Opportunity-Based Thinking: Why Your Risk Register Fails

Direct Answer

Opportunity-based thinking is the concept ISO 9001:2026 separated from risk-based thinking, and it now carries its own requirements at Clause 5.1.1 k), Clause 6.1.3, Clause 9.1.3 f) and Clause 9.3.2 h). The 2026 edition asks the organization to determine, analyse and evaluate opportunities, plan actions for them, integrate those actions, and evaluate their effectiveness as a separate line of evidence from risk. A combined register that scores opportunities on a risk matrix no longer demonstrates the requirement, because the two clauses are written to different acceptance criteria.

Opportunity-based thinking is the quietest change in ISO 9001:2026 and the one most likely to produce a finding, because almost every certified organization already has the risk half built and almost none has the other half. Walk into a quality office anywhere in manufacturing, technology, medical device, government or healthcare and ask to see the risk register. It will exist. It will have owners, dates, scores and a review cadence. Now ask the same person to show the opportunity equivalent — determined, analysed, evaluated, actioned, and measured for effectiveness. In MSI's experience across 200+ audits attended, the answer is usually a column on the same spreadsheet with three optimistic sentences in it and nobody's name attached.

That column was defensible under the 2015 edition. It is not defensible under the sixth edition, published on 16 September 2026. This article walks the four clauses where opportunity-based thinking now lives, shows the single sharpest structural finding in the revision — the two clauses use different acceptance tests — and lays out what evidence actually satisfies them. It also corrects the claim that transition coverage is about to repeat everywhere: that the standard now requires a second register. It does not, and knowing precisely why is the difference between a proportionate response and a year of wasted documentation effort.


What Is Opportunity-Based Thinking in ISO 9001:2026?

The Concept

Distinct. Named. Required.

Annex A.6.1.1 of the 2026 edition gives the cleanest definition available. Risk is described as the effect of uncertainty that can have a negative impact on the ability of the quality management system to achieve its intended results. Opportunity is described as circumstances that make it possible to achieve beneficial effects on the performance of the quality management system. Those are not two ends of one scale. They are two different objects, and the Annex says so in a single sentence that deserves to be printed and taped above every register: risks and opportunities are distinct, and they can be determined and addressed through separate processes.

The 2015 edition mentioned opportunities repeatedly but gave them no machinery of their own. Clause 6.1.1 asked the organization to determine risks and opportunities together, Clause 6.1.2 asked it to plan actions to address them together, and that was the extent of it. Risk-based thinking was named as a concept in the introduction. Its counterpart was not. The practical result, visible in register after register, was that the word “opportunity” travelled through fifteen hundred management systems as a passenger while risk did all the driving. Opportunity-based thinking did not exist as a named concept, and what has no name in a standard tends to have no owner in an organization.

ISO's own description of the sixth edition names the separation as one of the headline changes, alongside the clearer requirements and stronger focus on leadership and quality culture that ISO's 9001:2026 page highlights. The revision did not invent opportunity as a concept. It gave the concept a process, an owner, an evaluation step, and a place on the management review agenda. That is what turns opportunity-based thinking from a principle into a requirement.

Direct Answer

Where does opportunity-based thinking appear in ISO 9001:2026? In four places that together form a complete loop: Clause 5.1.1 k) makes promoting it a top management duty; Clause 6.1.3 requires opportunities to be determined, analysed, evaluated and actioned; Clause 9.1.3 f) requires the effectiveness of those actions to be evaluated; and Clause 9.3.2 h) makes that effectiveness a named management review input. Risk carries an identical, parallel set at 5.1.1 k), 6.1.2, 9.1.3 e) and 9.3.2 g).

The Four Clauses That Carry Opportunity-Based Thinking

Clause Map

Lead. Plan. Prove.

Clause 5.1.1 k) — It Starts as a Leadership Duty

The list of things top management shall do to demonstrate leadership and commitment now includes promoting risk-based thinking and opportunity-based thinking. Read that carefully, because the placement matters more than the wording. This is not an obligation on the quality manager or the process owner. It is an obligation on the people at the top of the organization, in the same list that carries promoting quality culture and ethical behaviour, promoting the process approach, and taking accountability for the effectiveness of the system.

