RSC Colour: Orange

  • Supply Chain Risk Management (SCRM)

    Supply Chain Risk Management (SCRM) is a structured set of processes and controls used to identify, assess, monitor, and mitigate risks across the end-to-end supply chain. In industrial and regulated manufacturing, it focuses on any disruption, constraint, or nonconformance that could affect material availability, quality, cost, delivery performance, compliance, or data security.

    Key elements of SCRM

    Although implementations vary, SCRM in manufacturing environments commonly includes:

    • Risk identification: Mapping suppliers, logistics routes, critical parts, and digital dependencies (such as ERP, MES, PLM integrations) to surface where failures or constraints might occur.
    • Risk assessment: Evaluating likelihood and impact of risks such as single-source suppliers, long lead times, export-controlled components, cyber incidents affecting OT/IT, or quality escape risks.
    • Risk mitigation and controls: Defining actions like dual sourcing, safety stocks, alternate routings, tighter incoming inspection, supplier development, or hardened data-sharing workflows.
    • Monitoring and detection: Using metrics (on-time delivery, defect rates, shortages), supplier scorecards, and multi-tier visibility tools to detect early signs of disruption.
    • Response and continuity planning: Documented playbooks for expediting, re-planning, rerouting work orders, or temporarily modifying specifications under controlled deviation processes.

    Typical risk categories in regulated manufacturing

    For manufacturers operating under aerospace, defense, or other regulated frameworks, SCRM commonly covers:

    • Supply and capacity risks: Shortages, capacity limits at key suppliers, long lead times for critical parts, and bottlenecks in outsourced processing.
    • Quality and compliance risks: Supplier nonconformances, missing certifications, traceability gaps, and risks to meeting requirements like AS9100, AS9102, or customer-specific quality clauses.
    • Logistics and geopolitical risks: Transportation delays, customs issues, tariffs, export controls, and country-of-origin constraints.
    • Cybersecurity and data-handling risks: Compromise of shared technical data, vendor access to OT/IT systems, and alignment with controls such as NIST 800-171, CMMC, DFARS, or ITAR-related workflows.
    • Operational integration risks: Failures in data exchange between ERP, MES, PLM, and supplier portals that affect purchase orders, work orders, and as-built records.

    How SCRM shows up operationally

    Operationally, Supply Chain Risk Management often appears as:

    • Supplier qualification and onboarding processes that evaluate risk factors.
    • Use of supplier scorecards, critical part tracking, and shortage dashboards in ERP or planning tools.
    • Cross-functional reviews that connect purchasing, planning/MRP, quality, engineering, and production.
    • Documented risk registers, exception workflows, and escalation paths tied to work orders and materials.
    • Controls on how drawings, models, and specifications are shared with external partners.

    Common confusion

    • SCRM vs general supply chain management (SCM): SCM covers planning and execution of material and information flows. SCRM focuses specifically on identifying and controlling risks within those flows.
    • SCRM vs business continuity planning: Business continuity is organization-wide and looks at sustaining critical operations. SCRM is supply-chain-focused and often feeds into wider continuity and resilience planning.
    • SCRM vs cybersecurity risk management: Cybersecurity programs address digital and network risks broadly. SCRM includes cyber and data-handling risks where they affect suppliers, logistics, and shared technical data, but is not limited to cybersecurity topics.
  • Safety-Critical Component

    A safety-critical component is any hardware or software element whose failure, malfunction, or unintended behavior could directly cause, or significantly contribute to, a safety incident, injury, environmental harm, or major equipment damage. These components are designed, manufactured, tested, and maintained under stricter controls because of their direct impact on safety outcomes.

    Key characteristics

    In industrial and manufacturing environments, a component is commonly treated as safety-critical when:

    • Its correct operation is necessary to prevent hazardous situations, and
    • Its failure could reasonably lead to harm to people, critical assets, or the environment.

    Examples include:

    • Machine guarding systems and interlock switches on production equipment
    • Emergency stop circuits and safety relays in control panels
    • Pressure relief devices, valves, and sensors in process plants
    • Safety PLC modules or safety-rated firmware that control protective functions
    • Software logic in MES or SCADA that triggers shutdowns or alarms used for safety decisions

    Operational context

    In regulated or high-risk manufacturing, safety-critical components typically:

    • Are identified through risk assessments, hazard analyses, or process hazard reviews
    • Have specific design, qualification, and verification requirements
    • Are subject to controlled procurement, traceability, and change management
    • Require documented inspection, calibration, maintenance, and replacement intervals
    • Are often covered by formal functional safety or reliability studies

    Information about safety-critical components may be referenced across OT and IT systems, including maintenance management, MES, and quality systems, to ensure consistent handling and documentation.

