Exemplar Global Certified Courses from USD 99. Ending Soon!

How to Audit Clause 6.1.1: Planning for Risks and Opportunities

AW

Team @ Audit Workshop

14 min read
How to Audit Clause 6.1.1: Planning for Risks and Opportunities

Why Clause 6.1.1 Matters More Than Most Auditors Realise

Clause 6.1.1 sits at the heart of every ISO management system built on the harmonised structure. It is the point where an organisation translates its understanding of context and interested parties into something actionable. Get it right, and the rest of the planning section has a solid foundation. Get it wrong, and you end up with a risk register that nobody uses and objectives that bear no relationship to what the business actually faces.

Yet in practice, this clause is one of the most commonly mishandled during internal audits. Auditors either rush through it, treating it as a tick-box exercise, or they go too far in the other direction and try to audit every risk on the register in detail. Neither approach serves the auditee or the audit well.

This article walks you through what Clause 6.1.1 actually requires, how to structure your audit approach, what evidence to gather, and the most common weaknesses you will find. The examples are drawn from real audit situations across ISO 9001, ISO 14001, and ISO 45001, but the principles apply across all standards that share the harmonised structure.

What Clause 6.1.1 Actually Requires

Before you can audit a clause effectively, you need to be clear on what it demands. Clause 6.1.1 requires the organisation to determine the risks and opportunities that need to be addressed. It does not require a particular format, a specific tool, or a formal risk register, though those are common ways organisations meet the requirement.

The clause has three core purposes. The organisation must determine risks and opportunities that could affect the ability of the management system to achieve its intended results. It must plan actions to address those risks and opportunities. And it must evaluate the effectiveness of those actions. That last part is often forgotten, both by organisations and by auditors.

Critically, the determination of risks and opportunities must take into account the outputs of Clause 4.1 (context of the organisation) and Clause 4.2 (interested parties and their needs). This is not optional. If an organisation has identified a significant external issue in its context analysis, that issue should logically appear somewhere in the risk and opportunity determination. If it does not, that is a gap worth exploring.

The standard also requires that the planned actions are integrated into the management system processes and that their effectiveness is evaluated. This is where many organisations fall short. They identify risks, list them in a register, and then never revisit whether the actions taken actually worked.

Building Your Audit Approach for Clause 6.1.1

Start With the Clause 4 Outputs

The most effective way to audit Clause 6.1.1 is to start with what the organisation has documented under Clause 4. Pull out the context analysis and the interested parties register before you look at the risk register. Ask yourself: if I were the organisation, what risks and opportunities would logically flow from these inputs?

Then compare that expectation to what the organisation has actually identified. You are not looking for a perfect match, but you should see a clear connection. If the context analysis identifies increasing regulatory pressure as a significant external issue but the risk register makes no mention of compliance risk, that is a meaningful gap. If the interested parties register identifies a major customer with specific quality requirements but no corresponding risk has been captured around meeting those requirements, that warrants a question.

This approach grounds your audit in logic rather than just checking whether a document exists. It also tends to generate much more productive conversations with auditees, because you are asking them to explain their thinking rather than just confirm a box has been ticked.

Assess the Identification Process, Not Just the Output

One of the most common audit mistakes with this clause is focusing entirely on the risk register itself. The register is an output. What you actually need to understand is the process that produced it.

Ask the organisation how they identify risks and opportunities. Who is involved? How often is the process repeated? What inputs do they use? A risk identification process that involves only the quality manager, happens once a year, and relies on a generic template is fundamentally weaker than one that involves process owners, draws on customer feedback, near miss data, and regulatory changes, and is reviewed when significant changes occur.

The standard does not prescribe the process, but it does require that the results are fit for purpose. Your job as an auditor is to assess whether the process is capable of producing a reliable and complete picture of the risks and opportunities the organisation faces.

Check the Scope and Coverage

Clause 6.1.1 requires the organisation to determine risks and opportunities that are relevant to the intended results of the management system. That means the scope of the risk identification should align with the scope of the management system.

In practice, you will often find risk registers that focus heavily on operational risks while neglecting risks to the management system itself. For example, an organisation might identify risks around product quality but overlook risks such as loss of a key quality manager, failure of the internal audit programme, or inadequate management review inputs. These are systemic risks that could undermine the management system's ability to achieve its intended results, and they should appear somewhere in the risk determination.

