Every organisation has a risk register. Ask for the other one
The 2024 edition separated actions to address risk from actions to address opportunities, which the 2014 edition ran together in a single subclause. That is not a drafting tidy. When one process has to serve both, loss avoidance wins every time, because it is the half with a committee, a template and an auditor.
Every asset-owning organisation of any size has a risk register. It will be in a system, it will have owners and scores and a review cycle, and somebody will present a heat map from it to a committee each quarter.
Ask the same organisation for its opportunity register.
Almost none has one. Not a weak one, not an out of date one. There is usually no such artefact, no process that would produce it, and no committee that would receive it. Yet for a decade the standard has asked organisations to address risks and opportunities, and they have all been passing that clause.
What the 2024 edition did about it
In the 2014 edition, risks and opportunities were handled together. The second edition splits Clause 6.1 into three parts: 6.1.1 general, 6.1.2 actions to address risk, and 6.1.3 actions to address opportunities.
ISO lists the split among the main changes from the first edition, describing it as making a clear distinction between how an organisation shall address risk and how it shall address opportunities.
Two separate subclauses means two sets of requirements, which means an assessor can find one satisfied and the other not. Under the combined clause that was awkward to argue. Now it is straightforward.
Why combining them buried one of them
This is worth understanding properly, because the same mechanism operates in other places and the fix is never a better template.
Loss avoidance arrives inside an organisation with a full institutional apparatus already attached. There is a risk function. There is a committee that meets. There is an internal audit plan that tests it, a regulator who asks about it, an insurer who prices it, and a board that has been trained by two decades of governance reform to ask what could go wrong. There is a scoring method, a register, a system to hold it and a person whose job title contains the word.
Opportunity arrives with none of that. There is no opportunity committee, no opportunity scoring method, no auditor who tests whether opportunities were identified, and no regulator who asks. There is usually not even agreement about what the word means in an asset context.
When one process is asked to serve both, the half carrying the machinery consumes the process. Not through anybody's decision. It simply has more gravity, and the combined register fills up with things that might go wrong because those are the things people know how to write down.
A single process serving two purposes does not split its attention evenly. It serves whichever purpose already has an owner.
What an asset management opportunity actually is
Part of why the opportunity half stays empty is that people reach for the phrase "upside risk" and then cannot think of any. That framing is the problem. In an asset context the opportunities are rarely windfalls and almost always decisions to do less, later, or differently.
Deferring a renewal because condition data says the intervention is premature. Consolidating two underused assets and disposing of one. Extending a maintenance interval that was inherited from a manufacturer recommendation and never tested against observed failure. Changing a specification on the next tranche because the last tranche revealed the original was conservative. Selling something.
Every one of those releases money or capacity. Every one of them requires evidence, a decision-making framework and someone willing to be accountable for an outcome that will not be observable for years. And every one of them is invisible to a process built to catch things that might go wrong, because none of them is a threat.
Note also the dependency. An organisation cannot pursue any of these without the criteria from Clause 4.5, because each is a decision to depart from precedent, and departing from precedent is exactly what requires a written standard to justify it.
Why the criteria have to exist first
, read: ISO 55001 now requires you to write down how you decideObjectives, and where the chain breaks
Clause 6.2.2 requires asset management objectives, and 6.2.3 requires planning to achieve them. The objectives must be measurable and monitored, and consistent with the organisational objectives.
The useful test is a chain in two directions. Take one asset management objective. Trace it upward to the organisational objective it serves, and downward to an activity that is funded and has a person doing it this year.
Breaks happen at both ends and they mean different things. A break downward means the objective is aspirational, which is common and relatively easy to fix. A break upward is more serious: it means the asset function has set itself a target the organisation has not asked for, and that target will lose every time it competes for money against something the organisation did ask for.
The second failure is often mistaken for a resourcing problem. It is not. A well-resourced function pursuing objectives nobody upstairs recognises will still be overruled, and will conclude that the organisation does not understand asset management, when the actual finding is that the translation layer above it never worked.
