Qualiopi8 min read

Qualiopi indicator 32: the quality risk analysis required by the decree of 1 August 2026

The Qualiopi framework moves from 32 to 33 indicators on 1 November 2026, as we reported in early August: decree n° 2026-728 of 1 August 2026, published in the Official Journal on 4 August, does more than add a new indicator 33 reserved for apprenticeship. It also changes the content of several existing indicators — we recently detailed the tightening of indicator 1 on commercial communication. Indicator 32, which closes the framework, is also given a precise addition: a quality risk analysis of the training service, on top of the existing requirement to handle feedback and complaints. Here is what this covers in practice, and how to prepare for it without confusing it with a document you may already hold.

What the decree changes on indicator 32

Until now, indicator 32 was limited to a continuous improvement plan fed by two sources: feedback from stakeholders (indicator 30) and complaints (indicator 31). The decree of 1 August 2026 adds a third building block to this requirement: the provider must now conduct an analysis of the risks likely to affect the quality of the service delivered, and derive preventive actions from it — not only corrective actions triggered after the fact by dissatisfaction or a complaint that has already occurred.

The difference matters. Until now, indicator 32 worked essentially in reaction: collect feedback, then improve. The new requirement introduces a prevention logic: identify upfront what could make a session fail or degrade a service, before the problem materialises and surfaces through a complaint.

This change concerns all certified categories of providers — continuing training, CFAs, skills assessment, VAE — with no sector restriction, unlike the new indicator 33 reserved for apprenticeship.

Quality risks: what does this actually cover

The text does not provide a closed list, which leaves room for interpretation for each provider — but also for each auditor. In practice, a quality risk is any event likely to prevent a service from running as planned or from reaching its objectives. Six families come up most often:

  • Pedagogical risks: a trainer unavailable with no identified backup, content not updated in line with a regulatory or technical change in the target occupation.
  • Technical risks: an LMS platform outage during a live remote session, a room unavailable on the day, faulty equipment on a technical training platform.
  • Human risks: excessive dependence on a single key trainer in a given field, poorly anticipated staff turnover.
  • Subcontracting risks: a subcontractor or wage-portage partner failing to deliver — a point that directly overlaps with indicator 27, also recently strengthened by this same decree.
  • Digital risks: loss of trainee data, information system unavailability following a cyberattack or ransomware incident.
  • Financial or organisational risks: dependence on a single funder or a single client, understaffed administration during peak periods.

The point is not to produce an exhaustive, theoretical list, but to identify the risks that are genuinely plausible for your activity, at a level of detail proportionate to your size.

Building your quality risk analysis grid

A simple table is enough to meet the requirement, provided it is actually used:

Risk identified Likelihood Impact on quality Preventive action Owner
Sole trainer unavailable Medium High (session postponed or cancelled) Identify a backup trainer per subject area Pedagogical lead
LMS platform outage during remote training Low High (interrupted follow-up) Fallback procedure (alternative support, trainee communication) Technical lead
Subcontractor failure Medium Medium Up-to-date file of backup subcontractors Management

Three principles to help this grid pass the audit without turning into a bureaucratic exercise:

  1. Cross-reference it with your existing sources. A recurring complaint on the same topic (indicator 31) or an incident that has already happened — even without a formal complaint — is the best starting point for identifying a real risk rather than a theoretical one.
  2. Tie it to your existing quality review. If you already hold a periodic review for the continuous improvement plan, add the risk analysis to the agenda rather than creating a parallel body.
  3. Document at least one preventive action actually taken. An auditor used to “following the thread” on indicator 32 will apply the same logic here: a risk identified with no associated action, or an action never implemented, reads as a statement of intent rather than a real practice.

Do not confuse it with the DUERP

A common reflex will be to reuse the single occupational risk assessment document (DUERP) to meet this new requirement. That is a scope mistake: the DUERP, mandatory for every employer under Article L4121-3 of the Labour Code, covers risks to your employees’ health and safety (falls, musculoskeletal disorders, psychosocial risks). The quality risk analysis in indicator 32 covers risks to the quality of the service delivered to beneficiaries. The two approaches share a method (identify, assess, prevent) but not an object: keep two separate documents, even if you run them through the same review meeting to save time.

Why this preventive shift matters

This shift from reactive to preventive is not unique to Qualiopi: it is the same movement the ISO 9001 standard went through in its 2015 revision, which introduced “risk-based thinking” as a cross-cutting principle of quality management. As a synthesis by Luís Miguel Fonseca, published in 2016 in the International Journal for Quality Research («From Quality Gurus and TQM to ISO 9001:2015: A Review of Several Quality Paths»), points out, this shift aims precisely to get organisations to act before a non-conformity occurs, rather than merely correcting it afterwards. Adding a risk analysis to indicator 32 transposes this logic to vocational training: after years in which Qualiopi mainly judged the ability to react to dissatisfaction, the framework now also asks for the ability to anticipate it.

Mistakes to avoid

  • Copy-pasting the DUERP: different scope, different document — see above.
  • A frozen grid: filled in once before the audit and never reopened. Plan at least an annual review.
  • Risks that are too vague: “lack of resources” or “various hazards” lead to no concrete action. Name the risk precisely.
  • No link to the improvement plan: the risk analysis should feed the same action plan as indicators 30 and 31, not live in an isolated file nobody consults.

Take action

Anticipating this change before 1 November 2026 avoids discovering the requirement on audit day. The Complete Kit Certif (€297, 14-day guarantee, documents in French) provides, for each of the 32 indicators of the framework that applies until 31 October 2026, a model procedure and an evidence table; the risk analysis grid described here still has to be built from this article. If you are launching your business, the ebook “Create your training organisation in 30 days” (€67, in French) lays the groundwork from day one, and the Complete Pack (€347) combines both to cover creation and certification.

FAQ

Frequently asked questions

+Does the quality risk analysis in indicator 32 replace the DUERP?

No, these are two distinct documents answering two different obligations. The DUERP assesses occupational health and safety risks for your employees (Article L4121-3 of the French Labour Code). The quality risk analysis in indicator 32 assesses risks likely to degrade the quality of the training delivered to beneficiaries. The two documents can coexist without overlapping.

+Which providers are affected by this change to indicator 32?

All providers certified or applying for Qualiopi, whatever the category of action (continuing training, apprenticeship, skills assessment, VAE). Unlike the new indicator 33, reserved for CFAs (apprenticeship training centres), the quality risk analysis in indicator 32 applies across the whole scope of the certification.

+From when is the quality risk analysis required at audit?

From 1 November 2026, the date decree n° 2026-728 comes into force. An initial, surveillance, or renewal audit scheduled before that date is still assessed against the current 32-indicator framework, without this requirement.

+Is a risk grid filled in just before the audit enough?

No, and that is the most likely trap. As with the rest of indicator 32, the auditor looks for a living practice: a grid dated once, with no review or update, reads as a facade document. Plan at least an annual review, tied to your existing quality review.

Read next