Back to Resources

    Mastering Risk-Based Thinking: The Core of Modern ISO Standards

    ByNicole Webb·
    Share:
    Mastering Risk-Based Thinking: The Core of Modern ISO Standards

    In the world of international standards, "Risk-Based Thinking" (RBT) is the engine that drives a successful management system. Gone are the days when quality was merely about following a static checklist. In 2026, staying competitive means anticipating challenges before they occur and seizing opportunities before they pass.

    What is Risk-Based Thinking (RBT)?

    Risk-based thinking is a proactive approach that replaces the "Preventive Action" requirement found in older versions of ISO standards. Instead of waiting for a mistake to happen and then fixing it, RBT encourages an organisation to identify potential risks and opportunities at every stage of its processes.

    ISO defines risk as the "effect of uncertainty on objectives". This means risk is not always negative. The primary ISO 9001 requirement for risk-based thinking sits in Clause 6.1. It requires organisations to determine the risks and opportunities that need to be addressed, plan actions to address them, integrate those actions into QMS processes, and evaluate their effectiveness. Importantly, Clause 6.1 does not mandate a specific format or tool. A formal risk register is not required by the standard , the approach should be proportionate to the size and complexity of your organisation.

    While a risk might be a potential supplier failure, an opportunity might be the chance to adopt a new digital tool that increases efficiency.

    What Changed from ISO 9001:2008

    ISO 9001:2008 included a specific clause on preventive action (Clause 8.5.3). Organisations were required to take action to eliminate the causes of potential nonconformities.

    In the 2015 revision, preventive action as a standalone clause was removed. Risk-based thinking replaced it with a broader scope: instead of a separate preventive action process, the expectation is that risk consideration is embedded into planning, process management, objectives, and management review throughout the QMS.

    If your quality manual or procedures still reference "preventive action" as an ISO 9001 requirement without connecting it to risk-based thinking, they need updating.

    Risk-Based Thinking Across ISO 9001, 27001, and 45001

    While all modern ISO standards follow the Annex SL high-level structure, the way they apply risk-based thinking varies slightly to suit their specific focus.

    ISO 9001 (Quality Management)

    As the foundation for most businesses, ISO 9001 uses RBT to ensure consistent product and service quality. The upcoming ISO 9001:2026 revision takes this further by splitting Clause 6.1 into separate sub-clauses for risks and opportunities, ensuring that strategic growth opportunities receive the same rigorous management as operational threats.

    ISO 27001 (Information Security)

    For information security, the approach is more stringent. ISO 27001 requires a formalised risk assessment process, often aligned with the ISO 31000.

    ISO 45001 (Health and Safety)

    In health and safety, RBT focuses on hazard identification. The goal is to evaluate any potential source of harm to workers and implement controls to prevent accidents, focusing on both physical and psychological well-being.

    Why Risk-Based Thinking Matters for Your Business

    Implementing a robust RBT culture offers several strategic advantages:

    • Operational Resilience: You become better at anticipating supply chain disruptions or technological shifts.

    • Increased Efficiency: By focusing resources on high-risk areas, you avoid wasting time on low-impact issues.

    • Stakeholder Trust: Demonstrating a proactive mindset builds confidence with customers, investors, and regulators.

    A Practical Walkthrough: The 5-Step Risk Register Process

    To demonstrate risk-based thinking to an auditor, most SMEs use a Risk and Opportunities Register. Follow these five steps to build yours:

    1. Establish the Context

    Before identifying risks, you must understand your business environment. Use tools like a SWOT Analysis (Strengths, Weaknesses, Opportunities, Threats) to look at internal and external factors that could affect your objectives.

    2. Identify Your Risks and Opportunities

    For every core process (e.g., Sales, Production, HR), ask your team: "What could go wrong?" and "What could we do better?".

    3. Analyse and Evaluate

    Determine the significance of each identified item by scoring it based on:

    • Likelihood: How often is this expected to happen?

    • Impact: What would the consequence be if it did occur?

    Multiply these scores to determine your Risk Factor. This allows you to prioritise which issues require immediate action.

    A Simple Risk Register: Example for a Manufacturing SME

    The table below shows what a completed risk register entry looks like for a small manufacturer. Note that the final row is an opportunity rather than a risk; ISO 9001 Clause 6.1 explicitly requires both risks and opportunities to be addressed, and including opportunities in the same register is the most practical approach.

    Risk / opportunity

    Likelihood (H/M/L)

    Impact (H/M/L)

    Response

    Action and owner

    Single source for key raw material: supplier failure could halt production

    M

    H

    Treat

    Qualify second supplier by Q3 2026. Owner: Procurement Manager

    Lead inspector retiring in 12 months: competence gap risk

    M

    H

    Treat

    Cross-train second inspector by Q2 2026. Owner: Quality Manager

    Customer requesting SPC data: current capability unknown

    L

    M

    Treat

    Run SPC pilot on top 3 product lines by Q4 2026. Owner: Quality Manager

    New ISO 9001:2026 revision: transition requirement from 2027

    L

    M

    Tolerate

    Monitor ISO TC/176 publications. Review at annual management review. Owner: MD

    Opportunity: key customer expanding, potential to grow account

    M

    H

    Treat

    Arrange capability presentation Q3 2026. Owner: Sales Director

    The register does not need to be more complex than this. What matters is that it is reviewed regularly, at least at each management review, updated when the risk landscape changes, and that the actions recorded in it are tracked to completion.