    What it includes and excludes

    Safety-critical components include both:

    • Physical parts, such as switches, sensors, actuators, and mechanical devices that perform or enable a protective function
    • Software or configuration items, such as safety-related logic, parameters, or control rules used to prevent or mitigate hazards

    They generally exclude:

    • Components that only affect production rate, yield, or quality without a credible path to a safety hazard
    • Purely cosmetic or non-functional elements, even if they are part of the same assembly

    Common confusion

    Safety-critical vs. mission-critical: A mission-critical component is necessary to continue production or business operations, but its failure does not automatically imply a safety risk. A safety-critical component is specifically tied to preventing or controlling hazards that could cause harm.

    Safety-critical vs. quality-critical: A quality-critical component affects whether a product meets specification. Some components are both safety-critical and quality-critical, especially in regulated products, but the terms are not interchangeable. Safety-critical focuses on hazard prevention and protection from harm.

    Use in manufacturing systems

    Within manufacturing systems, safety-critical components may be:

    • Flagged in bills of materials (BOMs) for special handling and traceability
    • Linked to specific work instructions, inspection plans, and verification steps
    • Captured in change control workflows when design or supplier changes occur
    • Referenced in audit trails, deviation records, and incident investigations

    Clear identification and consistent treatment of safety-critical components support systematic risk management and documentation across the lifecycle of equipment and products.

  • risk-based classification

    Risk-based classification is the practice of categorizing items, activities, or records into defined classes according to their assessed level of risk. In industrial and regulated manufacturing environments, it is used to decide how much control, oversight, documentation, or response is required for different situations.

    The approach typically relies on a structured risk assessment, such as considering likelihood and severity of impact on safety, quality, regulatory compliance, delivery, or business continuity. Based on this assessment, the subject is assigned to a discrete class (for example: low, medium, high, or Class I, II, III), which then drives predefined actions or requirements.

    How it is used in manufacturing and regulated operations

    Risk-based classification commonly appears in:

    • Nonconformances and deviations: Classifying nonconformance reports (NCRs) or deviations by risk level to set investigation depth, escalation paths, and target closure times.
    • Change control: Categorizing engineering changes, process changes, or software changes to determine required approvals, validation effort, and documentation.
    • Equipment and processes: Classifying equipment, production lines, or process steps based on potential impact on product quality or patient/user safety, which then drives maintenance, monitoring, and qualification expectations.
    • Documents and data: Assigning risk or criticality classes to procedures, specifications, and records to define review frequency, access control, and backup/retention rules.
    • Suppliers and materials: Classifying suppliers, components, or raw materials by risk to establish incoming inspection, audit frequency, and quality agreements.

    In practice, risk-based classification is often codified in the quality management system (QMS), MES workflows, or ERP/MRP master data as attributes or fields that influence routing, approvals, KPIs, and alerts.

    Key characteristics

    • Criteria-driven: Uses defined criteria such as severity, occurrence, detectability, or regulatory impact, often aligned with risk tools like FMEA.
    • Tiered levels: Breaks risk into a manageable number of classes that map to clear operational rules.
    • Repeatable and documented: Requires consistent methods and documented rationale so classifications can be explained during audits and reviews.
    • Dynamic: Classifications may be updated when new information emerges, processes change, or controls are improved.

    Common confusion

    • Risk-based classification vs. risk assessment: Risk assessment is the analysis used to understand and quantify risk. Risk-based classification is the step of assigning the outcome of that assessment to a discrete class that then drives rules and actions.
    • Risk-based classification vs. priority coding: Priority codes (for example, urgent vs. routine) may consider scheduling or resource constraints. Risk-based classification is specifically tied to the underlying risk to safety, quality, compliance, or business impact, even if it is later translated into priorities.

    Link to the derived context

    In the context of nonconformance management, risk-based classification is used to group NCRs into risk levels and set different time limits, escalation paths, and review expectations for each class. Higher-risk classes typically trigger faster response and more formal justification if targets are exceeded.

  • Consequence

    Consequence commonly refers to the outcome, impact, or result of an event, action, failure, or deviation. In industrial and regulated manufacturing environments, it is a core concept in risk, safety, and quality management, where consequence helps describe how serious a given hazard, nonconformance, or system failure could be.

    Typical uses in manufacturing and operations

    In operational contexts, consequence is often used as a structured way to describe impact in areas such as:

    • Safety and health: harm or injury to personnel resulting from an incident, unsafe condition, or equipment failure.
    • Product quality: effect on product performance, compliance to specification, or patient/end-user safety when a defect occurs.
    • Regulatory and compliance: impact on regulatory status, inspections, or legal standing if requirements are not met.
    • Business and operations: financial loss, downtime, scrap, rework, or delivery delays caused by disruptions.
    • Environment: impact on emissions, waste, or environmental releases from process upsets.

    In many risk methods, consequence is combined with likelihood (or probability) to estimate an overall risk level. For example, a risk matrix or FMEA will often rate consequence on a defined scale (such as negligible, minor, major, critical) for consistent evaluation.

    Consequence in risk and quality methodologies

    Several structured methodologies use consequence as a defined factor:

    • Risk assessments and HAZOP-style studies: consequence describes the severity of a scenario if a hazard is realized.
    • FMEA (Failure Modes and Effects Analysis): consequence aligns with the severity of the effect of a failure mode on the system, user, or process.
    • Process deviation and CAPA investigations: consequence helps classify deviations, nonconformances, or complaints (for example, critical vs. major vs. minor) and can guide prioritization.
    • Business continuity and supply risk assessments: consequence describes service disruption, revenue impact, or impact on critical customers if a risk occurs.

