PublishedISO 9001:2026 published 16 Sept 2026 · 2015 certificates must transition by 30 Sept 2029What changed →
← Back to Clause Explorer
6.1.2ISO 9001:2026

Actions to address risks

Changed in ISO 9001:2026

Restructured into three sub-clauses — 6.1.1 determining risks and opportunities, 6.1.2 actions to address risks, 6.1.3 actions to address opportunities. Each half is determined, analysed and evaluated, then planned with its own integration and effectiveness check; risk actions are proportionate to their potential impact, opportunity actions appropriate to your context. 'Opportunity' itself remains undefined — define it yourself.

Checked against the published text on 27 September 2026.

Plain-language summary

Risks now have a sub-clause of their own. Having determined them, you analyse and evaluate each one, plan actions proportionate to its potential impact on conformity and customer satisfaction, build those actions into the QMS processes, and evaluate whether they worked. No risk method is prescribed — proportionality is the rule — and a note reminds you that risks include those arising during and after a disruption.

What the clause is really asking

Whether the risk half of the register is a working control system: risks analysed and evaluated (a simple impact-and-likelihood score is enough), actions matched to the size of the risk, actions living inside processes (an FMEA control, an inspection point, a dual-sourcing rule) rather than only in the register, and a recorded verdict on whether each action reduced the risk.

What auditors look for

Auditors take a significant risk and walk it end to end: how it was evaluated, what action was planned, whether the action shows up in the process it was meant to change, and whether its effectiveness was evaluated — 9.1.3 and 9.3.2 now ask that question for risks specifically. Actions that have been 'ongoing' for three years, or effectiveness recorded as 'OK', draw the finding.

Typical evidence

The risk entries of the register with evaluation, planned action, owner, date and an effectiveness verdict; the process documents or controls that carry the action (FMEA, control plan, procedure step); the 9.1.3 evaluation and the 9.3.2 input on the effectiveness of actions on risks.

How to comply — recommendations

Score simply, act proportionately: big risks get real controls in the process, small risks get monitored. Write the effectiveness measure at planning time ('customer escapes from this failure mode: zero in twelve months') and review it on a date, not 'when we get to it'. Keep disruption scenarios — supply, utilities, key people — on the list; the note makes them fair game.

Common nonconformities

Risks with no evaluation, or all scored the same; actions disproportionate in either direction; actions recorded only in the register with no trace in the process; effectiveness never evaluated, or evaluated as one blended line with opportunities.

Related clauses

ISO 9001:2026 — see also 6.1.1, 6.1.3, 8.1, 9.1.3, 9.3; IATF 16949 6.1.2.1 contingency plans, 6.1.2.2 preventive action (2015 numbering); ISO 14001 6.1; ISO 45001 6.1.2

In the book

Chapter 6 — Planning — Risk, Opportunity and the Discipline of Change treats this clause family in full: what it is really asking, what auditors look for, the evidence that satisfies, how to make it work on a real floor, and where companies stumble.

The Clause Companion →Read a free sampleISO 9001 Edition · $9.99 · early edition, 2026 update free

Resources for this clause

Get the free ISO 9001:2026 Readiness Scorecard

Free, instant download. We'll only email you the occasional practical quality update — no spam, unsubscribe anytime.

Qlause provides interpretive guidance only and is not a substitute for the standard. Refer to your licensed copy of the relevant standard for the authoritative text.