The audit consequence is that the conversation can go upward. An assessor can sit with a chief executive and ask how the organization pursues opportunity systematically, and the answer has to be better than a gesture at a spreadsheet maintained two levels down. MSI's analysis of what ISO 9001:2026 means for boardrooms makes the same point about the culture clauses: the revision moved several expectations from implied to auditable, and leadership is where they land first. Opportunity-based thinking arrives the same way.

Clause 6.1 — The Planning Split

Clause 6.1.1 still asks the organization to consider its external and internal issues and the requirements of interested parties, and to determine the risks and opportunities that need to be addressed in order to give assurance the system can achieve its intended results, prevent or reduce undesired effects, achieve continual improvement, and enhance desired effects. Then the clause forks. Clause 6.1.2 handles risks. Clause 6.1.3 handles opportunities. Each has its own paragraph structure, its own verbs and its own closing qualifier — which is where opportunity-based thinking stops being a philosophy and becomes a process.

Clause 6.1.3 requires the organization to determine, analyse and evaluate opportunities that can have a desired effect on its ability to continually and consistently provide conforming products and services and enhance customer satisfaction. It then requires the organization to plan actions to address those opportunities, plan how to integrate and implement the actions into its quality management system processes, and plan how to evaluate the effectiveness of those actions.

Compare that to 2015, which asked only that opportunities be determined. Analyse and evaluate are new verbs applied to opportunity-based thinking, and they are the ones that create work. Determining an opportunity is a brainstorm. Analysing and evaluating one requires criteria — a defensible basis for saying this opportunity is worth pursuing and that one is not. For organizations building the procedure rather than the list, MSI's guide to the risk management procedure template works through the criteria-setting problem in detail and is the natural companion to this article.

Clause 9.1.3 — Effectiveness, Evaluated Separately

Clause 9.1.3 lists eight things the results of analysis shall be used to evaluate. Item e) is the effectiveness of actions taken to address risks. Item f) is the effectiveness of actions taken to address opportunities. Two items, not one. The organization cannot satisfy f) by pointing at the answer it gave for e), and an auditor following the clause list has a separate box to tick. Opportunity-based thinking has to produce its own answer.

Clause 9.3.2 — Two Rows on the Management Review Agenda

The same split repeats in the management review inputs. Item g) is the effectiveness of actions taken to address risks, cross-referenced to 6.1.2. Item h) is the effectiveness of actions taken to address opportunities, cross-referenced to 6.1.3. Most review decks in circulation carry a single slide headed “Risks and Opportunities,” and that slide is now structurally short of one required input. MSI's work on the management review procedure describes the failure mode exactly: an input that is only spoken and never recorded is an input the record cannot prove. Opportunity-based thinking lives or dies on that row.

Split the Slide Before the Auditor Does

Your management review agenda is now one row short.

Clause 9.3.2 g) and h) are two inputs, and a habit-built agenda carries one. MSI's ISO Management Review Toolkits ship matched deck-and-minutes pairs across ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001 and ISO 7101 — every section numbered and printed with the clause reference it satisfies, so a missing input is visible on the page instead of at the audit.

Compare the Management Review Toolkits by clause →

Why a Risk-Scored Register Cannot Evidence Opportunity-Based Thinking

The Sharpest Finding

Wrong. Tool. Wrong. Answer.

This is the part of the revision worth reading twice, and it hides in the closing sentence of each clause rather than in the headline text. It is also why opportunity-based thinking is harder to retrofit than it first appears.

Clause 6.1.2 closes by saying that actions taken shall be proportionate to the potential impact of the risks on the intended results of the quality management system. Clause 6.1.3 closes by saying that actions taken to address opportunities shall be appropriate to the organization's context and support the achievement of desired results.

Proportionality is a risk test. Contextual appropriateness is an opportunity test. They are not interchangeable, and the instrument that answers one cannot answer the other.

Think about what a severity-by-likelihood matrix actually does. It estimates how bad a thing would be and how probable it is, multiplies them, and sorts the result so the worst-and-likeliest gets attention first. That is a proportionality engine. It is precisely the right instrument for Clause 6.1.2, and it produces a number an auditor can trace from the score to the action to the effectiveness check.

Now apply the same matrix to an opportunity. What is the severity of a beneficial circumstance? What is the likelihood of a market opening you have not pursued yet? Organizations do it anyway — the fields are already on the form — and the output is a number that does not answer the question Clause 6.1.3 asks. Clause 6.1.3 asks whether the action fits the organization's context and moves it toward its desired results. A high score on a risk matrix does not demonstrate contextual fit. It demonstrates that someone applied a risk instrument to a non-risk object, which is the most common structural error opportunity-based thinking will surface during transition audits.

The correct instrument for opportunity-based thinking is a context test, and it is not complicated to build. Does this opportunity connect to an issue the organization identified under Clause 4.1, or to a need or expectation identified under Clause 4.2? Does the organization have the capability, capacity and competence to pursue it? Does pursuing it move a stated quality objective? Annex A.6.1.3 names those sources almost verbatim, listing external and internal context, the needs and expectations of interested parties, organizational capability, capacity and competence, and the results of monitoring and measurement activities with their related performance indicators. Build the evaluation against those five inputs and opportunity-based thinking has a defensible method behind it rather than a score borrowed from the wrong column.

Direct Answer

Can one register still cover both? Yes — provided it produces two separately analysed, separately evaluated and separately monitored outputs. Opportunity-based thinking fails an audit not because the entries share a spreadsheet, but because the opportunity entries were ranked with a severity-and-likelihood score that answers the Clause 6.1.2 proportionality test instead of the Clause 6.1.3 contextual-appropriateness test. Change the evaluation method, not necessarily the file.

The Correction Most Transition Coverage Will Get Wrong

Read the Annex

Can. Not. Shall.

Over the next eighteen months a great many articles are going to tell certified organizations that ISO 9001:2026 requires a second register as the price of admission for opportunity-based thinking. That claim is wrong on two counts, and getting it right is worth real money to anyone budgeting transition effort.

First, the Annex sentence that licenses separation uses a permissive verb. Risks and opportunities are distinct, and they can be determined and addressed through separate processes. Can, not shall. Annex A is informative guidance, not requirement text, and the guidance offers separate processes as an available design — not a mandated one. A single well-built process that applies two different evaluation methods to two different objects is entirely conforming.

Second, neither Clause 6.1.2 nor Clause 6.1.3 contains a documented information requirement. There is no “shall be available as documented information” sentence attached to either. Clause 6.1 in ISO 9001 has never mandated a register, and the 2026 edition did not add one. Annex A.6.1.2 goes further on the risk side, stating plainly that applying risk-based thinking does not imply the use of formal risk management approaches or a documented risk management process, with ISO 31000 referenced as optional further guidance for organizations that want a fuller framework.

So what does opportunity-based thinking actually require? Demonstrable determination, analysis and evaluation of opportunities. Planned actions. Integration of those actions into the system's processes. And an evaluation of whether the actions worked, surfaced at Clause 9.1.3 f) and carried into management review under 9.3.2 h). In practice, a register is the cheapest and most durable way to produce that evidence — which is why MSI builds one — but it is a chosen method, not a clause obligation. Anyone who tells a client otherwise is selling documentation the standard did not ask for, and honest ISO consulting means saying so.

Build the Opportunity Route Once

Stop rewriting Clause 6.1 from a blank page.

MSI's ISO Procedure Templates and Guides library covers thirteen procedure families and 100+ templates written to one architecture across ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001 and ISO 7101 — editable Microsoft Word, with worked examples instead of outlines and every judgment call already made and annotated from 200+ audits attended. The Clause 6.1 procedure carries the criteria-setting worksheet, the process interaction map, and the opportunity route almost no register has.

Browse the procedure template library →Go straight to the Clause 6.1 template →

Opportunity Is Not Improvement — Where 6.1.3 Ends and Clause 10 Begins

The Boundary

Different. Clause. Different. Object.

