Risk and ISO 9001: A Systematic Literature Review

  • Yasmin Silva Martins
  • Carlos Eduardo Sanches da SilvaEmail author
Conference paper
Part of the Springer Proceedings in Mathematics & Statistics book series (PROMS, volume 280)


The search for excellence, related to the processes, products and services quality and to the market requirement, makes organizations to implement their Quality Management Systems (QMS). In this context, with ISO 9001 standard revision, published in 2015, a new requirement is established: risk-based thinking. The main focus of this article is to provide information, by doing a Systematic Literature Review (SLR), about the state of the art of Risk and ISO 9001 standard, identifying the risks’ approaches used by the organizations and finding gaps and inconsistencies in the literature. This SLR was conducted as follows: (a) establishing the research main question; (b) locating studies (defining the research sources, timing and criteria); (c) analysis and synthesis (supported by QSR NVivo); and (d) findings and conclusions. The main field of research was chosen to answer the question “what kind of methodologies and methods, companies that have a QMS based on ISO 9001 can use as a support to the risk-based thinking requirement?” The paper’s aim is also to contribute with companies who are looking forward to implement the Risk Management in their processes.


Risk ISO 9001 Quality management system 



The authors thank CNPQ, CAPES, FAPEMIG, FUPAI and Sisvoo Sistemas Eletrônicos Ltda., for funding support.


