Under AS9100, risk management in design is proactive, model- and requirement-driven, and tightly coupled to configuration control and design change. In MRO, it is more condition-driven, field-data-based, and focused on continuing airworthiness, maintenance errors, and repair deviations. Both must be documented, traceable, and integrated with the QMS, but the triggers, data sources, and control levers differ substantially, especially in brownfield environments with legacy systems.