Exemplar Global Certified Courses from USD 119. Ending Soon!

Clause 6.1.4 Risks and Opportunities: The New Subclause in ISO 14001:2026

AW

Team @ Audit Workshop

12 min read
Clause 6.1.4 Risks and Opportunities: The New Subclause in ISO 14001:2026

Why ISO 14001:2026 Added a Dedicated Subclause for Risks and Opportunities

If you have been working with ISO 14001:2015 for a while, you will know that risks and opportunities were addressed under Clause 6.1.1 as part of the general planning requirements. The 2026 revision changes that structure. Clause 6.1.4 is now a standalone subclause dedicated entirely to the identification, evaluation, and planning of actions related to risks and opportunities. This is not a cosmetic change. It signals that the standard expects organisations to treat this topic with more rigour and more explicit documentation than many were applying under the 2015 edition.

For environmental managers, internal auditors, and anyone preparing for the ISO 14001:2026 transition, understanding what Clause 6.1.4 actually requires is essential. This article walks through the clause in detail, explains what changed, and gives you practical guidance on what auditors will be looking for when they review your environmental management system against the new requirements.

What Clause 6.1.4 Says: The Core Requirements

Clause 6.1.4 requires the organisation to determine the risks and opportunities that need to be addressed. The clause builds on the outputs of several earlier clauses, specifically the context analysis from Clause 4.1, the interested parties assessment from Clause 4.2, the environmental aspects and their significance from Clause 6.1.2, and the compliance obligations from Clause 6.1.3. These inputs feed directly into the risk and opportunity determination process.

The clause requires that the organisation consider risks and opportunities related to:

  • Environmental aspects, including those with significant environmental impact
  • Compliance obligations
  • Other issues and requirements identified from the context and interested parties analysis

Critically, the 2026 edition makes it explicit that climate change considerations must be factored into this process. This is one of the most discussed additions in the revised standard, and it has direct implications for how organisations document and evaluate their environmental risks.

How Clause 6.1.4 Differs From the 2015 Approach

Under ISO 14001:2015, risks and opportunities were bundled into Clause 6.1.1 alongside the general planning requirements. Many organisations treated this as a brief exercise, noting a handful of risks in a register and moving on. The connection between the context analysis, the aspects and impacts process, and the resulting risks and opportunities was often loose and hard to trace.

The 2026 revision separates these elements to make the logical flow clearer and the requirements more auditable. Clause 6.1.4 now sits alongside, rather than inside, the general planning clause. This structural change means auditors can assess the risks and opportunities process on its own terms, rather than as a footnote to a broader planning discussion.

The explicit mention of climate change is the other significant addition. Under 2015, climate change could be captured as a context issue, but many organisations did not connect it through to their risk evaluation in any meaningful way. The 2026 standard closes that gap by naming it directly.

If you want a broader picture of all the changes in the revised standard, the ISO 14001:2026 transition guide covers the full scope of what has changed and what organisations need to do before the April 2029 deadline.

The Climate Change Requirement: What It Means in Practice

The inclusion of climate change in Clause 6.1.4 is worth spending some time on because it catches a lot of organisations off guard. The standard does not require you to measure your carbon footprint or set net zero targets. What it does require is that you consider whether climate change creates risks or opportunities that are relevant to your environmental management system.

In practice, this means asking questions like:

  • Are our operations exposed to physical climate risks such as flooding, extreme heat, or water scarcity?
  • Are there regulatory or market changes driven by climate policy that create compliance risks?
  • Do our significant environmental aspects, particularly energy use or emissions, create transition risks as carbon pricing or regulations tighten?
  • Are there opportunities to reduce environmental impact through changes driven by the shift to a lower carbon economy?

The output does not need to be a standalone climate risk assessment. It needs to be integrated into the risks and opportunities determination in a way that is traceable and auditable. If your organisation operates in sectors where climate risk is material, such as construction, agriculture, mining, or logistics, auditors will expect to see substantive treatment of this topic, not a single line in a register saying “climate change: low risk.”

