ISO 9001 · Clause 6 · 6.1
Risks and opportunities
In plain words
This clause asks for a single habit of thought: look ahead deliberately before you plan. What could stop us from delivering what our customers expect? What could help us get better? And what, concretely, will we do about either?
What the standard does not ask for matters just as much: no risk-management system, no prescribed method, no risk matrix, not even necessarily a document. What is required is that you determine risks and opportunities, plan actions, build them into your processes, and later check whether they worked. The effort may — and should — stay in proportion to the possible impact.
For a small company this means: you almost certainly do this already — at the annual planning session, at the investment decision, when you look at the order book. The clause only asks that this forward thinking becomes traceable, so it no longer depends on chance or on one person.
Why this requirement exists
Earlier editions of the standard had “preventive action” as its own chapter — in practice it usually became a form nobody used. The 2015 edition turned it into a posture instead: risk-based thinking belongs inside planning itself, not in an annex. A quality management system should prevent problems, not administer them.
The clause is also the hinge of the whole planning chapter: from your context (clause 4.1) and the expectations of your interested parties (4.2) follow the risks and opportunities — and from how you address them follow your quality objectives (6.2). Skip 6.1, and you are setting objectives blind.
What good looks like
In a company of 12 people the good result is one page, not a binder: five to ten real, business-specific risks and two or three real opportunities — worked out in the leadership circle, for example during annual planning. Three entries per line: What would the impact be? What are we doing about it? Who owns it, by when?
Good means above all: the list lives. It comes back out at the management review (“Did the actions work?”) and gets updated on real occasions — a new key customer, the departure of a key person, a new machine, a new offering. Its actions flow into your objectives and your task list, not into a separate paper universe.
What changes as you grow: From around 50 people, each process owner sensibly assesses the risks of their own process, and a simple rating scale (likelihood × impact) helps with prioritising. From 100–250 people, formal methods join in where customers or the industry demand them — an FMEA (a systematic failure analysis) in product development, say — and the list gets a fixed maintenance cycle. The core stays the same at every size: few real risks, clear actions, honest follow-up.
The minimum to pass
The floor below which an audit gets difficult:
- A traceable, current overview of the most important risks and opportunities — the form is free: a section in the context or strategy document, a table in the management review, or a short standalone document.
- For each entry, visibly: what we do, who does it, by when.
- A recognisable connection to your context and objectives — the risks fit your business, not just any business.
- Evidence that effectiveness was evaluated — most naturally as a standing item of the management review.
What an auditor asks for
- The overview itself, with a visible date — and visibly maintained compared to last year.
- The management-review minutes in which risks, opportunities and the effectiveness of the actions were actually discussed.
- Two or three concrete actions with a status — planned, implemented, effective.
- In conversation: do the managing director and the team know the biggest risks of their area without looking them up?
- One example where a recognised risk actually led to something — the strongest evidence that the thinking is lived, not just documented.
Common traps
- The 40-page FMEA with no trigger. The most over-fulfilled clause of the standard: a small company buys itself a method built for series development and never maintains it again. The standard demands no method — it demands thinking with consequences.
- Template boilerplate risks. Fire, earthquake, pandemic — copied in, they look reassuringly complete and say nothing about your business. The cluster customer, the knowledge monopoly, the single qualified supplier: those are the entries that count.
- Only threats, no opportunities. The clause explicitly says risks and opportunities. A list without a single positive entry is half-thought.
- The dead register. Created once, never touched again. A short, living sheet beats the perfect dead register — in the audit and in the business.
- Software first. Buying the tool before thinking about what belongs in it. It works the other way round.
- Confusing it with the workplace hazard assessment. Assessing workplace hazards is occupational-safety law — a separate obligation with its own rules. Clause 6.1 means business risks to quality and customer satisfaction; one does not replace the other.
Worked example
Berger Präzisionsteile GmbH — 12 people, CNC turned and milled parts for medical technology and machine building — sits down for 90 minutes at annual planning: managing director, production manager, quality assurance. The result is a table with seven rows; four of them:
| Risk / opportunity | Impact | Action | Who, by when |
|---|---|---|---|
| Main customer is 45% of revenue | Price pressure; existential if they leave | Lift new-customer share to 20%: trade fair, grow the medical segment | Managing director, Q4 |
| Only one person knows the 5-axis programs | Standstill if they are out | Train a second person; document setup and program sheets | Production manager, June |
| Single hardening shop as partner | Delivery dates slip when they are at capacity | Qualify a second supplier | Purchasing, September |
| Customer asks about assembly work (opportunity) | New leg to stand on, better margin | Pilot order with an existing customer | Managing director, August |
The table lives inside the management review in the QMS. A year later the same table shows: second person trained (done), cluster risk down from 45% to 38% (working, continue), hardening alternative qualified (done) — and one new entry has appeared: the shortage of skilled machinists. Exactly this movement — done, working, new — is the evidence an auditor wants to see.
<!-- easo:worked_example profile=service -->
For contrast, Klarwerk GmbH, an IT service provider with 8 people: there the biggest entries read “our only certified cloud engineer resigns”, “an outage at the platform partner hits all customers at once” and “the largest contract is re-tendered every year”. As an opportunity: “customers keep asking about security checks — turn that into an offering”. Different industry, different entries — the movement of thought is exactly the same.
How easo covers it
Clause 6.1 requires no mandatory document — which is why it does not count in easo’s readiness denominator: your readiness stays honest and is never padded with paper the standard does not ask for.
- In the management review, the assistant carries the effectiveness of actions on risks and opportunities as a fixed point of the walkthrough — forgetting it is impossible.
- You capture actions there as trackable tasks (what, who, by when); easo collects them across all documents in the open task list.
- The risks overview itself is easiest kept as a section of your context or strategy document, or directly in the management review — released, versioned and signed like every controlled document.
Stay in the loop
easo is available for macOS — the Windows version is coming soon. Leave us a note and we'll reach out the moment it lands.