← Modules
Risk management · ISO 9001 clause 6.1
Assess risks before they become findings.
Risk-based thinking is not a spreadsheet that wakes up once a year. EnterpriseCAQ keeps risks as a living register – rated, visualised, linked to actions and effective all the way into the event chain.
The register with a heat map.
Every risk is rated by probability × impact and lands in the right band automatically.
- Probability × impact rating with consistent bands: critical, high, medium, low – comparable across the company
- Heat map visualisation: the whole risk profile at a glance
- Derive actions straight from a risk – with the origin “risk” in the central action register
- SWOT analyses as a structured way into the risk view of the organisational context
Risk rules: rating that runs by itself.
Besides the risks you record, EnterpriseCAQ also rates day-to-day business – automatically.
- A configurable rule table: “an object of type X in status Y carries this much risk while it stays open”
- Live rating of every tile in the event chain – without anyone rating it by hand
- Overdue objects and those close to their due date escalate in the rating automatically
- Rule changes take effect immediately – no migration, no restart
From context to risk.
Risks do not fall from the sky – they arise from the context of the organisation (ISO 9001 clause 4.1).
- SWOT analysis as a management view of the organisational context – derived live from internal and external issues and the PESTLE analysis
- Opportunities and risks carry their probability × impact rating right in the SWOT and can be taken over into the risk register
- Strengths and weaknesses with category and weighting – the basis for strategic quality planning
- “Freeze as document” turns the current state into a controlled record for the management review