  1. 1.
    Lee, C.K.M., Lv, Y., Hong, Z.: Risk modelling and assessment for distributed manufacturing system. Int. J. Prod. Res. 51, 2652–2666 (2013)CrossRefGoogle Scholar
  2. 2.
    Fonseca, L.M.: From quality gurus and TQM to ISO 9001:2015: a review of several quality paths. Int. J. Qual. Res. 9, 167–180 (2015)Google Scholar
  3. 3.
    Fonseca, L.M.: ISO 9001 quality management systems through the lens of organizational culture. Qual. Access Success 16, 54–59 (2015)Google Scholar
  4. 4.
    Fonseca, L.M., Domingues, J.P.: How to succeed in the digital age? monitor the organizational context, identify risks and opportunities, and manage change effectively. Manag. Mark. 12, 443–455 (2017)Google Scholar
  5. 5.
  6. 6.
    Antilla, J., Jussila, K.: ISO 9001:2015-a questionable reform. What should the implementing organizations understand and do? Total. Qual. Manag. Bus. Excel. 28, 1090–1105 (2017)CrossRefGoogle Scholar
  7. 7.
    Rybski, C., Jochem, R., Homma, L.: Empirical study on status of preparation for ISO 9001:2015. Total. Qual. Manag. Bus. Excel. 28, 1076–1089 (2017)CrossRefGoogle Scholar
  8. 8.
    Chiarini, A.: Risk-based thinking according to ISO 9001:2015 standard and the risk sources European manufacturing SMEs intend to manage. TQM J. 29, 310–323 (2017)CrossRefGoogle Scholar
  9. 9.
    International Organization for Standardization (2015).
  10. 10.
    Luko, S.N.: Risk management principles and guidelines. Qual. Eng. 25, 451–454 (2013)CrossRefGoogle Scholar
  11. 11.
    Aven, T.: Risk assessment and risk management: review of recent advances on their foundation. Eur. J. Oper. Res. 253, 1–13 (2016)CrossRefMathSciNetzbMATHGoogle Scholar
  12. 12.
    Reis, J., Amorim, M., Melão, N., Matos, P.: Digital transformation: a literature review and guidelines for future research, vol. 745, pp. 411–421. Springer Nature (2018)Google Scholar
  13. 13.
    Tranfield, D., Denyer, D., Smart, P.: Towards a methodology for developing evidence-informed management knowledge by means of systematic review. Br. J. Manag. 14, 207–222 (2003)CrossRefGoogle Scholar
  14. 14.
    Garza-Reyes, J.A.: Lean and green-a systematic review of the state of the art literature. J. Clean. Prod. 102, 18–29 (2015)CrossRefGoogle Scholar
  15. 15.
    Thomas, J., Harden, A.: Methods for the thematic synthesis of qualitative research in systematic reviews. BMC Med. Res. Methodol. 8, 45 (2008)CrossRefGoogle Scholar
  16. 16.
    Mongeon, P., Paul-Hus, A.: The journal coverage of Web of Science and Scopus: a comparative analysis. Scientometrics 106, 213–228 (2016)CrossRefGoogle Scholar
  17. 17.
    Li, J., Burnham, J.F., Lemley, T., Britton, R.M.: Citation analysis: comparison of Web of Science®, ScopusTM, SciFinder®, and Google Scholar. J. Electron. Resour. Med. Libr. 7, 196–217 (2010)CrossRefGoogle Scholar
  18. 18.
    Riplová, K.: Tool of risk management: failure mode and effects analysis and failure modes, effects and criticality analysis. J. Inf., Control. Manag. Syst. 5, 111–120 (2007)Google Scholar
  19. 19.
    Liu, H.C., Liu, L., Bian, Q.H., Lin, Q.L., Dong, N., Xu, P.C.: Failure mode and effects analysis using fuzzy evidential reasoning approach and grey theory. Expert Syst. Appl. 38, 4403–4415 (2011)CrossRefGoogle Scholar
  20. 20.
    Gorlenko, O., Miroshnikov, V., Borbatc, N.: Development of management methodology for engineering production quality. In: International Conference on Mechanical Engineering, Automation and Control Systems (2016)Google Scholar
  21. 21.
    Atan, H., Ramly, E.F., Musli Mohammad, M.S.Y.: A review of operational risk management decision support tool. In: International Conference on Industrial Engineering and Operations Management (2017)Google Scholar
  22. 22.
    Barata, J., Rupino, P.C., Costa, C.C.: Developing an IS quality culture with ISO 9001: hopefully, a never ending story. In: 24th Australasian Conference on Information Systems (2011)Google Scholar
  23. 23.
    Boiral, O.: Managing with ISO systems: lessons from practice. Long Range Plan. 44, 197–220 (2011)CrossRefGoogle Scholar
  24. 24.
    Budaj, P., Hrnciar, M.: The Importance of Risk-Based Thinking for Enterprise Performance Planning, pp. 244–252. Technical University of Liberec, Faculty Economics, Liberec (2015)Google Scholar
  25. 25.
    Chen, D., Chang, W.F.: A practical flow regarding 2nd party audit on quality proficiency in supplier management. In: Joint International Symposium on e-Manufacturing and Design Collaboration (2017)Google Scholar
  26. 26.
    Da Fonseca, L.M.C.M.: ISO 14001:2015: an improved tool for sustainability. J. Ind. Eng. Manag. 8, 37–50 (2015)Google Scholar
  27. 27.
    Emetumah, F.C.: Integrated management systems as a risk management tool: combining ISO 9001, ISO 14001 & OHSAS 18001 standards in process industries. In: Risk, Reliability and Safety: Innovating Theory and Practice, pp. 1216–1221. Taylor & Francis Group, London (2017)Google Scholar
  28. 28.
    Ezrahovich, A.Y., Vladimirtsev, A.V., Livshitz, I.I.: Risk-based thinking of ISO 9001:2015—the new methods, approaches and tools of risk management. In: International Conference “Quality Management, Transport and Information Security, Information Technologies”, pp. 506–511 (2017)Google Scholar
  29. 29.
    Galleto, M., Franceschini, F., Mastrogiacomo, L.: ISO 9001 certification and corporate performance of Italian companies. Int. J. Qual. Reliab. Manag. 34, 231–250 (2017)CrossRefGoogle Scholar
  30. 30.
    Giannetti, C., Ransing, R.S.: Risk based uncertainty quantification to improve robustness of manufacturing operations. Comput. Ind. Eng. 101, 70–80 (2016)CrossRefGoogle Scholar
  31. 31.
    Gołaś, H.: Risk management as part of the quality management system according to ISO 9001. Commun. Comput. Inf. Sci. 435, 519–524 (2014)Google Scholar
  32. 32.