    Operationally, consequence ratings may be captured in MES, QMS, EHS, or risk register tools, and then used to drive workflows such as escalation, approvals, or specific controls.

    What consequence is and is not

    • It is an impact measure: what happens if an event occurs.
    • It is not the probability, frequency, or likelihood that the event will occur.
    • It may be qualitative or quantitative, depending on the method and available data.
    • It is usually defined relative to a specific context, such as safety, quality, or business impact, using agreed rating criteria.

    Common confusion

    • Consequence vs. likelihood: Consequence addresses “how bad would it be if this happened?” Likelihood addresses “how often or how likely is it to happen?” Many risk frameworks treat these separately.
    • Consequence vs. severity: In many practical risk and quality tools, these are used almost interchangeably. “Severity” often refers to the level of consequence on a scale, while “consequence” describes the broader effect.
    • Consequence vs. root cause: Root cause explains why an event occurred. Consequence describes what resulted from that event.

    Link to operational decision making

    Defined consequence categories and criteria support consistent decision making in industrial operations. For example, a higher-consequence classification may trigger more stringent controls, faster investigation timelines, specific documentation requirements, or management notification. Clear definitions and documented scales help ensure that different teams assess consequence in a similar way across sites, systems, and processes.

  • Near-Miss

    Core meaning

    A **near-miss** is an unplanned event or condition that had the potential to cause harm, loss, or other adverse outcomes, but did not actually result in injury, damage, nonconforming product, or reportable incident.

    In industrial and manufacturing environments, this commonly refers to situations where:

    – A hazardous condition was present and almost led to a safety incident
    – A process deviation nearly produced nonconforming product
    – An equipment or system failure was narrowly avoided before causing downtime or quality impact

    Near-misses are treated as early warning signals that a hazard, weakness, or control gap exists in the system.

    Use in industrial and regulated environments

    In operations and manufacturing systems, near-miss reporting and analysis is typically integrated into:

    – **EHS and safety programs**: Near-misses related to worker safety, machine guarding, lockout/tagout, chemical handling, or ergonomics.
    – **Quality management systems (QMS)**: Near-misses related to out-of-spec parameters, incorrect materials, or documentation errors that were caught before product release.
    – **Maintenance and reliability workflows**: Near-misses indicating potential equipment failures, such as overheated components, atypical vibration, or control system faults that auto-recovered.
    – **OT/IT and MES environments**: Events such as incorrect recipe selection, mis-scanned material, or unauthorized parameter changes that were detected by system controls before affecting production.

    Near-misses are often logged in event management or deviation systems, reviewed in risk or safety meetings, and used as input for root cause analysis and corrective or preventive actions.

    Boundaries and what it is not

    A near-miss:

    – **Does include** events where no actual harm or nonconforming output occurred, but where credible potential existed.
    – **Does not require** physical injury, environmental release, or confirmed defective product.
    – **Does not include** routine process variation that remains within defined limits and poses no credible risk.
    – **Does not include** purely hypothetical scenarios with no triggering event (those are typically handled in risk assessments, not near-miss logs).

    Near-misses may still involve minor consequences such as short pauses, alarms, or temporary rework, as long as the primary adverse outcome (e.g., injury, major nonconformance, or significant loss) did not occur.

    Data and system handling

    In digital operations and manufacturing systems, near-misses may be:

    – Captured as **event records** in EHS, QMS, or incident management tools
    – Linked to **equipment, batches, work orders, or locations** in MES or ERP
    – Categorized by **risk type**, **root cause**, or **process area**
    – Analyzed as **leading indicators** in dashboards and operations intelligence tools

    Some organizations use standard fields such as severity potential, likelihood, and classification (safety, quality, environmental, cybersecurity, etc.) to support structured analysis.

    Common confusion and terminology

    Near-miss is sometimes confused with related terms:

    – **Incident**: An event where harm, damage, or nonconforming output actually occurred. A near-miss stops short of that outcome.
    – **Hazard**: A source of potential harm that may exist independent of any particular event. A near-miss involves an event or situation in which the hazard nearly produced an adverse outcome.
    – **Risk**: The combination of the probability and consequence of an event. Near-misses are real-world occurrences that inform risk assessment but are not themselves risk ratings.

    In some safety literature, the term **”near-hit”** is used instead of near-miss, but the operational meaning is the same.

    Role in continuous improvement

    Near-miss information is frequently used as input to:

    – Problem-solving methods (e.g., 5 Whys, fishbone diagrams) to understand underlying causes
    – Risk reviews in quality or safety committees
    – Changes to procedures, training, or control strategies

    Because near-misses occur more frequently than actual incidents, they are commonly treated as important signals when monitoring the effectiveness of controls in manufacturing and other industrial operations.