Why Clause 6.1 Trips Up So Many Auditors
Risk based thinking is one of the most misunderstood requirements in ISO 9001:2015. It sits at the heart of the standard, yet it is also one of the areas where auditors, both internal and external, tend to either over-complicate things or let organisations off far too lightly.
On this page
Some auditors treat it as a documentation exercise. They look at the risk register, tick a box, and move on. Others go the opposite way and demand elaborate quantitative risk matrices that the standard never actually requires. Neither approach serves the audit well.
This article is a practical guide to auditing risk based thinking under Clause 6.1. It covers what the clause actually requires, what good looks like in practice, the questions you should be asking, and the nonconformities you are most likely to find. Whether you are conducting an internal audit or preparing for a certification audit, this is the approach that holds up.
What Clause 6.1 Actually Requires
Before you can audit a requirement, you need to understand what it says. Clause 6.1 has two parts.
Clause 6.1.1: Determining Risks and Opportunities
The organisation must determine the risks and opportunities that need to be addressed, taking into account the context of the organisation (Clause 4.1) and the needs and expectations of interested parties (Clause 4.2). The purpose is to give assurance that the QMS can achieve its intended results, enhance desirable effects, prevent or reduce undesired effects, and achieve improvement.
Note the link to Clauses 4.1 and 4.2. Risk based thinking does not operate in isolation. The issues identified in the context analysis and the requirements of interested parties are meant to feed directly into the risk and opportunity assessment. If an organisation has done a thorough context analysis but the risks identified bear no relationship to those issues, something has gone wrong.
Clause 6.1.2: Planning Actions
Once risks and opportunities have been determined, the organisation must plan actions to address them, integrate those actions into the QMS processes, and evaluate the effectiveness of those actions. The clause does not require a documented risk register, a formal risk methodology, or a specific format. It does require that the actions are proportionate to the potential impact on product and service conformity.
That proportionality requirement is important. A small landscaping business and a pharmaceutical manufacturer will both have risks, but the depth and rigour of their approach should reflect the complexity of their operations and the consequences of getting things wrong.
For a deeper look at how risk based thinking works as a concept, the post on risk based thinking with practical examples is worth reading before you head into an audit.
Exemplar Global Recognised Training ProviderRTP No. 310970Preparing to Audit Clause 6.1
Review the Context Documentation First
Before you ask a single question, spend time reviewing what the organisation has documented about its context. Look at the SWOT or PESTLE analysis, the interested parties register, and whatever the organisation calls its risk assessment output. You are looking for logical flow. Do the risks identified trace back to the issues and interested party needs that were captured in Clause 4?
If the context analysis identifies that a key customer requires on time delivery performance above 98 percent, you would expect to see a corresponding risk around supply chain disruption, production capacity, or logistics. If the risk register is full of generic entries that could apply to any business, that is a red flag worth pursuing.
Check Whether the Organisation Has a Method
ISO 9001 does not prescribe a method, but the organisation should have one, even if it is simple. Ask to see how they identify, assess, and prioritise risks. Some organisations use a likelihood and consequence matrix. Others use a simple high, medium, low categorisation. Some use narrative descriptions. All of these can be acceptable. What matters is that the method is applied consistently and that the outputs make sense given the organisation's context.
Understand the Scope of the QMS
Risks and opportunities should cover the full scope of the QMS, not just the processes that are easy to document. If the scope includes design and development, procurement, and customer delivery, the risk assessment should reflect risks across all of those areas. An organisation that only identifies risks in production but ignores procurement or customer communication is not meeting the intent of the clause.
Audit Questions That Get to the Truth
The questions you ask during the audit will determine the quality of the evidence you gather. Here are the questions that consistently produce useful information when auditing Clause 6.1.
Questions for Top Management
- How does the organisation identify the risks that could affect the quality management system achieving its intended results?
- Who is responsible for maintaining the risk assessment, and how often is it reviewed?
- Can you walk me through a recent example where a risk was identified and an action was taken as a result?
- How do the risks identified here connect to the context analysis you completed under Clause 4.1?
- Has the risk picture changed recently? What triggered the review?
Questions for Process Owners
- What are the main risks in your area that could affect product or service quality?
- Are those risks captured in the organisation's risk register?
