Exemplar Global Certified Courses from USD 119. Ending Soon!

Risk Based Thinking in ISO 9001: Clause 6.1 Explained

AW

Team @ Audit Workshop

14 min read
Risk Based Thinking in ISO 9001: Clause 6.1 Explained

What Clause 6.1 Actually Requires

Risk based thinking is one of the most talked about concepts in ISO 9001:2015, and one of the most misunderstood. Clause 6.1 sits in the Planning section of the standard and carries a deceptively simple title: Actions to address risks and opportunities. But behind that title is a requirement that touches every part of your quality management system.

The clause has two sub-clauses. Clause 6.1.1 asks you to determine the risks and opportunities that need to be addressed. Clause 6.1.2 asks you to plan actions to address them, integrate those actions into your QMS processes, and evaluate whether those actions were effective.

That is it. The standard does not require a formal risk register. It does not require a risk matrix. It does not require documented risk assessments in any particular format. What it requires is evidence that you have thought about what could go wrong or go right, and that you have done something about it.

This is where many organisations get confused. They either over-engineer the process, building elaborate spreadsheets that nobody reads, or they under-deliver, producing a single page document that lists five generic risks and calls it done. Neither approach serves the intent of the standard.

Why Risk Based Thinking Replaced Preventive Action

If you worked with ISO 9001:2008, you will remember Clause 8.5.3, which required documented preventive action. The 2015 revision dropped that clause entirely and replaced it with risk based thinking embedded throughout the standard.

The reason was straightforward. Preventive action under the old standard had become a compliance exercise. Organisations documented preventive actions to satisfy auditors, not to actually prevent problems. The process was disconnected from how decisions were actually made.

Risk based thinking takes a different approach. Instead of treating risk management as a separate activity, ISO 9001:2015 asks you to build it into the way you plan, operate, and improve your QMS. The idea is that every significant decision in your organisation should consider what could go wrong and what could be gained.

This is a more mature approach, but it is also harder to audit because it is less prescriptive. An auditor cannot simply ask to see your preventive action register and tick a box. They need to assess whether risk thinking is genuinely embedded in your processes.

Understanding the Link Between Clause 4 and Clause 6.1

Clause 6.1.1 explicitly connects to Clauses 4.1 and 4.2. When you determine risks and opportunities, you are expected to consider the context of your organisation and the needs and expectations of your interested parties.

This is not accidental. The standard is telling you that your risk identification should be grounded in your actual operating environment. A risk that is relevant to a construction company will be very different from one relevant to a software developer or a food manufacturer.

In practice, this means your Clause 4.1 context analysis should feed directly into your Clause 6.1 risk assessment. If you have identified that your key supplier is based overseas and that exchange rate fluctuations affect your costs, that is a risk worth addressing. If you have identified that a new regulation is coming into force that affects your product, that is both a risk and potentially an opportunity to differentiate yourself from competitors who are not prepared.

The ISO 9001 Clause 4.1 context analysis is the starting point for meaningful risk identification. Organisations that treat Clause 4 as a separate compliance exercise and Clause 6 as another separate compliance exercise miss the connection entirely.

What Counts as a Risk and What Counts as an Opportunity

The standard defines risk as the effect of uncertainty on an objective. That definition is worth unpacking. A risk is not simply something bad that might happen. It is any uncertainty that could affect whether you achieve what you are trying to achieve.

This means risks can be positive or negative. A positive risk is what the standard calls an opportunity. For example, if a competitor exits the market, that creates uncertainty about whether you can absorb their customers. If you can, that is an opportunity. If you cannot handle the volume, it becomes a risk to your ability to meet customer requirements.

In practice, most organisations focus heavily on negative risks and treat opportunities as an afterthought. Auditors notice this. A risk register that lists twenty potential problems but only one or two opportunities suggests that the process has been driven by a compliance mindset rather than genuine business thinking.

Good examples of risks in a quality context include:

  • Key person dependency where a single employee holds critical knowledge or relationships
  • Supplier concentration where one supplier provides a critical input with no approved alternative
  • Technology change that could make your current processes or products obsolete
  • Regulatory change that affects product specifications or testing requirements
  • Customer concentration where losing one customer would have a significant impact on revenue

Good examples of opportunities include:

  • New market segments that align with your existing capabilities
  • Technology adoption that could improve process efficiency or product quality
  • Regulatory changes that create barriers for competitors but not for you
  • Customer feedback trends that point to unmet needs you could address

What the Standard Does Not Require

This is worth stating clearly because it causes a great deal of unnecessary work. ISO 9001 does not require:

  • A formal risk register in any specific format
  • A risk matrix or likelihood and consequence scoring
  • Documented risk assessments for every process
  • A risk management procedure
  • Documented information about the risk assessment process itself

The standard requires that you determine risks and opportunities, plan actions to address them, and evaluate whether those actions were effective. How you do that is up to you. A small business might do this through regular management meetings where risks are discussed and decisions are recorded in meeting minutes. A larger organisation might maintain a formal risk register reviewed quarterly. Both approaches can satisfy the standard if they are genuine and effective.