The clause almost nobody has
Clause 6.3, planning of changes, is new in the second edition and it is the quietest of the additions. It is also, for organisations in this region right now, arguably the most immediately applicable thing in the standard.
It needs distinguishing from something that already existed. Clause 8.2, control of change, sits in the operation clause and concerns changes that affect assets and the delivery of asset management activities. Most organisations have some version of that. It is the management of change procedure, and it is generally attached to physical and operational modification.
Clause 6.3 is upstream of it. It concerns changes to the asset management system itself, and it asks that such changes be assessed for risk and carried out in a planned manner.
Consider what changes an asset management system without ever touching an asset. A reorganisation that moves maintenance under a different director. Replacing the ERP or the maintenance management system. Outsourcing a function that was internal, or insourcing one that was not. Adopting a new operating model. Converting the basis of accounting. Establishing an asset management function in the first place.
Every one of those alters how decisions get made, who holds the data, what the data means, and which competencies the organisation retains. Almost none of them is assessed as a change to the management system, because they are treated as organisational or IT matters and are governed by whoever owns those, using processes that do not ask asset questions.
Why this arrives at a useful moment
The organisations across this region establishing asset management functions are, by definition, organisations undergoing a change to their asset management system. Several at once, in most cases.
They are standing up a function that did not exist. They are frequently converting from cash to accrual accounting, which changes what an asset is for reporting purposes and therefore what the register has to hold. Many are moving from a delivery operating model to an owning one. A good number are procuring or replacing the systems that will carry the data.
What the accounting change does to the register
, read: Accrual conversion gave three years. It did not give anyone a register.Clause 6.3 says those changes should be planned and their risks assessed. In practice they are usually run as separate programmes by separate sponsors, each with its own logic, and the interactions between them are nobody's scope. The accounting conversion sets a register structure that the maintenance function then has to live with. The system procurement fixes a data model before the data requirements have been derived from the decisions they serve.
None of that is a failure of any individual programme. It is the absence of the thing 6.3 now asks for, which is somebody looking at the changes together and assessing what they do to each other.
The assurance framework sets out how to test the objectives chain in both directions, and separately how to examine the changes that never enter a change register once assets are being built.
Sources. ISO 55001:2024, Asset management, Asset management system, Requirements, second edition, July 2024, prepared by ISO/TC 251, ISO standard 83054. The structure of Clause 6, the addition of Clause 6.3, the position of Clause 8.2 and the stated distinction between risk and opportunities are taken from the contents and foreword as published by ISO. ISO 55000:2024, ISO standard 83053, for the revised principles. Saudi Arabia's transition to accrual accounting is required by Royal Decree No. 13059 of December 2016. The requirement text of these standards is behind a paywall and is described here rather than reproduced.
Tags
- ISO 55000
- Risk
- Asset management
- Governance
- Change
Related reading
A strategic asset management plan that has never stopped anything is a description
Clause 6.2.1 gave the SAMP its own requirement in the 2024 edition, and ISO strengthened the leadership clause in the same revision. The two changes belong together. A plan only allocates if somebody senior enough is willing to let it decline something, and most asset management plans have never declined anything in their lives.
ReadAudited on the transactions, unaudited on the basis
Where an internal audit function covers the asset base at all, it usually covers maintenance spend and procurement compliance, because those resemble the rest of the audit universe. The decision framework, the plan and the data go unexamined. The organisation ends up assured about how it spends and unassured about what it decided to spend on.
ReadISO 55001 now requires you to write down how you decide
Clause 4.5 is new in the 2024 edition and asks for three things, a decision-making framework, the criteria, and the methods. Most organisations have all three in the sense that people know roughly how things get settled. Very few can produce them, and an option appraisal nobody can audit is not a decision. It is a preference with a spreadsheet attached.
Read