We use essential cookies to make the site work and, if you allow it, aggregated analytics cookies to improve the content. We do not use marketing cookies.
Clause 6.1 introduced risk-based thinking. You can meet it with a well-built matrix — no full ERM system required.
ISO 9001:2015 replaced "preventive actions" from the 2008 version with "risk-based thinking." Many companies interpreted this as needing a full ERM system. Not so. Clause 6.1 requires identifying risks relevant to QMS objectives and acting on them.
Two sub-requirements:
The standard doesn't require a probability-vs-impact matrix, ERM software, or a specific methodology. It requires evidence that risks are identified and actions planned.
For an industrial SMB, three levels cover 90% of what's auditable:
Don't mix levels. A process risk escalated to management review becomes noise.
Recommended columns:
| Risk | Context | Probability | Impact | Action | Owner | Date |
|---|---|---|---|---|---|---|
| Turnover > 20% in production | Cl. 4.1 | High | High | Retention plan H1 | HR | 2026-03-31 |
| CNC press failure | Cl. 7.1.3 | Medium | High | Maintenance plan | Maintenance | 2026-02-15 |
Probability and impact can be qualitative (high/medium/low). The auditor doesn't require a numeric scale; they require consistency.
The clause also requires identifying opportunities. Typical examples:
A matrix listing only threats is incomplete.
Clause 6.1.2 requires integrating actions into the QMS. It's not a parallel list. Risks must appear in:
If the matrix lives in a standalone spreadsheet, integration fails.
Review your current risk matrix. When was the last update? How many risks have an overdue date with no closure? Do any appear as quality objectives? If any answer makes you uncomfortable, spend 90 minutes fixing those three points. Passing the audit is a consequence, not the goal.
A Visio process map isn't a process approach. How to translate clause 4.4 into something that operates every day.
Clause 8.5.1 requires operational control. A well-written SOP is just the start. The next leap is automated recording from the ERP.
Clause 4 is the QMS foundation. Done badly, the whole system stays generic. Here's how to ground it in an industrial SMB.