What auditors are looking for is evidence that risk thinking actually influences decisions, not evidence that a document exists. A beautifully formatted risk register that nobody has looked at in twelve months is not evidence of risk based thinking. A set of meeting minutes that shows management discussing a supplier risk and deciding to qualify an alternative supplier is.

How to Structure Your Approach Without Over-Engineering It

The most practical approach to Clause 6.1 is to build risk thinking into the processes you already have, rather than creating a separate risk management process.

Start with your context analysis. What internal and external issues did you identify in Clause 4.1? Which of those issues represent risks to your ability to provide conforming products or services? Which represent opportunities to enhance customer satisfaction or improve performance?

Then look at your interested parties from Clause 4.2. What do your customers, suppliers, regulators, and other stakeholders need from you? Where could you fail to meet those needs? Where could you exceed them in ways that create competitive advantage?

From this, you can develop a practical list of risks and opportunities that is specific to your organisation. The list does not need to be exhaustive. It needs to be honest and relevant.

For each risk or opportunity, consider what action you will take. Actions to address risks might include:

  • Developing a contingency plan for a key supplier failure
  • Cross-training staff to reduce key person dependency
  • Implementing additional inspection steps for a high-risk process
  • Reviewing and updating procedures before a regulatory change takes effect

Actions to address opportunities might include:

  • Investing in a new capability to enter a growing market segment
  • Improving a process to reduce lead times and win more time-sensitive customers
  • Developing a new service offering based on customer feedback

Not every risk requires an action. The standard acknowledges that some risks are acceptable. If a risk has a very low likelihood and a minor consequence, you might decide to monitor it rather than act on it. That is a legitimate decision, but it should be a conscious one, not an oversight.

Integrating Risk Actions Into Your QMS Processes

Clause 6.1.2 requires that actions to address risks and opportunities be integrated into your QMS processes. This is the part that separates genuine risk based thinking from a compliance exercise.

Integration means that the actions you have decided to take actually show up in how your processes operate. If you have identified a risk around supplier quality and decided to implement incoming inspection, that inspection should be reflected in your process for receiving goods. If you have identified an opportunity to improve customer satisfaction through faster response times, that should be reflected in your customer communication process.

This is also where your quality objectives come in. Clause 6.2 requires quality objectives that are consistent with the quality policy and relevant to conformity of products and services. Many of these objectives should flow directly from your risk and opportunity assessment. If reducing supplier-related nonconformities is a risk mitigation action, a quality objective around supplier performance is a natural fit.

For a deeper look at how objectives connect to planning, the article on risk based thinking with practical examples walks through how this works across different types of organisations.

Evaluating the Effectiveness of Your Actions

Clause 6.1.2 also requires you to evaluate the effectiveness of the actions you have taken. This is the part that most organisations neglect.

Evaluating effectiveness means asking whether the action you took actually reduced the risk or captured the opportunity. It is not enough to implement an action and move on. You need to check whether it worked.

This evaluation does not need to be a formal process. It can happen through your regular monitoring and measurement activities under Clause 9.1, through management review under Clause 9.3, or through internal audit findings. What matters is that someone is asking the question and that the answer is informing future decisions.

For example, if you implemented cross-training to address a key person dependency risk, you would evaluate effectiveness by checking whether the cross-trained employees can actually perform the required tasks. If you introduced a new supplier qualification process to address a supplier quality risk, you would evaluate effectiveness by monitoring supplier performance data over time.

If an action has not been effective, that is not a failure. It is information. The standard expects continual improvement, and recognising that an action did not work and adjusting your approach is exactly what the standard is designed to encourage.

What Auditors Look for in Clause 6.1

When auditing Clause 6.1, experienced auditors are not simply checking whether a risk register exists. They are looking for evidence that risk based thinking is embedded in how the organisation operates.

Typical audit questions include:

  • How did you identify the risks and opportunities relevant to your QMS?
  • How does your context analysis inform your risk assessment?
  • Can you show me an example of a risk you identified and the action you took?
  • How do you evaluate whether your actions have been effective?
  • How are risks and opportunities considered when you plan changes to your QMS?

