Direct Answer
A risk management procedure template is the controlled document that defines how an organization identifies risk, rates it against written criteria, routes it to treatment, and reviews it on named events. ISO 9001:2015 does not require one at Clause 6.1 — and that is precisely why organizations get findings. The obligation arrives instead through Clause 4.4.1, which requires determined criteria and methods for every process in the quality management system. Risk identification is a process.
The clause that gets you cited is not the clause you think it is.
Ask a quality manager which requirement governs their risk process and you will hear “6.1” without hesitation. Ask an auditor where the finding was written and you will often hear something else entirely. That mismatch is not a technicality. It is the single most common reason a competent organization with a working risk register is surprised by a nonconformity, and it is the reason a risk management procedure template earns its place in a system that was explicitly told it did not need one.
In 2015 the message was unambiguous. The revision that introduced risk-based thinking was marketed on the point that it required no documented risk management process, no risk register, no formal methodology. Organizations read that correctly. They concluded they needed no procedure, and they were right about Clause 6.1. Nobody told them the obligation lived somewhere else in the same standard.
Clause 6.1 requires nothing. Clause 4.4.1 requires everything. The finding is written against the second one.
This article sets out what a risk management procedure template actually has to contain, where each of the five standards places the requirement, the one element almost nobody implements and why it is missed structurally rather than carelessly, two worked examples that are deliberately different in shape, and what changes across 2026. If you would rather see where your own process stands first, the free Risk, Aspect and Job Hazard Maturity Check takes about six minutes and gives you a band and a priority order before you read another word.
Contents
What a risk management procedure template actually has to contain
Trigger. Criteria. Route.
Most documents sold under this name are outlines. A workable risk management procedure template is not a shape with the hard parts left blank; it is a set of decisions already made and written down. Seven marks separate the two.
- A named trigger with an owner and a clock. Every route by which a risk can enter the system — a new process, a changed supplier, an incident, a complaint, a regulatory change, a customer requirement, an audit finding. If the only entry point is the annual review, everything that happens in between is invisible.
- Severity criteria written as described outcomes, not adjectives. “Major” is not a definition. “Product reaches a customer and is recalled” is.
- Likelihood criteria with a stated period. Likely over what? A week, a year, the life of the contract? Without the period, two assessors are answering different questions.
- A treatment route into the governing document, so a decision to act produces an action with an owner and a date rather than a colored cell.
- A record of acceptance. Somebody decided this risk was tolerable. Their name and the date belong on the page.
- A review trigger that is event-based, with the calendar as a backstop only.
- An interface map naming what feeds the process and what it hands on — corrective action, change control, management review, internal audit.
Direct Answer
A risk management procedure template should contain a named trigger with an owner and a clock, severity and likelihood criteria written as described outcomes rather than adjectives, a stated assessment period, a treatment route into the governing document, a recorded acceptance decision, an event-based review trigger, and a map of the interfaces to corrective action, change control and management review.
Notice what is not on that list: a matrix. Every risk management procedure template ships with one, and it is the least load-bearing part of the document. The matrix is the least important part of a risk management procedure template and the part everyone starts with. It is a display device. What makes it mean anything is the criteria behind it, and those are what almost nobody writes down. MSI's guide to what makes an effective ISO procedure covers the same distinction across every procedure family.
The Spine
The clause nobody reads: 6.1 requires nothing, 4.4.1 requires everything
Silent. Structural. Cited.
ISO 9001:2015 Clause 6.1 asks the organization to determine the risks and opportunities that need to be addressed, to plan actions, and to integrate those actions into its processes. It does not require a documented process. It does not require a register. It does not require criteria. Read on its own, it is satisfied by evidence that the thinking happened.
Clause 4.4.1 is four pages earlier and asks something different. The organization has to determine the processes needed for the quality management system, and for each of them determine the criteria and methods needed to ensure their effective operation and control. There is no carve-out, and no exemption for planning processes. This is the clause a risk management procedure template is actually written against. Risk identification is a process in the quality management system by any reading of the clause — it has inputs, it has outputs, it has people performing it.
So put the two together. If three people in an organization identify and rate risk three different ways, with no stated criteria and no defined method, the process is not controlled. That is a 4.4.1 c) finding, and it is a genuine one. The organization can produce a register, can demonstrate that risk-based thinking happened, can point to actions taken — and still be non-conforming, because the standard asked how the process is controlled and the honest answer is that it is not.
