Guide

ISO 9001:2026 Risk Management: What Changes in Clause 6.1 and How to Prepare

ISO 9001:2026 adds an explicit 'analyze and evaluate' step to Clause 6.1 risk management. This guide covers the precise clause changes, what analysis and evaluation means in practice, risk register requirements, and what auditors will look for in transition audits.

Konstantin Dolgan, Ph.D.
Konstantin Dolgan, Ph.D.

Quality Systems Engineer & Product Development Expert · Ph.D. Materials & Infrastructure Systems Engineering

August 10, 2026 11 min read

What Actually Changed in Clause 6.1: A Precise Comparison

The ISO 9001:2026 revision to Clause 6.1 is one of the most technically significant changes in the standard, yet it is also one of the most misunderstood. The change is not about adding new risk management requirements — it is about restructuring how organizations demonstrate that their risk management is systematic rather than ad hoc.

ISO 9001:2015 Clause 6.1 required organizations to determine risks and opportunities and plan actions to address them. ISO 9001:2026 adds a third step: organizations must now explicitly analyze and evaluate the risks and opportunities they have identified before deciding on actions. This analysis and evaluation step was implied in the 2015 version but is now an explicit requirement.

The practical difference is significant. Under ISO 9001:2015, an organization could list risks in a register and assign actions without demonstrating that it had assessed the likelihood, consequence, or significance of each risk. Under ISO 9001:2026, the organization must show that it has analyzed and evaluated each risk before determining what action (if any) is appropriate.

The Three-Step Risk Management Process Under ISO 9001:2026

ISO 9001:2026 Clause 6.1 now requires a three-step process:

StepISO 9001:2015ISO 9001:2026
1. IdentifyDetermine risks and opportunitiesDetermine risks and opportunities (unchanged)
2. Analyze and EvaluateNot explicitly requiredNew explicit requirement — analyze and evaluate identified risks and opportunities
3. Plan ActionsPlan actions to address risks and opportunitiesPlan actions to address risks and opportunities (unchanged)

The addition of the "analyze and evaluate" step aligns ISO 9001:2026 with ISO 31000:2018 (the international risk management standard) and with the risk management requirements in ISO 14001:2015 and ISO 45001:2018. This alignment is intentional — it makes it easier for organizations with integrated management systems to apply a consistent risk methodology across all three standards.

Key Insight

The "analyze and evaluate" requirement does not mandate a specific risk methodology.: ISO 9001:2026 does not require organizations to use risk matrices, likelihood-consequence tables, FMEA, HAZOP, or any other specific tool. The requirement is that the organization demonstrates it has analyzed and evaluated its risks — not that it has used a particular method. The choice of methodology should be proportionate to the complexity and nature of the organization's risks.

What "Analyze and Evaluate" Means in Practice

Stay Current

ISO 9001:2026 publishes September 16, 2026. Get weekly briefings.

The ISO 31000:2018 framework (which ISO 9001:2026 aligns with) defines risk analysis as the process of understanding the nature, sources, and characteristics of risk, and risk evaluation as the process of comparing the results of risk analysis with risk criteria to determine whether the risk is acceptable.

For most ISO 9001:2026 certified organizations, this translates to:

Risk Analysis — For each identified risk, determine:

  • What could go wrong (the risk event)
  • What causes it (root causes or contributing factors)
  • What the consequences would be if it occurred (impact on quality objectives, customers, or interested parties)
  • How likely it is to occur (frequency, probability, or likelihood)

Risk Evaluation — Based on the analysis, determine:

  • Is this risk significant enough to require action?
  • What level of action is proportionate to the risk?
  • Should the risk be treated, tolerated, transferred, or terminated?

The output of this analysis and evaluation should be documented in a way that allows an auditor to see the reasoning behind the organization's decisions about which risks to address and how.

The Risk Register: What ISO 9001:2026 Expects

ISO 9001:2026 does not require a risk register, but most organizations find it the most practical way to document their risk management process. A risk register that satisfies the ISO 9001:2026 Clause 6.1 requirements should include:

FieldPurpose
Risk IDUnique identifier for tracking
Risk descriptionWhat could go wrong
Risk categoryProcess, product, customer, supplier, regulatory, strategic
LikelihoodLow / Medium / High (or numerical score)
ConsequenceLow / Medium / High (or numerical score)
Risk levelCombined assessment (e.g., likelihood × consequence)
EvaluationIs this risk acceptable? What action is required?
ActionWhat will be done to address the risk
OwnerWho is responsible for the action
Due dateWhen the action will be completed
StatusOpen / In progress / Closed
EffectivenessWas the action effective? (reviewed at management review)

The key addition for ISO 9001:2026 compliance is the Likelihood, Consequence, Risk Level, and Evaluation fields. These are what demonstrate that the organization has analyzed and evaluated its risks rather than simply listed them.

The Three New Requirement Areas and Their Risk Implications

ISO 9001:2026 introduces three new requirement areas that have direct implications for risk management:

Clause 4.1 — Climate Change. Organizations must now consider whether climate change is a relevant external issue for their context. For most organizations, this means adding climate-related risks to the risk register — physical risks (flooding, extreme weather, supply chain disruption due to climate events) and transition risks (regulatory changes, energy costs, customer expectations). The risk analysis and evaluation requirements of Clause 6.1 apply to these climate-related risks in the same way as any other risk.