Similarly, check whether opportunities have been genuinely considered. Many organisations treat this clause as purely about risk, listing threats and hazards but giving little thought to what opportunities exist to improve performance, enhance customer satisfaction, or reduce environmental impact. The standard explicitly requires both, and a risk register that contains only negative entries is incomplete.

Evidence to Gather During the Audit

Documents to Review

Start with the documented information the organisation uses to capture its risk and opportunity determination. This might be a formal risk register, a risk matrix, a SWOT analysis, or a combination of tools. The format does not matter. What matters is that the content is meaningful and connected to the organisation's actual context.

Review the risk register or equivalent document and look for the following. Are risks described specifically enough to be actionable? A risk described as “regulatory changes” is too vague to be useful. A risk described as “failure to meet updated reporting requirements under the NGER Act by the annual deadline” is specific and actionable. Are the associated actions clearly identified? Are owners assigned? Are there target dates or review triggers?

Also review meeting minutes, management review records, and any internal audit reports that reference risk. These can tell you whether the risk and opportunity determination is a living process or a document that was created for certification and never touched again.

Interviews to Conduct

Interview the person responsible for maintaining the risk register, but do not stop there. Talk to process owners and ask them whether they are aware of the risks identified in their area, whether they were involved in identifying those risks, and whether the actions assigned to them are being implemented.

A common finding is that the quality manager or HSE manager has produced a detailed risk register, but the people responsible for implementing the associated actions have never seen it. This is a genuine systemic weakness, and it often surfaces when you ask a department manager to describe the risks in their area and compare their answer to what appears in the register.

Also ask top management about the risks they consider most significant for the organisation. If their answer bears little resemblance to what is in the risk register, that tells you something important about whether the process is genuinely integrated into strategic decision-making or exists only as a compliance artefact.

Observations to Make

Where possible, observe the process in action. If a risk review meeting is scheduled during your audit, sit in. Watch whether the discussion is genuine or whether participants are simply reading through a list and confirming nothing has changed.

On the shop floor or in operational areas, look for evidence that risk-based actions are actually implemented. If the risk register identifies a risk around equipment failure and the planned action is a preventive maintenance schedule, go and check whether that schedule exists and whether it is being followed. This connects Clause 6.1.1 to Clause 6.1.3 (planning actions) and to the operational controls in Clause 8, which is exactly the kind of audit trail that demonstrates a functioning system.

Common Weaknesses and How to Raise Them

The Disconnected Risk Register

This is the most frequent finding. The risk register exists as a standalone document with no visible connection to the context analysis, the interested parties register, or the management system objectives. When you ask the organisation how they determined the risks, they struggle to explain the process.

To raise this as a finding, document the specific gap. For example: the context analysis identifies supply chain disruption as a significant external issue, but no corresponding risk has been identified in the risk register, and no actions have been planned to address this issue. That is a specific, evidence-based finding that the organisation can act on.

You can read more about structuring findings clearly in our article on how to write audit findings that stand up to challenge.

Risks Without Actions

Some organisations identify risks but fail to plan any actions to address them. The risk sits in the register with a risk rating but no associated control or treatment. This directly fails the requirement of the clause, which requires the organisation to plan actions to address the risks and opportunities it has determined.

When you find this, check whether the organisation has at least made a conscious decision to accept the risk. Acceptance is a legitimate treatment option, but it should be documented as a deliberate decision, not a gap. If there is no evidence of a decision either way, that is a nonconformity.

No Evaluation of Effectiveness

This is the gap that most internal auditors miss. The clause requires the organisation to evaluate the effectiveness of the actions taken to address risks and opportunities. In practice, many organisations implement actions and then never assess whether those actions actually reduced the risk or captured the opportunity.

Look for evidence of effectiveness evaluation in management review records, internal audit findings, or performance monitoring data. If the only evidence of risk treatment is the action being marked as “complete” in the register, that is not the same as demonstrating effectiveness. Ask the organisation how they know the action worked. If they cannot answer that question, you have found a genuine gap.

Opportunities Ignored

As mentioned earlier, many organisations focus entirely on threats and neglect opportunities. If the risk register contains only negative entries, raise this as at least an observation. The standard explicitly requires the determination of opportunities that need to be addressed, and a process that systematically ignores the positive side of risk-based thinking is not fully conforming.