This is why the finding lands as a surprise. Organizations prepare for the clause they were told about. Auditors reach the same subject from a direction nobody anticipated, and a risk management procedure template that would have closed it was never written because Clause 6.1 said it was not needed.
Direct Answer
No, ISO 9001:2015 does not require a documented risk management procedure. Clause 6.1 requires the thinking and the actions, not the document. A risk management procedure template still earns its place because Clause 4.4.1 c) requires determined criteria and methods for the effective operation and control of every process in the quality management system, and risk identification is one of those processes.
The practical consequence is worth stating plainly, because it changes what you write. A risk management procedure template built to satisfy 6.1 is a short document about intent. A risk management procedure template built to satisfy 4.4.1 is a specification for how a repeatable process runs. The second one is what an auditor is actually looking at, and it is considerably harder to write from scratch. It is also the version that connects to everything else: the same discipline appears in ISO 9001 context of the organization work, where the question is not whether context was considered but whether the method for considering it was defined.
Comparison
What the five standards actually require of a risk management procedure template
Five. Standards. Different.
ISO 9001 is the outlier. The other four close the gap directly, and an organization running more than one standard cannot carry a risk management procedure template across without checking, because the clause numbers do not map and the obligations genuinely differ.
| Standard | What it requires of the documented process |
|---|---|
| ISO 9001:2015 | No documented procedure at Clause 6.1. The obligation arrives via 4.4.1 c) — criteria and methods for every process. |
| ISO 13485:2016 | Clause 7.1 requires one or more documented processes for risk management in product realization. Two sentences; the substance lives in ISO 14971. |
| ISO 14001:2026 | Clause 6.1.1 requires the process to be available as documented information, with criteria at 6.1.2. Aspects and risks are two separate documented outputs. |
| ISO 45001:2018 | Clause 6.1.2.2 requires the methodology and criteria defined for scope, nature and timing — held as documented information, maintained and retained. |
| ISO 7101:2023 | Clause 6.1.3 c) requires a defined risk criterion per objective type. Clause 6.1.2 e) requires risk awareness culture to be measured at defined intervals. |
Direct Answer
risk management procedure template requirements differ sharply by standard. ISO 45001:2018 Clause 6.1.2.2 and ISO 14001:2026 Clause 6.1.2 require documented criteria explicitly; ISO 7101:2023 Clause 6.1.3 c) requires a criterion per objective type; ISO 13485:2016 requires the documented process at Clause 7.1 with acceptability governed by ISO 14971:2019. Only ISO 9001 is silent, and Clause 4.4.1 closes the gap.
The ISO 45001 wording that most people miss
Two words in Clause 6.1.2.2 do a great deal of work: maintained and retained. Maintained means the methodology inside the risk management procedure template is a live controlled document, kept current. Retained means the outputs are kept as evidence. Most safety systems retain the assessments and never treat the method itself as a controlled document at all — it sits in a spreadsheet header or in somebody's memory. A risk management procedure template written to ISO 45001 has to put the methodology under document control, which is a document and records control question as much as a safety one. The ISO 45001 revision adds further weight here, with psychosocial hazards moving into scope.
The ISO 7101 requirement no other standard contains
Clause 6.1.2 e) of ISO 7101:2023 requires risk awareness culture to be measured at defined intervals. Not asserted, not encouraged — measured, on a schedule. No other management system standard in common use asks for this, and it is the most quotable line in the healthcare standard. It also raises an uncomfortable question for every other sector: if a risk management procedure template produces a register that only three people have ever seen, in what sense does a risk awareness culture exist? The first international standard for healthcare quality management makes the same argument from the governance side.
For organizations running several standards at once, the interaction is the whole problem, and it is the reason an integrated management system implementation is worth building deliberately rather than by accumulation.
The Criteria Problem
The element almost nobody implements: documented methodology and criteria
Inherited. Unowned. Untested.
Almost every organization has a five-by-five matrix. Almost none has the four things that make it mean anything.
- Severity anchors written as described outcomes rather than adjectives.
- The period over which likelihood is judged, stated on the page.
- Anybody currently employed who can say where the numbers came from.
- A check of what proportion of the score space can actually reach the top band — many matrices are arithmetically incapable of producing a high rating.
