Risk is back again. "Risk-Based" is the new trendy approach for QC. Is it any different from the last time Risk Management was touted as the future?
Ever since the publication of the latest ISO 15189:2022 and the forthcoming ISO 9001:2026, “Risk-Based” QC has been trending. Once upon a time, we spoke of Risk Management in relation to these standards, but now there’s a new term in town.
When laboratories are now being encouraged to embrace “Risk-based” QC, perhaps they also need to take a moment to understand the kind of QC they are currently performing. ISO seems to imply that our current QC efforts are “Risk-y”, not Risk-Based. There’s something true about that. As our 2025 global survey found, most QC practices in laboratories worldwide are far more arbitrary than we’d like to admit. The persistent use of the 1:2s rule for warning, rejection, and repeat; the routine reflexive repeating of controls when an outlier is encountered; the use of overly-broad ranges supplied by external resources rather than the actual mean and SD calculated by the laboratory itself. https://www.westgard.com/qc-applications/basic-qc-practices/2025-global-qc-survey.html
All of these practices increase risk to patients, rather than diminish it.
The central idea of ISO and “Risk-Based” is that laboratories need to place patient care at the center of their focus and design processes that minimize the risk to patients. Our typical laboratory processes are “compliance-based”, finding solutions that are cheapest to implement and most likely to survive an inspection.
Intriguingly, the GUM (ISO/IEC Guide 98-3: Guide to the Expression of Uncertainty in Measurement. which is the bible and 10 commandments all in one of measurement uncertainty) does NOT formally define or use the word "Risk." Its focus, as the title implies, is on uncertainty, not risk.
Ironically, other ISO standards do provide a definition of risk, and that definition includes uncertainty:
“Risk is now defined as the ‘effect of uncertainty on objectives’, which focuses on the effect of incomplete knowledge of events or circumstances on an organization’s decision making.” This, from the dedicated standard on Risk Management ISO 31000:2018. https://www.iso.org/news/ref2263.html
What is not stated at all, but we are meant to understand, is that the objectives are driven by the patient, and thus the process risk is also connected to patient risk. “Risk-Based” really means “[Patient] Risk-Based.”
If I ask you for a definition of Risk, I doubt that you’d come up with ‘effect of uncertainty on objectives.’ Like so much of ISO, the definition is intentionally vague, providing a lot of options and flexibility to the laboratory that implements it. Unfortunately, that flexibility can equally be mistaken for ambiguity, and laboratories are just as likely to become confused as they are to exercise their freedom and professional judgment. This ISO confusion helps support the consultant economy, where experts in translating the cryptic language of ISO standards into plain English can command high fees.
Outside of ISO, an older definition of Risk accompanies the semi-quantitative term, Risk Priority Numbers (RPN). https://www.westgard.com/essays/risk-management/risk-assessment.html A 3-Factor RPN is determined as the product of severity * occurrence * detectability. More commonly, a 2-Factor RPN is used: severity*occurrence. Various hazards or risk modes are assessed for severity and occurrence, often on a scale of 1 to 5, and then they are multiplied. Thus, the 2-Factor Risk of a particular hazard or failure mode might be a whole number from 1 to 25, with the higher number coinciding with higher risk. As you suspect, this kind of subjective ranking, multiplied, can generate wildly variable results. https://www.westgard.com/essays/risk-management/failure-modes-risk-assessment.html
And, again, this is not the common understanding of risk.
For those of you with long-ish memories, some of the latest discussion may sound familiar, almost an echo of the earlier appearance of Risk in laboratory QC.
We’re referring, of course, to the CLSI EP23 guideline, which gave birth to the IQCP era.
https://clsi.org/shop/education/courses/ep23-iqcp/
There was a period of regulatory chaos in the early 21st century, where CLIA regulations struggled with "Electronic QC" for POC devices. The idea of “Equivalent QC” was introduced as a rationale for substituting other control mechanisms for traditional statistical QC. https://www.westgard.com/essays/risk-management/official-risk-qc.html https://www.westgard.com/clia-and-quality-regulation-requirements/clia-final-rule/cliafinalrule13.html “Equivalent QC” was poorly defined and even more poorly received. Two committees were formed at CLSI, for EP22 (risk information from manufacturers) and EP23 (risk management by customers) as a way to develop a solution. EP22 voted itself out of existence (manufacturers, it turns out, don’t want to provide risk information to their customers). So all that was left was EP23, which stressed Risk management as the way to handle QC for any test method, not just those found on POC devices. EP23 was adopted by the regulators and implemented in the form of IQCP (Individualized Quality Control Plan).
While IQCP emphasized the concept of Risk Management, the practical implementation was anything but. The problem that IQCP was built to solve was the “wild west” of QC for POC devices. POC manufacturers were telling users to reduce how often they ran “traditional QC”, and to rely instead on built-in function checks. IQCP allowed laboratories to justify these lax QC practices. Labs that were doing QC once a month, after IQCP, performed QC once a month, now with regulatory blessing. I have never encountered a laboratory implementing IQCP that actually increased their QC to run more frequently or more levels.
[Running QC only once a month, by the way, is literal lunacy. Using the phase of the moon to determine your QC frequency has no basis in science, unless you are werewolf.]
After IQCP was implemented by laboratories for POC devices, any thought of Risk Management faded away. IQCP was not real Risk Management, it was simply providing regulatory cover for the reduced QC practices found at POC.
