ISO 9001 risks and opportunities changed shape in September 2026. For eleven years, clause 6.1.2 of ISO 9001:2015 dealt with both in a single sentence, and most organizations kept them in a single register where the “opportunity” column was rarely filled in. ISO 9001:2026 splits the requirement: 6.1.2 covers actions to address risks, 6.1.3 covers actions to address opportunities, and each has its own determine–analyze–evaluate–act cycle. Clauses 9.1.3 and 9.3.2 then ask for the effectiveness of the two sets of actions separately. This guide explains the mechanics and what to change in an existing register.
For the other changes in the sixth edition, see ISO 9001:2026 changes. For the standard as a whole, start with our complete ISO 9001 guide; the requirements themselves are in ISO 9001:2026 on iso.org.
What this guide covers
- ISO 9001 risks and opportunities: 2015 versus 2026
- Step one: determining ISO 9001 risks and opportunities (6.1.1)
- Step two of ISO 9001 risks and opportunities: risks (6.1.2)
- Step three of ISO 9001 risks and opportunities: opportunities (6.1.3)
- Why one register no longer evidences ISO 9001 risks and opportunities
- Effectiveness, analysis and management review
- Updating an existing ISO 9001 risks and opportunities register for 2026
- Frequently asked questions about ISO 9001 risks and opportunities

ISO 9001 risks and opportunities: 2015 versus 2026
| Element | ISO 9001:2015 | ISO 9001:2026 |
|---|---|---|
| Determination | 6.1.1 — determine risks and opportunities from the context (4.1) and interested-party (4.2) work, for four purposes | 6.1.1 — same four purposes, reordered |
| Actions | 6.1.2 — plan actions to address risks and opportunities, integrate them, evaluate effectiveness; actions proportionate to potential impact | 6.1.2 risks: determine, analyze and evaluate; plan actions; integrate; evaluate effectiveness; proportionate to potential impact 6.1.3 opportunities: determine, analyze and evaluate; plan actions; integrate; evaluate effectiveness; appropriate to context |
| Disruption | Not mentioned | Note to 6.1.2: risks can include the ability to provide conforming products and services during and after a disruption |
| Example opportunity actions | Note lists adopting new practices, launching new products, opening new markets, new customers, partnerships, new technology | Note lists adopting new practices, launching new products or services, creating partnerships, leveraging emerging technologies, implementing initiatives |
| Analysis and evaluation | 9.1.3 e) — effectiveness of actions to address risks and opportunities, one item | 9.1.3 e) risks and f) opportunities — two items |
| Management review | 9.3.2 e) — one input | 9.3.2 g) risks and h) opportunities — two inputs |
| Leadership | 5.1.1 — promote risk-based thinking | 5.1.1 — promote risk-based thinking and opportunity-based thinking |
The pattern for ISO 9001 risks and opportunities is consistent from planning through review: the 2026 edition wants to be able to see opportunities being handled as opportunities, not as the optimistic column of a risk assessment.
Step one: determining ISO 9001 risks and opportunities (6.1.1)
Determination is unchanged in substance. When planning the QMS you consider the external and internal issues from 4.1 and the interested-party requirements from 4.2, and determine the risks and opportunities to be addressed for four purposes: assurance that the QMS can achieve its intended results; preventing or reducing undesired effects; achieving continual improvement; and enhancing desired effects. In practice the most reliable way to run this is a facilitated review that asks, for every issue in the context register and every process on the process map, what could stop this delivering (a risk) and what could make it deliver more (an opportunity). One issue often produces both — a new technology threatens current capability and offers a new service — and is recorded in both places.
A topic the 2026 edition names explicitly is disruption: the note to 6.1.2 says risks can include the ability to provide conforming products and services during and after a disruption. Site loss, supplier failure, cyber incident and climate events belong in the risk register, and the contingency information the organization gives customers under 8.2.1 e) is derived from them.
Step two of ISO 9001 risks and opportunities: risks (6.1.2)
For each risk the organization determines, analyzes and evaluates it, then plans the action, how the action is integrated into QMS processes and how its effectiveness will be evaluated. The one word that matters most is proportionate: actions must be proportionate to the potential impact of the risk on the intended results of the QMS. A high-impact risk warrants a control built into the process; a low-impact risk warrants monitoring. The note in 6.1.2 lists the options — avoiding the risk, taking a risk to pursue an opportunity, eliminating the source, changing the likelihood or consequences, sharing the risk, or retaining it by informed decision.
A usable risk register therefore carries, per row: source, description, effect on conformity or customer satisfaction, existing controls, likelihood and impact scores, the evaluation against acceptance criteria, the planned action and its option, owner and due date, the integration reference (which procedure, control or indicator changed), a one-line proportionality note, and the effectiveness result. The proportionality note is what an auditor reads to see that the judgment was made rather than defaulted.
