All projects, even ISO 9000 projects, are not without risks. As with other projects, these risks, or vulnerabilities, can lay waste to the best plans. The project manager who performs a risk assessment can determine where some of the vulnerabilities may occur and adjust the estimates, schedules, and resource allocations accordingly. Doing a risk assessment enables the project manager to effectively control the project. Some common risks facing an ISO 9000 project include:

■ Failing to agree upon what is an acceptable level of defects

■ Failing to follow a standardized audit process

■ Failing to receive ISO 9000 certification

■ Lacking "buy-in" from key project participants

■ Lacking senior management support or commitment

■ Not agreeing upon a measurement criteria

■ Not identifying a process owner

■ Using an ill-defined criterion for benchmarking

