Insights

Opportunities: the half of clause 6.1 that goes missing

Open a typical ISO 9001 risk register and count the opportunities. In most, the answer is zero.

Published by CAS — Conformity Assessment Services · 2 October 2026 · 3 min read
ShareLinkedInFacebook
Opportunities: the half of clause 6.1 that goes missing

Key takeaways

  1. 1Most registers are built on likelihood and severity.
  2. 2ISO 9001 is unusually concrete here.
  3. 3Clause 6.1 determines risks and opportunities considering the issues in 4.1 and the requirements in 4.2.

Open a typical ISO 9001 risk register and count the opportunities. In most, the answer is zero.

The clause says risks and opportunities, in that phrase, repeatedly. The omission is so consistent that it is worth asking why it happens rather than simply noting that it does.

The tool cannot hold them

Most registers are built on likelihood and severity. That structure describes a threat well: how probable, how bad.

An opportunity does not decompose the same way. "Opening a new market" has no severity. "Adopting a new practice" has no probability in the sense the column intends. So opportunities either get forced into a shape that does not fit, or they get left out — and leaving them out is tidier.

The tool was chosen first and the clause read afterwards. That order is the root of it.

What the standard says they look like

ISO 9001 is unusually concrete here. Its note gives examples: adopting new practices, launching new products, opening new markets, addressing new customers, building partnerships, using new technology, and other desirable and viable possibilities.

Notice what these have in common. They are things an organization might do, not conditions it might face. An opportunity in the sense clause 6.1 means is a course of action available to the organization that would help the management system achieve its intended results — not a favourable circumstance that happens to it.

That distinction explains a second common pattern: registers where the opportunities column contains inverted risks. "Risk: supplier failure. Opportunity: supplier does not fail." That is not an opportunity. It is the absence of a risk, and it tells nobody anything.

Where they actually come from

Clause 6.1 determines risks and opportunities considering the issues in 4.1 and the requirements in 4.2.

Context includes positive factors — the standard says so explicitly in its note to 4.1, that issues can include positive and negative factors or conditions for consideration. An organization whose context determination lists only threats has already settled what its 6.1 output will contain, because the input held nothing else.

So the missing opportunities in clause 6.1 frequently originate one clause earlier.

What "addressed" means for an opportunity

For a risk, addressing it is intuitive: reduce, avoid, share, retain by informed decision.

For an opportunity, the standard's language is the same — determine which need to be addressed, plan actions, integrate them, evaluate effectiveness. Which means an opportunity that is identified and not pursued is a legitimate outcome, provided the decision was made rather than avoided.

The evaluation obligation applies equally. If an opportunity was pursued, did it deliver? A register recording that a new market was entered, with no evaluation of whether it improved the system's ability to achieve intended results, has stopped at the same point the risk entries usually stop.

What an audit team notices

Zero opportunities across the whole register. Not a nonconformity in itself, but a prompt: how were these determined, and did anything positive in the context reach them?

Opportunities that are inverted risks. Suggests the column was filled to satisfy the word rather than the requirement.

Opportunities with no actions and no decision. Identified, then abandoned silently.

Opportunities pursued with no evaluation. The same gap as risks, in the half nobody looks at.

The useful question

Not "do we have opportunities in our register" — that produces a column filled in the week before the audit.

The question the clause actually poses is what an organization could do, given what it knows about its situation, that would make its management system better at delivering what it is supposed to deliver.

Answered honestly, that question produces entries no template would have suggested. Answered as a documentation exercise, it produces a column of inverted risks.

This article describes what the requirement says and how conformity is assessed. It is generic information about the standard, not advice on any particular management system.

CAS — An EGAC accredited MS certification body No. 012418.

Verify any certificate: cas.com.eg/certsearch

Apply for certification →Verify a certificate

Read next

Opportunities: the half of clause 6.1 that goes missing · CAS