Step three of ISO 9001 risks and opportunities: opportunities (6.1.3)
Opportunities run the same cycle but on different criteria. A risk is scored on likelihood and impact; an opportunity is scored on the value it would realize and how achievable it is with the organization’s resources. Actions must be appropriate to the organization’s context and support the achievement of desired results — which means an opportunity that would need resources the organization cannot obtain, or that cuts against its strategic direction, is legitimately recorded as evaluated and not pursued. That record is itself evidence.
The effectiveness measure for an opportunity action is usually a quality objective: the opportunity to raise first-pass yield through a new inspection method becomes an objective with a target and a date, and the objective’s result is the effectiveness result. Opportunity actions that produce no measurable desired effect within the planned period are re-planned or closed, not left open indefinitely.
Why one register no longer evidences ISO 9001 risks and opportunities
Nothing in the standard prescribes a register, let alone two. What it prescribes is a chain of evidence: opportunities determined, analyzed and evaluated in their own right; actions appropriate to context; effectiveness evaluated (9.1.3 f) and reviewed (9.3.2 h) separately from the risk equivalents. A single risks-and-opportunities register can in principle carry all of that. In practice it almost never does, because a likelihood-and-impact scale makes no sense for an opportunity, the “opportunity” column is a free-text afterthought, and the management-review pack reports one blended effectiveness figure. Two registers with their own criteria is the straightforward fix; a single workbook with two clearly separated sheets is the same thing.
Effectiveness, analysis and management review
ISO 9001 risks and opportunities are only half handled when the action is planned. Every action — risk or opportunity — carries a measure and an evaluation date set when it is planned. At the due date, and again at the next quarterly review, the owner records whether the action was effective against that measure. Those results feed two separate evaluations under 9.1.3, e) for risks and f) for opportunities, and two separate management-review inputs under 9.3.2, g) and h). Presenting them as a single line (“risk and opportunity actions 80% effective”) is the most common way a transitioned system still fails the 2026 wording. Report them apart: how many risk actions were evaluated and how many worked, how many risks materialized; how many opportunity actions were evaluated, how many delivered their desired effect, and what benefit was realized.
Updating an existing ISO 9001 risks and opportunities register for 2026
- Split the current register into a risk register and an opportunity register, or into two clearly separated sheets.
- Give the opportunity register its own scoring — value if realized and achievability — and a pursue / park / not-pursued decision with a reason.
- Re-determine the opportunities. Most inherited rows were written as risks with the sign flipped; ask the 6.1.1 question directly: what could make this process deliver more, or what is working well that could be extended?
- Add the proportionality note to every risk action and the appropriateness note to every opportunity action.
- Add an effectiveness measure, date and result to every action, and make the two effectiveness summaries separate items on the management-review agenda.
- Add disruption as a standing risk topic and link it to the contingency information given to customers.
- Re-point any procedure that cites “6.1.2” for opportunities to 6.1.3.
The ISO 9001 Toolkit — 84 templates rebuilt on the 2026 text, $99 — ships the risk register and the opportunity register as separate workbooks with their own criteria sheets, proportionality and appropriateness columns and effectiveness summaries, plus the procedure that runs the two cycles and the management-review agenda with g) and h) as separate items. See also our guides to the ISO 9001:2026 transition and to risk appetite, which is how the acceptance thresholds in step two are set.
Frequently asked questions about ISO 9001 risks and opportunities
Does ISO 9001:2026 require a formal risk management process or ISO 31000?
No. ISO 9001 has never required a formal risk management methodology and the 2026 edition does not add one. It requires risks and opportunities to be determined, analyzed, evaluated and acted on proportionately; how formally you do that is your choice. ISO 31000 is useful guidance if you want a structured method.
Are two ISO 9001 risks and opportunities registers mandatory?
No register is mandatory. What is mandatory is evidence that opportunities are analyzed, actioned and evaluated in their own right and that their effectiveness is reviewed separately from risks. Two registers are the simplest way to produce that evidence.
What does “proportionate to the potential impact” mean in an audit?
That the effort and cost of a risk action match the potential effect of the risk on the intended results of the QMS. Auditors look for the reasoning, not a formula: a one-line note per action showing why a control was built in for a high-impact risk and why monitoring was enough for a low-impact one.
How often should ISO 9001 risks and opportunities be reviewed?
The standard says “when planning” and, through 9.1.3 and 9.3.2, at analysis and management review. A quarterly review with re-determination at the annual context review, plus event-driven updates after a nonconformity, a change or a disruption, is a workable rhythm for most organizations.
Where do nonconformities fit?
Clause 10.2.1 requires the organization to update the risks and opportunities determined during planning, if necessary, after a nonconformity. Every corrective action record should say whether the event revealed a risk not in the register, a wrongly evaluated one, or an opportunity.