ISO 9001:2026 Risk Management: Evolution from 2015 Requirements

Blog

ISO
9001:2026 Risk Management: Evolution from 2015 Requirements

The Risk Register Nobody
Read

I once audited a manufacturing company that had a 94-row risk
register. Beautifully formatted. Color-coded risk levels. Detailed
mitigation columns. The register had been created by a consultant during
their ISO 9001:2015 implementation and updated exactly twice in three
years — both times the week before a certification audit.

When I asked the production manager about the top three risks in his
area, he said: “I don’t know. The risk register lives in the quality
department.” When I asked the quality manager when she’d last reviewed
it, she said: “Before the last audit. We need to update it again before
the next one.”

That risk register represented everything wrong with how most
organizations approach risk-based thinking. It was a document created to
satisfy an auditor, not a tool used to manage a business. ISO 9001:2026
significantly deepens the risk management requirements — not by making
them more complex, but by making them more real. The standard is pushing
organizations away from risk registers as paperwork and toward risk
management as daily practice.


Where 2015 Left Off

ISO 9001:2015 introduced “risk-based thinking” as a replacement for
the old preventive action clause. It was a well-intentioned change that
aimed to integrate risk management into the fabric of the QMS rather
than treating it as a separate process.

In practice, most organizations interpreted risk-based thinking as
“create a risk register, review it occasionally, and mention risk in
management review minutes.” The standard’s language was deliberately
flexible — it said to “determine risks and opportunities” without
specifying methodology, depth, or frequency. This flexibility was both
its strength and its weakness. Organizations with mature risk cultures
thrived. Organizations checking a box created risk registers that
gathered dust.

The 2026 edition doesn’t eliminate the flexibility. It still doesn’t
mandate a specific risk management methodology like FMEA or ISO 31000.
But it significantly sharpens the expectations in four areas: depth,
integration, monitoring, and organizational knowledge.


What 2026 Changes: The
Four Dimensions

Dimension 1: Depth of Risk
Analysis

2015 expectation: Identify risks and opportunities
relevant to your QMS.

2026 expectation: Identify, analyze, and evaluate
risks at a level of detail sufficient to inform action. The standard
expects you to go beyond “what could go wrong?” to “how likely is it,
how severe would the impact be, and what are we doing about it?”

This means your risk analysis needs:

Risk identification with context. Don’t just list
risks — describe them with enough specificity to be actionable. “Supply
chain risk” is not a risk. “Single-source dependency for critical
component X, where the supplier is located in a region with increasing
geopolitical instability” is a risk.

Risk analysis methodology. You need a consistent
approach to analyzing risks. This could be a simple probability-impact
matrix, a structured FMEA, or a full ISO 31000 process. The standard
doesn’t prescribe the method, but it expects consistency.

Risk evaluation criteria. Define what makes a risk
acceptable or unacceptable. This requires decision criteria — typically
a combination of probability, impact, and detection capability. Without
evaluation criteria, every risk is just a list item with no
priority.

I implemented a three-tier risk evaluation at SNOP that worked
well:

Risk Level Probability Impact Action Required
Red High or Medium Severe or Major Immediate mitigation plan, monthly review
Amber Medium Moderate Mitigation plan within 90 days, quarterly review
Green Low Minor to Moderate Monitor, annual review

This simple framework — one page, understood by everyone — drove more
meaningful risk management than any consultant-produced risk register
I’ve ever seen.

Dimension 2:
Integration into Daily Operations

2015 expectation: Consider risks when planning the
QMS.

2026 expectation: Risk-based thinking must be
demonstrably integrated into operational decisions — not just strategic
planning.

This is where most organizations will feel the gap. The auditor isn’t
just looking for a risk register anymore. They’re looking for evidence
that risk thinking influences:

Production planning: Do you consider quality risks
when scheduling production — new product introductions, process changes,
personnel changes on critical operations?

Supplier selection: Do risk evaluations factor into
supplier approval and ongoing sourcing decisions?

Change management: When you change a process,
material, or supplier, do you assess the quality risks before
implementing the change?

Corrective action: When you investigate a
nonconformity, do you assess whether the root cause creates broader
risks beyond the immediate problem?

Resource allocation: Do risk evaluations inform
decisions about where to invest in quality improvement, training, or
technology?

The evidence the auditor wants to see isn’t a risk register — it’s
risk-based decisions documented in management meeting minutes,
engineering change records, supplier approval files, and production
planning documents.

Dimension 3: Risk
Monitoring and Review

2015 expectation: Monitor and review risks and
opportunities.

2026 expectation: Risk monitoring must be
systematic, documented, and connected to both management review and
continuous improvement.

This means:

Defined review frequency. Critical risks reviewed
monthly. Significant risks reviewed quarterly. Full risk register
reviewed at management review. These frequencies should be defined in
your risk procedure — not left to discretion.