Auditors will also look for evidence of risk thinking in other parts of the system. If a nonconformity keeps recurring, that suggests a risk was not identified or an action was not effective. If quality objectives are not connected to any identified risks or opportunities, that suggests the planning process is fragmented.

Common nonconformities against Clause 6.1 include:

  • Risks and opportunities that are generic and not specific to the organisation
  • No evidence that actions have been integrated into QMS processes
  • No evaluation of the effectiveness of actions taken
  • Risk assessment that does not consider the context of the organisation or interested party needs
  • Actions that exist on paper but are not reflected in actual operations

If you are preparing for a certification audit, the article on common ISO 9001 Clause 6 nonconformities covers the specific findings that auditors raise most often and how to avoid them.

Practical Examples Across Different Sectors

Understanding how Clause 6.1 applies in practice is much easier with concrete examples.

Construction

A construction company might identify risks around weather delays affecting project timelines, subcontractor performance affecting quality, and changes in client specifications mid-project. Opportunities might include a growing pipeline of government infrastructure projects that align with their capabilities. Actions might include buffer scheduling, subcontractor prequalification, and a formal variation management process. Effectiveness would be evaluated through project completion rates, defect rates, and client satisfaction scores.

Manufacturing

A manufacturer might identify risks around raw material price volatility, machine downtime affecting output, and key operator turnover. Opportunities might include automation investment that could reduce per-unit costs. Actions might include multi-supplier agreements, a preventive maintenance programme, and cross-training. Effectiveness would be evaluated through material cost trends, equipment availability data, and production output against targets.

Professional Services

A consulting firm might identify risks around staff turnover affecting client relationships, scope creep eroding project profitability, and regulatory changes affecting the advice they can give. Opportunities might include growing demand for a service area where they have deep expertise. Actions might include knowledge management systems, contract management processes, and investment in staff development. Effectiveness would be evaluated through client retention rates, project profitability, and staff satisfaction surveys.

Connecting Clause 6.1 to the Rest of the Standard

Risk based thinking does not live in isolation in Clause 6. The standard expects it to flow through the entire QMS. Clause 8.1 on operational planning requires you to implement actions from Clause 6.1. Clause 9.1 on monitoring and measurement provides the data you need to evaluate effectiveness. Clause 9.3 on management review requires risks and opportunities to be considered as part of the review inputs. Clause 10 on improvement closes the loop by requiring you to act on what you have learned.

This interconnection is deliberate. The standard is designed as a system, not a collection of independent requirements. When organisations treat each clause as a separate compliance exercise, they miss the intent of the standard entirely and end up with a QMS that satisfies auditors on paper but does not actually improve performance.

Understanding how the clauses connect is a core skill for internal auditors. If you are building your auditing capability, the ISO 9001 clauses explained in plain English gives you a solid foundation for understanding how each requirement fits into the overall system.

Building Genuine Risk Based Thinking Into Your Organisation

The organisations that get the most value from Clause 6.1 are the ones that treat risk based thinking as a management discipline, not a compliance requirement. They discuss risks and opportunities in management meetings. They connect their quality objectives to their identified risks. They track whether their actions are working and adjust when they are not.

This does not require a sophisticated risk management framework. It requires honest thinking about what could go wrong, what could go right, and what you are going to do about it. That is something any organisation can do, regardless of size or sector.

If you want to develop your ability to audit Clause 6.1 effectively, or to implement risk based thinking in a way that satisfies both the standard and your business needs, Audit Workshop offers practical ISO 9001 internal auditor and lead auditor training that covers risk based thinking in depth. The training is built around real audit scenarios, not just theory, so you leave with skills you can apply immediately.

Frequently Asked Questions

No. ISO 9001:2015 does not require a formal risk register or any specific format for documenting risks and opportunities. The standard requires that you determine risks and opportunities, plan actions to address them, and evaluate the effectiveness of those actions. How you document this process is up to your organisation. A risk register is one common approach, but meeting minutes, process notes, or other records can also serve as evidence of risk based thinking.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor Training Course
20+ enrolled
View Details
Exemplar Global certified
ISO 9001:2015 Lead Auditor Training Course badge
ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
ISO 45001:2018 Lead Auditor Training Course
15+ enrolled
View Details
Exemplar Global certified
ISO 45001:2018 Lead Auditor Training Course badge
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
ISO 14001:2026 Lead Auditor Training Course
10+ enrolled
View Details
Exemplar Global certified
ISO 14001:2026 Lead Auditor Training Course badge
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.