Linking Clause 6.1.4 to the Rest of the Planning Process

One of the things that makes Clause 6.1.4 more demanding than it might first appear is the number of upstream inputs it draws on. To do this properly, your organisation needs to have completed meaningful work in Clauses 4.1, 4.2, 6.1.2, and 6.1.3 before the risks and opportunities determination can be robust.

Here is how the linkage works in practice:

From Context and Interested Parties

The issues identified in your context analysis, both internal and external, should feed into the risks and opportunities register. If your context analysis identifies that your organisation operates in a water stressed region, that issue should appear as a risk in Clause 6.1.4 and eventually connect to planned actions. The same applies to interested party requirements. If your key customers require evidence of environmental performance improvement, that is a risk if you fail to deliver and an opportunity if you can demonstrate leadership.

From Environmental Aspects and Impacts

Your significant environmental aspects are a primary source of environmental risk. If your operation generates significant air emissions, the risk of regulatory non compliance, community complaint, or reputational damage should be captured. Opportunities might include process changes that reduce those emissions and improve both environmental and business performance.

From Compliance Obligations

Compliance obligations are a direct source of risk. Failure to meet a licence condition or statutory requirement is an environmental risk with legal consequences. Changes to legislation, particularly in areas like waste, water, and emissions, create both risks and opportunities that should be tracked through this clause.

What Auditors Will Look For Under Clause 6.1.4

When auditors assess conformity with Clause 6.1.4, they are looking for evidence that the process is systematic, traceable, and genuinely connected to the organisation's environmental context. Here are the specific things they will probe.

A Traceable Determination Process

Auditors want to see that the risks and opportunities in your register did not appear from nowhere. They will look for evidence that the outputs of your context analysis, aspects and impacts assessment, and compliance obligations review were actually used as inputs. If your risk register contains generic entries that could apply to any organisation, that is a red flag. The entries should be specific to your operations, your location, and your environmental aspects.

Consideration of Climate Change

This will be a specific audit point under the 2026 standard. Auditors will ask how your organisation has considered climate change in the determination of risks and opportunities. They will want to see that this consideration is documented and that it has been evaluated rather than dismissed without analysis. For organisations in high exposure sectors, a superficial treatment will likely result in a nonconformity.

Evaluation of Significance

Not all risks are equal, and the clause expects organisations to evaluate which risks and opportunities need to be addressed. Auditors will look for evidence of a methodology for evaluating significance, whether that is a risk matrix, a scoring system, or another defensible approach. The methodology does not need to be complex, but it needs to be applied consistently and documented.

Connection to Planned Actions

Clause 6.1.4 does not operate in isolation. The risks and opportunities it identifies feed into the planning of actions under Clause 6.1.5. Auditors will trace the connection between identified risks and the actions planned to address them. If a significant risk appears in the register but has no corresponding action, that gap will need to be explained.

For a practical look at how to audit this clause in your own organisation, the article on auditing risks and opportunities under ISO 14001:2026 provides detailed audit questions and evidence gathering guidance.

Common Mistakes Organisations Make With This Clause

Having reviewed environmental management systems across a range of industries, there are patterns in how organisations get this wrong. Being aware of these mistakes before your transition audit will save you from unnecessary nonconformities.

Treating the Risk Register as a One Off Exercise

Risks and opportunities are not static. They change as your context changes, as legislation evolves, as your operations grow or shift, and as the climate risk landscape develops. Organisations that complete the risk register once and then leave it untouched for three years are not meeting the intent of the clause. Auditors will ask when the register was last reviewed and what triggered the review.

Disconnecting the Register From the Aspects and Impacts Process

Many organisations run their aspects and impacts assessment and their risk register as separate exercises with no visible connection between them. This creates a gap that auditors will find quickly. Your significant environmental aspects should be a primary input to your risk determination. If they are not, the register lacks the environmental grounding the standard requires.

Generic or Copied Entries

Risk registers that contain entries like “environmental incident: medium risk” without any specificity about what type of incident, which process, which aspect, or which impact are not fit for purpose. Every entry should be traceable to a specific source and should reflect the organisation's actual operations.

