Clause 6 of ISO 9001:2015 sits right in the middle of the planning requirements, and it is one of the most consistently misunderstood sections of the standard. Auditors across Australia and internationally keep raising the same ISO 9001 Clause 6 nonconformities year after year, and the root causes are almost always the same. Organisations treat risk based thinking as a documentation exercise, write quality objectives that nobody tracks, and ignore the planning of changes requirement entirely until something goes wrong. This article breaks down what auditors actually look for in Clause 6, where organisations consistently fall short, and what you can do to make your system genuinely conform.
On this page
What Clause 6 Actually Requires
Before diving into the nonconformities, it helps to be clear about what Clause 6 is asking for. The clause has three subclauses:
- Clause 6.1 requires the organisation to determine risks and opportunities, plan actions to address them, and integrate those actions into the QMS.
- Clause 6.2 requires quality objectives to be established, made measurable, monitored, communicated, and updated as needed.
- Clause 6.3 requires that when changes to the QMS are needed, they are carried out in a planned manner.
None of these requirements are ambiguous. The standard is reasonably direct. Yet Clause 6 consistently generates a significant proportion of findings during both internal and certification audits. The problem is not usually a lack of understanding of the words. It is a gap between what the system says on paper and what is actually happening in practice.
Exemplar Global Recognised Training ProviderRTP No. 310970Clause 6.1: The Most Common Risk Based Thinking Nonconformities
Risk and Opportunity Registers That Are Never Reviewed
The most frequent Clause 6.1 finding is a risk register that was created during the initial implementation and has not been touched since. Auditors will ask: when was this last reviewed? Who reviewed it? What triggered the review? If the answer is a blank stare or a date from three years ago, that is a nonconformity waiting to be written.
ISO 9001 does not specify a review frequency, but it does require that actions address risks and opportunities and that the effectiveness of those actions is evaluated. If the register has not been updated when the context of the organisation has changed, for example after a key supplier went under, a new product line was launched, or a major customer was added, there is a clear gap. The register is not reflecting reality.
For internal auditors, the question to ask is: what changed in the last twelve months, and is that reflected here? If the answer is no, you have your finding.
Risks Identified But No Actions Planned
Another common pattern is a risk register that lists risks quite thoroughly but then stops. There are no corresponding actions, no owners, no timelines, and no evidence that anything was done. The standard requires that the organisation plan actions to address risks and opportunities and integrate those actions into QMS processes. Identifying a risk and then doing nothing about it does not satisfy the requirement.
This is particularly common in smaller organisations where the quality manager built the register but did not have the authority or the buy-in to assign actions to operational managers. The register becomes a document that satisfies the auditor on paper but has no real connection to how the business manages risk.
No Link Between Context, Interested Parties and Clause 6.1
Clause 6.1 explicitly states that when determining risks and opportunities, the organisation shall take into account the issues from Clause 4.1 and the requirements from Clause 4.2. Many organisations treat these clauses in isolation. They have a context analysis document, a stakeholder register, and a risk register, but the three documents have no visible connection to each other.
An auditor will trace the logic. If a key interested party requirement is documented in Clause 4.2 but does not appear anywhere in the risk register, and there is no documented rationale for why it was excluded, that is a gap. You can read more about how auditors approach this in our article on how to audit risk based thinking under ISO 9001 Clause 6.1.
Opportunities Completely Absent
The standard requires organisations to consider both risks and opportunities. In practice, the opportunities side is often completely absent from documented outputs. Organisations focus almost exclusively on threats and negative risks, which is understandable, but it does not meet the full requirement. Opportunities might include expanding into a new market, improving a process to reduce waste, or taking advantage of new technology to improve customer communication. If the register only contains risks, raise it as an observation at minimum, or a nonconformity if there is no evidence that opportunities were considered at all.
Clause 6.2: Quality Objectives Nonconformities That Keep Coming Up
Objectives That Are Not Measurable
Clause 6.2.1 requires quality objectives to be measurable where practicable. The phrase “where practicable” is sometimes used as a loophole, but auditors see through it quickly. Objectives like “improve customer satisfaction” or “reduce complaints” without any associated target, baseline, or measurement method are not measurable. They are aspirations. An auditor will ask: how would you know if you had achieved this? If the answer cannot be quantified or assessed in any meaningful way, the objective does not meet the requirement.
Good quality objectives follow a structure that includes what is being measured, what the target is, who is responsible, when it will be achieved, and how it will be monitored. Our article on example quality objectives that pass an audit provides worked examples you can use as a reference.
Objectives Not Communicated to Relevant Functions
Clause 6.2.1 specifically requires that quality objectives be communicated. This is a requirement that is easy to verify and easy to find gaps in. An auditor will interview staff in different functions and ask: what are the quality objectives for this year? What is the target? Are you on track?
If frontline staff, supervisors, or department heads cannot answer those questions, the communication requirement has not been met. Having objectives pinned to a noticeboard in the quality manager's office does not constitute communication to relevant functions. The objectives need to reach the people who are responsible for contributing to them.
No Monitoring or Evidence of Progress
Even where objectives are well written and communicated, the monitoring requirement is frequently missed. Clause 6.2.1 requires that objectives be monitored. This means there should be evidence of regular data collection against each objective, trend analysis, and a mechanism for escalating objectives that are falling behind.
Auditors will ask to see objective tracking data. If the only evidence available is the objective itself and a management review from twelve months ago that noted it as “on track” without any supporting data, that is insufficient. Monitoring means ongoing, documented measurement, not a once-a-year assertion.
Objectives Not Aligned to the Quality Policy
Clause 6.2.1 requires that quality objectives be consistent with the quality policy. This is a logical linkage requirement that auditors check by reviewing both documents side by side. If the quality policy commits to continual improvement of on-time delivery but none of the quality objectives relate to delivery performance, there is an obvious misalignment. The objectives should flow logically from the commitments made in the policy.
Plans Not Established to Achieve Objectives
Clause 6.2.2 requires that when determining how objectives will be achieved, the organisation shall determine what will be done, what resources will be required, who will be responsible, when it will be completed, and how results will be evaluated. Many organisations have objectives but no corresponding plans. The objective exists as a statement, but there is no documented plan showing how it will be achieved.
This is a straightforward nonconformity to raise. The requirement is explicit. Ask for the plan, not just the objective. If there is no plan, document the finding clearly against Clause 6.2.2.
Clause 6.3: Planning of Changes Nonconformities
Changes Made Without Any Planning
Clause 6.3 is the most overlooked subclause in the entire planning section. It requires that when the organisation determines the need for changes to the QMS, those changes shall be carried out in a planned manner, considering the purpose of the changes, the integrity of the QMS, the availability of resources, and the allocation of responsibilities.
In practice, organisations make significant changes to their QMS without any documented planning. A procedure gets rewritten by a new quality manager without any assessment of downstream impacts. A new software system replaces a manual process without any consideration of how that affects other QMS processes. A major organisational restructure happens and the QMS is updated reactively rather than proactively.
Auditors look for evidence that changes were planned. This does not need to be a complex document. It can be a simple change request that captures the four considerations listed in Clause 6.3. But if there is no evidence of planning, and the auditor can demonstrate that significant changes occurred, that is a nonconformity.
Our article on planning of changes under ISO 9001 Clause 6.3 covers this requirement in detail, including practical examples of what a change planning record should contain.
No Mechanism for Identifying When Changes Are Needed
A related issue is that many organisations have no systematic mechanism for identifying when QMS changes are needed. Changes might be triggered by nonconformities, customer complaints, audit findings, new regulatory requirements, or internal process improvements. If there is no defined process for capturing these triggers and routing them through a change planning process, the organisation cannot demonstrate that Clause 6.3 is being applied consistently.
This often surfaces during an audit when the auditor asks: how do you determine that a change to the QMS is needed? If the answer is informal or relies entirely on the quality manager's personal judgement with no documented process, that is a gap worth noting.
Changes That Undermine QMS Integrity
One of the four considerations in Clause 6.3 is maintaining the integrity of the QMS. This means that when one element of the system changes, the organisation should consider whether that change creates inconsistencies or gaps elsewhere. For example, if a new supplier approval process is introduced, does it align with the existing Clause 8.4 controls? If a new product category is added to the scope, are all relevant QMS processes updated to cover it?
