Skip to main content
Category: Risk Assessment and Treatment

Actions to Address Risks and Opportunities

Also known as: Clause 6.1, Risk and Opportunity Actions
Simply put

This is a management system requirement that asks an organization to identify the risks and opportunities that could affect its objectives and then plan concrete actions to deal with them. Rather than reacting to problems after they occur, the organization builds these actions into its normal processes. In an ISO management system, this is set out in Clause 6.1 of the requirements.

Formal definition

Clause 6.1 ("Actions to Address Risks and Opportunities") is part of the certifiable management system requirements. It requires an organization to determine the risks and opportunities relevant to its intended outcomes, plan actions to address them, and integrate those actions into its management system processes, then evaluate their effectiveness. The evidence provided references this clause primarily in the context of ISO 9001, where it replaces the older concept of preventive action; the specific approach, documentation, and integration of these actions typically depend on the organization's scope, existing processes, and risk assessment. Note that the evidence supplied does not establish the precise wording or numbering of this requirement within ISO/IEC 27001, so any cross-reference to the ISMS standard should be confirmed against the applicable edition of that standard.

Why it matters

Actions to Address Risks and Opportunities represents a shift in how management systems handle uncertainty. Rather than waiting for problems to surface and then correcting them, the requirement asks an organization to anticipate what could affect its objectives and to build responses into its normal processes. In the evidence provided, this concept is described primarily in the context of ISO 9001, where it formally replaces the older idea of preventive action. The practical effect is that risk thinking becomes a planned, ongoing activity rather than an occasional exercise triggered by incidents.

For GRC and compliance professionals, the value of this clause lies in its integration mandate. The sources emphasize capturing risk and opportunity information through existing mechanisms such as audits and toolbox talks, and folding the resulting action plans into processes the organization already runs. This reduces the tendency to treat risk management as a standalone document that lives apart from day-to-day operations, which is a common weakness auditors look for. Because risks exist across all systems, processes, and functions, an approach that is embedded is more likely to be sustained and evidenced over time.

It is worth noting a scope limitation. The evidence supplied references Clause 6.1 chiefly in relation to ISO 9001, and it does not establish the precise wording or numbering of an equivalent requirement within ISO/IEC 27001. Practitioners working toward ISO 27001 certification should confirm the applicable clause language and structure against the current edition of that standard rather than assuming direct equivalence. The general principle, determine risks and opportunities, plan actions, integrate them, and evaluate their effectiveness, is a recognizable feature of ISO management system standards, but the specific requirement text varies by standard and edition.

Who it's relevant to

GRC and Compliance Managers
Those responsible for building and maintaining a management system will use this requirement to structure how risks and opportunities are identified, planned for, and tracked. The emphasis on integrating actions into existing processes helps compliance managers avoid creating disconnected documentation and instead demonstrate that risk thinking is embedded in operations.
Internal and Certification Auditors
Auditors assessing a management system will look for evidence that the organization has determined its risks and opportunities, planned corresponding actions, and evaluated their effectiveness. Since this clause replaces the older concept of preventive action in the ISO 9001 context, auditors familiar with that transition can assess whether the shift to proactive, integrated risk handling has genuinely taken hold rather than existing only on paper.
Process and Quality Owners
Individuals who own specific processes are often the ones who capture risk and opportunity information through everyday activities such as audits and toolbox talks. Because risks exist across all systems, processes, and functions, these owners play a central role in surfacing information and executing the planned actions within their areas.
Organizations Cross-Referencing to an ISMS
Teams pursuing ISO/IEC 27001 alongside or instead of ISO 9001 should treat this entry's ISO 9001-based description as a general orientation only. The precise clause wording and numbering within the ISMS standard should be confirmed against the applicable edition of ISO/IEC 27001, since the evidence here does not establish that text.

Inside Actions to Address Risks and Opportunities

Clause 6.1 Context
"Actions to address risks and opportunities" is the requirement found in clause 6.1 of ISO/IEC 27001, part of the certifiable ISMS requirements in clauses 4 through 10. It sits within the planning function of the management system.
Determination of Risks and Opportunities
The organization determines the risks and opportunities that need to be addressed to give assurance the ISMS can achieve its intended outcomes, prevent or reduce undesired effects, and achieve continual improvement, taking into account the issues (context) and interested-party requirements identified in clause 4.
Information Security Risk Assessment Process
The organization defines and applies a process to identify, analyze, and evaluate information security risks, establishing and maintaining risk criteria including risk acceptance criteria. The specific methodology and criteria are set by the organization rather than prescribed by the standard.
Information Security Risk Treatment Process
The organization selects appropriate risk treatment options and determines the controls necessary to implement them. Controls are compared against the Annex A reference controls to verify none have been overlooked, though controls may also be drawn from other sources.
Statement of Applicability (SoA)
A required output that documents the necessary controls, justifies their inclusion, states whether they are implemented, and justifies any exclusions of Annex A controls. The Annex A reference set was restructured in the 2022 revision into 93 controls across four themes, compared with 114 in the 2013 version; cite counts against a specified edition.
Risk Treatment Plan and Approvals
The organization formulates a risk treatment plan and obtains risk owners' approval of the plan and their acceptance of residual information security risks. Retained documented information provides evidence that these processes were carried out.
Planned Actions and Integration
The organization plans actions to address the identified risks and opportunities and plans how to integrate and implement these actions into its ISMS processes and how to evaluate their effectiveness.

