Managing Risks and Opportunities in an ISO 9001 Quality Management System

ISO 9001 Clause 6.1

This clause requires the organisation to consider its context, and the needs and expectations of interested parties, when determining its risks and opportunities

What Does ISO 9001 Clause 6.1 Require?

Clause 6.1 of ISO 9001:2015 requires organisations to identify the risks and opportunities that are relevant to the QMS and to plan actions to address them. The starting point is the context work done under Clause 4.1 (internal and external issues) and Clause 4.2 (interested parties and their requirements) - those outputs feed directly into the risk and opportunity identification process here.

The clause is split into two parts. Clause 6.1.1 sets out what the risk and opportunity identification must achieve: ensuring the QMS can deliver its intended results, enhancing desirable effects, preventing or reducing undesired effects, and driving improvement. Clause 6.1.2 then requires the organisation to plan actions to address the identified risks and opportunities, integrate those actions into QMS processes, and evaluate their effectiveness.

Risks and Opportunities - What Is the Standard Actually Asking For?

The standard does not require a formal risk management framework or a complex risk matrix. It requires proportionate, considered action - the actions taken should be appropriate to the potential impact on products and services. A small organisation with simple operations can satisfy this clause with a simple register listing key risks, the actions in place to manage them, and a record that these are reviewed periodically.

Risks under Clause 6.1 are not limited to operational hazards. They include anything that could affect the QMS achieving its intended results - losing a key supplier, regulatory changes, staff turnover in critical roles, over-dependence on a single customer. Opportunities are the other side of the coin - new markets, process improvements, technology changes that could enhance quality or efficiency.

The alphaZ F-IMS23 Opportunities and Risks Register uses a SWOT and PESTLE framework to structure this analysis, covering both internal and external factors in a way that directly addresses the outputs of Clause 4.1 and Clause 4.2.

How to Evidence Compliance

The most common approach is a maintained risks and opportunities register, reviewed at regular intervals and updated when the business context changes. Evidence that actions have been taken and their effectiveness evaluated - through management review outputs, internal audit findings, or an issues and actions register - demonstrates that the clause is being actively addressed rather than just documented.

The standard does not require risks to be scored or weighted, though many organisations choose to do so. What matters is that risks and opportunities have been considered, that proportionate actions are in place, and that the organisation can show it revisits these regularly.

When auditing against Clause 6.1, I want to see that the organisation has genuinely thought about what could go wrong and what could go right - not just that a register exists. I'll look at whether the risks identified reflect the actual business context, whether the actions against each risk are meaningful, and whether the register has been reviewed recently. A register that hasn't been updated since initial certification tells me this is being treated as a one-time exercise rather than an ongoing process. I also look for linkage between Clause 6.1 and the management review - risks and opportunities should feature in management review inputs and outputs.

The F-IMS23 register is one of the most useful documents in the alphaZ toolkit for this clause because it structures the analysis using SWOT and PESTLE, which naturally captures both the internal factors from Clause 4.1 and the stakeholder considerations from Clause 4.2. When I implement this with clients, I encourage them to treat it as a working document - reviewed at management review, updated when significant business changes happen, and linked to their actions register so that follow-through is visible.

Clause 6.1 is risk-based thinking written down. Most businesses already think about risk informally - what could go wrong, who depends on us, what would happen if a key person left. The standard is just asking you to capture that and show you're doing something about the important ones. Use the F-IMS23 register, fill in the SWOT and PESTLE sections, add actions against the key risks, and review it at your management review. That's it - most organisations can satisfy this clause in an afternoon.

Practical Compliance Guidance

To comply with Clause 6.1, you need a process for identifying risks and opportunities relevant to your QMS, planned actions to address them, and evidence that those actions are being implemented and reviewed. The level of formality should be proportionate to the size and complexity of your organisation.

The alphaZ documents below support compliance with Clause 6.1. The F-IMS23 register provides the primary tool for identifying and documenting risks and opportunities, while the ER1 Issues Actions Register provides a way to track and close out the actions arising from them.

alphaZ document How it supports Clause 6.1
ISO 9001 Management System Toolkit The complete toolkit for implementing an ISO 9001 compliant management system. Includes the risks register, issues register and all supporting documents.
F-IMS22 Interested Parties Register Used alongside the risks register - the correlation between interested parties and the risks they represent is a key input to Clause 6.1 planning.
F-IMS23 Opportunities and Risks Register The primary document for identifying and recording risks and opportunities using SWOT and PESTLE analysis. Links directly to the context outputs of Clause 4.1 and Clause 4.2.
ER1 Issues and Actions Register Tracks actions arising from identified risks and opportunities, providing evidence that planned actions are being implemented and followed up.

Note - all the above files can be downloaded with an alphaZ subscription

Frequently Asked Questions

No. The standard requires proportionate, considered actions to address risks and opportunities - not a formal risk management framework. The actions taken should be appropriate to the potential impact on the organisation's ability to deliver conforming products and services. For most small to medium organisations, a well-maintained risks and opportunities register reviewed at regular intervals is sufficient.
The standard does not require risks to be scored, weighted or categorised. Many organisations choose to do so as it helps prioritise actions, but it is not a requirement. What matters is that risks have been considered, that actions are in place where needed, and that the register is reviewed and kept current.
In 2024, ISO 9001 was updated with a NOTE requiring organisations to consider whether climate change is relevant as an external issue under Clause 4.1. Where it is relevant, this should feed into the risks and opportunities identified under Clause 6.1. This is a NOTE rather than a new requirement - it does not create new obligations, but it does mean auditors may ask whether climate-related risks have been considered. Adding a relevant entry to the F-IMS23 register where applicable is the most proportionate response.
At a minimum, the register should be reviewed as part of the annual management review process. It should also be reviewed whenever there are significant changes to the organisation's context - new contracts, regulatory changes, changes to the supply chain, or other events that could affect the risks and opportunities relevant to the QMS. A register that is only updated at initial certification quickly becomes out of date and is a common audit finding.
Under ISO 9001, risks relate to the quality management system - anything that could prevent the QMS from achieving its intended results, affect the ability to deliver conforming products and services, or impact customer satisfaction. This is distinct from health and safety risk assessment, which focuses on hazards to people. The two are related in that both use a risk-based approach, but they address different things and require different documentation. Organisations certified to both ISO 9001 and ISO 45001 will have separate risk processes for each, though they can be managed within a combined register.

Further Resources

payment logos