ISO 9001 · Clause 6 · 6.1

Risks and opportunities

In plain words

This clause asks for a single habit of thought: look ahead deliberately before you plan. What could stop us from delivering what our customers expect? What could help us get better? And what, concretely, will we do about either?

What the standard does not ask for matters just as much: no risk-management system, no prescribed method, no risk matrix, not even necessarily a document. What is required is that you determine risks and opportunities, plan actions, build them into your processes, and later check whether they worked. The effort may — and should — stay in proportion to the possible impact.

For a small company this means: you almost certainly do this already — at the annual planning session, at the investment decision, when you look at the order book. The clause only asks that this forward thinking becomes traceable, so it no longer depends on chance or on one person.

Why this requirement exists

Earlier editions of the standard had “preventive action” as its own chapter — in practice it usually became a form nobody used. The 2015 edition turned it into a posture instead: risk-based thinking belongs inside planning itself, not in an annex. A quality management system should prevent problems, not administer them.

The clause is also the hinge of the whole planning chapter: from your context (clause 4.1) and the expectations of your interested parties (4.2) follow the risks and opportunities — and from how you address them follow your quality objectives (6.2). Skip 6.1, and you are setting objectives blind.

What good looks like

In a company of 12 people the good result is one page, not a binder: five to ten real, business-specific risks and two or three real opportunities — worked out in the leadership circle, for example during annual planning. Three entries per line: What would the impact be? What are we doing about it? Who owns it, by when?

Good means above all: the list lives. It comes back out at the management review (“Did the actions work?”) and gets updated on real occasions — a new key customer, the departure of a key person, a new machine, a new offering. Its actions flow into your objectives and your task list, not into a separate paper universe.

What changes as you grow: From around 50 people, each process owner sensibly assesses the risks of their own process, and a simple rating scale (likelihood × impact) helps with prioritising. From 100–250 people, formal methods join in where customers or the industry demand them — an FMEA (a systematic failure analysis) in product development, say — and the list gets a fixed maintenance cycle. The core stays the same at every size: few real risks, clear actions, honest follow-up.

The minimum to pass

The floor below which an audit gets difficult:

What an auditor asks for

Common traps

Worked example

Berger Präzisionsteile GmbH — 12 people, CNC turned and milled parts for medical technology and machine building — sits down for 90 minutes at annual planning: managing director, production manager, quality assurance. The result is a table with seven rows; four of them:

Risk / opportunity Impact Action Who, by when
Main customer is 45% of revenue Price pressure; existential if they leave Lift new-customer share to 20%: trade fair, grow the medical segment Managing director, Q4
Only one person knows the 5-axis programs Standstill if they are out Train a second person; document setup and program sheets Production manager, June
Single hardening shop as partner Delivery dates slip when they are at capacity Qualify a second supplier Purchasing, September
Customer asks about assembly work (opportunity) New leg to stand on, better margin Pilot order with an existing customer Managing director, August

The table lives inside the management review in the QMS. A year later the same table shows: second person trained (done), cluster risk down from 45% to 38% (working, continue), hardening alternative qualified (done) — and one new entry has appeared: the shortage of skilled machinists. Exactly this movement — done, working, new — is the evidence an auditor wants to see.

<!-- easo:worked_example profile=service -->

For contrast, Klarwerk GmbH, an IT service provider with 8 people: there the biggest entries read “our only certified cloud engineer resigns”, “an outage at the platform partner hits all customers at once” and “the largest contract is re-tendered every year”. As an opportunity: “customers keep asking about security checks — turn that into an offering”. Different industry, different entries — the movement of thought is exactly the same.

How easo covers it

Clause 6.1 requires no mandatory document — which is why it does not count in easo’s readiness denominator: your readiness stays honest and is never padded with paper the standard does not ask for.

← All ISO 9001 topics · To the knowledge hub

Stay in the loop

easo is available for macOS — the Windows version is coming soon. Leave us a note and we'll reach out the moment it lands.

Notify me