Guide

ISO 9001:2026 Risk Management Clause 6.1: What Changes

ISO 9001:2026 risk management Clause 6.1 changes: the new three-part structure for risks and opportunities, and what auditors check.

Konstantin Dolgan, Ph.D.
Konstantin Dolgan, Ph.D.

Quality Systems Engineer & Product Development Expert

August 10, 2026 11 min read
ISO 9001:2026 Risk Management Clause 6.1: What Changes

At a glance

ISO 9001:2026 risk management Clause 6.1 changes: the new three-part structure for risks and opportunities, and what auditors check.

  • Focus: risk management · clause 6.1
  • Read time: 11 minutes
  • Updated: August 10, 2026

ISO 9001:2026 risk management changes in Clause 6.1 restructure the risk framework and introduce a new opportunities register.

What Actually Changed in Clause 6.1: A Precise Comparison

ISO 9001:2026 risk management Clause 6.1 introduces a structural change. ISO 9001 Clause 6.1 2026 changes: risks and opportunities were restructured. The ISO 9001 2026 risks and opportunities framework now requires systematic management. It requires management of opportunities as well as risks.

The ISO 9001:2026 revision to Clause 6.1 is one of the most technically significant changes in the standard, yet it is also one of the most misunderstood. The change is not about adding new risk management requirements — it is about restructuring how organizations demonstrate that their risk management is systematic rather than ad hoc.

ISO 9001:2015 Clause 6.1 required organizations to determine risks and opportunities. It also required planning actions to address those risks and opportunities. ISO 9001:2026 adds a third step: analyze and evaluate identified risks and opportunities. Organizations must analyze and evaluate before deciding on actions. This analysis and evaluation was implied in 2015 but is now explicit.

The practical difference is significant. Under ISO 9001:2015, organizations could list risks and assign actions without assessment. They did not need to demonstrate assessing likelihood, consequence, or significance of each risk. Under ISO 9001:2026, organizations must analyze and evaluate each risk before deciding actions.

The Three-Step Risk Management Process Under ISO 9001:2026

ISO 9001:2026 Clause 6.1 now requires a three-step process:

StepISO 9001:2015ISO 9001:2026
1. IdentifyDetermine risks and opportunitiesDetermine risks and opportunities (unchanged)
2. Analyze and EvaluateNot explicitly requiredNew explicit requirement — analyze and evaluate identified risks and opportunities
3. Plan ActionsPlan actions to address risks and opportunitiesPlan actions to address risks and opportunities (unchanged)

The addition of the "analyze and evaluate" step aligns ISO 9001:2026 with ISO 31000:2018 (the international risk management standard) and with the risk management requirements in ISO 14001:2015 and ISO 45001:2018. This alignment is intentional — it makes it easier for organizations with integrated management systems to apply a consistent risk methodology across all three standards.

Key Insight

The "analyze and evaluate" requirement does not mandate a specific risk methodology.: ISO 9001:2026 does not require organizations to use risk matrices, likelihood-consequence tables, FMEA, HAZOP, or any other specific tool. The requirement is that the organization demonstrates it has analyzed and evaluated its risks — not that it has used a particular method. The choice of methodology should be proportionate to the complexity and nature of the organization's risks.

ISO 9001:2026 Risk Management Clause 6.1: The New Structure

Stay Current

ISO expects the next edition in September 2026. Get source-checked weekly briefings.

What "Analyze and Evaluate" Means in Practice

The ISO 31000:2018 framework, which ISO 9001:2026 aligns with, defines risk analysis. It defines risk analysis as understanding risk nature, sources, and characteristics. Risk evaluation compares analysis results with risk criteria to judge acceptability.

For most ISO 9001:2026 certified organizations, this translates to:

Risk Analysis — For each identified risk, determine:

  • What could go wrong (the risk event).
  • What causes it (root causes or contributing factors).
  • What the consequences would be if it occurred (impact on quality objectives, customers, or interested parties).
  • How likely it is to occur (frequency, probability, or likelihood).

