AI Quality Risk Register & Heat Map Software

By David Cook on September 23, 2026

quality-risk-register-software

ISO 9001:2015 clause 6.1 formalised risk-based thinking as a QMS requirement. IATF 16949 goes further, requiring a systematic risk management approach that integrates with FMEA, control plans, and change management. In practice most organisations respond with a static spreadsheet — populated at certification audit and revisited the same day next year. A living quality risk register with scoring, heat-map visualisation, owned mitigations, and review cadence is what the standards actually envision: risks captured continuously as the operation evolves, prioritised by severity and likelihood, mitigated with tracked actions, and reviewed on schedule. Not a spreadsheet that satisfies an auditor; a decision tool the leadership team actually uses.

iFactory / Quality risk register

A Living Quality Risk Register — Scored, Visualised, and Owned

Maintain quality risks with severity/likelihood scoring, 5x5 heat map visualisation, named mitigation owners, and review cadence — aligned to ISO 9001:2015 clause 6.1, IATF 16949 risk-based thinking, and ICH Q9 for regulated environments.
Risk Heat Map
Severity × Likelihood, 5x5
5




R
4


•


3

•



2


•


1





Sev↑
1
2
3
4
5
Living register. Every risk with owner, mitigation, and next review date.
5x5 heat map
severity × likelihood
ISO 9001 6.1
risk-based thinking
Living
not annual spreadsheet

The Problem in Quality Risk Management

An ISO 9001 or IATF 16949 certified operation is required to demonstrate risk-based thinking — identifying risks that could affect product conformity and customer satisfaction, evaluating them, and taking action commensurate with impact. In practice, most quality teams produce a risk register spreadsheet before the certification audit, populate it with a defensible set of risks, walk the auditor through it, and set it aside for another year. The register that made sense on audit day becomes stale within weeks — a new supplier is qualified, a design changes, a process moves to a different line, a complaint reveals a risk nobody scored. When the next audit arrives, the register is either regenerated in a rush or defended as-is.

Where the Risk Register Actually Fails as a Tool

Quality risk register failure modes are consistent across certified organisations. Each is a specific ISO 9001 or IATF 16949 finding category.

Audit-day artifact
Register populated for certification, filed after. Not updated as risks emerge or change. Next surveillance audit finds the same list and the same scores from 12 months earlier.
Unowned risks
Risks captured without a named owner or review cadence. Mitigation actions listed but nobody accountable for closure. Audit finding: risk-based thinking is documented but not implemented.
Score inflation
Every risk scored high because 'we take everything seriously.' Heat map shows all red. Nothing is prioritised because nothing is de-prioritised. Register becomes noise.
Disconnected from FMEA
Risk register and product/process FMEAs run as separate exercises. A risk on the register doesn't propagate to the relevant FMEA and vice versa. Two views of risk that never reconcile.

What Good Looks Like in Risk Management

A working risk register holds four disciplines together — living capture with continuous update, calibrated scoring with heat-map visualisation, owned mitigation with tracked closure, and linkage to FMEA and process controls.

Living Capture
Risks added, updated, and closed continuously as the operation changes. New supplier, product change, complaint, or process move each trigger a register update prompt.
Continuous, not annual
Calibrated Scoring
Severity and likelihood scales calibrated with worked examples so scores are comparable across risks and reviewers. Heat map visualisation surfaces the top risks at a glance.
Calibrated, comparable
Owned Mitigation
Every risk with named owner, mitigation actions, target dates, and review cadence. Closure tracked to evidence. Overdue actions surfaced weekly to the quality lead.
Owned to closure
FMEA Linkage
Register risks link to relevant DFMEA/PFMEA records and to control plan controls. Movement in one propagates to the other. One consolidated view of risk.
One risk picture

How iFactory AI Fits

iFactory AI works alongside your existing FMEA, control plan, and CAPA workflows — providing the register layer that consolidates risks from complaint, audit, FMEA, and management-review sources into one heat-mapped view.

Risk Register
Risk Layer
Every risk with description, source, severity, likelihood, owner, mitigation actions, target date, and next review. Living record, not annual snapshot.
Heat Map
Risk Layer
5x5 (or configurable) severity-vs-likelihood matrix with every open risk plotted. Filters by source, area, product family, and owner for focused review.
Mitigation Tracker
Risk + Action
Mitigation actions with owner, target date, evidence attachment, and closure tracking. Overdue and approaching-due actions escalated on cadence.
FMEA Bridge
Risk + FMEA
Bidirectional link between register risks and DFMEA/PFMEA records. New high-AP FMEA items propose register additions; register additions prompt FMEA review.

