Identifying Risks in ISO 9001
Risk in ISO 9001 runs through the whole standard, not just a single clause. This guide explains what risk-based thinking means, how risk and opportunity differ, where risk appears across the standard, and how to identify and assess it under Clause 6.1. Building this skill sits at the heart of our ISO 9001 Lead Auditor Course, ISO 9001 Internal Auditor training course and ISO 9001 Foundation Course, and it underpins many of the wider ISO 9001 requirements.
In this article
- What Is Risk-Based Thinking in ISO 9001?
- What Is Risk and Opportunity in ISO 9001?
- Where Does Risk Appear in ISO 9001? (Beyond Clause 6.1)
- Clause 6.1: Actions to Address Risks and Opportunities
- Practical Risk Assessment Methods for ISO 9001
- Common Mistakes in ISO 9001 Risk and Opportunity Management
- Frequently Asked Questions
What Is Risk-Based Thinking in ISO 9001?
Risk-based thinking is the principle that you should anticipate and address potential problems before they happen, rather than reacting after something goes wrong. People often ask what risk-based thinking in ISO 9001 actually means, and the short answer is that it replaced the old requirement for a separate preventive action procedure. Prevention is now built into how you plan and run every process.
In practice, this means weighing what could affect your ability to deliver conforming products and services, then deciding which risks are worth acting on. It does not demand a formal risk management system or documented risk register; it asks you to think about risk in ISO 9001 consistently and to show that your decisions are deliberate.
What Is Risk and Opportunity in ISO 9001?
So how do risk and opportunity differ in ISO 9001? Risk is the effect of uncertainty, usually something that could stop you meeting requirements or objectives. An opportunity is the flip side: a favourable situation you could exploit to improve results, such as new technology, a new market, or a more efficient process.
ISO 9001:2015 addresses the two together under Clause 6.1 as a single, balanced activity, while the 2026 edition distinguishes them more clearly, with separate requirements for the actions you take to address risks and those you take to address opportunities. Either way the intent is the same: you are not only avoiding harm, you are also looking for ways to do better. Crucially, ISO 9001 does not require you to act on every opportunity, only to consider them and decide which are worth pursuing.
Where Does Risk Appear in ISO 9001? (Beyond Clause 6.1)
Although Clause 6.1 is the obvious home for risk, the concept of risk in ISO 9001 is woven across several clauses. Recognising this helps you avoid treating risk as a one-off box-ticking task.
Seen this way, risk is a continuous thread, not a single document you complete once a year.
Clause 6.1: Actions to Address Risks and Opportunities
Clause 6.1 is where managing risk in ISO 9001 becomes a defined requirement. It asks you to do two things: determine the risks and opportunities that need to be addressed, and plan actions to address them, then integrate those actions into your QMS and evaluate their effectiveness.
- Determine: Identify risks and opportunities linked to your context and processes.
- Plan actions: Decide how you will avoid, reduce, share, accept or pursue each one.
- Integrate: Build the actions into normal process activity, not a side document.
- Evaluate: Check whether the actions worked and adjust as needed.
The actions you take must be proportionate to the potential impact on conformity of products and services. Done well, this is where risk in ISO 9001 stops being theoretical and starts protecting your customers.
Practical Risk Assessment Methods for ISO 9001
The standard does not mandate a method, so you can choose tools that suit your business. Effective risk assessment in ISO 9001 simply needs to be consistent, evidence-based and proportionate. Common approaches include:
- Risk matrix: Score likelihood against impact to prioritise what matters most.
- SWOT analysis: Useful at context level for strengths, weaknesses, opportunities and threats.
- FMEA: Failure mode and effects analysis for process and product risks.
- PESTLE: Scans external political, economic, social, technological, legal and environmental factors.
Whichever you pick, document your thinking so an auditor can see that risk assessment in ISO 9001 is driving real decisions, not just filling a template.
Common Mistakes in ISO 9001 Risk and Opportunity Management
A few recurring errors weaken how organisations handle risk. Avoiding them keeps your approach credible and audit-ready.
- Treating risk as a single annual register rather than ongoing thinking.
- Listing risks but never planning or evaluating actions against them.
- Ignoring opportunities entirely and focusing only on threats.
- Over-documenting with complex tools the business does not actually use.
- Failing to link risks to the context and objectives they affect.
Handled well, risk in ISO 9001 becomes a practical driver of improvement rather than a compliance burden.
Frequently Asked Questions
No. ISO 9001 requires risk-based thinking but does not mandate a documented risk register or a formal risk management process. You simply need to show that risks are considered and addressed.
Risk-based thinking is a mindset applied across the QMS. Formal risk management is a structured, documented process. ISO 9001 requires the former and allows, but does not require, the latter.
An opportunity is any favourable circumstance you could use to improve, such as new markets, new technology, efficiency gains or stronger customer relationships. You must consider opportunities but need not pursue them all.
Start from your context and processes, then use tools such as a risk matrix, SWOT or FMEA. Involve process owners, focus on what affects conformity and objectives, and record your decisions.
Clause 6.1 is the main requirement, but risk also features in clauses on context (4.1), processes (4.4), leadership (5.1), management review (9.3) and improvement (10).


