<br />
<b>Deprecated</b>:  Non-canonical cast (double) is deprecated, use the (float) cast instead in <b>/var/www/aec.llc/html/blog/wp-content/plugins/wordfence/vendor/wordfence/wf-waf/src/lib/xmlrpc.php</b> on line <b>216</b><br />
<br />
<b>Deprecated</b>:  Non-canonical cast (boolean) is deprecated, use the (bool) cast instead in <b>/var/www/aec.llc/html/blog/wp-content/plugins/wordfence/vendor/wordfence/wf-waf/src/lib/xmlrpc.php</b> on line <b>235</b><br />
<br />
<b>Deprecated</b>:  Non-canonical cast (double) is deprecated, use the (float) cast instead in <b>/var/www/aec.llc/html/blog/wp-content/plugins/wordfence/lib/wfConfig.php</b> on line <b>2096</b><br />
<br />
<b>Deprecated</b>:  Non-canonical cast (binary) is deprecated, use the (string) cast instead in <b>/var/www/aec.llc/html/blog/wp-content/plugins/wordfence/lib/wfMD5BloomFilter.php</b> on line <b>79</b><br />
{"id":99,"date":"2026-04-04T03:19:09","date_gmt":"2026-04-04T03:19:09","guid":{"rendered":"https:\/\/aec.llc\/blog\/?p=99"},"modified":"2026-04-04T03:19:10","modified_gmt":"2026-04-04T03:19:10","slug":"iso-9001-clause-6-1-risk-register","status":"publish","type":"post","link":"https:\/\/aec.llc\/blog\/iso-9001-clause-6-1-risk-register\/","title":{"rendered":"Your Risk Register Doesn&#8217;t Satisfy ISO 9001 Clause 6.1 \u2014 Here&#8217;s What Does"},"content":{"rendered":"\n<p>Most ISO 9001-certified organisations have a risk register. A spreadsheet listing risks by category, scored for likelihood and impact, with a response column that reads &#8220;monitor&#8221; or &#8220;mitigate.&#8221; It was built during implementation, updated before management review, and presented to auditors as evidence of risk-based thinking.<\/p>\n\n\n\n<p>It satisfies none of the ISO 9001 Clause 6.1 requirements it&#8217;s supposed to address.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What ISO 9001 Clause 6.1 Actually Requires<\/h2>\n\n\n\n<p>ISO 9001:2015 Clause 6.1.2 requires organisations to plan actions to address risks and opportunities \u2014 then integrate those actions into QMS processes and evaluate their effectiveness. The clause does not require a risk register. It does not require a risk matrix. It requires that identified risks produce observable downstream effects in how the organisation plans and controls its work.<\/p>\n\n\n\n<p>The operative word is &#8220;integrate.&#8221; Clause 8.1 makes the connection explicit: organisations must plan, implement, and control processes needed to implement the actions determined in Clause 6. That cross-reference is not editorial \u2014 it is the mechanism by which risk planning outputs must reach operational controls.<\/p>\n\n\n\n<p>Clause 6.2 closes the loop on the other side. Quality objectives must respond to the organisation&#8217;s context, and the planning to achieve them must specify what will be done, by whom, and how results will be evaluated. A high-rated supply chain risk identified in <a href=\"https:\/\/aec.llc\/blog\/iso-9001-clause-4-transition-risk\/\">ISO 9001 Clause 6.1<\/a> that produces no corresponding supply chain resilience objective under Clause 6.2 is a risk entry with no operational consequence.<\/p>\n\n\n\n<p>The standard&#8217;s architecture is a chain: 6.1 identifies \u2192 6.2 sets objectives \u2192 8.1 implements controls. Break any link and the register becomes a standalone document that satisfies none of them.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_00-PM-1024x683.png\" alt=\"Auditor tracing risk register entry with no downstream process control change\" class=\"wp-image-103\" srcset=\"https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_00-PM-1024x683.png 1024w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_00-PM-300x200.png 300w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_00-PM-768x512.png 768w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_00-PM-600x400.png 600w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_00-PM.png 1536w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Where Organisations Fail the Integration Test<\/h2>\n\n\n\n<p>The failure mode is consistent enough to have a name among auditors: the document artifact.<\/p>\n\n\n\n<p>An auditor picks a high-rated entry from the risk register and traces it forward. Where did this risk produce a change? Which work instruction was modified? Which acceptance criterion was tightened? Which Clause 6.2 objective was set in response?<\/p>\n\n\n\n<p>The quality manager retrieves the register, points to the action column \u2014 &#8220;monitor quarterly&#8221; \u2014 and cannot identify a single process document that changed because of that entry. The risk was identified, scored, and filed. The process ran unchanged beside it.<\/p>\n\n\n\n<p>Opportunities fare worse. In most registers, they occupy a compliance column alongside risks. Someone needed to fill the field because the standard says &#8220;risks and opportunities.