Ask your quality manager to show the risk register update history for the last quarter. If updates are clustered around audit dates and sparse in between, the register is an audit artifact — not a risk tool. Book a risk register review.

8-Week Risk Register Rollout

One site or one product family, eight weeks. The pilot loads the current risk landscape, activates continuous update, and produces a first quarterly management review from the living register.

Weeks 1–2
Landscape Load
Load current risks from existing register, recent complaints, audit findings, and high-priority FMEA items. Calibrate scoring with quality team on worked examples.
Weeks 3–4
Owners + Cadence
Assign named owner to every risk. Set review cadence per risk score. Configure escalation for overdue actions. First management review with the heat map.
Weeks 5–6
FMEA Linkage
Bidirectional FMEA linkage active. Register updates from FMEA changes and vice versa. New-risk workflow tested via a real complaint or process change.
Weeks 7–8
Quarterly Review
First quarterly management review from the living register. Rollout to remaining sites and product families scoped based on register-currency and action-closure numbers.

Who Owns the KPI

Risk register crosses quality, operations, engineering, and executive leadership. Each function owns a specific KPI or the register becomes a compliance artifact.

Quality Manager
Register updates per month
Owns the currency — the count of register updates per month (additions, score changes, closures). Sparse update means the register is not being used as a tool.
Risk Owners
Mitigation actions closed on target
Owns the action closure — every named owner meets their target dates for the risks they own. Rising overdue signals the ownership assignment isn't landing.
Engineering Lead
Register-FMEA alignment
Owns the linkage integrity — high-AP FMEA items reflected in register, register additions prompt FMEA review. Alignment breakdown creates two views of risk.
Executive Sponsor
Top-5 risks reviewed quarterly
Owns the leadership discipline — the top-5 risks by heat-map position reviewed with named actions at every quarterly management review.

FAQ

How does this align with ISO 9001 clause 6.1 and IATF 16949 requirements?
ISO 9001:2015 clause 6.1 requires organisations to determine risks and opportunities that could affect product/service conformity and customer satisfaction, and to plan actions to address them proportional to impact. IATF 16949 adds specific requirements including risk analysis, contingency plans, and integration with FMEA. The living register with owned mitigation and review cadence directly evidences clause 6.1 implementation for surveillance audits. Where your industry adds pharmaceutical (ICH Q9), medical device (ISO 14971), or aerospace (AS9100) risk requirements, the register configures to those specific scoring and documentation rules.
What's the right scoring scale — 3x3, 5x5, 10x10?
5x5 (severity 1-5 × likelihood 1-5) is the most common because it forces enough distinction to surface priorities without inviting false precision. 3x3 collapses too many risks into the same bucket to prioritise well. 10x10 invites false precision — nobody can reliably distinguish between likelihood 6 and 7. The specific score-to-action-priority mapping (which combinations of severity × likelihood require which response) configures per your quality plan. For AIAG-VDA-aligned organisations, register scoring can align with the FMEA Severity/Occurrence scales for cross-reference consistency. Book a demo to see the scoring calibration.
How does this differ from FMEA — do we need both?
Yes, and they serve different purposes. FMEA (DFMEA, PFMEA) is a bottom-up analysis of failure modes within a specific product or process, driving control plan and design decisions. The quality risk register is a top-down view of enterprise-level risks that affect the QMS as a whole — supplier risks, regulatory changes, capacity constraints, competency gaps, contingency scenarios. High-AP items from FMEAs feed the register when they represent broader systemic risk; register risks prompt targeted FMEA review when they surface a failure mode not yet analysed. The two are complementary views that share the same underlying data.
Stop treating the risk register as an audit artifact.

Load Your Current Risks and Produce a Live Heat Map

Bring your current risk register, recent audit findings, and top complaints from the last quarter. We'll load them into the living register, calibrate scoring with your team, and produce a heat map that surfaces where mitigation attention actually belongs.
Living
register
Owned
mitigation
Heat-map
prioritised
ISO + IATF
aligned

Share This Story, Choose Your Platform!