ISO Clause 6: Planning Explained — this guide is part of our series on the ISO harmonized structure, the shared clause framework behind most ISO management system standards.
Most ISO management system standards share the same skeleton. It is set out in Annex SL, Appendix 2 of the ISO/IEC Directives Part 1 — the harmonized structure — and it gives every adopting standard the same ten clauses, the same core text and the same defined terms. Learn clause 6 once and you have learned it for ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 22301, ISO 42001 and the rest.
What ISO clause 6 actually asks for
Clause 6 turns the understanding built in clause 4 into intent. It is where risk-based thinking
becomes concrete and where most of the documented planning lives.
6.1 Actions to address risks and opportunities
Considering the issues from 4.1 and requirements from 4.2, determine the risks and opportunities
that need to be addressed to give assurance the system can achieve its intended outcomes, prevent or
reduce undesired effects, and achieve improvement. Then plan actions to address them, how to integrate
those actions into system processes, and how to evaluate their effectiveness.
This is the sub-clause adopting standards expand most. ISO
27001 splits it into 6.1.1 general, 6.1.2 information security risk assessment and 6.1.3
information security risk treatment, and it is 6.1.3 that requires the Statement of Applicability.
ISO 14001 adds environmental aspects and compliance obligations. ISO 45001 adds hazard identification
and legal requirements. The parent requirement is identical in each case; only the specialisation
differs.
6.2 Objectives and planning to achieve them
Objectives must be established at relevant functions and levels, be consistent with the policy,
measurable where practicable, take account of applicable requirements, be monitored, communicated and
updated. You must also document what will be done, what resources are required, who is responsible,
when it will be completed and how results will be evaluated.
Those five planning elements are an explicit list in the standard. An objective recorded without
them is an incomplete objective, and it is an easy finding for an auditor to write.
6.3 Planning of changes
Added in the 2021 edition of Annex SL and now present in newer and revised
standards. Where the organization determines a need for change to the management system, the change
must be carried out in a planned manner. It is short, it is frequently overlooked, and it is easy to
satisfy: a lightweight change record showing purpose, consequences, resources and responsibilities.
Because 6.3 arrived with the 2021 structure, older certified systems often have no evidence for it
at all. If your system predates 2021, check this one specifically.
Documented information ISO clause 6 expects
- A risk and opportunity register with treatment actions and evaluation of effectiveness
- A documented risk assessment methodology — required explicitly by ISO 27001
- A Statement of Applicability, for ISO 27001
- Objectives, documented, with the five planning elements against each
- A change planning record for system changes
Common audit findings against ISO clause 6
- Objectives that are not measurable. “Improve security” is not an objective;
“reduce mean time to patch critical vulnerabilities to 14 days by Q3” is. - Risks identified, treatments never closed. A register with open actions from two
audit cycles ago undermines the whole clause. - No evaluation of effectiveness. The standard requires you to evaluate whether the
actions worked, not merely that they were done. - Clause 6.3 with no evidence. Very common on systems certified before 2021.
Risk registers, methodologies and objectives.
Our toolkits include a documented risk methodology, a populated risk register, objective planning sheets with all five required elements, and for ISO 27001 a Statement of Applicability.
Which standards ISO clause 6 applies to
The harmonized structure covers the great majority of ISO management system standards, including ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 22301, ISO 20000-1, ISO 22000, ISO 42001, ISO 37301, ISO 50001, ISO 55001, ISO 41001, ISO 21001, ISO 28000 and ISO 39001. Adopting standards may add sub-clauses of their own, but they do not renumber the ten top-level clauses.
Two exceptions worth knowing. ISO 13485:2016 deliberately did not adopt the harmonized structure — its technical committee kept the older clause 4 to 8 layout to stay closer to medical device regulation, so the clause numbers on this page do not map to it. ISO/IEC 17025 and ISO 15189 are conformity assessment standards for laboratories rather than management system standards in the Annex SL sense, and they use their own structure.
Toolkits that implement ISO clause 6
Each of these standards uses the harmonized structure, so clause 6 applies to all of them. The toolkit for each ships the documented information the clause requires.
ISO 9001 · ISO 14001 · ISO 45001 · ISO 27001 · ISO 22301 · ISO 42001 · ISO 20000 · ISO 22000 · ISO 27701 · ISO 37301 · ISO 50001 · ISO 55001 · ISO 41001 · ISO 21001 · ISO 28000 · ISO 39001
ISO clause 6: frequently asked questions
What is the difference between a risk and an opportunity?
A risk is an effect of uncertainty that could stop the system achieving its intended outcomes; an opportunity is a circumstance that could improve them. Both must be determined and both need planned action where you decide to act.
Is clause 6.3 in every standard?
Only in standards published or revised against the 2021 edition of Annex SL. Older certified systems frequently have no evidence for it, so check your own version.
References for ISO clause 6
- ISO/IEC Directives and Policies — where Annex SL and the harmonized structure are published.
- ISO management system standards — the full list of standards that adopt this structure.
Beyond ISO clause 6: the rest of the series
Clauses 4 to 10 are the harmonized structure shared by most ISO management system standards. Each guide in this series covers one clause across every standard that uses it.
- Clause 4: Context of the Organization
- Clause 5: Leadership
- Clause 6: Planning — you are here
- Clause 7: Support
- Clause 8: Operation
- Clause 9: Performance Evaluation
- Clause 10: Improvement