The most common way an opportunity register goes wrong is that it quietly fills up with improvement actions. Reduce scrap by four percent. Shorten corrective-action close-out. Retrain the second shift. All worthwhile, none of them what Clause 6.1.3 is about — and all of them already owned by Clause 10.1, which requires the organization to consider monitoring and measurement results and management review results in order to determine opportunities, and to address those opportunities as part of continual improvement.

Look instead at the note attached to Clause 6.1.3. It says actions to address opportunities can include adopting new practices, launching new products or services, creating new partnerships, leveraging emerging technologies, and implementing initiatives that respond to the changing needs and expectations of customers and other interested parties. Note that this is a NOTE — informative, creating no obligation of its own — but it tells you unmistakably what the drafters had in mind. New partnerships. New technologies. New products. That is strategy, not housekeeping. It is also why opportunity-based thinking works best inside a wider strategy, where risks and opportunities are evaluated separately and then weighed together at the point of decision — the leadership layer MSI covers in risk-based strategy and the eight methods that make it work.

Which produces the most useful consequence in the whole revision, and the one worth taking to your leadership team. Opportunity-based thinking gives the quality function a certifiable reason to be present when the organization decides what it is going to pursue next. For twenty-eight years, quality professionals have asked for a seat in that conversation on the strength of good arguments. Clause 6.1.3 replaces the argument with a clause, and Clause 5.1.1 k) puts the duty to promote it on the people already in the room.

Keep the opportunity-based thinking boundary clean in your own documentation. Improvement actions belong in the continual improvement route, and MSI's analysis of continual improvement in ISO 9001 maps how Clause 6.2 objectives and Clause 10.1 improvement work together. Opportunities under 6.1.3 belong in the planning route, evaluated against context. Two clauses, two objects, two evidence trails.

Direct Answer

Is opportunity-based thinking the same as continual improvement? No. Clause 10.1 already owns improvement — refining what the organization currently does, based on monitoring, measurement and management review results. Clause 6.1.3 concerns circumstances that could produce beneficial effects the organization is not yet capturing, which its own note illustrates with new practices, new products and services, new partnerships and emerging technologies. Improvement raises the existing baseline. Opportunity changes what the baseline is.

What Evidence of Opportunity-Based Thinking Actually Looks Like

In Practice

Named. Dated. Measured.

First Example: A Customer Signal Nobody Had Actioned

Here is a worked example in the shape a competent assessor will accept. A technology manufacturer identifies, through Clause 4.2 interested-party analysis, that three of its largest customers have begun asking for component-level traceability data in a machine-readable format. That is a circumstance capable of producing beneficial effects — an opportunity, not a risk, and exactly the object opportunity-based thinking was written to handle.

Determination. Recorded with its source: customer requirement signals captured in the quarterly account review, cross-referenced to the Clause 4.2 register entry.

Analysis and evaluation. Assessed against the five Annex A.6.1.3 inputs. Context fit: aligns with the stated strategic direction toward regulated-sector customers. Capability: the data exists in the MES but is not exportable. Capacity: one engineer, eleven weeks. Competence: an external integration partner is required. Desired result supported: a named quality objective on first-pass customer data acceptance.

Planned action. Build the export layer, pilot with one customer, extend to all three. Owner named. Dates set.

Integration. The action lands inside existing processes rather than beside them — the change runs through the Clause 6.3 planning-of-changes route, the export becomes a controlled output under Clause 8.5, and the acceptance measure joins the Clause 9.1 monitoring plan.

Effectiveness evaluation. The measure was defined before the work started: first-pass acceptance of submitted data, baselined at the pilot, reviewed at twelve months. That number is what satisfies Clause 9.1.3 f), and it is what goes on the management review agenda under 9.3.2 h) — not a status update, a result.

Notice what makes that record work. Every element of opportunity-based thinking is traceable to a clause, the evaluation used context rather than a hazard score, and the effectiveness measure was chosen at the start rather than reverse-engineered at the review. That discipline is the same one behind a well-built customer satisfaction procedure, where the number only means something if you decided in advance what it was supposed to prove.

Second Example: Transitioning Early While 1.4 Million Certificates Wait

The best available example of opportunity-based thinking is the one sitting on your own desk right now, because the transition to ISO 9001:2026 is itself a circumstance capable of producing beneficial effects — and almost nobody is treating it as one.

Start with the arithmetic. The ISO Survey put valid ISO 9001:2015 certificates at 1,474,118 in its most recent published figures. Every one of those certificates is against the fifth edition. Every one of them has to move to the sixth edition inside the same transition window, through a finite population of auditors who must themselves be re-accredited to the new edition before they can assess anyone against it. Certification body capacity does not expand to meet a deadline. It fills up, and then it schedules people where it can.

That produces a genuine asymmetry between the organization that transitions in the first year and the organization that transitions in the third, and the difference is not compliance — both end up conforming. The difference is what each one gets along the way. Early movers pick their assessment date instead of accepting one. They get an assessor who has time to discuss interpretation rather than one working through a backlog. They have consultant and trainer availability at ordinary rates. And they hold a current-edition certificate at a moment when their competitors cannot yet produce one, which is a real answer to a real question on customer prequalification forms.

Run that through Clause 6.1.3 properly and it looks like this. Determination: the transition window is a circumstance arising from an external issue identified under Clause 4.1, recorded with its source rather than asserted. Analysis and evaluation: tested against the Annex A.6.1.3 inputs — context fit with a stated strategy of bidding into regulated supply chains, capability in an existing healthy management system, capacity across a specific quarter, competence available internally or bought in, and the objective it supports. Planned action: a dated transition project with a named owner and a target assessment window in the first year. Integration: the project runs through the Clause 6.3 planning-of-changes route rather than beside it. Effectiveness evaluation: a measure chosen before the work starts — customer prequalification submissions answered with a current-edition certificate, or assessment scheduled on a requested date rather than an assigned one — baselined and reported at Clause 9.1.3 f) and again at management review under Clause 9.3.2 h).

Now the honest half, because opportunity-based thinking is a test and not a slogan. For some organizations the context test returns a no, and a recorded no is fully conforming. An organization mid-way through an acquisition, running a system that already struggles to generate records, or carrying a certification body that has not yet been re-accredited, may evaluate early transition and decide the action is not appropriate to its context. That evaluation, written down with its reasoning, is better evidence of opportunity-based thinking than an enthusiastic yes with nothing behind it. Clause 6.1.3 asks the organization to determine, analyse and evaluate. It does not ask the organization to pursue everything it finds.

What makes this example worth using inside your own system is that it is self-demonstrating. Write the transition up as an opportunity under Clause 6.1.3, evaluate it against context, give it an owner and a measure, and you have simultaneously produced the transition plan and the first real record under the clause the transition is adding. MSI's analysis of the management review benefits that transfer to project governance makes the same connection from the other direction: the projects an organization runs are management-system activity, and the review is where they get governed.

Five Moves That Add the Opportunity Route to a System You Already Run

Transition Work

Precise. Small. Sufficient.

None of this demands a system rebuild. Opportunity-based thinking is an insertion into machinery you already have, and MSI client experience suggests the whole of it is a few days of considered work rather than a documentation project.

  1. Write the two definitions into your procedure. Take the Annex A.6.1.1 language — negative effect of uncertainty versus circumstances enabling beneficial effects — and put it at the front of the Clause 6.1 procedure. Most misfiling happens because nobody ever defined the two objects on paper.
  2. Replace the score on the opportunity rows with a context test. Five fields: context link, capability, capacity, competence, objective supported. This is the single highest-value edit in the whole transition, and it takes an afternoon.
  3. Add an effectiveness measure field, and require it at entry. Not at closure. If the measure cannot be named when the action is planned, the action is not ready to be approved.
  4. Split the management review agenda row into two. One for 9.3.2 g), one for 9.3.2 h), each with its own trend and owner, so the record shows two inputs rather than one conversation.
  5. Give top management something real to promote. Clause 5.1.1 k) asks top management to promote opportunity-based thinking, and that duty is satisfied by evidence, not intention — a standing agenda item, a leadership communication, an opportunity approved at the top and funded. One genuine artifact beats a policy sentence every time.

Do those five and audit the result. MSI's guidance on the internal audit procedure edits the 2026 standards require explains why the internal audit is where new requirements get rehearsed before a certification body ever sees them, and opportunity-based thinking is exactly the kind of new requirement that benefits from one cycle of internal scrutiny first.

Direct Answer

How much work is opportunity-based thinking during transition? For a healthy ISO 9001:2015 system, a few days. The five insertions are a definitions paragraph, a context-test evaluation replacing the risk score on opportunity entries, a mandatory effectiveness-measure field, a split management review agenda row, and one piece of genuine top-management evidence. What takes longer is not the documentation — it is generating real records under the revised arrangement before the transition audit arrives.

Where Opportunity-Based Thinking Sits in Your Transition Timeline

The Clock

Publish. Accredit. Assess.

The sixth edition of ISO 9001 was published on 16 September 2026, and a three-year transition window is expected, with the precise date confirmed by your certification body rather than assumed. The sequencing behind that window is what matters for planning. Certification bodies must themselves be accredited to the new edition before they can issue 2026 certificates, and accreditation follows publication rather than preceding it — the framework now administered by Global ACI, which has taken over the former roles of the International Accreditation Forum and ILAC as described on ISO's certification page.

Work backwards from a realistic 2028 transition assessment and the arithmetic is unforgiving in a helpful way. Subtract one internal audit cycle conducted against the 2026 requirements. Subtract a run-in period long enough that your opportunity entries have real history rather than a first record dated the week before the assessor arrives. Subtract documentation revision. The procedure edits need to be finished considerably earlier than most plans assume — the same backward calculation MSI sets out in its analysis of why the transition clock already started.

Opportunity-based thinking deserves an early slot in that sequence for one specific reason: it is the only change in the revision that needs elapsed time to generate evidence. A definitions paragraph can be written the week before an audit and still be true. An effectiveness evaluation cannot. Clause 9.1.3 f) asks whether the actions worked, and answering that requires an action that has been running long enough to have produced a result. Organizations that leave opportunity-based thinking until the final year will arrive at the assessment with a well-written procedure and nothing to show under it.

For organizations holding more than one certificate, sequence the work as a single program. MSI's analysis of the combined ISO 9001 and 14001 transition explains why the shared harmonized structure lets one project serve both, and its work on connected quality management across multi-site networks covers the document-layer decisions that follow. Device organizations need one additional caution, covered in MSI's treatment of ISO 13485 risk management: ISO 13485 contains no opportunity requirement at all, so an integrated system must not export opportunity-based thinking into the device risk management file, where it does not belong.

Start Where the Evidence Takes Longest

Scope your opportunity route in one working session.

A planning session with MSI puts your current Clause 6.1 arrangement side by side with the 2026 text, identifies which entries are misfiled, and sets the evaluation criteria your organization can actually defend. Veteran-owned, female-owned, founded in 1998 — 28 years, 80+ certifications supported, 200+ audits attended and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare and other regulated industries.

Book a planning session — 760-434-9141

Leadership team needs the short version first? Watch the ISO Executive Decision Briefs — built for the people Clause 5.1.1 k) now names.

Opportunity-Based Thinking: Frequently Asked Questions

Straight Answers

Ask. Answer. Move.

Does ISO 9001:2026 require a separate opportunity register?

No. Neither Clause 6.1.2 nor Clause 6.1.3 carries a documented information requirement, and Annex A.6.1.1 says risks and opportunities can — not shall — be addressed through separate processes. What opportunity-based thinking requires is that opportunities be determined, analysed, evaluated, actioned, integrated and evaluated for effectiveness. A single register satisfies that if it applies the right evaluation method to the opportunity entries. A register is a sensible method, not a clause obligation.

What changed about opportunities between ISO 9001:2015 and ISO 9001:2026?

