What Actually Changed in Clause 6.1: A Precise Comparison
The ISO 9001:2026 revision to Clause 6.1 is one of the most technically significant changes in the standard, yet it is also one of the most misunderstood. The change is not about adding new risk management requirements — it is about restructuring how organizations demonstrate that their risk management is systematic rather than ad hoc.
ISO 9001:2015 Clause 6.1 required organizations to determine risks and opportunities and plan actions to address them. ISO 9001:2026 adds a third step: organizations must now explicitly analyze and evaluate the risks and opportunities they have identified before deciding on actions. This analysis and evaluation step was implied in the 2015 version but is now an explicit requirement.
The practical difference is significant. Under ISO 9001:2015, an organization could list risks in a register and assign actions without demonstrating that it had assessed the likelihood, consequence, or significance of each risk. Under ISO 9001:2026, the organization must show that it has analyzed and evaluated each risk before determining what action (if any) is appropriate.
The Three-Step Risk Management Process Under ISO 9001:2026
ISO 9001:2026 Clause 6.1 now requires a three-step process:
| Step | ISO 9001:2015 | ISO 9001:2026 |
|---|---|---|
| 1. Identify | Determine risks and opportunities | Determine risks and opportunities (unchanged) |
| 2. Analyze and Evaluate | Not explicitly required | New explicit requirement — analyze and evaluate identified risks and opportunities |
| 3. Plan Actions | Plan actions to address risks and opportunities | Plan actions to address risks and opportunities (unchanged) |
The addition of the "analyze and evaluate" step aligns ISO 9001:2026 with ISO 31000:2018 (the international risk management standard) and with the risk management requirements in ISO 14001:2015 and ISO 45001:2018. This alignment is intentional — it makes it easier for organizations with integrated management systems to apply a consistent risk methodology across all three standards.
Key Insight
The "analyze and evaluate" requirement does not mandate a specific risk methodology.: ISO 9001:2026 does not require organizations to use risk matrices, likelihood-consequence tables, FMEA, HAZOP, or any other specific tool. The requirement is that the organization demonstrates it has analyzed and evaluated its risks — not that it has used a particular method. The choice of methodology should be proportionate to the complexity and nature of the organization's risks.
What "Analyze and Evaluate" Means in Practice
Stay Current
ISO 9001:2026 publishes September 16, 2026. Get weekly briefings.
The ISO 31000:2018 framework (which ISO 9001:2026 aligns with) defines risk analysis as the process of understanding the nature, sources, and characteristics of risk, and risk evaluation as the process of comparing the results of risk analysis with risk criteria to determine whether the risk is acceptable.
For most ISO 9001:2026 certified organizations, this translates to:
Risk Analysis — For each identified risk, determine:
- What could go wrong (the risk event)
- What causes it (root causes or contributing factors)
- What the consequences would be if it occurred (impact on quality objectives, customers, or interested parties)
- How likely it is to occur (frequency, probability, or likelihood)
Risk Evaluation — Based on the analysis, determine:
- Is this risk significant enough to require action?
- What level of action is proportionate to the risk?
- Should the risk be treated, tolerated, transferred, or terminated?
The output of this analysis and evaluation should be documented in a way that allows an auditor to see the reasoning behind the organization's decisions about which risks to address and how.
The Risk Register: What ISO 9001:2026 Expects
ISO 9001:2026 does not require a risk register, but most organizations find it the most practical way to document their risk management process. A risk register that satisfies the ISO 9001:2026 Clause 6.1 requirements should include:
| Field | Purpose |
|---|---|
| Risk ID | Unique identifier for tracking |
| Risk description | What could go wrong |
| Risk category | Process, product, customer, supplier, regulatory, strategic |
| Likelihood | Low / Medium / High (or numerical score) |
| Consequence | Low / Medium / High (or numerical score) |
| Risk level | Combined assessment (e.g., likelihood × consequence) |
| Evaluation | Is this risk acceptable? What action is required? |
| Action | What will be done to address the risk |
| Owner | Who is responsible for the action |
| Due date | When the action will be completed |
| Status | Open / In progress / Closed |
| Effectiveness | Was the action effective? (reviewed at management review) |
The key addition for ISO 9001:2026 compliance is the Likelihood, Consequence, Risk Level, and Evaluation fields. These are what demonstrate that the organization has analyzed and evaluated its risks rather than simply listed them.
The Three New Requirement Areas and Their Risk Implications
ISO 9001:2026 introduces three new requirement areas that have direct implications for risk management:
Clause 4.1 — Climate Change. Organizations must now consider whether climate change is a relevant external issue for their context. For most organizations, this means adding climate-related risks to the risk register — physical risks (flooding, extreme weather, supply chain disruption due to climate events) and transition risks (regulatory changes, energy costs, customer expectations). The risk analysis and evaluation requirements of Clause 6.1 apply to these climate-related risks in the same way as any other risk.
Clause 5.1.1 — Quality Culture. The new quality culture requirement creates a category of organizational risks that many organizations have not previously addressed in their QMS risk register: the risk of cultural failure. What is the risk that leadership behaviors undermine quality commitments? What is the risk that ethical failures damage customer trust? These are legitimate risks that ISO 9001:2026 implicitly requires organizations to consider.
