Step 12 — Review & Continuous Improvement
Ensuring capability evolves with changing conditions.
Context
Product risk management is not a one-time activity. Technologies, suppliers, regulations, and risks continue to evolve throughout the product lifecycle.
Regular reviews ensure that strategies, plans, and decisions remain aligned with changing conditions.
Continuous improvement enables organizations to learn, adapt, and strengthen resilience over time.
Focus
What It Enables
→ Review risks, plans, and decisions
→ Ongoing relevance
→ Assess changing internal and external conditions
→ Organizational adaptability
→ Update strategies, actions, and governance
→ Sustained organizational capability
→ Apply lessons learned
→ Continuous improvement
Governance & Reviews
Establish structured review processes and responsibilities.
Risk Validation
Ensure risks and actions remain relevant and effective.
Plan Maintenance
Keep Product Risk Management Strategies and Plans aligned with current conditions.
Continuous Improvement
Apply lessons learned to strengthen future decisions.
Learning & Accountability
Ensure review outcomes lead to action.
Core Elements
Author
Darren Topley
Managing Director, CMCA(UK)
Integrated logistics support, lifecycle management, governance, and obsolescence management.

01.
What is the main objective of Step 12?
To ensure product risk management strategies and plans remain effective, relevant, and aligned with changing business, technology, compliance, and supply chain conditions.
02.
Why are regular reviews important?
Because product risks evolve continuously through technology changes, supplier developments, regulatory updates, geopolitical events, and market conditions.
03.
What should be reviewed?
Risk assessments, mitigation actions, supplier risks, compliance status, KPIs, governance processes, PRMS documents, and PRMPs should all be reviewed regularly.
04.
How often should reviews be performed?
Review frequency should be risk-based, typically annually for standard programs and more frequently for higher-risk products or environments. Triggered reviews should occur after significant events.
05.
What events should trigger an immediate review?
Examples include supplier exits, EOL notifications, major design changes, regulatory updates, significant disruptions, or newly identified high-impact risks.
06.
How do reviews support continuous improvement?
Reviews provide opportunities to incorporate lessons learned, evaluate mitigation effectiveness, improve governance processes, and strengthen future decision-making.
07.
Which standards support this step?
Primarily IEC 62402, SD-22, and associated governance, review, and continuous improvement practices.
Frequently Asked Questions
Standards Traceability
Theme
Standard & Clause
Governance & Policy for Reviews
IEC 62402 §5 • SD-22 §2.2
Roles & Responsibilities in Review Process
IEC 62402 §6.3 • SD-22 §2.2
Periodic Review of Risk Assessments
IEC 62402 Annex E §E.3.5 • SD-22 §3.3
Structured Review of Plans (PRMS & PRMPs)
IEC 62402 §7.2 • SD-22 §4.4
Continuous Improvement & Lessons Learned
IEC 62402 §11.2 • SD-22 §4.4
Communication & Documentation of Updates
IEC 62402 §7.2 • SD-22 §4.2
Implementation Guidance
Practical considerations and implementation details for this step.

.png)
