Insights · 5 min read
ISO 9001 clause 6.1: risk-based thinking is not a risk register
Clause 6.1 requires no risk register. It requires no methodology, no matrix, no scoring, and no documented information at all.
Published by CAS — Conformity Assessment Services · 4 September 2026
Clause 6.1 requires no risk register. It requires no methodology, no matrix, no scoring, and no documented information at all.
What most organizations produce in response to it is a spreadsheet with likelihood and severity columns, filled in once, scored against a scale nobody calibrated, and reviewed annually because a procedure says so. That artefact can exist alongside conformity. It is not what the clause asked for, and on its own it does not demonstrate it.
What the clause says
When planning for the quality management system, the organization shall consider the issues referred to in 4.1 and the requirements referred to in 4.2, and determine the risks and opportunities that need to be addressed in order to give assurance the system can achieve its intended results, enhance desirable effects, prevent or reduce undesired effects, and achieve improvement.
It shall then plan actions to address them, plan how to integrate and implement those actions into its processes, and evaluate the effectiveness of those actions.
And: actions taken shall be proportionate to the potential impact on the conformity of products and services.
Read that sequence again, because four separate obligations are hiding in it — determine, plan, integrate, evaluate — and most implementations stop after the first two.
"Risk-based thinking" is not a process you install
The phrase appears in the introduction to ISO 9001, where it explains the concept underlying the standard. It is not a clause requiring you to operate a risk management process, and the standard does not require conformity with ISO 31000 or any other risk methodology.
This distinction has practical consequences. An organization that adopts a formal risk management framework because it believes clause 6.1 demands one has taken on obligations the standard never imposed — and will be audited against the framework it chose, because a documented process becomes auditable once it exists.
The standard leaves the method open. That is a permission, and it is regularly read as an omission to be filled with a template.
Downstream of clause 4.1 — structurally
The clause does not say determine your risks. It says consider the issues in 4.1 and the requirements in 4.2, and determine the risks and opportunities that need to be addressed.
The word consider is doing structural work. Clause 6.1 sits downstream of context and interested parties by design, and this is the link an audit team follows most often.
Which is why a risk register populated from a generic industry hazard list — rather than from what the organization determined about its own situation — breaks the thread. Every entry may be plausible. None of them arrived from anywhere.
The half that goes missing: opportunities
The clause says risks and opportunities, and most registers are entirely risk.
The standard's own note is specific about what opportunities can look like: adopting new practices, launching new products, opening new markets, addressing new customers, building partnerships, using new technology, and other desirable and viable possibilities.
None of that is a threat expressed backwards, and none of it fits comfortably in a likelihood-and-severity grid. Which is part of why it gets dropped — the tool that was reached for cannot hold it.
"Proportionate to the potential impact on conformity"
This phrase is the filter, and it is narrower than general business risk.
The test is impact on the conformity of products and services. A genuine commercial threat that does not bear on whether your product conforms is not what clause 6.1 is asking about — it may be an issue under 4.1, but the actions clause 6.1 requires are calibrated to product and service conformity.
Proportionality also runs downward. A risk with negligible impact does not require an elaborate response, and an organization that treats every entry with the same weight has stopped discriminating — which is the opposite of what the clause asks.
The obligation almost everyone misses
Clause 6.1.2 requires the organization to plan how to evaluate the effectiveness of the actions taken.
Not whether the action was completed. Whether it worked.
A register showing thirty actions all marked "done" answers a different question. Did the undesired effect reduce? Did the desirable one increase? Is the risk still there? An audit team asking this is not being difficult; it is reading the clause.
What auditors look for
That the determination traces to context. Not that a register exists — that its contents came from 4.1 and 4.2 rather than from a template.
That opportunities appear. Their complete absence suggests the clause was read as being about risk alone.
That actions were integrated into processes, not maintained as a parallel list nobody operating the process has seen.
That effectiveness was evaluated. This is where the evidence usually thins.
That proportionality is visible. Different responses to different impacts, rather than uniform treatment of everything.
None of this requires a particular document. All of it requires that somebody thought, and that the thinking left a trace.
Why the register became the default answer
Clause 6.1 arrived with the 2015 revision, replacing preventive action. Organizations transitioning had no equivalent to map it onto, and the available tools were risk registers borrowed from other disciplines.
A decade on, the register has become so standard that it is mistaken for the requirement. It is a legitimate method — one of several the standard permits and none of which it mandates. The failure is not using one. The failure is producing one and believing the clause is satisfied because it exists.