In the world of international standards, "Risk-Based Thinking" (RBT) is the engine that drives a successful management system. Gone are the days when quality was merely about following a static checklist. In 2026, staying competitive means anticipating challenges before they occur and seizing opportunities before they pass.
What is Risk-Based Thinking (RBT)?
Risk-based thinking is a proactive approach that replaces the "Preventive Action" requirement found in older versions of ISO standards. Instead of waiting for a mistake to happen and then fixing it, RBT encourages an organisation to identify potential risks and opportunities at every stage of its processes.
ISO defines risk as the "effect of uncertainty on objectives". This means risk is not always negative. The primary ISO 9001 requirement for risk-based thinking sits in Clause 6.1. It requires organisations to determine the risks and opportunities that need to be addressed, plan actions to address them, integrate those actions into QMS processes, and evaluate their effectiveness. Importantly, Clause 6.1 does not mandate a specific format or tool. A formal risk register is not required by the standard , the approach should be proportionate to the size and complexity of your organisation.
While a risk might be a potential supplier failure, an opportunity might be the chance to adopt a new digital tool that increases efficiency.
What Changed from ISO 9001:2008
ISO 9001:2008 included a specific clause on preventive action (Clause 8.5.3). Organisations were required to take action to eliminate the causes of potential nonconformities.
In the 2015 revision, preventive action as a standalone clause was removed. Risk-based thinking replaced it with a broader scope: instead of a separate preventive action process, the expectation is that risk consideration is embedded into planning, process management, objectives, and management review throughout the QMS.
If your quality manual or procedures still reference "preventive action" as an ISO 9001 requirement without connecting it to risk-based thinking, they need updating.
Risk-Based Thinking Across ISO 9001, 27001, and 45001
While all modern ISO standards follow the Annex SL high-level structure, the way they apply risk-based thinking varies slightly to suit their specific focus.
ISO 9001 (Quality Management)
As the foundation for most businesses, ISO 9001 uses RBT to ensure consistent product and service quality. The upcoming ISO 9001:2026 revision takes this further by splitting Clause 6.1 into separate sub-clauses for risks and opportunities, ensuring that strategic growth opportunities receive the same rigorous management as operational threats.
ISO 27001 (Information Security)
For information security, the approach is more stringent. ISO 27001 requires a formalised risk assessment process, often aligned with the ISO 31000.
ISO 45001 (Health and Safety)
In health and safety, RBT focuses on hazard identification. The goal is to evaluate any potential source of harm to workers and implement controls to prevent accidents, focusing on both physical and psychological well-being.
Why Risk-Based Thinking Matters for Your Business
Implementing a robust RBT culture offers several strategic advantages:
Operational Resilience: You become better at anticipating supply chain disruptions or technological shifts.
Increased Efficiency: By focusing resources on high-risk areas, you avoid wasting time on low-impact issues.
Stakeholder Trust: Demonstrating a proactive mindset builds confidence with customers, investors, and regulators.
A Practical Walkthrough: The 5-Step Risk Register Process
To demonstrate risk-based thinking to an auditor, most SMEs use a Risk and Opportunities Register. Follow these five steps to build yours:
1. Establish the Context
Before identifying risks, you must understand your business environment. Use tools like a SWOT Analysis (Strengths, Weaknesses, Opportunities, Threats) to look at internal and external factors that could affect your objectives.
2. Identify Your Risks and Opportunities
For every core process (e.g., Sales, Production, HR), ask your team: "What could go wrong?" and "What could we do better?".
3. Analyse and Evaluate
Determine the significance of each identified item by scoring it based on:
Likelihood: How often is this expected to happen?
Impact: What would the consequence be if it did occur?
Multiply these scores to determine your Risk Factor. This allows you to prioritise which issues require immediate action.
A Simple Risk Register: Example for a Manufacturing SME
The table below shows what a completed risk register entry looks like for a small manufacturer. Note that the final row is an opportunity rather than a risk; ISO 9001 Clause 6.1 explicitly requires both risks and opportunities to be addressed, and including opportunities in the same register is the most practical approach.
Risk / opportunity | Likelihood (H/M/L) | Impact (H/M/L) | Response | Action and owner |
|---|---|---|---|---|
Single source for key raw material: supplier failure could halt production | M | H | Treat | Qualify second supplier by Q3 2026. Owner: Procurement Manager |
Lead inspector retiring in 12 months: competence gap risk | M | H | Treat | Cross-train second inspector by Q2 2026. Owner: Quality Manager |
Customer requesting SPC data: current capability unknown | L | M | Treat | Run SPC pilot on top 3 product lines by Q4 2026. Owner: Quality Manager |
New ISO 9001:2026 revision: transition requirement from 2027 | L | M | Tolerate | Monitor ISO TC/176 publications. Review at annual management review. Owner: MD |
Opportunity: key customer expanding, potential to grow account | M | H | Treat | Arrange capability presentation Q3 2026. Owner: Sales Director |
The register does not need to be more complex than this. What matters is that it is reviewed regularly, at least at each management review, updated when the risk landscape changes, and that the actions recorded in it are tracked to completion.
4. Plan Your Treatment
The Four Ts framework is a practical structure for deciding how to respond to each identified risk. It maps directly onto the response options ISO standards recognise, and is more precise than the simpler Mitigation / Transfer / Acceptance model because it forces a clear decision about whether to reduce the risk, move it, accept it, or eliminate the activity that causes it.
Response | What it means | When to use it | Example |
|---|---|---|---|
Tolerate | Accept the risk without specific action | Low-likelihood, low-impact risks where the cost of mitigation exceeds the benefit | Minor delay risk on a low-value order with a flexible customer |
Treat | Implement controls to reduce likelihood or impact | Risks that are manageable with reasonable effort and cost | Dual-source a critical component to reduce supply chain risk |
Transfer | Shift the risk to another party | Risks better managed by a specialist third party | Insurance, contractual liability clauses, outsourcing a hazardous process |
Terminate | Eliminate the activity that creates the risk | Risks that are unacceptable and cannot be adequately controlled | Withdraw from a market segment where regulatory compliance costs are prohibitive |
5. Monitor and Review
Risk-based thinking is not a one-off event. You must review your register during regular Management Reviews to ensure your actions were effective and to identify any emerging threats.
Free Download: Click here to download our ISO Risk Register template for free.
Common Mistakes and How to Avoid Them
Creating a risk register once for certification and never updating it: an auditor reviewing a register that has not changed since initial certification will raise a nonconformity. The register should show evidence of updates, new risks added, and closed actions.
Treating risks and opportunities as separate activities: ISO 9001 Clause 6.1 addresses both in the same requirement. Your risk process should capture opportunities alongside threats, not treat them as a different exercise.
Listing risks at too high a level of abstraction: "quality risk" or "supplier risk" is not a useful register entry. A specific named risk with a clear cause and consequence is what allows meaningful action planning.
Keeping the risk register disconnected from the rest of the QMS: risks that are not reflected in process controls, quality objectives, or competence requirements are being listed, not managed.
Confusing risk-based thinking with risk elimination: the standard requires deliberate, proportionate decisions about how to address risk. A documented decision to tolerate a low-level risk is as valid as a decision to treat a high-level one.
What Auditors Look For on Risk-Based Thinking
Auditors will typically ask to see your risk register or equivalent evidence of risk identification. They will then trace a sample of risks through to the actions taken, checking that the actions are reflected in your processes rather than sitting in isolation in the register.
The most common findings are: a risk register that has not been reviewed since initial certification; risks not connected to any process controls or objectives; and no evidence that opportunities have been considered alongside threats.
The question an auditor is asking is not "do you have a risk register?" but "how does consideration of risk and opportunity shape how you plan and manage your processes?"
About The Author
Nicole Webb is an ISO compliance specialist with extensive experience in ISO management systems, accreditation and internal auditing, providing a strong foundation for writing practical, expert-led articles on ISO topics. She has managed accredited management systems and supported Global compliance teams across ISO 9001, ISO 14001, ISO 45001, ISO 22301, ISO 27001 and ISO 13485, giving her a broad, cross-standard perspective that informs her writing. She now runs ISOLiteBites, an ISO-focused training company delivering both e-learning courses and bespoke training for businesses of all sizes.