Triggered reviews. Certain events should trigger an
automatic risk review: new product introductions, significant process
changes, supplier changes, customer complaints indicating systemic
issues, external events (regulatory changes, geopolitical shifts,
climate events).

Effectiveness measurement. Are your risk mitigation
actions actually reducing risk? If you implemented a mitigation three
months ago, has the risk level decreased? Too many organizations add
mitigations to the register and never check if they worked.

Connection to opportunities. The 2015 standard
linked risks and opportunities. The 2026 edition deepens this
connection. For every significant risk, ask: “Is there an opportunity
here?” A supply chain risk might reveal an opportunity to diversify
suppliers in a way that improves both resilience and cost.

Dimension 4: Risk
and Organizational Knowledge

2016 expectation: Implicit connection between risk
management and organizational learning.

2026 expectation: Explicit connection. Risks
identified through experience must be captured in organizational
knowledge. Lessons learned from risk events must feed back into the risk
management process.

This creates a closed loop:

  1. Risk identified → added to risk register
  2. Risk materializes → nonconformity or incident
    occurs
  3. Root cause investigated → deeper understanding
    gained
  4. Lesson captured → organizational knowledge
    updated
  5. Risk register updated → risk re-evaluated with new
    information
  6. Mitigation improved → risk level reduced
  7. Monitoring continues → cycle repeats

This closed-loop approach transforms risk management from a periodic
exercise into a continuous learning system. At Airbus, we implemented
this loop using a simple “risk event log” — every time a risk
materialized, the event was logged, investigated, and fed back into the
risk register. Over two years, the log became our most valuable quality
knowledge asset.


The Practical Risk
Management Framework

Here’s the framework I implement with clients who are transitioning
to ISO 9001:2026. It’s designed to be practical, not bureaucratic.

Monthly Risk Review (15
Minutes)

Every month, the quality team reviews: – Any new risks identified
during the month – Status of existing mitigation actions – Any risk
events that occurred (risks that materialized) – Changes in risk levels
based on new information

This is a working session, not a meeting. Fifteen minutes, focused on
action items.

Quarterly Risk Review (60
Minutes)

Every quarter, the leadership team reviews: – Top 10 risks and their
current status – Effectiveness of mitigation actions – Emerging risks
from internal and external sources – Risk trends over time

This review feeds directly into the management review cycle.

Annual Risk Assessment (Half
Day)

Once a year, conduct a comprehensive risk refresh: – Reassess all
identified risks – Identify new risks through structured brainstorming –
Validate risk evaluation criteria – Align risk management with strategic
objectives – Update the risk register

The annual assessment is a facilitated workshop — not a solo quality
manager exercise.


Common Risk Management
Mistakes

The “Everything Is a Risk” Trap. If your risk
register has 200 items, nothing is a priority. I’ve seen registers so
comprehensive that they became useless. Aim for 15–25 significant risks
that are actively managed. Document lesser risks separately if needed,
but don’t clutter your active management focus.

The “Set and Forget” Syndrome. A risk identified and
never reviewed is worse than no risk management at all — it creates
false confidence. Every risk needs a review date and a responsible
owner.

The “Mitigation Illusion.” Writing “training will be
provided” as a mitigation doesn’t reduce risk. Training delivered,
verified as effective, and demonstrated in practice reduces risk. Track
mitigation effectiveness, not just mitigation plans.

The “Quality Department Risk Register.” If risks are
only discussed in the quality department, they’re not being managed —
they’re being documented. Risk management is a leadership
responsibility. The quality team facilitates; the organization acts.


Risk Management as
Competitive Advantage

Here’s the thing about risk management that most organizations miss:
it’s not just about preventing bad things. It’s about being faster,
smarter, and more resilient than your competitors.

Organizations with mature risk management: – Respond faster to supply
chain disruptions because they’ve already identified the vulnerabilities
– Make better investment decisions because they understand the
risk-reward trade-offs – Recover faster from quality incidents because
their crisis response is pre-planned – Adapt faster to market changes
because their risk monitoring catches trends early

ISO 9001:2026 is pushing risk management from a compliance exercise
to a business capability. The organizations that embrace this shift will
find that risk management isn’t a cost — it’s a competitive
advantage.


About the Author

Peter Stasko is a Quality Director with 20+ years of
experience leading quality management systems across the automotive and
aerospace industries. He has implemented and transitioned ISO 9001
systems at Airbus, SNOP, and WITTE Automotive, and has served as a lead
auditor for IATF 16949 and ISO 9001 certifications across European
manufacturing operations. Peter specializes in practical, no-nonsense
QMS architecture — building systems that work in production
environments, not just on paper.

Peter Stasko

Scroll top