Insight
Risk vs Opportunity: Why ISO 9001:2026 Splits Them Apart
In the 2015 edition of ISO 9001, risks and opportunities lived in one combined clause. The FDIS splits them — and turns separate thinking into a documentation requirement.
When ISO 9001:2015 introduced risk-based thinking, it gathered risks and opportunities into a single clause: 6.1. Organizations were asked to determine and address both. Most rose to the risk half of the requirement. Few applied equally serious treatment for opportunity. Risk registers proliferated; opportunity registers did not.
The FDIS revisits this. Clause 6.1 splits into three sub-clauses:
- 6.1.1 — Determine risks and opportunities
- 6.1.2 — Actions to address risks
- 6.1.3 — Actions to address opportunities
This is the cleanest, most concrete technical change in the revision. It is also one of the most consequential for documentation practice.
What Changes in Practice
The split is not symbolic. It carries through to clause 9.1.3 (analysis and evaluation), where effectiveness of actions taken to address risks must be evaluated separately from effectiveness of actions taken to address opportunities. The implication: a single combined register, with combined effectiveness measures, will likely not survive an audit against the revised clauses.
Most existing risk registers will need an opportunity twin. The twin does not need to be a separate document — it could be a section, a tab, a parallel set of rows — but it does need to be visible as a distinct stream of work, with its own identification, analysis and evaluation, planned actions, designated owners and effectiveness review.
Risk and Opportunity Are Not Opposites
A common confusion is that opportunity is just the inverse of risk. It is not. The cleanest working definitions track to the desired-effect framing implied by the FDIS:
- A risk is a potential undesired effect on intended QMS results.
- An opportunity is a potential desired effect on intended QMS results.
Risk asks: what could go wrong or reduce our ability to conform and satisfy customers? Opportunity asks: what could improve our ability to perform, conform, adapt or satisfy customers?
Some examples of properly paired thinking:
- Risk: single-source supplier instability for a critical component. Opportunity: supplier diversification that improves delivery resilience and shortens recovery time after disruption.
- Risk: knowledge concentrated in a small number of senior staff who are approaching retirement. Opportunity: a structured knowledge-capture program that builds redundancy and reduces single-point dependence.
- Risk: customer complaints concentrated around a particular service handoff. Opportunity: a redesigned handoff that reduces complaint volume and improves customer satisfaction scores.
Notice that the opportunities are not simply "reduce the risk." They are positive, value-creating moves. That distinction is what the FDIS clause separation is asking organizations to make routinely visible.
Setting Up a Parallel System Without Overbuilding
The most common over-correction is to build a parallel opportunity register that mirrors the risk register's structure and ends up filled with opportunities that are really business-as-usual improvement ideas. A better starting point:
- Begin with a small number of substantive opportunities — five to 10 — drawn from current strategic priorities, recent management review outputs or known improvement programs.
- Treat them with the same discipline as risks: owner, planned action, expected outcome, effectiveness measure, review date.
- Resist the temptation to log every improvement idea. The clause is about substantive opportunities tied to intended QMS results, not a wish list of optimizations.
Effectiveness Review is Where Many Will Trip
Clause 9.1.3 in the FDIS asks organizations to evaluate the effectiveness of actions taken — separately, for risks and for opportunities. In practice, this means two different things:
- For risks, effectiveness is typically a downstream metric: did the risk materialize less often, or with less impact, than before the action?
- For opportunities, effectiveness is typically a value metric: did the desired effect on QMS results occur, and is it sustained?
Both will need indicators, ownership and a review cadence. Management review (clause 9.3) becomes the natural place to land these conversations, but the inputs to management review will need to evolve to support them.
A Practical Sequence
For most organizations, the preparation work in this area follows a clean order:
- Refresh the risk register against intended QMS results.
- Identify five to 10 substantive opportunities tied to the same intended results.
- Define effectiveness measures for each.
- Update management review inputs to bring both streams to the table.
- Run one cycle internally before the surveillance audit cycle covers it.
Plan the Transition
Access the ABS QE ISO 9001:2026 Transition Roadmap, a 12-page guide covering all six changes, a clause-by-clause gap assessment framework, a maturity model for scoring your current QMS, sample action plans with priorities and owners and a suggested four-phase timeline running from now through the transition window.

