Build a simple ISO 17025 risks and opportunities register
CALA recommends a simplified register with three columns: the identified risk, an assessment of probability, and the mitigation actions in place. You can add a fourth column for opportunities and a fifth for owner and review date. Keep it short. Ten to twenty well-chosen entries are better than a hundred generic ones.
- Brainstorm. Gather analysts, the quality manager and the technical manager, and walk through each process: sample receipt, handling, testing, calculation, reporting and records.
- Record risks. Write each in plain words, for example “reference standard expires without notice, leading to out-of-tolerance calibration”.
- Rate. Use a simple scale such as low, medium and high for likelihood, and add impact if it helps.
- Act. Note the existing controls and any new actions, with an owner and due date.
- Add opportunities. For example, adding a new method that meets customer demand, or automating data capture to reduce transcription errors.
- Review. Revisit the register at management review and whenever something significant changes.
Risk-based thinking in daily work
A register alone does not prove that risk-based thinking works. Show it in decisions. When you introduce new equipment, record the risks and the checks you put in place. When staff change, assess competence and supervision needs. When a customer asks for a rush job, consider the effect on validity of results. Recording these decisions in change requests and meeting notes gives assessors real examples to review.
Opportunities are part of the requirement
Many laboratories focus only on risks. The standard names opportunities as well, and evidence that you have identified some improves the picture. Examples include extending scope to a related test, adopting more efficient sample tracking or sharing calibration services between sites. Record the opportunity, the decision taken and the result.
Linking risk to measurement uncertainty and decision rules
Technical risk often sits in the numbers. If uncertainty is large compared with the specification limit, the chance of a wrong conformity decision rises. Our guides to measurement uncertainty and decision rules explain how to quantify and control this. A short note in your register that links high-risk products to the decision rule you apply shows that risk thinking reaches the results you report.
Evaluating effectiveness
Clause 8.5.2 asks you to evaluate effectiveness. Keep this simple: at each review, ask whether the action was done, whether the risk has changed and whether any incident occurred. If a risk materialised despite the action, revise the action. Record the conclusion, and update the register. Where a risk keeps recurring, escalate it to management review.
Roles and management review for ISO 17025 risks and opportunities
Assign the register to a named owner, usually the quality manager, and make each risk the responsibility of the person closest to the process. The technical manager should review technical risks, and top management should see a summary. Put a standing agenda item into management review: what changed in the register, which actions are overdue and which risks materialised. Recording this discussion in the minutes provides evidence that ISO 17025 risks and opportunities are managed at the right level, and it links risk thinking to the improvement clauses of the standard.
Keep the tone practical. Staff are more likely to report near misses and weak points when the register is seen as a tool for improvement and not as a list of blame. Encourage analysts to add items whenever they see a problem, and thank them for doing so.
Keeping the process light as the laboratory grows
A small laboratory can run the whole process from a single spreadsheet. As the laboratory adds staff, methods and sites, the register may need sections by department, or links to your corrective action system. Resist the urge to build complexity ahead of need. Add a field only when someone asks a question the register cannot answer. Review the design once a year, and delete entries that no longer apply. A concise register that people trust is worth more than an exhaustive one that nobody reads.
When you apply for an extension of scope, use the register to show that you assessed the new risks: equipment, competence, sample handling and validity monitoring. This gives the assessor confidence, and it saves time at the assessment.
A hypothetical example
A hypothetical environmental testing laboratory holds a one-hour workshop and lists twelve risks. One is a balance calibration that lapses during a holiday period, giving a high likelihood and moderate impact. The mitigation is a calendar alert and a spare balance with a valid certificate. One opportunity is to add a screening test that customers have requested. The quality manager stores the register, workshop notes and the management review minutes in one folder. At the next assessment, the assessor asks how risks are considered, and the laboratory shows the register, the decision on the balance and the follow-up. The example is invented for illustration.
Common findings about ISO 17025 risks and opportunities
- Laboratories build a complex formal process that nobody uses.
- The register exists but has no owners or review dates.
- Opportunities are never recorded.
- Actions are listed but not evaluated for effectiveness.
- Risk is discussed at meetings but not documented.
- Risk thinking is not connected to validity of results.
The CALA article on risk in ISO/IEC 17025:2017 offers further practical advice. Follow your accreditation body’s guidance where it differs from this summary.
Templates for ISO 17025 risks and opportunities
To avoid building the register, workshop guide and review templates from scratch, the ISO 17025 Toolkit provides documents you can adapt to your laboratory. Review them against your licensed copy of the standard and your accreditation body’s rules.
ISO 17025 risks and opportunities FAQ
Do we need a formal risk management procedure?
No. A note in the standard says formal risk management methods or a documented process are not required. You still need objective evidence that risks and opportunities are considered.
What is the simplest way to comply?
A short register of risks, likelihood and mitigations, reviewed at management review, plus records showing risk was considered in decisions.
Do opportunities have to be recorded?
The clause covers risks and opportunities, so record some, together with the action or decision taken.
How often should we review the register?
At least at management review and whenever something significant changes, such as new equipment, methods or key staff.
Will assessors check this?
Yes. Expect questions on how you consider risk, and be ready to show examples in records.