This is the element to fix first in any risk management procedure template, and it is worth being careful about why it is missing, because the honest explanation is structural. It is not carelessness, and treating it as carelessness is why improvement efforts here usually fail.
Three structural causes, none of them carelessness
- ISO 9001 said no documented procedure was required, and organizations believed it. They were told the truth about Clause 6.1. Nobody mentioned 4.4.1.
- The matrix is inherited, not authored. It arrived with a template, a consultant, or a predecessor. Because nobody wrote the numbers, nobody owns them, and there is no one to ask what “Moderate” was supposed to mean.
- Nothing fails when it is wrong. An inconsistent matrix produces a plausible register every single time. There is no feedback signal — no alarm, no rework, no complaint — until an auditor asks the question, or until an incident lands whose cause was rated Low.
That third cause is the important one. Most process failures announce themselves. This one is silent by construction, which is why it survives in mature, well-run systems for years. A risk management procedure template that does not force the criteria decision will not surface it either.
An inconsistent matrix produces a plausible register every time. That is not a small problem. It is the reason the problem lasts.
The two-assessor test — the highest-yield hour in the discipline
Here is something you can run this week without buying anything. Take five events that have already happened in your organization — a real incident, a real supplier failure, a real spill, a real complaint. Give the list to two people who both use your risk process. Have them rate each event independently, against your existing criteria. They must not confer.
Then compare. Every disagreement points at an anchor that is perfectly clear to whoever wrote it and ambiguous to everybody else. You are not testing the people; you are testing the definitions. Most organizations running this for the first time find disagreement on three of the five, and the disagreements cluster on severity rather than likelihood, because severity adjectives carry the most unstated assumption.
Why past events and not hypothetical ones: a hypothetical risk lets both assessors imagine a different scenario, so a disagreement tells you nothing. An event that already happened is fixed. If the ratings still diverge, the criteria are the only variable left. This is also why the test belongs in a risk management procedure template rather than in training — it produces a record of what was ambiguous and what was changed.
The fastest way to test a risk management procedure template is the two-assessor test: have two people independently rate five events that have already happened, without conferring, then compare. Every disagreement identifies a severity or likelihood anchor that is clear to its author and ambiguous to everyone else. It takes an afternoon and it is the highest-yield diagnostic in the discipline.
If you want to go deeper on which method to choose once the criteria are settled, MSI's comparison of risk assessment methodologies covers selection across the common approaches. The Portrait is a different instrument again — an independent read on how the process behaves in practice rather than how the document describes it.
Worked Example One
The two-dollar connector: low value, high exposure
Cheap. Critical. Invisible.
A molded connector. Low unit cost, dual-sourced, entirely unremarkable — and sitting in the fluid path of a Class II infusion accessory. Ranked by spend it falls in the bottom quartile of the supplier base and receives the lightest control the system offers: no audit, no change agreement, an annual certificate on file.
Now read the clause. ISO 13485:2016 Clause 7.4.1 names three things supplier criteria must reflect: the effect on the quality of the medical device, the risk associated with the device, and applicable regulatory requirements. Purchase value is not among them. The categorization that put this connector in the lightest tier was not a lenient reading of the clause — it was an answer to a question the clause never asked.
A risk management procedure template that never asks the effect question has no mechanism to catch it. What happens next is ordinary. The supplier changes a process aid — a mold release, a purge compound — and does not notify anybody, because the purchase specification names only the base polymer and the dimensional tolerances. Nothing in the agreement obliged them to tell you. An unqualified residue is now on the fluid path of a device, and no incoming inspection is looking for it because nobody wrote down that they should.
A risk management procedure template that routes on criteria rather than value catches this on the first question — does patient contact or device performance depend on this item? — and routes it upward regardless of price. Criteria-based routing costs nothing extra to operate. It asks a different question, once, at intake. The same argument runs through MSI's treatment of the purchasing and supplier control procedure, where rating providers on spend is the single most common structural error.
The regulatory weight of this changed on February 2, 2026. The FDA Quality Management System Regulation now incorporates ISO 13485:2016 by reference into 21 CFR Part 820, which makes supplier records, risk records and the decisions behind them federally inspectable. MSI covers the shift in detail in its analysis of the QMSR and ISO 13485 alignment, and the device-side reading of risk in the medical device cybersecurity pillar.