Opportunities might include new markets, new technologies, changes in customer preferences, regulatory incentives, or improvements to existing processes. They do not need to be grand strategic initiatives. Even a modest improvement opportunity, if it is genuine and actionable, satisfies the requirement.

Connecting Clause 6.1.1 to the Rest of the System

One of the most valuable things you can do as an auditor is trace the connections between Clause 6.1.1 and other parts of the management system. This is what separates a process-based audit from a clause-by-clause checklist exercise.

Check whether the risks identified in Clause 6.1.1 are reflected in the quality objectives set under Clause 6.2. If a significant risk has been identified, you would expect to see a corresponding objective aimed at managing or reducing that risk. If the objectives bear no relationship to the identified risks, the planning process is not integrated.

Check whether the actions planned to address risks have been incorporated into operational controls under Clause 8. If the risk register says the action is to implement a supplier qualification process, go and verify that the supplier qualification process actually exists and is being applied.

Check whether the risks and opportunities are reviewed as part of management review under Clause 9.3. The inputs to management review should include information about the effectiveness of actions taken to address risks and opportunities. If this is absent from management review records, that is a finding against both clauses.

For a deeper look at how risk-based thinking flows through the entire management system, our article on risk-based thinking with practical examples covers the concept in detail.

Differences Across Standards

While the core requirement of Clause 6.1.1 is consistent across the harmonised structure, there are differences in how it is applied across different standards that are worth understanding.

In ISO 9001, the focus is on risks and opportunities related to the ability of the QMS to achieve its intended results, including conformity of products and services and enhancement of customer satisfaction. The risks tend to be quality-focused, though they can extend to strategic and operational considerations.

In ISO 14001, Clause 6.1.1 is a general planning requirement that sets the scene for the more specific requirements of Clauses 6.1.2 (environmental aspects), 6.1.3 (compliance obligations), and the new Clause 6.1.4 in the 2026 edition (risks and opportunities). The relationship between these sub-clauses is important to understand when auditing the EMS.

In ISO 45001, Clause 6.1.1 is similarly a general planning requirement that precedes the more detailed requirements for hazard identification and risk assessment in Clause 6.1.2. The OH&S context tends to produce a richer set of risks given the direct connection to worker safety, and you should see evidence that the risk determination under 6.1.1 is informed by the hazard identification process.

If you are auditing against multiple standards simultaneously, understanding these differences helps you ask the right questions for each system. Our article on auditing an IMS across ISO 9001, 14001 and 45001 together covers the practical challenges of integrated audits in detail.

Practical Tips for Getting the Most From This Audit Area

Prepare your audit questions before you arrive. Generic questions like “how do you manage risk?” produce generic answers. Specific questions like “can you show me how the supply chain issues identified in your context analysis have been reflected in your risk register?” produce much more useful responses.

Do not accept the risk register at face value. A well-formatted document does not mean a well-functioning process. Dig into the thinking behind it. Ask who was involved, when it was last reviewed, and what has changed since the last review.

Be alert to risk registers that have not been updated since the initial certification. If the register was last reviewed two years ago and the organisation has since changed its scope, taken on new clients, moved to a new facility, or experienced significant staff turnover, the register is almost certainly out of date.

Use the risk register as a thread to pull throughout the audit. When you move into operational areas, refer back to what the register says about those areas. This creates a coherent audit narrative and often surfaces the most significant findings.

Finally, remember that your role is to assess conformity and identify opportunities for improvement, not to redesign the organisation's risk management framework. If the system is working, even if it is not the system you would have designed, that is conforming. Your job is to verify the requirement is met, not to impose a particular methodology.

If you want to build the skills to audit Clause 6.1.1 and the broader planning section with confidence, Audit Workshop offers practical internal auditor and lead auditor training across ISO 9001, ISO 14001, ISO 45001, and other standards. The courses are designed by practising auditors and focus on the kind of real-world audit scenarios covered in this article. You can explore the available courses at auditworkshop.com.

Frequently Asked Questions

No. The clause requires the organisation to determine risks and opportunities and plan actions to address them, but it does not prescribe a specific format or tool. A risk register is a common and practical way to meet the requirement, but organisations can use a SWOT analysis, risk matrix, or other documented approach provided the output is meaningful, connected to the organisation's context, and used to drive action.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
Limited timeUSD 199(Was USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
Limited timeUSD 199(Was USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
Limited timeUSD 199(Was USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.