ISO 9001:2026 Risks and Opportunities: What Changed and How to Transition New

ISO 9001 Clause 6.1 — transition guidance

ⓘ Working draft — ISO 9001:2026 is expected in September 2026 but is not yet published. Clause-level statements on this page reflect the ISO/FDIS 9001 text and CBG's independent analysis, and will be reviewed once ISO releases the final edition.

ISO 9001:2015 introduced risk-based thinking. The 2026 revision doesn't replace it — it makes the two management responses harder to blur together: protecting what you already have, and deliberately pursuing what could make it better.

Download the free Clause 6.1 guide (PDF) New to the 2026 changes? Start with the Change Guide →

ISO 9001:2026 risks and opportunities — Clause 6.1 transition guide
The short answer

Clause 6.1 gets clearer structure, not a new risk-management system

ISO 9001:2015 addressed risks and opportunities together, in one short clause. In practice, many organizations read it mainly as “keep a risk register,” and opportunities often ended up buried inside it, treated as low-priority, or skipped. The 2026 revision gives the subject clearer structure.

6.1.1 · 6.1.2

Determine and address risks

Identify, analyze and evaluate risks that could undesirably affect your ability to consistently deliver conforming products and services — then plan, integrate and evaluate the actions you take.

6.1.1 · 6.1.3

Determine and address opportunities

Identify favorable circumstances that could desirably affect that same ability — then apply the same discipline: plan, integrate and evaluate, for the opportunities worth pursuing.

For an organization already conforming to ISO 9001:2015, the real transition question isn't “do we need a second risk-management system?” It's whether your existing planning process gives both sides deliberate, proportionate, traceable treatment — and whether you can show the resulting actions actually got integrated into the QMS and evaluated for effectiveness.

What changed

ISO 9001:2015 vs. the 2026 direction

Based on ISO/FDIS 9001 text currently in the final pre-publication stage. Reconcile clause-level wording against the published standard once it is released.

Topic ISO 9001:2015 ISO 9001:2026 direction Transition significance
Clause structure Risks and opportunities addressed together in 6.1.1 and 6.1.2 Determination stays together in 6.1.1; action-planning splits into 6.1.2 (risk) and 6.1.3 (opportunity) Moderate documentation change; potentially significant practice change where opportunities were neglected
Risks Shared the same planning text as opportunities Own action-planning sub-clause and risk-specific notes Review whether responses are proportionate and connected to QMS processes
Opportunities Required, but easy to bury inside a risk-focused process Dedicated sub-clause and examples Need a visible, repeatable way to select and pursue worthwhile opportunities
Continual improvement Clause 6.1 referred to achieving improvement Structure reinforces continual improvement Link opportunity planning to improvement, not a brainstorming list
Guidance Limited explanation in Clause 6.1 / Annex A Expanded guidance on risk-based thinking and the risk/opportunity distinction Update training, internal-audit criteria and implementation guidance
Context inputs Internal/external issues and interested-party requirements already fed planning Same chain, with the 2024 climate-change amendment folded in Confirm whether climate change is relevant to your QMS — don't automatically invent a climate risk
What has not changed

Don't overbuild the QMS on the back of this revision

A few points are worth stating plainly, because they're the most common way organizations over-engineer a Clause 6.1 response.

Why the separation matters

A list is not a plan

The practical weakness in many 2015-era systems was never a failure to identify risks — it was a failure to carry the significant ones through ownership, action, process integration and effectiveness review. The clearer 2026 structure gives auditors, and organizations, a sharper trail to follow:

  1. What relevant risk or opportunity was determined?
  2. Why did it need addressing?
  3. What action was selected?
  4. Where was it integrated into a QMS process?
  5. Who owns it, and when is it reviewed?
  6. How was effectiveness evaluated?

Opportunities, in particular, now need their own management attention. Useful evidence includes selected improvement initiatives, quality objectives, process-change plans, technology evaluations, supplier-development activity, lessons-learned actions, or approved business cases — not chasing every good idea, but showing a credible route from favorable circumstance to decision, planned action and evaluation.

The CBG interpretation

Protect intended results. Create better ones.

A risk concerns uncertainty that could adversely affect intended QMS results, product or service conformity, or customer satisfaction. An opportunity is a favorable circumstance that may help you improve those same results. Reducing a threat doesn't automatically capture an opportunity — qualifying a second supplier protects continuity; collaborating with that supplier to redesign a component is a different decision entirely.

