Guide

ISO 9001:2026 Risk Management: Clause 6 Changes

ISO 9001:2026 risk management changes in Clause 6: three-part structure, new opportunities register, and climate risk integration.

Konstantin Dolgan, Ph.D.
Konstantin Dolgan, Ph.D.

Quality Systems Engineer & Product Development Expert

July 30, 2026 Updated August 7, 2026 10 min read
ISO 9001:2026 Risk Management: Clause 6 Changes

At a glance

ISO 9001:2026 risk management changes in Clause 6: three-part structure, new opportunities register, and climate risk integration.

  • Focus: Clause 6.1 · risk management
  • Read time: 10 minutes
  • Updated: August 7, 2026

ISO 9001:2026 risk management requirements in Clause 6 introduce a three-part risk structure and a new opportunities register.

Why Clause 6.1 Was Restructured

ISO 9001:2026 Clause 6.1 explained: the ISO 9001 2026 three-part risk structure divides risk and opportunity management into three sub-clauses. The ISO 9001 2026 risks and opportunities framework now requires systematic management of both risks and opportunities.

One of the most consistent pieces of feedback from ISO 9001:2015 users — captured in the 2021 ISO user survey and in audit findings from certification bodies worldwide — was that Clause 6.1 conflated two conceptually distinct activities: managing risks and pursuing opportunities.

Key Insight

Key Takeaway:: This article covers essential ISO 9001:2026 requirements and what they mean for certified organizations transitioning from ISO 9001:2015.

For the authoritative source, see the ISO 9001 standard page on ISO.orgISO 9001 standard page on ISO.orghttps://www.iso.org/standard/62085.html and the ISO TC 176 committeeISO TC 176 committeehttps://committee.iso.org/home/tc176sc2 responsible for the revision.

In the 2015 edition, Clause 6.1 addressed "actions to address risks and opportunities" as a single, unified requirement. While this reflected the reality that risks and opportunities are often two sides of the same coin, it created practical difficulties for organizations trying to demonstrate compliance. Auditors frequently found that organizations had robust risk management processes but had given little systematic attention to opportunity identification and pursuit. Others had conflated risk mitigation with opportunity management in ways that obscured both.

ISO 9001:2026 addresses this by splitting Clause 6.1 into three distinct sub-clauses, each with a clear and separate focus. This structural change is designed to make compliance demonstration clearer, more auditable, and more practically useful.

ISO 9001:2026 Risk Management Clause 6: The New Framework

The New Three-Part Structure

Stay Current

ISO expects the next edition in September 2026. Get source-checked weekly briefings.

Clause 6.1.1 — Determining Risks and Opportunities

This sub-clause covers the identification phase. Organizations must determine the risks and opportunities that need to be addressed to give assurance that the QMS can achieve its intended results, enhance desirable effects, prevent or reduce undesired effects, and achieve improvement.

The identification process should be systematic and documented. It should draw on the context analysis (Clause 4.1), the interested party analysis (Clause 4.2), and operational experience. The output is a documented list of identified risks and opportunities — typically a risk register or equivalent document.

Clause 6.1.2 — Planning Actions to Address Risks

This sub-clause covers the organization's response to identified risks. For each identified risk, the organization must plan actions to address it, integrate those actions into QMS processes, and evaluate the effectiveness of those actions.

The standard does not require a formal risk assessment methodology (such as FMEA or risk matrices), but the planned actions should be proportionate to the potential impact of the risk. Actions may include eliminating the risk source, changing the likelihood or consequences of the risk, sharing the risk, or accepting the risk by informed decision.

Clause 6.1.3 — Planning Actions to Pursue Opportunities

This sub-clause covers the organization's proactive response to identified opportunities. For each identified opportunity, the organization must plan actions to pursue it and integrate those actions into QMS processes.

This separation is important. It signals that opportunity management is not simply the absence of risk, but an active, distinct management activity. Organizations should be able to point to specific opportunities they have identified — new markets, new technologies, new processes — and demonstrate that they have systematically planned to pursue them.

What This Means for Your Risk Register

Most organizations will find that their existing risk register already captures the information required by all three sub-clauses. The primary task is to reorganize the documentation to clearly map to the new structure.

A practical approach is to restructure your risk register with three clearly labeled sections or columns:

Section 1 (Clause 6.1.1): Risk/opportunity identification — description of the risk or opportunity, its source, and its potential impact on QMS objectives.

Section 2 (Clause 6.1.2): Risk actions — planned actions to address identified risks, the process or function responsible, the target completion date, and the effectiveness evaluation criteria.

Section 3 (Clause 6.1.3): Opportunity actions — planned actions to pursue identified opportunities, the process or function responsible, and the expected benefit.

For many organizations, adding column headers or section labels to an existing risk register — distinguishing between "Risk Actions" and "Opportunity Actions" — may be sufficient. The goal is to make the three-part structure explicit and auditable, not to create a new document from scratch.

The Expanded Annex A Guidance on Risk-Based Thinking

One of the most valuable additions in ISO 9001:2026 is the significantly expanded Annex A guidance on risk-based thinkingrisk-based thinking/glossary#risk-based-thinking and opportunity management. This guidance addresses many of the questions that practitioners have struggled with since 2015:

  • What is the difference between a risk and an opportunity?
  • How detailed does the risk assessment need to be?
  • What does "proportionate" action look like?
  • How should opportunities be identified and evaluated?
  • What is the relationship between Clause 6.1 and the rest of the QMS?

Quality professionals are strongly encouraged to read the expanded Annex A guidance carefully. It provides practical context that will help both in implementing the requirements and in preparing for audits.