Four things. Opportunities got their own requirement clause at 6.1.3 rather than sharing 6.1.2 with risks. The verbs expanded from “determine” to “determine, analyse and evaluate.” The effectiveness of opportunity actions became its own evaluation item at Clause 9.1.3 f) and its own management review input at Clause 9.3.2 h). And promoting opportunity-based thinking became an explicit top management duty at Clause 5.1.1 k), where the 2015 edition named only risk-based thinking as a concept.

Can we score opportunities on our existing risk matrix?

It will produce a number, but not the evidence opportunity-based thinking needs. Clause 6.1.2 requires risk actions to be proportionate to the potential impact of the risks — a severity-and-likelihood question. Clause 6.1.3 requires opportunity actions to be appropriate to the organization's context and to support the achievement of desired results — a fit question. Evaluate opportunities against context, capability, capacity, competence and the objective supported, which are the sources Annex A.6.1.3 names.

Is an improvement project an opportunity under Clause 6.1.3?

Usually not. Clause 10.1 already requires the organization to determine improvement opportunities from monitoring, measurement and management review results and to address them as continual improvement. The note to Clause 6.1.3 points somewhere else entirely — new practices, new products and services, new partnerships, emerging technologies and initiatives responding to changing customer and interested-party expectations. Filing improvement actions under 6.1.3 leaves the planning clause looking satisfied while the activity it actually describes never happens.

What evidence will an auditor ask for under Clause 9.1.3 f)?

A result, not a status. The clause asks the organization to use the results of analysis to evaluate the effectiveness of actions taken to address opportunities, which means a measure defined before the action started, a baseline, and an evaluated outcome. An entry reading “in progress” answers nothing. This is why opportunity-based thinking belongs early in a transition plan — it is the one change that needs elapsed time to produce evidence.

Does this change apply to ISO 13485 systems as well?

No. ISO 13485 predates the harmonized structure and contains no risks-and-opportunities construct at all; its risk requirement concerns the safety and performance of the device and regulatory compliance. Organizations running one system against both standards should keep ISO 9001 opportunity-based thinking inside the quality management system and out of the device risk management file, which has a different object, a different audience and a different regulatory reader.

The Half Nobody Built

Closing

Find. Fund. Prove.

For eleven years the profession built one half of Clause 6.1 beautifully and let the other half ride along. The registers are good. The scoring is disciplined. The reviews happen. And the opportunity column has been, in most organizations, a place where good intentions go to be archived. Opportunity-based thinking was the half nobody built.

ISO 9001:2026 ended that arrangement without much fanfare — a clause number, a few new verbs, two extra items on two lists. But the effect is that opportunity-based thinking now has to work in practice rather than exist on paper, and the organizations that build it properly will get something better than a clean transition report. They will get a quality function that is consulted before decisions, not after them. That was always the argument for the management system. This is the first edition that put it in the requirement text.

If you want the procedure built rather than the concept explained, start with the ISO 9001 procedure templates and guides package or pair it with the Catch. Correct. Continually Improve. corrective action course for the improvement side of the boundary. If the harder problem is getting leadership to own Clause 5.1.1 k), the Inspired Leadership workshop is built for exactly that room. And if you would rather have someone look at your actual register before you change anything, experienced ISO consulting is a phone call away at 760-434-9141 — MSI has supported 80+ certifications and attended 200+ audits across 28 years, and knows what a defensible opportunity route looks like because it has watched assessors test them.

Related Reading from MSI

Risk-Based Strategy: Why Proven Methods Always Win

The companion piece: the strategy layer and the risk half of ISO 9001:2026 Clause 6.1, across every major ISO standard.

Your Contingency Plan Has Never Been Validated

The disruption side of Clause 6.1.2, and how to turn a written plan into a tested control.

Executive Accountability: Why the FDA Now Names the CEO

Why leadership duties like Clause 5.1.1 k) now land on the people at the top.

References and further reading

About Management Systems International (MSI)

Diana Lynn is President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 work in MSI's early years, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.

msi-international.com · 760-434-9141

Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 15 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply