Register / MIQ-ART-006

Risk-Based Thinking Without the Buzzwords: What Clause 6.1 Actually Asks For

ISO 9001 killed preventive action and replaced it with risk-based thinking, then explained it badly. Here's what clause 6.1 actually requires, what auditors accept as evidence, and why a risk register nobody reads fails on both counts.

Document No.
MIQ-ART-006
Revision
A
Effective Date
Jun 29, 2026
Category
Risk
Prepared By
My ISO Consultants

When ISO 9001:2015 landed, it deleted the standalone preventive action clause and scattered something called “risk-based thinking” across the whole standard. A decade on, it’s still the requirement quality managers are least sure they’re meeting, mostly because the standard tells you to do it without telling you what doing it looks like.

Here’s the working version, from the side of the table where we sit as auditors.

What the clause actually says

Clause 6.1 requires you to determine the risks and opportunities that need to be addressed so the QMS can achieve its intended results, prevent undesired effects, and improve. Then it requires you to plan actions to address them, integrate those actions into your processes, and evaluate whether they worked.

Notice what it does not say. It doesn’t say “risk register.” It doesn’t say “5×5 matrix.” It doesn’t require FMEA, a risk management procedure, or a documented risk methodology. Annex A.4 states this outright: there’s no requirement for formal risk management methods or a documented risk management process.

That freedom is the trap. Teams either import a heavyweight framework built for aerospace, or they write nothing down and hope the auditor accepts “it’s how we think.”

The two failure modes

The ornamental register. A spreadsheet with forty risks, scored red-amber-green during a workshop three years ago, untouched since. Every row says “mitigation: training and monitoring.” When we audit these, one question collapses them: show me a decision this register changed. Silence. A risk register that never altered a plan, a control, or a priority isn’t risk-based thinking; it’s risk-based typing.

The invisible instinct. The opposite claim: “we manage risk in our heads, it’s baked into how we work.” Sometimes genuinely true. But clause 6.1 actions have to be planned, integrated into QMS processes, and evaluated for effectiveness, and clause 9.3 requires management review to consider the effectiveness of actions taken on risks. You cannot review the effectiveness of something that exists only as instinct. There has to be a trace.

What auditors actually accept

Evidence of risk-based thinking is rarely a document titled “risk.” It’s risk showing up inside the decisions the QMS already makes:

  • Supplier controls scaled by consequence. Your one-source machined-casting supplier gets audited and dual-sourced; the supplier of shop rags gets a PO. That asymmetry is clause 6.1, applied through clause 8.4.
  • Audit programs weighted by history. Clause 9.2 says the program must consider the importance of processes and results of previous audits. Auditing the process that generated last quarter’s NCR spike twice as often is risk-based thinking with a paper trail.
  • CAPA triggers with thresholds. Deciding which nonconformances escalate to root-cause investigation based on severity, recurrence, and customer impact is a risk evaluation, and the criteria are the evidence.
  • Change reviews that ask “what could this break.” A one-paragraph risk note on an engineering change beats a forty-row register nobody opens.

The common thread: the risk assessment lives where the decision lives, and you can point to the decision it changed.

Keep the register, shrink it

None of this means registers are bad. A short one is genuinely useful: the eight to fifteen risks that could actually prevent your QMS from delivering conforming product, each with an owner, a current action, and a date it was last looked at. What kills registers is volume and orphanhood. If a risk has no owner and no action, it’s not being addressed; it’s being displayed.

The test we apply, and the one worth applying to yourself before your next audit: pick any risk you claim to be managing and walk the chain. Where was it identified? What action did it produce? Where did that action land in a real process? And when management review last met, did anyone check whether it worked? If the chain holds for your top five risks, clause 6.1 is not your problem, whatever your register looks like.

Where the tooling matters

The chain is the hard part, and it’s a linkage problem, which is exactly where spreadsheets quietly fail, the same way they fail the NCR-to-CAPA connection. A risk that lives in one file, an action that lives in a task list, and an effectiveness check that lives in someone’s calendar will drift apart within a quarter. When the risk, the action it spawned, the process it landed in, and the review that evaluated it are linked records in one system, the evidence assembles itself, and the auditor’s walk-the-chain question takes ninety seconds instead of a scramble.

Risk-based thinking was never meant to be a new department. It’s the standard asking a fair question: do your decisions show that you saw trouble coming? Answer that with linked, living records and you’ve met the clause. Answer it with a heat map from 2023 and you haven’t, no matter how red the corner cells are.

MIQ-ART-006 · Rev A · 4 min read · Uncontrolled when printed← Back to the Register

Reading About It Is the Slow Way.

Request early access and a consultant will walk you through the system live, on your processes, not canned demo data.

Request Early Access