PublishedISO 9001:2026 published 16 Sept 2026 · 2015 certificates must transition by 30 Sept 2029What changed →
← Back to Clause Explorer
6.1.1ISO 9001:2026

Determining risks and opportunities

Changed in ISO 9001:2026

Restructured into three sub-clauses — 6.1.1 determining risks and opportunities, 6.1.2 actions to address risks, 6.1.3 actions to address opportunities. Each half is determined, analysed and evaluated, then planned with its own integration and effectiveness check; risk actions are proportionate to their potential impact, opportunity actions appropriate to your context. 'Opportunity' itself remains undefined — define it yourself.

Checked against the published text on 27 September 2026.

Plain-language summary

The starting point of the restructured 6.1: take the issues from 4.1 and the interested-party requirements from 4.2 and work out which risks and which opportunities the QMS has to deal with — so the system gives the results it should, undesired effects are prevented or reduced, desired effects are enhanced, and improvement happens. In 2026 this determination stands on its own, ahead of two separate sub-clauses on what to do about each half.

What the clause is really asking

Whether the thread from context to risk-and-opportunity is real and traceable: each significant issue or interested-party requirement leads to a named risk or opportunity (or a conscious 'no action'), and the register is built from that analysis rather than from a brainstorm in certification week. The four purposes of the exercise are the test of whether an entry belongs — does it protect intended results, prevent or reduce something undesirable, enhance something desirable, or drive improvement?

What auditors look for

Auditors pick an issue from 4.1 — a supply constraint, a skills shortage, a regulatory change, climate — and ask where it went. They expect to find it in the register as a risk, an opportunity or both, and to see the reverse trail too: a register entry that points back to the issue or party that gave rise to it. Entries with no origin, and issues with no destination, are the usual gaps.

Typical evidence

The risk and opportunity register cross-referenced to the context analysis and the interested-parties register; a dated review showing the determination is refreshed when context changes; management review minutes where changes in context and in interested-party expectations (a 9.3.2 input) feed back into it.

How to comply — recommendations

Give the register two columns it usually lacks: 'source' (which 4.1 issue or 4.2 party) and 'type' (risk or opportunity). Run the determination as a short workshop after each context review rather than as a standing document. Keep the list honest — twenty well-sourced entries beat a hundred generic ones.

Common nonconformities

Register entries with no link to context; context issues that never became a risk or opportunity; determination done once at certification and never revisited; opportunities determined as inverted risks rather than genuine upside.

Related clauses

ISO 9001:2026 — see also 4.1, 4.2, 6.1.2, 6.1.3, 9.3; IATF 16949 6.1.2.1–6.1.2.3 (2015 numbering); ISO 14001 6.1.1; ISO 45001 6.1.1

In the book

Chapter 6 — Planning — Risk, Opportunity and the Discipline of Change treats this clause family in full: what it is really asking, what auditors look for, the evidence that satisfies, how to make it work on a real floor, and where companies stumble.

The Clause Companion →Read a free sampleISO 9001 Edition · $9.99 · early edition, 2026 update free

Resources for this clause

Get the free ISO 9001:2026 Readiness Scorecard

Free, instant download. We'll only email you the occasional practical quality update — no spam, unsubscribe anytime.

Qlause provides interpretive guidance only and is not a substitute for the standard. Refer to your licensed copy of the relevant standard for the authoritative text.