&#8221; That was the entire rationale. No owner. No completion date. No linkage to improvement planning. Auditor Training Online documents this as a recurring nonconformity pattern: risk logs that are generic, disconnected from Clause 4.1 context analysis and Clause 4.2 interested party requirements.<\/p>\n\n\n\n<p>The auditor&#8217;s integration test, as NovelVista frames it: risks must be reflected in quality objectives, operational controls, supplier evaluation processes, and change management practices. A register that feeds none of these is not evidence of ISO 9001 Clause 6.1 conformance \u2014 regardless of how carefully it scores likelihood and impact.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_02-PM-1024x683.png\" alt=\"Diagram showing ISO 9001 clause 6.1 to 6.2 to 8.1 integration chain for risk-based planning\" class=\"wp-image-102\" srcset=\"https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_02-PM-1024x683.png 1024w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_02-PM-300x200.png 300w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_02-PM-768x512.png 768w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_02-PM-600x400.png 600w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_02-PM.png 1536w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">What Changes Under ISO DIS 9001:2025<\/h2>\n\n\n\n<p>The draft standard targets this pattern structurally. ISO DIS 9001:2025 splits the current Clause 6.1.2 into two independent requirements: Clause 6.1.2 for actions to address risks, and a new Clause 6.1.3 for actions to address opportunities. Both are classified as Major changes by Advisera&#8217;s clause-by-clause analysis.<\/p>\n\n\n\n<p>This is not a wording refinement. It is a structural separation that makes it procedurally impossible to satisfy both requirements through a single undifferentiated register. Opportunities will require their own identification process, their own analysis, their own planned actions, and their own effectiveness evaluation \u2014 a standalone process obligation, not a column header.<\/p>\n\n\n\n<p>The DIS also raises the evidentiary standard. Organisations must &#8220;analyse and evaluate&#8221; risks and opportunities \u2014 not merely identify them. SGS transition guidance confirms the risk\/opportunity split as a top action item, advising organisations to revisit how risks and opportunities are distinguished and addressed in planning. That revisit is not cosmetic.<\/p>\n\n\n\n<p>Notably, Clause 8.1 receives only an editorial change classification in the DIS. The operational planning linkage requirement does not change. The failure mode is entirely owned by current practice \u2014 meaning organisations cannot wait for the new edition to fix it. The gap exists now, under ISO 9001:2015, and auditors are already testing for it.<\/p>\n\n\n\n<p>\u26a0\ufe0f <em>ISO DIS 9001:2025 content is draft and subject to change before final publication, currently targeted for Q3\u2013Q4 2026.<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_09-PM-1024x683.png\" alt=\"ISO DIS 9001 2025 structural split of clause 6.1.2 risks and 6.1.3 opportunities\" class=\"wp-image-101\" srcset=\"https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_09-PM-1024x683.png 1024w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_09-PM-300x200.png 300w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_09-PM-768x512.png 768w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_09-PM-600x400.png 600w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_09-PM.png 1536w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">The Audit Traceability Gap No Guidance Resolves<\/h2>\n\n\n\n<p>No IAF guidance document, UKAS technical note, or major CB publication defines what constitutes sufficient traceability between Clause 6.1 risk\/opportunity outputs and Clause 8.1 operational planning inputs. The mechanism by which a risk register entry must connect to a process control change is not specified in any T1 audit checklist identified.<\/p>\n\n\n\n<p>This silence matters practically. It means the sufficiency of your integration evidence is assessed by individual auditors against their interpretation of the clause chain. Some auditors will accept a narrative in the management review minutes. Others will require cross-referenced process documentation. The absence of a defined minimum creates audit variability \u2014 and that variability falls on the organisation to manage by building traceability that satisfies the strictest reasonable interpretation.<\/p>\n\n\n\n<p>This gap is not unique to ISO 9001. The Annex SL harmonised structure shares the same 6.1\u21928.1 architecture across <a href=\"https:\/\/aec.llc\/blog\/iso-14001-legal-register\/\">ISO 14001:2015<\/a> and <a href=\"https:\/\/aec.llc\/blog\/iso-45001-hazard-identification-scope-gap\/\">ISO 45001:2018<\/a>. Organisations running an integrated management system face the identical linkage problem three times, with no standard-specific guidance resolving it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Practical Steps to Close the ISO 9001 Clause 6.1 Gap<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Audit the chain, not the register.<\/strong> For every risk entry rated medium or above, trace it forward to a specific Clause 8.1 process control. If no process document, work instruction, or controlled condition reflects the risk response \u2014 the entry is unimplemented regardless of its register status. Document the gap and initiate a Clause 6.3 change plan. A structured <a href=\"https:\/\/aec.llc\/consulting-pages\/gap-assessment.html\">gap assessment<\/a> against the clause chain \u2014 not just the register \u2014 is the most effective starting point.<\/li>\n\n\n\n<li><strong>Separate opportunities now.<\/strong> Extract every opportunity entry from the risk register into a dedicated opportunity log. Assign an owner, a planned action, a linkage to a Clause 6.2 objective or improvement initiative, and a review date. An opportunity with no owner and no action does not conform now \u2014 and the DIS will make that gap structurally visible.<\/li>\n\n\n\n<li><strong>Build the cross-reference.<\/strong> Create a traceability document that maps each risk\/opportunity to the objective it affected or the process control it changed. Where no change was required, document the rationale. This table \u2014 risk\/opportunity \u2192 objective or process control affected \u2192 evidence reference \u2014 is the primary audit-defensible integration artefact for Clauses 6.1, 6.2, and 8.1.<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_12-PM-1024x683.png\" alt=\"ISO 9001 clause 6.1\" class=\"wp-image-100\" srcset=\"https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_12-PM-1024x683.png 1024w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_12-PM-300x200.png 300w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_12-PM-768x512.png 768w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_12-PM-600x400.png 600w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-08_07_12-PM.png 1536w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Key Takeaway<\/h2>\n\n\n\n<p>A risk register that lists risks without changing anything downstream is the most common ISO 9001 Clause 6.1 conformance failure \u2014 and most organisations don&#8217;t know they have it because the register itself looks complete. The conformance test is not whether you documented risks. It is whether those risks produced observable changes to process controls and quality objectives. ISO DIS 9001:2025 will make this gap structurally visible. Separate, affirmative responses to risks and to opportunities \u2014 not a merged register column. The preparation work is not a future task \u2014 the integration gap exists under the current edition, and closing it now is both a conformance fix and a transition head start.<\/p>\n\n\n\n<p><em>Clause references reflect mapped standard requirements. Verify against current edition before audit use.<\/em><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>About AEC International<\/strong><\/p>\n\n\n\n<p>AEC International provides <a href=\"https:\/\/aec.llc\/certifications\/quality-and-sector-qms\/iso-9001.html\">ISO 9001 certification<\/a>, <a href=\"https:\/\/aec.llc\/training-pages\/training-iso-9001.html\">training<\/a>, and consultancy services at the intersection of quality management, risk integration, and management system transition. We support organisations across industries in achieving and maintaining ISO certification \u2014 from gap analysis and implementation through audit preparation and continual improvement.<\/p>\n\n\n\n<p>Learn more: www.aec.llc<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Most ISO 9001 risk registers list risks without changing anything downstream. Clause 6.1 conformance requires traceable integration into process controls and quality objectives \u2014 a gap ISO DIS 9001:2025 will make structurally visible.<\/p>\n","protected":false},"author":1,"featured_media":104,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[37,36,16,13,15,12],"class_list":["post-99","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-audit-preparation","tag-annex-sl","tag-corrective-action","tag-gap-analysis","tag-internal-audit","tag-iso-9001","tag-risk-management"],"reading_time":"6 min read","_links":{"self":[{"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/posts\/99","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/comments?post=99"}],"version-history":[{"count":2,"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/posts\/99\/revisions"}],"predecessor-version":[{"id":106,"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/posts\/99\/revisions\/106"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/media\/104"}],"wp:attachment":[{"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/media?parent=99"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/categories?post=99"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/tags?post=99"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}