- What actions have been put in place to address the risks in your area?
- How do you know those actions are working?
Questions About Opportunities
Many organisations focus entirely on risks and forget that Clause 6.1 also requires them to address opportunities. Ask specifically about this.
- Has the organisation identified any opportunities to improve quality outcomes or enhance customer satisfaction?
- Can you give me an example of an opportunity that was identified and acted upon?
Opportunities are often where organisations can demonstrate genuine improvement thinking rather than just compliance. If an organisation can only talk about risks and has nothing to say about opportunities, that is worth noting.
What Good Looks Like in Practice
Good risk based thinking under Clause 6.1 does not require a sophisticated system. It requires genuine thinking about what could go wrong, what could go right, and what the organisation is doing about it.
A Realistic Example
Consider a medium sized engineering services company. Their context analysis identifies that they rely heavily on two specialist subcontractors for a particular type of work, and that a key customer has strict quality requirements for that work. Their risk register includes an entry along these lines:
Risk: Subcontractor quality failure leading to rework or customer complaint. Likelihood: Medium. Consequence: High. Action: Prequalification of subcontractors, monthly performance review, and hold point inspection at critical stages. Owner: Operations Manager. Review date: Quarterly.
That is a well formed risk entry. It traces back to a real issue in the context analysis, it has a proportionate response, it has an owner, and it has a review mechanism. When you audit this, you can verify the prequalification records, check the performance review minutes, and confirm that hold point inspections are actually happening.
What Poor Practice Looks Like
Poor risk based thinking tends to look like one of these patterns.
- A generic risk register that was created at certification time and has not been touched since.
- Risks that are completely disconnected from the context analysis or interested party needs.
- Actions that are vague and unassigned, such as monitor situation or review periodically with no owner or timeframe.
- No evidence that the effectiveness of actions has ever been evaluated.
- Opportunities section left blank or populated with placeholder text.
Linking Clause 6.1 to the Rest of the QMS
One of the most powerful audit techniques for Clause 6.1 is to trace the risk based thinking through the rest of the QMS. Risks identified in Clause 6.1 should show up as controls in operational processes, as monitoring activities in Clause 9.1, and as topics in management review under Clause 9.3.
If the risk register identifies supplier quality as a significant risk but there is no corresponding supplier evaluation process under Clause 8.4, no monitoring of supplier performance under Clause 9.1, and no mention of supplier performance at management review, the risk based thinking is not actually integrated into the QMS. That is a systemic finding, not just a Clause 6.1 issue.
This is the difference between auditing for conformity and auditing for effectiveness. An organisation can have a risk register that technically satisfies Clause 6.1 on paper while the actual system takes no account of the risks identified. Your job as an auditor is to find out whether the risk thinking is real.
The article on auditing the process approach under ISO 9001 Clause 4.4 covers the related skill of tracing requirements through processes, which pairs well with this kind of integrated audit approach.
Common Nonconformities Under Clause 6.1
After conducting hundreds of audits across a wide range of industries, the nonconformities that come up most often under Clause 6.1 fall into a consistent set of patterns.
Risk Assessment Not Linked to Context
The organisation has completed a context analysis under Clause 4.1 and an interested parties register under Clause 4.2, but the risks identified in Clause 6.1 bear no logical relationship to those inputs. This is a genuine nonconformity because the clause explicitly requires the risk assessment to take into account the context and interested party requirements.
No Evidence of Effectiveness Evaluation
Actions have been planned and implemented, but there is no evidence that the organisation has ever evaluated whether those actions actually worked. Clause 6.1.2 requires the organisation to evaluate the effectiveness of the actions taken. If the only evidence is the action plan itself, that is not enough.
Risks Not Reviewed After Significant Change
The organisation went through a significant change, such as a new major customer, a new production process, or a change in key personnel, but the risk assessment was not updated. Clause 6.1 requires the organisation to determine risks and opportunities, and that determination needs to remain current. A static risk register that never changes is almost always a sign that it is not being actively used.
Opportunities Not Addressed
The organisation has identified risks but has made no attempt to identify or address opportunities. This is a straightforward nonconformity because the clause explicitly requires both.