Risk Evaluation — Based on the analysis, determine:

  • Is this risk significant enough to require action?
  • What level of action is proportionate to the risk?
  • Should the risk be treated, tolerated, transferred, or terminated?

The output of this analysis and evaluation should be documented in a way that allows an auditor to see the reasoning behind the organization's decisions about which risks to address and how.

The Risk Register: What ISO 9001:2026 Expects

ISO 9001:2026 does not require a risk register. Most organizations find registers the most practical way to document risk management. A risk register that satisfies the ISO 9001:2026 Clause 6.1 requirements should include:

FieldPurpose
Risk IDUnique identifier for tracking
Risk descriptionWhat could go wrong
Risk categoryProcess, product, customer, supplier, regulatory, strategic
LikelihoodLow / Medium / High (or numerical score)
ConsequenceLow / Medium / High (or numerical score)
Risk levelCombined assessment (e.g., likelihood × consequence)
EvaluationIs this risk acceptable? What action is required?
ActionWhat will be done to address the risk
OwnerWho is responsible for the action
Due dateWhen the action will be completed
StatusOpen / In progress / Closed
EffectivenessWas the action effective? (reviewed at management review)

The key addition for ISO 9001:2026 compliance is the Likelihood, Consequence, Risk Level, and Evaluation fields. They show the organization analyzed and evaluated risks instead of merely listing them.

The Three New Requirement Areas and Their Risk Implications

ISO 9001:2026 introduces three new requirement areas that have direct implications for risk management:

Clause 4.1 — Climate Change. Organizations must now consider whether climate change is a relevant external issue for their context. For most organizations, this means adding climate-related risks to the risk register — physical risks (flooding, extreme weather, supply chain disruption due to climate events) and transition risks (regulatory changes, energy costs, customer expectations). The risk analysis and evaluation requirements of Clause 6.1 apply to these climate-related risks in the same way as any other risk.

Clause 5.1.1 — Quality Culture. The new quality culture requirement creates a category of organizational risks that many organizations have not previously addressed in their QMS risk register: the risk of cultural failure. What is the risk that leadership behaviors undermine quality commitments? What is the risk that ethical failures damage customer trust? These are legitimate risks that ISO 9001:2026 implicitly requires organizations to consider.

Clause 8.2.1 — Contingency Communication. The requirement to communicate contingency plans to customers in the event of disruptions creates a risk management obligation: organizations must identify the disruption scenarios that would require customer communication, assess the likelihood and impact of those scenarios, and have documented plans for how they would respond.

Warning

Risk management under ISO 9001:2026 is not a standalone exercise.: The risks and opportunities identified in Clause 6.1 must be inputs to management review (Clause 9.3), must inform the internal audit programme (Clause 9.2), and must be addressed through the corrective action process (Clause 10.2) when they materialize. Auditors will look for evidence that the risk register is a living document that drives decisions — not a static compliance artifact.

What Auditors Will Look For in Transition Audits

Transition auditors assessing Clause 6.1 compliance will focus on the new analysis and evaluation requirement. Based on early guidance from certification bodies, the key audit questions are:

  1. How did you identify your risks and opportunities? The auditor will look for a systematic approach — not just a list of obvious risks, but evidence that the organization has considered its context (Clause 4.1), its interested parties (Clause 4.2), and its quality objectives (Clause 6.2) when identifying risks.
  1. How did you analyze and evaluate each risk? The auditor will look for evidence that each risk has been assessed for likelihood and consequence, and that the organization has made a reasoned judgment about whether the risk requires action.
  1. How did your risk evaluation drive your action decisions? The auditor will look for traceability between the risk evaluation and the actions planned. If a risk was evaluated as high-likelihood and high-consequence, the auditor will expect to see a corresponding action. If a risk was evaluated as low-significance and no action was taken, the auditor will expect to see the reasoning documented.
  1. How do you review the effectiveness of your risk actions? The auditor will look for evidence that the organization reviews whether its risk actions have worked — typically through management review and internal audit.

