77R-15Intermediate11 min read

Quality Control & Assurance for Risk Management

A beginner's guide to QA/QC for risk management — applying quality assurance and quality control to the risk process so the analysis is sound, the inputs are credible, and the outputs can be trusted. Built on AACE International RP 77R-15.

What QA/QC for risk management means

Every other lesson in this track produces something — a risk register, a matrix, a decision, a contingency. This lesson asks the obvious follow-up question: how do we know any of it is any good? A risk analysis is only as trustworthy as the process behind it, and that process is itself prone to error and bias. QA/QC is the safeguard.

QA vs QC — prevention vs detection

The two letters do different jobs, exactly as in physical quality management:

  • QA · PREVENT — Quality assurance builds quality in up front — the process and standards that make a good result likely: A defined, repeatable risk process; Competent, trained risk practitioners; Standard templates, scales, and methods; Clear roles and documented procedures
  • QC · DETECT — Quality control inspects the output after the fact — checking the actual analysis for errors: Peer review of the risk register; Sense-checking probabilities and impacts; Validating model inputs and assumptions; Benchmarking results against history

The errors QA/QC catches

Good risk QA/QC hunts for the specific failure modes that corrupt a risk analysis:

  • Bias in the estimates — Optimism, anchoring, and motivational bias skew probabilities and impacts — the analyst wants a low number. Check inputs against data, not just opinion.
  • Gaps and double-counting — Missing risks (nothing was identified for a whole area) and the same risk counted twice both distort the result. Cross-check coverage and overlap.
  • Method misuse — A method applied wrongly — bad correlations in a Monte Carlo, a P×I scale used inconsistently — produces confident nonsense. Verify the technique fits and is applied correctly.
  • Unsupported inputs — Numbers with no basis ("we figured 20%") can't be defended. Every significant input should trace to data, benchmark, or documented expert judgment.

Applying QA/QC to risk work

Build quality in (QA): adopt a defined risk process, standard scales and templates, and trained people. Then check the output (QC): have someone independent review the risk register and any quantitative model, sense-check the headline numbers, and confirm inputs are supported. Scale the rigor to the stakes — a major capital project's risk study deserves formal, independent review; a small job needs a lighter touch.

Nine things to remember

  1. QA/QC for risk management quality-checks the risk process itself.
  2. A risk analysis is only as good as the process behind it.
  3. QA prevents (good process); QC detects (checks the output).
  4. You need both — a sound process and verification it worked.
  5. Hunt for bias, gaps, double-counting, method misuse, and unsupported inputs.
  6. Optimism bias is the headline failure — probabilities and impacts set too low.
  7. Independence is the active ingredient — a reviewer with no stake in the result.
  8. Scale the rigor to the stakes — major projects get formal independent review.
  9. Trustworthy analysis is what makes every later risk decision defensible.

Glossary

Benchmarking
Comparing results against history or peers.
Double-counting
The same risk reflected more than once.
Independent review
Review by someone with no stake in the result.
Optimism bias
Systematic tendency to understate risk.
Peer review
Check of the analysis by another competent person.
Quality assurance (QA)
Building quality in via process and standards.
Quality control (QC)
Inspecting outputs to detect errors.
Sense-check
Quick reasonableness test of a number.

Check your understanding

1QA/QC applied to risk management checks the:
2QA versus QC: QA mainly:
3The single most common failure QA/QC catches in risk work is: