ISO 9001

ISO 9001 Risk and Opportunity Management: A Practical Guide

Risk and opportunity management under ISO 9001 means identifying what could prevent the QMS from succeeding and what could genuinely improve it. Once identified, each item needs evaluation, a proportionate action plan, and regular review — not a document built once and left alone.

Clause 6.1 replaced what used to be a standalone "preventive action" requirement in earlier editions of ISO 9001. That same forward-looking discipline is now built directly into everyday planning, not treated as a separate exercise. This guide covers a practical method for identifying, evaluating, and acting on risks and opportunities — not just what a good register looks like, but how to actually build one. It's written by Maria Falbo, a Lead Auditor with decades of ISO 9001 experience.

Maria Falbo|Lead Trainer, Logix ISO|August 2026|7 min read

Why Risk-Based Thinking Replaced Preventive Action

Earlier editions of ISO 9001 included a standalone clause requiring "preventive action" — a separate, somewhat disconnected process for anticipating problems before they occurred. The current standard removed that as a distinct clause and instead built risk-based thinking directly into planning itself, under Clause 6.1.

The practical difference matters: preventive action was often treated as a checkbox exercise, disconnected from actual planning decisions. Risk-based thinking is meant to be inseparable from how the organization plans — every planning decision should already reflect what could go wrong and what could go better, rather than risk assessment happening as a separate, bolted-on activity afterward.

A Practical Method for Identifying Risks and Opportunities

The most effective identification method starts from actual processes, not a blank page. Walk through each significant process in the QMS and ask two questions specifically: what could prevent this process from achieving its intended outcome, and what could make this process perform meaningfully better than it currently does? This is the same process-mapping discipline covered in our how to implement ISO 9001 guide — risk and opportunity identification works best when it's grounded in how work actually happens.

Good sources to draw from include customer complaints and returns, supplier performance history, near-misses that didn't cause a nonconformity but easily could have, changes already planned or anticipated in the business, and input from the people who actually run the process day to day — not just management's view of how it operates. A risk or opportunity that emerges from someone who actually does the work tends to be far more specific and actionable than one generated in a planning meeting removed from the floor.

Evaluating and Prioritizing What You've Found

Not every identified risk or opportunity deserves the same response. Once something's been identified, it needs some form of evaluation — typically considering how likely it is to occur and how significant the consequence would be if it did, for risks, or how significant the potential benefit would be, for opportunities.

This doesn't require a complex scoring system to be useful. What matters is that the evaluation is consistent and defensible — the same organization applying the same logic across its risk register, not treating one risk as urgent based on gut feeling while a comparably significant one sits ignored because it wasn't top of mind that week.

In Practice

A useful discipline I recommend: for every item on the register, be able to answer "compared to what" in one sentence. "This risk is more significant than X because Y" or "this opportunity matters more than Z because of its potential impact on customer satisfaction." If a team can't make that comparison for an item on their register, it usually means the item was added reflexively rather than genuinely evaluated against everything else already on the list.

Learn to audit risk and opportunity management with advance technical knowledge

Our ISO 9001 Internal Auditor course covers Clause 6.1 in depth, along with the full range of ISO 9001 requirements.

View Course

Turning Findings into Real Actions

Clause 6.1 doesn't just require identifying risks and opportunities — it requires planning actions to address them, integrating those actions into QMS processes, evaluating the effectiveness of those actions, and doing all of this proportionate to the potential impact on product and service conformity.

The proportionality requirement matters in practice: a minor, low-impact risk doesn't need an elaborate action plan, and treating every item on the register with the same weight of response wastes effort on low-value items while diluting attention from the ones that actually matter. A well-run register has action plans that are visibly scaled to significance — substantial responses for high-impact items, lighter or even monitoring-only responses for genuinely minor ones. This is exactly the kind of evidence an auditor should be probing for — see our ISO 9001 Internal Audit: The Complete Guide for the full audit methodology this register feeds into.

Reviewing and Updating the Register Over Time

A risk and opportunity register built once at initial certification and never revisited stops reflecting reality almost immediately. New equipment, a new customer, a supplier change, a near-miss that just happened — all of these should trigger a genuine review, not just wait for the next scheduled annual update.

The review itself should ask whether previously identified risks and opportunities are still relevant, whether their significance has changed, whether planned actions were actually completed and effective, and whether anything new has emerged since the last review. A register that looks identical audit after audit, with the same items in the same order, is a strong signal it isn't actually being used as a working document.

In Practice

One test I use when auditing whether a risks and opportunities register is genuinely being reviewed: ask when the last entry was actually added or removed, not just when the document was last opened and saved. A register that's been "reviewed" quarterly for two years but hasn't gained or lost a single item in that time usually means the review is a formality — someone confirming the document still exists, not actually re-examining whether it still reflects reality.

What Changes Under ISO 9001:2026

Clause 6.1 is restructured under the 2026 revision — risks and opportunities, previously addressed together in one combined clause, are split into three separate subclauses with their own dedicated treatment. The underlying discipline covered throughout this guide — identifying, evaluating, acting on, and reviewing risks and opportunities — remains the same either way; what changes is the standard's own internal organization of the requirement. For the full technical breakdown of this restructuring, see our ISO 9001 Requirements Explained guide.

FAQ

Frequently asked questions

Is a formal risk register required by ISO 9001?

The standard requires documented information as evidence that risks and opportunities have been determined, but doesn't mandate a specific register format. Most organizations use some form of structured register because it's the most practical way to demonstrate ongoing, consistent evaluation.

How is risk-based thinking under ISO 9001 different from formal risk management standards like ISO 31000?

ISO 9001's risk-based thinking is integrated directly into QMS planning and is comparatively lightweight — it doesn't require the more elaborate risk management framework ISO 31000 describes. Organizations with more mature risk management practices sometimes draw on ISO 31000 concepts, but it isn't required to meet ISO 9001's requirements.

How often should risks and opportunities be reviewed?

There's no fixed frequency required by the standard, but reviewing at least annually, plus whenever a significant change occurs — new equipment, a new customer, a relevant near-miss — keeps the register current rather than outdated.

What happens if an identified opportunity isn't pursued?

Nothing requires every identified opportunity to be acted on immediately. What matters is that the decision not to pursue it was a thought-through, documented evaluation, not simply forgotten or never revisited.

About the Author
Maria Falbo — Lead Trainer, Logix ISO
Maria Falbo
Founder & Lead Trainer, Logix ISO · 25+ Years Global Experience

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.

Learn more about Maria →
ISO 9001 Internal Auditor Training
Ready to become a qualified ISO 9001 internal auditor?

Self-paced · 365-day access · Training certificate included

View Course