Direct Answer
A risk management procedure template should route on effect, never on value. ISO 13485 Clause 7.4.1 requires supplier criteria to reflect the effect on device quality, the risk associated with the device, and regulatory requirements — purchase price is not among them. A two-dollar connector in a fluid path carries exposure that no financial threshold can detect.
Worked Example Two
The bund that created a hazard: when two systems both stay right
Solved. Shifted. Silent.
Different shape entirely. The first example was about how an item is ranked. This one is about how two systems fail to talk.
After a spill, an organization installs a bunded chemical store. The environmental entry closes cleanly and correctly: containment in place, receptor protected, rating drops from significant to low, action verified, register updated. By every environmental measure this is a well-run control implemented well.
Nine months later a technician is injured lifting a two-hundred-liter drum over the six-hundred-millimeter bund wall. The loading ramp was value-engineered out during design, and manual handling at the new store was never assessed — because it was an environmental project, with an environmental budget, an environmental owner, and an environmental register.
Both systems were correct on their own terms. The environmental assessment was right. The safety assessment was never wrong, because it never happened. The failure was in the space between two registers that had no obligation to look at each other.
No risk management procedure template written to a single discipline will ever surface this. This is not an exotic scenario. Controls migrate between safety and environment constantly — a ventilation change alters emissions, a containment change alters manual handling, a substitution for an environmental reason introduces a new health hazard. In separate systems they migrate silently. A risk management procedure template that includes a cross-discipline check at the treatment step — does this control create or move a risk in another discipline? — is the cheapest control in the whole document, and it is one line.
It is also where integrated management earns its keep on the operational side rather than the paperwork side. The seams between disciplines are where the exposure sits, and no single-standard risk management procedure template will find them.
Keep the two examples apart in your own thinking. One is a ranking failure inside a single system. The other is an interface failure between two correct systems. They need different fixes: the first needs criteria, the second needs a handoff. A risk management procedure template that only addresses the first will leave the second entirely open.
Opportunity
Opportunity: required by four standards out of five, implemented by almost nobody
Required. Structural. Absent.
ISO 9001 Clause 6.1.1 b), ISO 14001 Clause 6.1.4, ISO 45001 Clause 6.1.2.3 and ISO 7101 Clause 6.1.3 all require opportunities to be determined. Four out of five.
ISO 13485 has no opportunity concept anywhere in the standard. That is worth stating plainly because it surprises nearly everyone, and because it creates a real problem for device organizations running a quality system derived from an ISO 9001 base. If you hold both, opportunities are an ISO 9001 obligation that belongs in the quality register — and they must never be filed into the ISO 14971 risk management file, which has a different audience, a different purpose and a regulator reading it.
Why the requirement is asserted rather than met
The structural explanation is a form. In almost every register ever built, opportunity is a column beside risk. And a column beside a risk can only ever hold the mirror image of that risk — “risk: supplier fails; opportunity: find a better supplier.” The structure makes a standalone opportunity physically impossible to record. There is nowhere to put one.
So none get recorded, and no risk management procedure template built on that form will change the outcome. And the organization draws the reasonable conclusion that it does not have opportunities, rather than the correct one — that its form has no room for them. A risk management procedure template that gives opportunity its own entry route, its own trigger and its own owner produces different content within a month.
The one-minute audit test
Show me an entry in your opportunity record that did not begin as a risk.
If there is none, the requirement is being asserted rather than met. It takes a minute, it needs no preparation, and it is the fastest conformity check in this article. Run it before your next internal audit planning cycle, because the answer changes what the register is for.
Direct Answer
No, ISO 13485 does not require opportunities to be identified — the standard contains no opportunity concept at all. ISO 9001 6.1.1 b), ISO 14001 6.1.4, ISO 45001 6.1.2.3 and ISO 7101 6.1.3 all do. A risk management procedure template for a dual-certified device organization should route opportunities into the quality register and never into the ISO 14971 risk management file.
Maturity
The eight elements of a mature risk identification process
Eight. Elements. Four levels.
Across 200+ audits attended in 28 years, MSI client experience suggests that organizations with a risk management procedure template that works in practice tend to be strong on the same eight elements, and organizations that struggle tend to be weak on the same ones. Naming them separately matters, because it stops the improvement conversation collapsing into a single verdict. Most organizations are not uniformly weak — they are strong on identification and weak on review, or the reverse, and knowing which is what changes what you do on Monday. The free Risk, Aspect and Job Hazard Maturity Check scores all eight.
- Trigger coverage — every route a risk can enter by, written down.
- Scope and boundary — what the process covers and what it deliberately excludes.
- Criteria — severity and likelihood as described outcomes, with the period stated.
- Consistency — whether two competent assessors reach the same rating.
- Treatment routing — decisions becoming actions with owners and dates.
- Acceptance and residual risk — who decided, on what basis, recorded.
- Review — event-based triggers, calendar as backstop only.
- Interfaces — corrective action, change control, management review, audit.
Each is scored across four levels — Documented, Controlled, Measured, Anticipatory — described as observable behavior rather than intention. Worth saying outright: Controlled is a legitimate place to stop. Conformity is a threshold, not a destination, and a risk management procedure template that pushes every element to the top rung is describing a system nobody will run.
Two interfaces deserve specific attention because they fail most often. Corrective action feeds risk: ISO 9001 Clause 10.2.1 e) requires the organization to update risks and opportunities determined during planning, if necessary, as part of corrective action — which means a risk management procedure template and a corrective action procedure that never exchange information are both incomplete. And management review closes the loop: Clause 9.3.2 e) makes the effectiveness of actions taken to address risks and opportunities a required input, so the register has to reach the table as data. MSI's ISO 13485 management review playbook covers what that review actually has to contain.
Change control is the third. A risk management procedure template that is not triggered by change will be current only until the next process modification, which is why change management and risk belong in the same conversation.
A mature risk management procedure template is strong across eight elements: trigger coverage, scope and boundary, criteria, consistency between assessors, treatment routing, acceptance and residual risk, event-based review, and the interfaces to corrective action, change control, management review and internal audit. Scoring them separately prevents the improvement effort collapsing into one undifferentiated verdict.
2026
What changes for a risk management procedure template in 2026
Published. Pending. Now.
Three things moved this year, and one is still moving. Each of them changes what a risk management procedure template has to say. If you are writing or revising a risk management procedure template, writing it to the current editions now is considerably cheaper than retrofitting it twice.
- QMSR took effect February 2, 2026, amending 21 CFR Part 820 to incorporate ISO 13485:2016 by reference. The FDA moved to a risk-driven, lifecycle-based inspection approach the same day. Design-control-exempt Class I devices still need risk records for production, purchasing and labeling — a point that catches organizations who read the design-control exemption too broadly.
- ISO 14001:2026 published April 15, 2026, with a three-year transition. It requires two separate documented outputs — environmental aspects at Clause 6.1.2 and risks and opportunities at 6.1.4 — which a single combined register does not satisfy.
- ISO 9001:2026 reached FDIS in April 2026; the ballot closed July 9, 2026, with publication anticipated September 2026 and a three-year transition expected. The technical content is frozen, but the draft text is not public and should not be quoted.
- ISO 19011:2026 published May 27, 2026 and immediately withdrew the 2018 edition — no transition period. Any risk management procedure template citing ISO 19011:2018 in its references is citing a withdrawn document.
On transition dates, sources vary slightly on the exact ISO 14001 deadline, commonly reported as the end of April 2029. Treat your accreditation body's transition document as governing rather than any secondary summary, and note that Global Accreditation Cooperation Incorporated replaced IAF and ILAC effective January 1, 2026, so oversight of how these clauses are assessed now sits with a single cooperation body. ANAB remains the accreditation body for many US certificate holders. MSI's guidance on running the ISO 9001 and 14001 transition as one project applies directly here.
The environmental side carries the largest change to identification practice. The ISO 14000 family brings biodiversity, ecosystem health, pollution and resource availability into scope as conditions requiring evaluation, which means aspects registers built in 2015 are structurally incomplete rather than merely out of date — a point covered in MSI's work on biodiversity and ISO 14001:2026 and on Clause 4.1 in the 2026 edition. The official ISO 14001:2026 brochure explains the revision's intent in ISO's own words.
Direct Answer
For 2026, a risk management procedure template should be written to QMSR (effective February 2, 2026), ISO 14001:2026 (published April 15, 2026, with aspects at 6.1.2 and risks and opportunities at 6.1.4 as separate documented outputs), and ISO 19011:2026 rather than the withdrawn 2018 edition. ISO 9001:2026 is expected in September 2026; do not build to draft text.