Common Mistakes to Avoid

Based on audit experience with the 2015 edition, the following are the most common mistakes organizations make with Clause 6.1 — and the ones most likely to be flagged in transition audits:

Treating risk management as a one-time exercise. Clause 6.1 requires ongoing risk and opportunity management, not a one-time risk assessment. The risk register should be a living document, reviewed and updated regularly — at minimum as part of the management reviewmanagement review/glossary#management-review process.

Focusing only on risks and ignoring opportunities. The 2015 edition's conflation of risks and opportunities led many organizations to build robust risk management processes while giving little attention to opportunity identification. The new three-part structure makes this imbalance more visible and more likely to be flagged in audits.

Disproportionate documentation. Some organizations respond to risk management requirements by creating elaborate risk matrices and scoring systems that consume significant resources without adding proportionate value. The standard requires actions proportionate to the potential impact of risks — not a specific methodology or level of documentation complexity.

Disconnecting risk management from QMS processes. Clause 6.1 requires that planned actions be integrated into QMS processes. Risk management that exists as a standalone document, disconnected from the processes it is supposed to inform, does not meet this requirement.

Key Resources

The following resources support your ISO 9001:2026 transition planning:

  • Track the forthcoming standard: ISO/FDIS 9001:2026 on ISO.orgISO/FDIS 9001:2026 on ISO.orghttps://www.iso.org/standard/88464.html is listed as under development with publication planned for September 2026. The final standard will be available through ISO and national standards bodies after publication.
  • IAF transition guidance: The International Accreditation Forum (IAF)International Accreditation Forum (IAF)https://www.iaf.nu publishes mandatory documents that certification bodies must follow during the transition period.
  • Free gap analysis template: Download our ISO 9001:2026 Gap Analysis TemplateISO 9001:2026 Gap Analysis Template/resources/gap-analysis-template — a clause-by-clause PDF worksheet covering all 29 requirements with ★ markers for the three new clauses.
  • Free transition checklist: Download our ISO 9001:2026 Transition ChecklistISO 9001:2026 Transition Checklist/resources/transition-checklist — a 30-item action checklist covering all four transition phases.
  • Transition guide: Our comprehensive ISO 9001:2026 transition guideISO 9001:2026 transition guide/article/how-to-transition-iso-9001-2015-to-2026 covers the full three-year transition window with a step-by-step action plan.
  • Certification costs: See our ISO 9001:2026 certification cost guideISO 9001:2026 certification cost guide/article/iso-9001-2026-certification-cost-guide for current pricing by organization size and region.
  • Internal audit preparation: Our ISO 9001:2026 internal audit guide and checklistISO 9001:2026 internal audit guide and checklist/article/iso-9001-2026-internal-audit-guide-checklist covers all new clause requirements.
  • Frequently asked questions: Visit our ISO 9001:2026 FAQ pageISO 9001:2026 FAQ page/faq for answers to the most common questions about the new revision.

Frequently Asked Questions: Clause 6.1 Risk Management

What is the ISO 9001 2026 three-part risk structure?

ISO 9001:2026 Clause 6.1 explained: the ISO 9001 2026 three-part risk structure divides risk and opportunity management into three sub-clauses. The ISO 9001 2026 risks and opportunities framework now requires systematic management of both risks (6.1.2) and opportunities (6.1.3) — the key change from ISO 9001:2015.

Does ISO 9001:2026 require a formal risk assessment methodology?

No. The standard does not prescribe a specific risk assessment methodology. Organizations may use FMEA, risk matrices, bow-tie analysis, or any other approach that is appropriate for their context and proportionate to the risks involved.

What is the difference between a risk and an opportunity in ISO 9001:2026?

A risk is an effect of uncertainty that could have a negative impact on the QMS's ability to achieve its intended results. An opportunity is a circumstance that could have a positive impact — a chance to improve performance, expand capability, or enhance customer satisfaction. The same uncertainty can sometimes present both a risk and an opportunity.

How often should the risk register be reviewed?

At minimum, the risk register should be reviewed as part of the management review process (Clause 9.3). It should also be reviewed whenever significant changes occur in the organizational context, when new risks or opportunities are identified, or when risk actions are found to be ineffective.

Can I use the same document for Clause 6.1 and Clause 4.1?

Yes. Many organizations integrate their context analysis and risk register into a single document. This is entirely acceptable and can improve the coherence of the QMS.

Clause 6.1risk managementrisk registeropportunitiesrisk-based thinkingISO 9001:2026 risks

Share this article

Editorial Disclaimer

This article is provided for informational and educational purposes only. It does not constitute legal, regulatory, certification, or professional advice. ISO 9001:2026 is an evolving standard and information may change as it is interpreted and implemented. Author attribution reflects the primary writer; it does not imply personal liability for any consequences arising from reliance on this content. Always consult your certification body and qualified professionals for advice specific to your organisation. See our Terms of Use for full details.

Was this article helpful?

Konstantin Dolgan, Ph.D.
Konstantin Dolgan, Ph.D.Quality Systems Engineer & Product Development Expert
Ph.D. Materials & Infrastructure Systems EngineeringCertified New Product Development Professional (NPDP)Forbes The Next 1000 (2021)7 Granted US Patents

Konstantin Dolgan, Ph.D., is a product development engineer and quality systems architect who first encountered ISO 9001 from the inside — as an R&D engineer designing API 610 centrifugal pumps inside a certified manufacturer. He has since led the development of over 1,000 physical products and holds a Ph.D. in Materials and Infrastructure Systems Engineering from Louisiana Tech University.

Expertise:Quality data architecture and traceabilityNew product development under ISO 9001 clause 8.3Design control and documented informationRoot cause analysis and risk-based thinkingISO 9001 for manufacturing and engineeringAI applied to quality managementERP integration and records management