Practical Template Language for ISO 9001:2026 Clause 6.1

The following template language can be adapted for a risk register entry. It satisfies the ISO 9001:2026 analysis and evaluation requirement:

"Risk: [Description of what could go wrong]. Analysis: This risk arises from [root cause/contributing factor] and context. If it occurs, the consequence would be [impact on quality, customers, or objectives]. Based on our assessment, the likelihood is [Low/Medium/High] and the consequence is [Low/Medium/High]. This gives an overall risk level of [Low/Medium/High]. Evaluation: This risk [is/is not] acceptable without action because [reasoning]. Action: [Description of action to be taken], owned by [name/role], to be completed by [date]. Effectiveness will be verified by [method] at the next management review."

Key Resources

Frequently Asked Questions

Does ISO 9001:2026 require a formal risk assessment methodology like FMEA or a risk matrix?

No. ISO 9001:2026 requires organizations to analyze and evaluate their risks. It does not mandate any specific methodology for risk analysis or evaluation. The approach should be proportionate to the complexity and nature of risks. A simple likelihood-consequence assessment suffices for most organizations.

What is the difference between risk analysis and risk evaluation under ISO 9001:2026?

Risk analysis involves understanding the nature, likelihood, and potential consequences of a risk. Risk evaluation compares analysis results against the organization's risk criteria. It determines whether the risk is acceptable and what action level is required.

Do opportunities need to be analyzed and evaluated in the same way as risks?

Yes. ISO 9001:2026 Clause 6.1 applies to both risks and opportunities. Organizations should analyze and evaluate opportunities — assessing their likelihood and potential benefit — in the same way they analyze and evaluate risks.

How often should the risk register be reviewed?

ISO 9001:2026 does not specify a review frequency. Review the risk register whenever significant changes occur (new processes, new customers, new regulations, significant nonconformities). Also review the effectiveness of risk actions at management review.

What happens if a risk materializes and the organization did not have it in the risk register?

If a significant risk materializes that was not identified in the risk register, this is typically a finding in an audit — either a nonconformity with Clause 6.1 (failure to identify the risk) or an observation about the adequacy of the risk identification process. The corrective action would involve updating the risk register and improving the risk identification methodology.

risk managementclause 6.1ISO 9001:2026risk registerrisk analysisrisk evaluationtransition audit

Share this article

Editorial Disclaimer

This article is provided for informational and educational purposes only. It does not constitute legal, regulatory, certification, or professional advice. ISO 9001:2026 is an evolving standard and information may change as it is interpreted and implemented. Author attribution reflects the primary writer; it does not imply personal liability for any consequences arising from reliance on this content. Always consult your certification body and qualified professionals for advice specific to your organisation. See our Terms of Use for full details.

Was this article helpful?

Konstantin Dolgan, Ph.D.
Konstantin Dolgan, Ph.D.Quality Systems Engineer & Product Development Expert
Ph.D. Materials & Infrastructure Systems EngineeringCertified New Product Development Professional (NPDP)Forbes The Next 1000 (2021)7 Granted US Patents

Konstantin Dolgan, Ph.D., is a product development engineer and quality systems architect who first encountered ISO 9001 from the inside — as an R&D engineer designing API 610 centrifugal pumps inside a certified manufacturer. He has since led the development of over 1,000 physical products and holds a Ph.D. in Materials and Infrastructure Systems Engineering from Louisiana Tech University.

Expertise:Quality data architecture and traceabilityNew product development under ISO 9001 clause 8.3Design control and documented informationRoot cause analysis and risk-based thinkingISO 9001 for manufacturing and engineeringAI applied to quality managementERP integration and records management