Risks and Opportunities in ISO 9001:2026: Clauses 6.1.2 and 6.1.3 Explained

ISO Cloud Consulting editorial team
Separate risk and opportunity registers

Clause 6.1 of ISO 9001:2026 has three sub-clauses (6.1.1 determining risks and opportunities, 6.1.2 actions to address risks, 6.1.3 actions to address opportunities), where the 2015 edition planned actions for both together in 6.1.2. The two action sub-clauses expect the same cycle: determine, analyse, evaluate, plan actions, build them into your processes and check whether they worked. If your register has an opportunities column that nobody fills in, this is the change that affects you.

Why were risks and opportunities separated?

Under the 2015 edition many organizations built a risk register but did little that was structured with opportunities, because risk was the familiar concept. Separating them makes it clear that opportunities are not the opposite of risks or a by-product of managing them. They need to be looked for, evaluated and pursued deliberately. Leadership commitments in clause 5.1.1 now refer to opportunity-based thinking as well as risk-based thinking for the same reason.

What does clause 6.1.2 expect for risks?

  • Determine the risks that could affect conformity of products and services, customer satisfaction and the intended results of the QMS, using your context (4.1) and interested parties (4.2) as inputs.
  • Analyse and evaluate them so that action is proportionate.
  • Plan actions, integrate them into QMS processes and evaluate their effectiveness.
  • A note in the standard says risks can include the ability to provide conforming products and services during and after a disruption.

What does clause 6.1.3 expect for opportunities?

The same cycle, applied to things that could improve performance: new technology, new markets, better supplier arrangements, process simplification, customer feedback that points to a new service. For each opportunity you decide whether to pursue it, plan how, and later review the result.

How do you score an opportunity?

Likelihood and consequence do not fit well. A simple alternative is benefit and feasibility, each on a scale of one to five:

Opportunity Benefit Feasibility Score Decision
Qualify a second supplier for a critical component 4 4 16 Pursue this year
Automate final inspection data capture 3 2 6 Review next year
Offer on-site calibration as a service 5 3 15 Pilot with two customers

How to convert a 2015 risk register

The standard separates the clauses and the actions for risks and opportunities. It does not require separate registers, so treat the steps below as one practical approach.

  1. Split the register into two sheets or two sections.
  2. Move any genuine opportunities across. Delete entries that are just the absence of a risk.
  3. Hold a one-hour workshop with process owners to identify opportunities. Use context issues, customer feedback, audit findings and objectives as prompts.
  4. Add an effectiveness review column to both sheets and a date for each review.
  5. Add disruption scenarios to the risk sheet: loss of a key supplier, key person, site or system.
  6. Report both at management review.

The Risk and Opportunity Register has both sheets, scoring matrices, heat maps, 48 example entries (28 risks and 20 opportunities) and a procedure.

Questions worth asking yourself

  • Show me how you determined opportunities, and who was involved.
  • Pick one opportunity: what did you decide, what did you do, and did it work?
  • How do actions from the register reach your processes, objectives or plans?
  • How would you keep supplying conforming product if this supplier or system failed?

Free sample

Get the free ISO 9001:2026 transition checklist

The one-page, 20-step checklist from gap analysis to transition audit. Real, unedited pages so you can judge the files before you buy.

You will also get occasional template updates and guidance. Unsubscribe any time. See our privacy policy.

Back to blog

Frequently asked questions

What is the difference between clause 6.1.2 and 6.1.3 in ISO 9001:2026?

Clause 6.1.2 covers actions to address risks and clause 6.1.3 covers actions to address opportunities. Each requires you to determine, analyse and evaluate, plan actions, integrate them into your processes and evaluate their effectiveness.

Is a risk register mandatory in ISO 9001:2026?

The standard does not mandate a particular document, but you need to be able to show how risks and opportunities were determined, evaluated and acted on. A register is a simple way to do that.

Does ISO 9001:2026 require a formal risk management process like ISO 31000?

No. The standard requires risk-based thinking and proportionate action. You choose the method and level of formality.

What is an example of an opportunity in ISO 9001?

Examples include qualifying a second supplier to shorten lead times, automating an inspection step to reduce errors, entering a new market with an existing certification, or using customer feedback to launch a service.

Templates that do this job

Editable Word and Excel files. Instant download. Licensed for one organization.