Actions Disproportionate to Risk
This one requires more judgement. Clause 6.1.2 requires actions to be proportionate to the potential impact on conformity of products and services. If a high consequence risk has only a vague monitoring action assigned to it, that is worth raising. Equally, if a low consequence risk has generated an elaborate and resource intensive control, that might be worth noting as an observation, though it is rarely a nonconformity.
For guidance on how to classify findings correctly, the post on what is an audit finding vs observation vs nonconformity is a useful reference.
Documented Information and Clause 6.1
A common question from auditors is whether the organisation must have a documented risk register. The answer is that ISO 9001 does not explicitly require documented information for Clause 6.1. However, it does require documented information where the absence of it would undermine confidence that processes are being carried out as planned.
In practice, it is very difficult for an organisation to demonstrate that it has determined risks and opportunities, planned actions, integrated those actions, and evaluated their effectiveness without some form of documented output. Most organisations maintain a risk register or equivalent document, and most auditors will expect to see one.
If an organisation claims to manage risk based thinking entirely through informal processes with no documentation, your audit questioning needs to be thorough enough to determine whether that claim is credible. In most cases, it is not.
Auditing Clause 6.1 in Small Organisations
Small organisations sometimes feel overwhelmed by the concept of risk based thinking, and some auditors make the mistake of applying the same expectations to a five person business that they would apply to a large manufacturer. The standard does not require this.
For a small business, a simple one page document that lists the main risks, assigns an owner, describes the action taken, and notes when it was last reviewed can be entirely adequate. What matters is that the thinking is genuine and that the actions are real. A small cleaning company that identifies the risk of key staff leaving and has cross trained their team as a response has done exactly what the clause requires, even if the documentation is minimal.
The post on ISO 9001 for small business provides useful context on how the standard scales to smaller operations.
Audit Techniques That Work Well for Clause 6.1
Beyond the standard interview and document review, a few specific techniques work particularly well when auditing risk based thinking.
Trace a Risk Forward
Pick a specific risk from the register and trace it forward through the QMS. Ask to see the action that was implemented, the records that demonstrate the action is operating, and the evidence that its effectiveness has been evaluated. This technique quickly reveals whether the risk register is a living document or a compliance artefact.
Trace a Problem Backward
If the organisation has had a customer complaint, a significant nonconformity, or a near miss in the past twelve months, ask whether that issue was reflected in the risk assessment before it occurred. If a risk that materialised was not on the register, ask why. This is not necessarily a nonconformity, but it is a valuable conversation that often reveals gaps in the risk identification process.
Ask About What Has Changed
Ask the organisation what has changed in their business or operating environment in the past year and then check whether the risk assessment reflects those changes. New customers, new suppliers, new technology, regulatory changes, and staff turnover are all the kinds of changes that should trigger a review of risks and opportunities.
Exemplar Global Recognised Training ProviderRTP No. 310970Writing Up Clause 6.1 Findings
When you write up findings against Clause 6.1, be specific. A nonconformity statement that says risk based thinking is inadequate is not useful. A well written nonconformity identifies the specific requirement that has not been met, describes the objective evidence that supports the finding, and makes it clear what the organisation needs to address.
For example: Clause 6.1.2 requires the organisation to evaluate the effectiveness of actions taken to address risks and opportunities. A review of the risk register dated March 2024 and the associated corrective actions identified no evidence that the effectiveness of these actions has been evaluated. Three actions listed as complete had no effectiveness review recorded.
That is a finding that can be acted upon. It is specific, it cites the requirement, and it describes the evidence gap clearly.
Building Your Skills in Auditing Risk Based Thinking
Auditing Clause 6.1 well requires a combination of technical knowledge about the standard, practical questioning skills, and the judgement to distinguish between genuine conformity and paper compliance. These are skills that develop with practice, but they also benefit enormously from structured training.
At Audit Workshop, the ISO 9001 Internal Auditor and Lead Auditor courses cover risk based thinking in depth, with practical exercises that simulate real audit scenarios. Trainer Dilawar Laghari brings over 14 years of compliance experience and 500 plus external certification audits to the training, which means the examples and techniques taught reflect what actually happens in audits across a wide range of industries. If you are building your auditing skills or preparing to conduct your first Clause 6.1 audit, the courses at Audit Workshop are worth exploring.