Regulation
Why a conforming register is not an OSHA certification
Register. Certification. Different.
One trap worth naming, because a risk management procedure template written to ISO 45001 alone will walk straight into it in the United States.
OSHA 29 CFR 1910.132(d)(2) requires a written certification that the workplace hazard assessment has been performed, and it names four elements the certification must contain: the workplace evaluated, the person certifying that the evaluation has been performed, the date or dates of the assessment, and identification of the document as a certification of hazard assessment. OSHA has issued interpretation letters confirming the same four elements.
No ISO clause requires this. A fully conforming ISO 45001 risk register is not an OSHA certification, and an organization holding a clean certificate can still be cited. The fix is a single appendix to the risk management procedure template: a certification page carrying those four elements, generated from the same assessment. It costs one form. Its absence is a common citation.
Direct Answer
No. A conforming ISO 45001 register does not satisfy OSHA 29 CFR 1910.132(d)(2), which requires a separate written certification identifying the workplace evaluated, the person certifying, the date or dates, and the document's identity as a certification of hazard assessment. A risk management procedure template used in the United States should generate that certification as an output of the same assessment.
Where To Start
Three routes to a working risk management procedure template
Score first. Fix second. Buy last.
There is no single right way to arrive at a working risk management procedure template. If you are building from scratch, the order that works is criteria first, then triggers, then treatment routing, then everything else. The first two are load-bearing: improvements to review or interfaces do not hold if risks never enter the process or are rated on an undefined basis.
Start free · No email required
Find out which of the eight elements is costing you most
Score. Diagnose. Decide.
The free Risk, Aspect and Job Hazard Maturity Check scores your identification process across the eight elements above — four levels each, about six minutes, five standard paths, rated on how the process behaves on a busy week rather than how the document describes it. Your score and band appear immediately, without entering anything. There is a genuine Controlled band that tells you to stop, because an assessment that fails everyone is not an assessment.
If you would rather start from a complete document, MSI's ISO procedure templates and guides are working procedures written as filled-in worked examples rather than outlines — editable Microsoft Word, built to a sixteen-section architecture, with the judgment calls already made and annotated from 200+ audits attended. Each carries its records, its register, a desk-level work instruction and the same eight-element maturity ladder the free check scores you against. Choose your standard: ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001 or ISO 7101.
There is also a route that builds the document with you rather than handing it over. MSI's Catch. Correct. Continually Improve. course walks through building four connected procedures at once — risk management at Clause 6.1, nonconformity at 8.7 and 10.2, corrective action at 10.2, and continual improvement at 10.3. Those four are the ones most often written in isolation and then found, at the third surveillance visit, not to talk to each other. Building a risk management procedure template alongside the three procedures it has to interface with is what stops findings recurring.
If the result surprises you, or the priority order does not match what you expected, a conversation is usually quicker than a rewrite. MSI's ISO consulting practice has supported 80+ certifications and attended 200+ audits across 28 years, and a planning session on 760-434-9141 will tell you in half an hour whether your risk management procedure template needs repair or replacement. You can also watch the ISO Executive Decision Briefs — short leadership-level videos on what a management system is supposed to produce — or read about The Portrait, MSI's independent operational assessment. For organizations building from the ground up, SurePath is the turnkey route; SureResults keeps the system current once it is running.
New to the family of standards entirely? Start with MSI's plain-language explanation of what ISO actually is, or the leadership-level view in ISO 9001:2026 for boardrooms. For environmental programs specifically, ISO 14001 continual improvement covers the improvement loop this process feeds.
FAQ
Frequently asked questions
Ask. Answer. Apply.
Does ISO 9001 require a documented risk management procedure?
No. Clause 6.1 of ISO 9001:2015 requires the organization to determine risks and opportunities, plan actions and integrate them into its processes — it does not require a documented procedure, a register or a methodology. The obligation arrives from Clause 4.4.1 c), which requires determined criteria and methods for the effective operation and control of every process in the quality management system. Risk identification is such a process, so a finding is written against 4.4.1 rather than 6.1, which is why it surprises organizations that prepared for the wrong clause.
Is a risk register the same as a risk management file?
