Overview
ISO/IEC TR 33015:2019 - "Information technology - Process assessment - Guidance for process risk determination" provides practical guidance on using results from process assessments to identify and determine process-related risk. It explains how to map assessment output (e.g., process attribute ratings and gaps against a target process profile) into meaningful risk findings that support decision-making, supplier selection, and risk mitigation. The guidance is independent of specific organizational structures, life-cycle models or development methods and is applicable across customer–supplier relationships or any organization performing a process risk determination.
Key topics and technical requirements
- Purpose and outcomes: Defines the objective of process risk determination and the significance of assessment scope and process context.
- Process risk determination workflow: A nine-step approach that includes:
- Initiate process risk determination
- Identify relevant processes and process context
- Define target process profile
- Define target assessment input
- Assess current process quality
- Determine proposed process quality characteristic achievement
- Verify proposed achievement
- Analyse process-related risk
- Act on results
- Assessment inputs and models:
- Selection of process quality characteristics, measurement frameworks, process reference models and assessment models.
- Guidance on defining the target assessment input and target process profile that align with the particular requirement or category of requirements.
- Mapping assessment output to risk:
- Using process attribute ratings and identified weaknesses to infer risks.
- Recommendations for data/information collection, rating guidelines, comparability of outputs, and verification of proposed achievements.
- Annex guidance: Informative annexes categorize types of process-related risks, provide analysis techniques, and give example target process profiles.
Practical applications
- Supplier selection and acquisition: Use process risk determination to compare suppliers’ process capabilities and identify contract-level risks.
- Risk mitigation planning: Translate assessment weaknesses into prioritized process-related risks to inform remediation actions.
- Decision support: Provide objective evidence for go/no-go decisions, resource allocation, and acceptance criteria for products/services.
- Process improvement: Feed assessment-based risk findings into continual improvement and organizational risk management processes (noting scope is limited to process-related risk).
Who should use this standard
- Stakeholders commissioning process risk determinations (customers, program managers)
- Lead assessors and assessment team members performing or interpreting assessments
- Organizations evaluating their processes against specific requirements
- Developers of assessment methods and tools seeking alignment with the ISO/IEC 330xx assessment framework
Related standards
- ISO/IEC 33001 - Concepts and terminology for process assessment
- ISO/IEC 33002 - Requirements for process assessment execution (process context)
- ISO/IEC 33014 - Guidance on process improvement (continual improvement)
- ISO/IEC 330xx family (replaces parts of ISO/IEC 15504)
Keywords: ISO/IEC TR 33015:2019, process risk determination, process assessment, process-related risk, process profile, assessment scope, process context, supplier selection, risk mitigation.