Clause 8.2.1 — Contingency Communication. The requirement to communicate contingency plans to customers in the event of disruptions creates a risk management obligation: organizations must identify the disruption scenarios that would require customer communication, assess the likelihood and impact of those scenarios, and have documented plans for how they would respond.
Warning
Risk management under ISO 9001:2026 is not a standalone exercise.: The risks and opportunities identified in Clause 6.1 must be inputs to management review (Clause 9.3), must inform the internal audit programme (Clause 9.2), and must be addressed through the corrective action process (Clause 10.2) when they materialize. Auditors will look for evidence that the risk register is a living document that drives decisions — not a static compliance artifact.
What Auditors Will Look For in Transition Audits
Transition auditors assessing Clause 6.1 compliance will focus on the new analysis and evaluation requirement. Based on early guidance from certification bodies, the key audit questions are:
- How did you identify your risks and opportunities? The auditor will look for a systematic approach — not just a list of obvious risks, but evidence that the organization has considered its context (Clause 4.1), its interested parties (Clause 4.2), and its quality objectives (Clause 6.2) when identifying risks.
- How did you analyze and evaluate each risk? The auditor will look for evidence that each risk has been assessed for likelihood and consequence, and that the organization has made a reasoned judgment about whether the risk requires action.
- How did your risk evaluation drive your action decisions? The auditor will look for traceability between the risk evaluation and the actions planned. If a risk was evaluated as high-likelihood and high-consequence, the auditor will expect to see a corresponding action. If a risk was evaluated as low-significance and no action was taken, the auditor will expect to see the reasoning documented.
- How do you review the effectiveness of your risk actions? The auditor will look for evidence that the organization reviews whether its risk actions have worked — typically through management review and internal audit.
Practical Template Language for ISO 9001:2026 Clause 6.1
The following template language can be adapted for a risk register entry that satisfies the ISO 9001:2026 analysis and evaluation requirement:
"Risk: [Description of what could go wrong]. Analysis: This risk arises from [root cause/contributing factor]. If it occurs, the consequence would be [impact on quality, customers, or objectives]. Based on our assessment, the likelihood is [Low/Medium/High] and the consequence is [Low/Medium/High], giving an overall risk level of [Low/Medium/High]. Evaluation: This risk [is/is not] acceptable without action because [reasoning]. Action: [Description of action to be taken], owned by [name/role], to be completed by [date]. Effectiveness will be verified by [method] at the next management review."
Key Resources
- ISO 9001:2026 Complete Transition GuideISO 9001:2026 Complete Transition Guide/article/how-to-transition-iso-9001-2015-to-2026 — Full transition methodology including Clause 6.1 updates
- ISO 9001:2026 Gap Analysis TemplateISO 9001:2026 Gap Analysis Template/resources/gap-analysis-template — Free PDF with Clause 6.1 gap analysis section
- ISO 9001:2026 Transition ChecklistISO 9001:2026 Transition Checklist/resources/transition-checklist — Includes risk management preparation steps
- ISO 9001:2026 Management Review GuideISO 9001:2026 Management Review Guide/article/iso-9001-2026-management-review-clause-9-3-what-changes — How risk review connects to management review
- ISO 9001:2026 GlossaryISO 9001:2026 Glossary/glossary#risk — Definitions of risk, opportunity, and related terms
- ISO 9001:2026 Key Changes AnalysisISO 9001:2026 Key Changes Analysis/article/iso-9001-2026-key-changes-complete-analysis — Full breakdown of all clause changes
- ISO.org — ISO 31000:2018ISO.org — ISO 31000:2018https://www.iso.org/standard/65694.html — Risk management guidelines
Frequently Asked Questions
Does ISO 9001:2026 require a formal risk assessment methodology like FMEA or a risk matrix?
No. ISO 9001:2026 requires organizations to analyze and evaluate their risks but does not mandate any specific methodology. The approach should be proportionate to the complexity and nature of the organization's risks. A simple likelihood-consequence assessment is sufficient for most organizations.
What is the difference between risk analysis and risk evaluation under ISO 9001:2026?
Risk analysis involves understanding the nature, likelihood, and potential consequences of a risk. Risk evaluation involves comparing the results of that analysis against the organization's risk criteria to determine whether the risk is acceptable and what level of action is required.
Do opportunities need to be analyzed and evaluated in the same way as risks?
Yes. ISO 9001:2026 Clause 6.1 applies to both risks and opportunities. Organizations should analyze and evaluate opportunities — assessing their likelihood and potential benefit — in the same way they analyze and evaluate risks.
How often should the risk register be reviewed?
ISO 9001:2026 does not specify a review frequency, but the risk register should be reviewed whenever significant changes occur (new processes, new customers, new regulations, significant nonconformities) and as a minimum at each management review. The effectiveness of risk actions should also be reviewed at management review.
What happens if a risk materializes and the organization did not have it in the risk register?
If a significant risk materializes that was not identified in the risk register, this is typically a finding in an audit — either a nonconformity with Clause 6.1 (failure to identify the risk) or an observation about the adequacy of the risk identification process. The corrective action would involve updating the risk register and improving the risk identification methodology.