    Gołaś, H., Mazur, A., Gruszka, J.: Improving an organization functioning in risk conditions in accordance with ISO 9001: 2015. In: 2016 International Conference on Economics and Management Innovations, vol. 57, pp. 257–261 (2016)Google Scholar
  33. 33.
    Harafonova, O.I., Zhosan, G.V., Yankovoi, R.V.: Distinctions and features of ISO 9001:2015 standard implementation in the context of social and strategic development of enterprises. Sci. Bull. Polissia 3, 66–71 (2017)CrossRefGoogle Scholar
  34. 34.
    Harasymiuk, J., Barski, J.: Risk management as a determinant of the effectiveness of the quality management system in a building company. In: 2016 International Conference on Economics and Management Innovations, vol. 57, pp. 8–12 (2016)Google Scholar
  35. 35.
    Kline, J.J., Hutchins, G.: Enterprise risk management: a global focus on standardization. Glob. Bus. Organ. Excel. 36, 44–53 (2017)CrossRefGoogle Scholar
  36. 36.
    Kotek, L., Nosek, A., Fiala, A., Bartos, V.: Risks in industrial management systems. MM Sci. J. 12, 1608–1612 (2016)CrossRefGoogle Scholar
  37. 37.
    Lenning, J., Gremyr, I.: Making internal audits business-relevant. Total. Qual. Manag. Bus. Excel. 28, 1106–1121 (2017)CrossRefGoogle Scholar
  38. 38.
    Liu, F., He, Y., Cui, J.: Product assembling quality risk analysis approach based on RQR chain. In: 2nd International Conference on Reliability Systems Engineering (2017)Google Scholar
  39. 39.
    Liu, Q., Du, Q., Shi, W., Zhu, J.: Modeling of risk treatment measurement model under four clusters standards (ISO 9001, 14001, 27001, OHSAS 18001). In: 2nd SREE Conference on Engineering Modelling and Simulation, vol. 37, pp. 354–358 (2012)Google Scholar
  40. 40.
    Luburić, R.: Quality management principles and benefits of their implementation in central banks. J. Cent. Bank. Theory Pract. 4, 91–121 (2015)CrossRefGoogle Scholar
  41. 41.
    Luburić, R.: Knowledge and learning in terms of operational risk management in the financial and banking systems. Int. J. Qual. Res. 10, 559–568 (2016)Google Scholar
  42. 42.
    Medić, S., Karlović, B., Cindrić, Z.: New standard ISO 9001:2015 and its effect on organizations. Interdiscip. Descr. Complex Syst. 14, 188–193 (2016)CrossRefGoogle Scholar
  43. 43.
    Novaková, R., Pauliková, A., Cekanová, K.: Risk management as a part of a quality management system in woodworking companies. In: Czech University Life Sciences Prague, Prague 6, pp. 170–178 (2017)Google Scholar
  44. 44.
    Pacaiová, H., Sinay, J., Nagyová, A.: Development of GRAM—a risk measurement tool using risk based thinking principles. Measurement 100, 288–296 (2017)CrossRefGoogle Scholar
  45. 45.
    Parra-López, C., Hinojosa-Rodríguez, A., Carmona-Torres, C., Sayadi, S.: ISO 9001 implementation and associated manufacturing and marketing practices in the olive oil industry in southern Spain. Food Control 62, 23–31 (2016)CrossRefGoogle Scholar
  46. 46.
    Psomas, E.L.: The effectiveness of the ISO 9001 quality management system in service companies. Total. Qual. Manag. Bus. Excel. 24, 769–781 (2013)CrossRefGoogle Scholar
  47. 47.
    Rebelo, M.F., Silva, R., Santos, G.: The integration of standardized management systems: managing business risk. Int. J. Qual. Reliab. Manag. 34, 395–405 (2017)CrossRefGoogle Scholar
  48. 48.
    Rewilak, J.: MSA Planning—a proposition of a method. Key Eng. Mater. 637, 45–56 (2015)CrossRefGoogle Scholar
  49. 49.
    Rodriguez, D.R.: Partial implementation of the Quality Management System by ISO 9001:2015. Case study. Dilemas Contemporaneos-Educacion Politica Y Valores, 4:31 (2017)Google Scholar
  50. 50.
    Ruamchat, K., Thawesaengskulthai, N., Pongpanich, C.: Development of quality management system under ISO 9001:2015 and Joint Inspection Group (JIG) for aviation fuelling service. Manag. Prod. Eng. Rev. 8, 50–59 (2017)Google Scholar
  51. 51.
    Sari, Y., Wibisono, E., Wahyudi, R.D., Lio, Y.: From ISO 9001:2008 to ISO 9001:2015: significant changes and their impacts to aspiring organizations. In: International Conference on Informatics, Technology and Engineering (2017)Google Scholar
  52. 52.
    Sartor, M., Orzes, G., Di Mauro, C., Ebrahimpour, M., Nassimbeni, G.: The SA8000 social certification standard: literature review and theory-based research agenda. Int. J. Prod. Econ. 175, 164–181 (2016)CrossRefGoogle Scholar
  53. 53.
    Savino, M.M., Brun, A., Xiang, C.: A fuzzy-based multi-stage quality control under the ISO 9001: 2015 requirements. Eur. J. Ind. Eng. 11, 78–100 (2017)CrossRefGoogle Scholar
  54. 54.
    Sitnikov, C.S., Bocean, C.G.: The role of risk management in ISO 9001: 2015. In: 9th International Management Conference: Management and Innovation for Competitive Advantage (2015)Google Scholar
  55. 55.
    Sitnikov, C.S., Bocean, C.G., Berceanu, D., Pîrvu, R.: Risk management model from the perspective of implementing ISO 9001:2015 standard within financial services companies. Amfiteatru Economic 19, 1017–1034 (2017)Google Scholar
  56. 56.
    Sousa, S., Nunes, E., Lopes, I.: Measuring and managing operational risk in industrial processes. FME Trans. 43, 295–302 (2015)CrossRefGoogle Scholar
  57. 57.
    Vasile, F.: A critical approach of thinking risk-based existing in the new issue of ISO 9001: 2015 standard (in Romanian). EEA—Electrotehnica, Electronica, Automatica 65, 19–23 (2017)Google Scholar
  58. 58.
    Vasile, F.: The improvement of the manufacturing processes of electric servomotors by applying the new editions of the international standards on the quality and environment (in Romanian). EEA—Electrotehnica, Electronica, Automatica 65, 79–84 (2012)Google Scholar
  59. 59.
    Wong, S.K.: Risk-based thinking for chemical testing. Accred. Qual. Assur. 22, 103–108 (2017)CrossRefGoogle Scholar

Copyright information

© Springer Nature Switzerland AG 2019

Authors and Affiliations

  • Yasmin Silva Martins
    • 1
  • Carlos Eduardo Sanches da Silva
    • 1
    Email author
  1. 1.Federal University of Itajubá – UNIFEIItajubáBrazil

Personalised recommendations