Overview - ISO 17666:2025 (Space systems - Programme management - Risk management)
ISO 17666:2025 defines principles and requirements for integrated risk management on space projects, extending the requirements of ISO 14300-1. Applicable to all space project phases, this third edition formalizes a project-level, iterative approach to identifying, assessing, reducing, accepting and controlling risks across customer and supplier chains (customer, first‑level and lower‑level suppliers). The standard summarizes a general risk management process divided into four basic steps and nine tasks, and includes informative annexes such as a risk register example and a risk management plan.
Key technical topics and requirements
- Integrated risk management process: a structured, iterative process for optimizing project resources in line with the project’s risk management policy.
- Four steps (nine tasks):
- Step 1 - Define risk management implementation requirements
- Step 2 - Identify and assess risks
- Step 3 - Decide and act (risk reduction/mitigation)
- Step 4 - Monitor, communicate and accept risks
- Risk terminology and metrics: standardized definitions (risk, risk scenario, residual/resolved/unresolved risk, risk index, risk trend) to ensure consistent assessment and communication.
- Documentation and visibility: requirements for risk registers, ranked risk logs, and a formal risk management plan to support decision making and traceability.
- Roles and responsibilities: mandates clear lines of accountability from corporate/project management through the supplier network.
- Life‑cycle and tailoring: applicability across all space project phases (per ISO 14300-1) and allowance for project‑specific tailoring of requirements.
- Integration with engineering analyses: complements existing analyses (safety, critical items, dependability, schedule/cost trade-offs) as part of the overall risk strategy.
- Clause structure: normative references, terms/definitions, principles, process, implementation, and specific risk management requirements (including Clause 7 process and implementation requirements).
Practical applications - who should use it
- Programme and project managers seeking a standardized framework for space programme risk governance.
- Systems and risk engineers responsible for risk identification, assessment and mitigation activities.
- Suppliers and contractors implementing supplier-level risk processes consistent with customer requirements.
- Quality, safety and configuration managers integrating risk outputs into assurance and decision processes.
- Procurement and contract managers aligning contractual risk responsibilities and visibility.
Use ISO 17666:2025 to create consistent risk registers, support management trade-offs (cost, schedule, technical performance), and increase risk visibility across multi‑tier space projects.
Related standards and references
For implementation details and authoritative text, consult the full ISO 17666:2025 document from ISO.