Risk-based thinking is the requirement, expressed through clause 6.1, to determine the risks and opportunities that need to be addressed to give the management system its best chance of achieving intended results.
What it replaced
ISO 9001:2008 had a separate clause for preventive action. The 2015 revision removed it — not because prevention stopped mattering, but because prevention had become a reactive procedure invoked after the fact. Risk-based thinking moves it into planning, where it belongs.
It is not formal risk management
ISO 9001 does not require a risk register, a risk matrix, FMEA, or any specific methodology. It does not require documented information about the risk process at all. What it requires is that risks and opportunities are determined, that actions to address them are planned and integrated into the system, and that the effectiveness of those actions is evaluated.
Many organisations adopt a register because it is a convenient way to demonstrate this. That is a choice, not a requirement.
Opportunities are not just upside risks
The standard treats opportunities as a distinct concept — new markets, new customers, new partnerships, new technology, improved efficiency. Systems that treat the opportunity column as “risks we might benefit from” have usually missed the intent.
A change coming in the 2026 revision
Certification bodies working from the final draft consistently report that risks and opportunities are separated into distinct subclauses in ISO 9001:2026. Practically, that means a single combined risk-and-opportunity register will need reworking. If you are building a system now, splitting them from the start costs nothing and saves that rework.