But with the publication of ISO 15189:2022 and the upcoming release of ISO 9001:2026, Risk has returned to fore. It’s in fashion again.
Here are just a few of the recent papers I have come across that mention Risk and QC.
What do most of these papers have in common? They adopt a customized, individualized QC approach instead of a single monolithic QC approach. The QC rules and sometimes even QC frequency varies test by test.
But having different QC rules for different tests doesn’t mean you are automatically implementing “Risk-based” QC. The reasons for rule customization may not be tied directly to patient risk.
Remember, the optimization of QC is driven by analytical Sigma-metrics. Specifically, the allowable total error (TEa), which sets the quality requirement, and then the imprecision and bias of the method inform whether or not the test can hit that target with any reliability. Six Sigma means hitting the target almost all the time. As the Sigma metric goes lower, the reliability of the test also declines, and the need for more QC rules and frequency increases.
The Milan 2015 Hierarchy enshrined three kinds of performance specifications:
1. Clinical Use
2. Biology
3. State of the Art
https://www.westgard.com/clia-and-quality-regulation-requirements/quality-requirements/milan-mandate.html
So if the goal being applied is derived from actual Clinical Use, for instance, patient diagnosis, treatment, etc, then it could be considered that the Sigma metric is Risk-Based. It could be argued that a goal based on the within-subject biological variation is also very patient-focused, and thus Sigma metrics from that source would also be Risk-Based. The third type of goal, however, is more distant from the patient. Goals of the State of the Art (SOTA) kind are often coming from regulations, accreditation guidelines, external quality assessment (proficiency testing) targets. These goals may be more focused on compliance than the patient. Of course, one can argue that SOTA goals should be related to the Patient as well. But the global consensus seems to be that SOTA goals are the least attractive, and should only be used when the other two types of goals aren’t available.
There’s just one problem: labs mostly use SOTA goals. Very few Patient goals exist, and as the EFLM found out, the biological goals are often impossible to reach with today’s instrumentation (so much so, they lowered the recommended default from desirable to minimum, and even then many of the goals are still too small to hit. https://www.westgard.com/essays/quality-requirements-and-standards/era-minimum-quality-begins.html
[Side note: There is strong desire among the EFLM elite to abandon TEa goals entirely for the exclusive pursuit of measurement uncertainty. https://www.degruyterbrill.com/document/doi/10.1515/cclm-2024-0377/html We strongly disagree. https://www.researchgate.net/publication/381340579_The_value_of_Sigma-metrics_in_laboratory_medicine]
With all that said, it remains the laboratory’s choice to determine what is Risk-Based and what is not. Your Risk-Based QC may not be the same as mine. Perhaps your patient population is different. Perhaps your clinicians have a different risk tolerance, or use different diagnosis cutoffs. Perhaps your instruments perform differently. You may even consider running QC once a month is an acceptable risk. You may believe that a SOTA goal is just as appropriate as a biological goal.
Let’s make this more explicit. In one of the papers above, the “Risk-based redesign of internal quality control procedures for emergency immunoassays” by Guangjun Xiao, Juan Hu, Yaning Liu et al, they describe a QC frequency that varied from every 2 days to more than 165 days. The mathematics of QC frequency driven by Sigma metrics can state that a Six Sigma method can go 1,000 patients before needing QC to be run again. But if the context is that the method is only being used to run 6 patients a day, that’s an important qualifier. In Sigma-driven QC frequency, the recommendation is built on the assumption/requirement that the method is stable for the entire period of the proposed run, and also that regulatory mandates and manufacturer instructions must be followed. If the manufacturer of the method requires a daily calibration step, that means you cannot extend the run to 165+ days. Similarly, if there is a regulatory minimum QC frequency, that trumps any Sigma recommendation. This is a Chinese study, so I’m unaware of any mandates on QC frequency, but I’m confident that waiting 165 days before running QC again is going to be frowned upon. Such a practice would not find favor in a CLIA/CAP/JCI laboratory, and probably any ISO 15189 laboratories would reject this approach, too. Nevertheless, this shows that following a Risk-Based process can lead to Risk-y solutions, particularly if context and practical reality are ignored.
In the US, inspectors are not likely to challenge the way laboratory IQCPs assess risk. So effectively a laboratory IQCP is always valid, as long as the document is properly structured (has the right table of contents and sections). ISO inspectors, however, may not be so hamstrung or generous. They may have their own interpretation of what Risk-Based means.
Outside the USA, a laboratory must be prepared to back up whatever “Risk-Based” QC they have designed with references and reasons why that particular choice is actually addressing risk.
As discussed on this website 20 years ago, there are Risks of Risk Management: https://www.westgard.com/essays/guest-essay/guest31.html
Laboratories will need to make the same decisions about Risk-Based QC.
If you select a TEa that is the intended quality for patient care, and use your observed imprecision and bias, you can calculate an analytical Sigma metric strongly connected to Risk. Your assessment of method quality will be Risk-Based. Your QC will be Risk-Based. It won't be an arbitrarly ranking of two elements from 1 to 5 and 1 to 5. It will derive directly from the actual performance of the method.
Of course, the simplest choice is to make no choice at all. To maintain the same minimum QC that labs have performed for decades: 1:2s with 2 controls, repeating and repeating, recalibrating, slowing results. This status quo, for many laboratories, is ruinously wasteful. In the US, the funding of laboratories is increasingly fraught (reimbursements declining, government funding of healthcare has been significantly degraded). The current waste is untenable. So perhaps the biggest risk is making no change at all.