    4. Plan Your Treatment

    The Four Ts framework is a practical structure for deciding how to respond to each identified risk. It maps directly onto the response options ISO standards recognise, and is more precise than the simpler Mitigation / Transfer / Acceptance model because it forces a clear decision about whether to reduce the risk, move it, accept it, or eliminate the activity that causes it.

    Response

    What it means

    When to use it

    Example

    Tolerate

    Accept the risk without specific action

    Low-likelihood, low-impact risks where the cost of mitigation exceeds the benefit

    Minor delay risk on a low-value order with a flexible customer

    Treat

    Implement controls to reduce likelihood or impact

    Risks that are manageable with reasonable effort and cost

    Dual-source a critical component to reduce supply chain risk

    Transfer

    Shift the risk to another party

    Risks better managed by a specialist third party

    Insurance, contractual liability clauses, outsourcing a hazardous process

    Terminate

    Eliminate the activity that creates the risk

    Risks that are unacceptable and cannot be adequately controlled

    Withdraw from a market segment where regulatory compliance costs are prohibitive

    5. Monitor and Review

    Risk-based thinking is not a one-off event. You must review your register during regular Management Reviews to ensure your actions were effective and to identify any emerging threats.

    Free Download: Click here to download our ISO Risk Register template for free.

    Common Mistakes and How to Avoid Them

    • Creating a risk register once for certification and never updating it: an auditor reviewing a register that has not changed since initial certification will raise a nonconformity. The register should show evidence of updates, new risks added, and closed actions.

    • Treating risks and opportunities as separate activities: ISO 9001 Clause 6.1 addresses both in the same requirement. Your risk process should capture opportunities alongside threats, not treat them as a different exercise.

    • Listing risks at too high a level of abstraction: "quality risk" or "supplier risk" is not a useful register entry. A specific named risk with a clear cause and consequence is what allows meaningful action planning.

    • Keeping the risk register disconnected from the rest of the QMS: risks that are not reflected in process controls, quality objectives, or competence requirements are being listed, not managed.

    • Confusing risk-based thinking with risk elimination: the standard requires deliberate, proportionate decisions about how to address risk. A documented decision to tolerate a low-level risk is as valid as a decision to treat a high-level one.

    What Auditors Look For on Risk-Based Thinking

    Auditors will typically ask to see your risk register or equivalent evidence of risk identification. They will then trace a sample of risks through to the actions taken, checking that the actions are reflected in your processes rather than sitting in isolation in the register.

    The most common findings are: a risk register that has not been reviewed since initial certification; risks not connected to any process controls or objectives; and no evidence that opportunities have been considered alongside threats.

    The question an auditor is asking is not "do you have a risk register?" but "how does consideration of risk and opportunity shape how you plan and manage your processes?"

    About The Author

    Nicole Webb is an ISO compliance specialist with extensive experience in ISO management systems, accreditation and internal auditing, providing a strong foundation for writing practical, expert-led articles on ISO topics. She has managed accredited management systems and supported Global compliance teams across ISO 9001, ISO 14001, ISO 45001, ISO 22301, ISO 27001 and ISO 13485, giving her a broad, cross-standard perspective that informs her writing. She now runs ISOLiteBites, an ISO-focused training company delivering both e-learning courses and bespoke training for businesses of all sizes.

    Frequently Asked Questions

    What is risk-based thinking in ISO 9001?
    Risk-based thinking is a core principle of ISO 9001:2015 that requires consideration of risk and opportunity to be embedded throughout the quality management system. The primary requirement is Clause 6.1, which requires organisations to identify the risks and opportunities relevant to their context and objectives, plan actions to address them, integrate those actions into QMS processes, and evaluate their effectiveness. It replaced the standalone preventive action clause of ISO 9001:2008.
    Does ISO 9001 require a formal risk register?
    No. ISO 9001:2015 Clause 6.1 requires organisations to determine risks and opportunities and plan actions to address them, but it does not mandate a specific format or tool. A formal risk register is not required by the standard. Most SMEs find a simple risk register in a spreadsheet to be the most practical approach, but the format is flexible and should be proportionate to the size and complexity of the organisation.
    What is the difference between risk-based thinking and formal risk management?
    Risk management is a formal discipline with established methodologies such as ISO 31000 and FMEA, typically involving dedicated resources and detailed documentation. Risk-based thinking in ISO 9001 is a mindset requirement: the standard requires that risk and opportunity considerations are embedded into how the organisation plans and manages its processes, but it does not require a formal risk management framework. For most SMEs, risk-based thinking means consistently asking what could go wrong, what could be improved, and what can be learned from past problems.
    How do I demonstrate risk-based thinking to an ISO 9001 auditor?
    Auditors want to see that risk and opportunity consideration is woven into your management system rather than sitting in an isolated document. Show a risk identification process with assessed likelihood and impact; evidence that actions are reflected in process controls or quality objectives; management review records that discuss risks and opportunities; and corrective action records that address root causes. The most common audit findings are a risk register not updated since initial certification and risks not connected to any process controls.
    Share:

    Need Help With ISO Certification?

    Get quotes from accredited registrars and ISO experts.