No, and they should never be merged. A quality risk register serves the management system and its auditors. An ISO 14971 risk management file serves the device, its regulator and its notified body, and has a defined structure and lifecycle of its own. Merging them produces a document that serves neither audience and exposes management system content to regulatory review that was never intended for it. Connect them with a flag on any register entry that touches a device, rather than combining the two.
Does ISO 13485 require opportunities to be identified?
No. ISO 13485:2016 contains no opportunity concept anywhere in the standard, which surprises most people who come to it from ISO 9001. If you hold both certifications, ISO 9001 Clause 6.1.1 b) applies and opportunities belong in the quality register. They should never be recorded in the ISO 14971 risk management file.
Can I use one risk matrix for quality, environmental and safety?
Not without qualification. The receptors differ — a customer, an ecosystem and a worker are not interchangeable — so a single severity scale will either trivialize injury or overstate a delivery delay. A workable approach is one shared likelihood scale with a stated period, and separate severity anchors per discipline, all held in the same procedure so the interfaces stay visible.
Is a five-by-five matrix acceptable?
Yes, provided the anchors are described outcomes rather than adjectives and the likelihood period is stated on the page. The matrix size is not the issue. Worth checking one thing: what proportion of your score space can actually reach the top band? Some matrices are arithmetically incapable of producing a high rating, which means the organization has never once been told it has a serious risk.
What does “maintained and retained” mean for risk criteria under ISO 45001?
Clause 6.1.2.2 requires the methodology and criteria to be held as documented information that is both maintained and retained. Maintained means the method itself is a live controlled document, kept current and under change control. Retained means the assessment outputs are kept as evidence. Most organizations do the second and not the first, leaving the method in a spreadsheet header that no document control process has ever seen.
Do design-control-exempt Class I devices need risk records?
Yes. Under the QMSR, effective February 2, 2026, the exemption applies to design controls specifically — it does not remove risk obligations across production, purchasing and labeling. Organizations reading the exemption broadly and concluding that no risk records are required for exempt Class I devices are reading it more widely than it is written.
How often should a risk register be reviewed?
On named events, with a calendar interval only as a backstop. Useful triggers include a process or equipment change, a new or changed supplier, an incident or near-miss, a complaint, a regulatory change, an audit finding and a change of process owner. An annual-only cycle describes the organization as it was at the last review, which for most of the year is a description of somewhere that no longer exists.
References
- ISO 9001:2015 — Quality management systems, Clauses 4.4.1 and 6.1
- ISO 13485:2016 — Medical devices, Clauses 7.1 and 7.4.1
- ISO 14001:2026 — Environmental management systems, Clauses 6.1.1, 6.1.2 and 6.1.4
- ISO 45001:2018 — Occupational health and safety, Clause 6.1.2.2
- ISO 7101:2023 — Healthcare organization management, Clauses 6.1.2 e) and 6.1.3
- ISO 14971:2019 — Application of risk management to medical devices
- ISO 31000:2018 — Risk management guidelines (reviewed and confirmed 2023)
- ISO 19011:2026 — Guidelines for auditing management systems, published May 27, 2026
- ISO 14001:2026 brochure — ISO's own summary of the revision
- ISO 14000 family — environmental management standards overview
- OSHA 29 CFR 1910.132 — hazard assessment and written certification
- OSHA standard interpretation, March 28, 2024 — the four certification elements
- FDA Quality Management System Regulation — effective February 2, 2026
- 21 CFR Part 820 — Quality Management System Regulation, eCFR
- Global Accreditation Cooperation Incorporated — replaced IAF and ILAC on January 1, 2026
- ANAB — ANSI National Accreditation Board
- ANSI on ISO 7101:2023 — the first international healthcare quality standard
About MSI
Diana Lynn is President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she co-founded in 1998. With 28 years of experience, including extensive AS9100 implementation work in MSI’s early years, MSI’s track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, ISO 45001, and ISO 7101. MSI is veteran-owned and female-owned.
To talk through your own process, call 760-434-9141 or visit msi-international.com.
This article is general guidance and does not replace ISO 9001:2015, ISO 13485:2016, ISO 14001:2026, ISO 45001:2018, ISO 7101:2023, ISO 14971:2019, any applicable regulation, or the judgment of a competent professional. Standards are revised, amended and withdrawn; confirm the current status of your standard at iso.org before relying on clause references. Clause references were verified on July 21, 2026.