No Treatment of Climate Change

Under the 2026 edition, failing to address climate change in the risks and opportunities determination is a nonconformity. Organisations that have not yet thought about how climate change affects their environmental risks need to start that conversation before their transition audit.

Documented Information Requirements

The 2026 standard requires documented information as evidence that the risks and opportunities determination has been carried out. This does not mean you need a lengthy formal document, but it does mean the process and its outputs need to be recorded in a way that can be reviewed and verified.

At a minimum, your documented information should show:

  • The inputs used to determine risks and opportunities, including context issues, interested party requirements, significant aspects, and compliance obligations
  • The risks and opportunities identified, with sufficient specificity to be meaningful
  • The evaluation of which risks and opportunities need to be addressed
  • How climate change considerations were factored into the determination
  • The connection to planned actions under Clause 6.1.5

The format is flexible. A risk register, a planning matrix, or a documented review process can all work, provided the content meets the requirements and the document is maintained and reviewed on an appropriate cycle.

For context on how the broader planning structure of the 2026 edition fits together, the article on general planning requirements under Clause 6.1.1 is a useful companion read.

Practical Steps to Implement Clause 6.1.4

If you are working through the transition from ISO 14001:2015 to the 2026 edition, here is a practical sequence for addressing Clause 6.1.4.

  1. Review your existing context and interested parties outputs. Check whether these documents are current and whether they contain the level of detail needed to drive a meaningful risk determination.
  2. Map your significant environmental aspects to potential risks. For each significant aspect, identify the risks that arise if it is not managed effectively, including regulatory, reputational, financial, and environmental risks.
  3. Conduct a climate change review. Assess whether your operations face physical or transition risks from climate change, and document the assessment. Even if the conclusion is that climate risks are low, the analysis needs to be visible.
  4. Evaluate and prioritise. Apply a consistent methodology to assess which risks and opportunities are significant enough to require action. Document the methodology and the results.
  5. Connect to planned actions. Ensure that every significant risk or opportunity has a corresponding planned action under Clause 6.1.5, with ownership and timeframes assigned.
  6. Set a review cycle. Establish when and how the risks and opportunities determination will be reviewed and updated, and document this in your EMS procedures.

How This Clause Connects to Auditor Training

For anyone working as an internal auditor or preparing to audit against ISO 14001:2026, understanding Clause 6.1.4 is not optional. This is one of the clauses where the 2026 revision has made substantive changes, and auditors who are still working from 2015 checklists will miss the new requirements around climate change and the more explicit linkage requirements.

Updating your audit checklist to reflect the 2026 structure is a starting point, but the more important skill is knowing how to trace the connections between clauses during an audit. An auditor who can follow the thread from the context analysis through to the risk register and then to the planned actions will conduct a far more effective audit than one who simply checks whether a risk register exists.

If you are preparing to audit ISO 14001:2026 systems, Audit Workshop offers training for internal auditors and lead auditors that covers the 2026 edition in full, including the new planning requirements under Clause 6. The courses are built around practical audit scenarios, not just clause by clause theory, so you leave with skills you can apply immediately.

Frequently Asked Questions

Clause 6.1.4 is a new standalone subclause in the 2026 revision. Under ISO 14001:2015, risks and opportunities were addressed within Clause 6.1.1 as part of the general planning requirements. The 2026 edition separates them into their own subclause to make the requirements more explicit and more auditable. The intent existed in 2015, but the structure and the specific requirements, including the climate change consideration, are new.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2026 Lead Auditor Training Course
Launching on 22 Sept 20265+ enrolled
View Details
Exemplar Global certified
ISO 9001:2026 Lead Auditor Training Course badge
ISO 9001:2026 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 299USD 789
ISO 45001:2018 Lead Auditor Training Course
15+ enrolled
View Details
Exemplar Global certified
ISO 45001:2018 Lead Auditor Training Course badge
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
ISO 14001:2026 Lead Auditor Training Course
10+ enrolled
View Details
Exemplar Global certified
ISO 14001:2026 Lead Auditor Training Course badge
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Digital badges and a certificate
  • Access to webinars, events, and online resources

Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Instant Certificate

Download your digital certificate the moment you complete the course.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.