“ISO 9001:2015 taught organizations to think about uncertainty. ISO 9001:2026 asks them to make the two management responses clearer: control what could prevent the QMS from succeeding, and deliberately pursue what could make it perform better.”
Centauri Business Group — editorial position on Clause 6.1

Seeing it by process

The same event, two different management decisions

Illustrative only — use these as a starting point for identifying your own risks and opportunities, not as a checklist to copy directly into your Risk List.

Supplier management

Protect (risk): Dependence on a single source for a critical material or component.

Create (opportunity): Developing a second qualified supplier jointly, improving reliability and cost together.

Design and development

Protect (risk): A regulatory or customer-specification change invalidating a current design assumption.

Create (opportunity): A new material, method or standard that lets a planned redesign cut cost or improve durability.

Competence and training

Protect (risk): Critical knowledge concentrated in one person nearing retirement or reassignment.

Create (opportunity): Cross-training that builds resilience and also enables more flexible scheduling.

Infrastructure

Protect (risk): Aging equipment or a single point of failure in a production or IT system.

Create (opportunity): A planned technology upgrade that also increases capacity or throughput.

Service delivery

Protect (risk): A seasonal or single-site bottleneck that threatens on-time delivery.

Create (opportunity): A process change that both reduces that exposure and shortens overall cycle time.

Customer communication

Protect (risk): Inconsistent communication of nonconformities or delays to affected customers.

Create (opportunity): Proactive, structured communication practices that increase satisfaction and repeat business.

Getting ready

Seven things to do before — and after — publication

Transition checklist

Twelve items to work through

Free download

Download

ISO 9001:2026 Risks and Opportunities — Clause 6.1 Transition Guide

A plain-language PDF you can keep and share: the 2015-vs-2026 comparison, what has and hasn't changed, the CBG interpretation, and the transition checklist from this page in one document.

FREE

Free Download — No Email Required
Present it internally

Need to brief your team or leadership?

Get the editable PowerPoint version of the transition guide — adapt it to your QMS, add your own notes, and present what's changing in Clause 6.1 and what to review first.

FAQ

Common questions

Does ISO 9001:2026 require separate risk and opportunity registers?
No. Separate views can improve clarity, but a combined register or system can still work as long as opportunities get genuine, visible attention rather than being an afterthought.
Do we need a risk matrix or a likelihood/severity scoring method?
No. That's a sound method for many organizations, not a universal requirement. The standard doesn't prescribe a scoring system or a specific treatment vocabulary.
Do we have to pursue every opportunity we identify?
No. You need to determine relevant opportunities and plan proportionate actions for the ones worth addressing — not chase every good idea.
Is climate change automatically a new risk we have to manage?
No. The required step is to determine whether climate change is relevant to your QMS and to consider any climate-related requirements from relevant interested parties — not to assume relevance by default.
Is Clause 6.1 being rewritten from scratch?
Not wholly. The most defensible way to describe it is clearer separation, stronger visibility for opportunities, and expanded guidance — with much of the underlying planning logic continuing from 2015.
What will internal auditors need to check differently?
Both sides of Clause 6.1: that significant risks were identified, treated, integrated and evaluated for effectiveness — and that opportunities were considered systematically, not only mentioned once at management review.
CBG risk resources

Which resource is actually right for you

These aren't competing risk products — they solve different problems. Start with whichever matches what you need right now.

See the revision in context

Free ISO 9001:2026 Change Guide New

The entry point for the full transition — every revised clause, not just 6.1. Start here if you haven't reviewed the whole standard yet.

View the Change Guide →
Implement and control the process

QPS 6.1-01 Actions to Address Risks Updated for 2026

An editable working procedure: roles, the four-phase framework, assessment, treatment and effectiveness evaluation. Currently focused on the risk side of Clause 6.1.

View Actions to Address Risks Procedure →
Build deeper capability

Methodical Manual — Risks and Opportunities

Detailed methods, risk matrices, treatment planning, monitoring and field-based examples covering both risk and opportunity.

View Risks & Opportunities Manual →
Get a concise reference

Risk Management in QMS Processes

A short, practical guide to what risk is, where it comes from, and how to identify, assess and treat it.

View Risk Management Guide →
Establish the overall framework

ISO 9001:2026 Quality Manual Template Updated for 2026

The system-level framework connecting context, process management, risk-based thinking and improvement.

View Quality Manual →
Source base

Sources

Status

Status of this page

ISO expects to publish ISO 9001:2026 in September 2026; an exact publication date has not been confirmed, and the standard remains in its final pre-publication stage. Clause-level statements on this page reflect ISO/FDIS 9001 text and CBG's independent analysis. This page will be reviewed and updated once ISO releases the final edition — see the full Change Guide for the broader transition picture. This summary is provided for educational purposes and is not a substitute for the applicable ISO publication.

All ISO Products