Clause 5.1.1 — Quality Culture. The new quality culture requirement creates a category of organizational risks that many organizations have not previously addressed in their QMS risk register: the risk of cultural failure. What is the risk that leadership behaviors undermine quality commitments? What is the risk that ethical failures damage customer trust? These are legitimate risks that ISO 9001:2026 implicitly requires organizations to consider.

Clause 8.2.1 — Contingency Communication. The requirement to communicate contingency plans to customers in the event of disruptions creates a risk management obligation: organizations must identify the disruption scenarios that would require customer communication, assess the likelihood and impact of those scenarios, and have documented plans for how they would respond.

Warning

Risk management under ISO 9001:2026 is not a standalone exercise.: The risks and opportunities identified in Clause 6.1 must be inputs to management review (Clause 9.3), must inform the internal audit programme (Clause 9.2), and must be addressed through the corrective action process (Clause 10.2) when they materialize. Auditors will look for evidence that the risk register is a living document that drives decisions — not a static compliance artifact.

What Auditors Will Look For in Transition Audits

Transition auditors assessing Clause 6.1 compliance will focus on the new analysis and evaluation requirement. Based on early guidance from certification bodies, the key audit questions are:

  1. How did you identify your risks and opportunities? The auditor will look for a systematic approach — not just a list of obvious risks, but evidence that the organization has considered its context (Clause 4.1), its interested parties (Clause 4.2), and its quality objectives (Clause 6.2) when identifying risks.
  1. How did you analyze and evaluate each risk? The auditor will look for evidence that each risk has been assessed for likelihood and consequence, and that the organization has made a reasoned judgment about whether the risk requires action.
  1. How did your risk evaluation drive your action decisions? The auditor will look for traceability between the risk evaluation and the actions planned. If a risk was evaluated as high-likelihood and high-consequence, the auditor will expect to see a corresponding action. If a risk was evaluated as low-significance and no action was taken, the auditor will expect to see the reasoning documented.
  1. How do you review the effectiveness of your risk actions? The auditor will look for evidence that the organization reviews whether its risk actions have worked — typically through management review and internal audit.

Practical Template Language for ISO 9001:2026 Clause 6.1

The following template language can be adapted for a risk register entry that satisfies the ISO 9001:2026 analysis and evaluation requirement:

"Risk: [Description of what could go wrong]. Analysis: This risk arises from [root cause/contributing factor]. If it occurs, the consequence would be [impact on quality, customers, or objectives]. Based on our assessment, the likelihood is [Low/Medium/High] and the consequence is [Low/Medium/High], giving an overall risk level of [Low/Medium/High]. Evaluation: This risk [is/is not] acceptable without action because [reasoning]. Action: [Description of action to be taken], owned by [name/role], to be completed by [date]. Effectiveness will be verified by [method] at the next management review."

Key Resources

Frequently Asked Questions

Does ISO 9001:2026 require a formal risk assessment methodology like FMEA or a risk matrix?

No. ISO 9001:2026 requires organizations to analyze and evaluate their risks but does not mandate any specific methodology. The approach should be proportionate to the complexity and nature of the organization's risks. A simple likelihood-consequence assessment is sufficient for most organizations.

What is the difference between risk analysis and risk evaluation under ISO 9001:2026?

Risk analysis involves understanding the nature, likelihood, and potential consequences of a risk. Risk evaluation involves comparing the results of that analysis against the organization's risk criteria to determine whether the risk is acceptable and what level of action is required.

Do opportunities need to be analyzed and evaluated in the same way as risks?

Yes. ISO 9001:2026 Clause 6.1 applies to both risks and opportunities. Organizations should analyze and evaluate opportunities — assessing their likelihood and potential benefit — in the same way they analyze and evaluate risks.

How often should the risk register be reviewed?

ISO 9001:2026 does not specify a review frequency, but the risk register should be reviewed whenever significant changes occur (new processes, new customers, new regulations, significant nonconformities) and as a minimum at each management review. The effectiveness of risk actions should also be reviewed at management review.

What happens if a risk materializes and the organization did not have it in the risk register?

If a significant risk materializes that was not identified in the risk register, this is typically a finding in an audit — either a nonconformity with Clause 6.1 (failure to identify the risk) or an observation about the adequacy of the risk identification process. The corrective action would involve updating the risk register and improving the risk identification methodology.

risk managementclause 6.1ISO 9001:2026risk registerrisk analysisrisk evaluationtransition audit

Share this article

Was this article helpful?

Konstantin Dolgan, Ph.D.
Konstantin Dolgan, Ph.D.Quality Systems Engineer & Product Development Expert
Ph.D. Materials & Infrastructure Systems EngineeringCertified New Product Development Professional (NPDP)Forbes The Next 1000 (2021)7 Granted US Patents

Konstantin Dolgan, Ph.D., is a product development engineer and quality systems architect who first encountered ISO 9001 from the inside — as an R&D engineer designing API 610 centrifugal pumps inside a certified manufacturer. He has since led the development of over 1,000 physical products and holds a Ph.D. in Materials and Infrastructure Systems Engineering from Louisiana Tech University.

Expertise:Quality data architecture and traceabilityNew product development under ISO 9001 clause 8.3Design control and documented informationRoot cause analysis and risk-based thinkingISO 9001 for manufacturing and engineeringAI applied to quality managementERP integration and records management