Auditors look for evidence that this systemic thinking was applied. A common finding is that a change was made to one procedure but related procedures were not updated, leaving the system internally inconsistent. That inconsistency is evidence that the integrity consideration was not adequately addressed.
How Auditors Approach Clause 6 During an Audit
The Document Review
Before any interviews, an auditor will review the documented outputs of Clause 6. This includes the risk register or risk log, quality objectives documentation, and any change management records. The auditor is looking for completeness, currency, and logical coherence. Are the risks linked to context? Are the objectives measurable? Are there plans? Are changes documented?
The Interview Trail
After the document review, the auditor will interview relevant personnel. For Clause 6.1, this typically means asking operational managers and process owners about how risks are managed in their areas. For Clause 6.2, it means asking frontline staff about quality objectives. For Clause 6.3, it means asking about recent changes and how they were managed.
The interview is where document-only conformity falls apart. A well-written risk register means nothing if the operations manager has never seen it and cannot describe how risks are managed in their process. Auditors are trained to follow the evidence trail from documents to people to records, and gaps in that trail become findings.
Sampling Objective Data
For Clause 6.2, auditors will typically request to see objective tracking data for the current period. They will look at how many objectives are being monitored, whether the data is current, and whether there is any analysis of trends. If objectives are consistently not being met with no documented response or corrective action, that raises a further question about whether the objectives are realistic and whether the organisation is genuinely committed to achieving them.
Exemplar Global Recognised Training ProviderRTP No. 310970Practical Steps to Address These Gaps Before Your Next Audit
For Clause 6.1
- Review your risk register and confirm it reflects the current context of the organisation, including any changes in the past twelve months.
- Ensure every identified risk has a corresponding action, owner, and timeline.
- Check that opportunities are documented alongside risks.
- Trace the logical connection between your Clause 4.1 issues, Clause 4.2 interested party requirements, and your risk register.
For Clause 6.2
- Review each quality objective and confirm it has a measurable target, a monitoring method, an owner, and a timeline.
- Confirm that objectives have been communicated to the functions responsible for contributing to them, and document that communication.
- Establish a regular monitoring cycle, whether monthly or quarterly, and keep records of the data collected.
- Ensure each objective has a documented plan covering what will be done, who is responsible, what resources are needed, and when it will be achieved.
For Clause 6.3
- Establish a simple change request process that captures the four considerations from Clause 6.3.
- Review any significant changes made in the past year and confirm they were planned and documented.
- Check for internal consistency across procedures and processes following any recent changes.
- Define what triggers a formal change request in your organisation and communicate that to relevant staff.
Why These Nonconformities Matter Beyond Certification
It is worth stepping back from the audit context for a moment. The reason Clause 6 exists is not to create paperwork. Risk based thinking, measurable objectives, and planned change management are genuinely useful management tools. Organisations that do these things well tend to be more resilient, more consistent, and better at achieving their goals. Organisations that treat Clause 6 as a documentation exercise to satisfy auditors tend to find that their QMS adds bureaucracy without adding value.
When an auditor raises a Clause 6 nonconformity, they are not just pointing to a gap in documentation. They are identifying a gap in how the organisation plans and manages its quality system. Addressing the root cause of that gap, rather than just updating the document, is what genuine conformity looks like.
If you are preparing for a certification audit or trying to lift the quality of your internal audit programme, understanding the common patterns in Clause 6 findings will help you focus your effort where it matters most. You might also find it useful to review our article on common ISO 9001 nonconformities and how to avoid them for a broader view across all clauses.
At Audit Workshop, our ISO 9001 internal auditor and lead auditor training courses cover Clause 6 in practical depth, including how to audit risk based thinking, evaluate quality objectives, and assess change planning. Participants work through real audit scenarios and learn to identify the exact gaps described in this article. If you want to build genuine auditing competence rather than just pass an exam, our courses are built for exactly that purpose.