Common questions

Answers to the questions practitioners most commonly ask about Actions to Address Risks and Opportunities.

Is 'Actions to Address Risks and Opportunities' the same as the formal information security risk assessment?
No. Clause 6.1.1 sets the broader planning requirement to determine risks and opportunities relating to the ISMS as a whole, including those tied to the context and interested-party requirements identified in clauses 4.1 and 4.2. The information security risk assessment and treatment activities in clauses 6.1.2 and 6.1.3 are more specific processes that sit within this planning. Treating the two as identical typically understates the wider organizational and ISMS-level considerations that clause 6.1.1 expects you to address.
Does this clause require a separate standalone 'risks and opportunities' document?
Not necessarily. ISO 27001 requires that the actions be planned and that the process produce results, but it does not prescribe a single mandatory document format. In most implementations organizations satisfy this through a combination of their risk assessment records, treatment plan, and ISMS planning outputs. What a certification body typically looks for is evidence that risks and opportunities were determined and that planned actions are integrated into ISMS processes, rather than the existence of any particular template.
How do we tie the actions from this clause into the rest of the ISMS?
The clause expects planned actions to be integrated and implemented within your ISMS processes and their effectiveness evaluated, rather than being handled in isolation. In practice this often means linking determined risks and opportunities to your risk treatment decisions, to objectives set under clause 6.2, and to the operational planning and control activities. Auditors generally examine whether the connection between planning and execution is demonstrable through your records.
What kinds of 'opportunities' should we consider, not just risks?
The clause pairs risks with opportunities, so planning is not limited to threats to be reduced. Opportunities are often framed in terms of improving the ISMS, achieving its intended outcomes, or preventing or reducing undesired effects. The specific opportunities depend on your context, scope, and interested-party requirements, so organizations typically derive them from the same context analysis used to identify risks rather than from a fixed list.
How should we evaluate whether the planned actions were effective?
The clause calls for evaluating the effectiveness of the actions taken, which connects to the performance evaluation activities in clause 9. In most engagements organizations do this through monitoring, measurement, internal audit, and management review, using evidence to judge whether the actions achieved their intended result. The appropriate method depends on the nature of each action and is a scoping decision rather than a single prescribed approach.
How does this clause relate to the Statement of Applicability and Annex A controls?
Actions planned under clause 6.1 frequently lead into risk treatment, which in turn draws on the reference controls listed in Annex A and is documented through the Statement of Applicability. However, the clause itself is a planning requirement and does not mandate specific controls; controls are selected based on the risk assessment and justified in the Statement of Applicability. Control counts and structure depend on the edition of the standard, so the linkage should be described in terms of your selected version's Annex A rather than a fixed set.

Common misconceptions

Organizations must implement all Annex A controls to satisfy clause 6.1.
Annex A is a set of reference controls, not a mandatory checklist. Controls are selected through the risk treatment process and recorded in the Statement of Applicability, where inclusions are justified and exclusions are justified. In most engagements the selection depends on the risk assessment and defined scope rather than a requirement to adopt every control.
Addressing risks and opportunities is the same activity as producing a SOC 2 report's control assessment.
This is an ISO/IEC 27001 ISMS requirement leading toward certification by an accredited certification body against a management system standard. SOC 2 is a separate attestation examination performed by a licensed CPA firm under SSAE 18 that reports against the Trust Services Criteria. The two are not interchangeable, and satisfying one does not automatically satisfy the other; any mapping between them is partial.
Completing the risk assessment and treatment once is sufficient for ongoing conformity.
The clause supports the ISMS's intended outcomes and continual improvement, and typically the risk assessment and treatment are revisited when the context, scope, or risk environment changes and at planned intervals. The retained documented information is expected to reflect the current state rather than a one-time exercise.

Best practices

Ground the risk assessment in the context (clause 4) and interested-party requirements so that determined risks and opportunities align with the intended outcomes of the ISMS and its defined scope.
Establish and document risk criteria, including risk acceptance criteria, before conducting the assessment so results are repeatable and comparable across cycles.
Use Annex A as a completeness check against the controls you have selected, and document the justification for each inclusion and exclusion in the Statement of Applicability, specifying which edition of the standard you are working against.
Formulate a risk treatment plan and secure documented approval from risk owners, including their explicit acceptance of residual risks, retaining this as evidence.
Plan how each action will be integrated into existing ISMS processes and how its effectiveness will be evaluated, rather than treating treatment decisions as standalone tasks.
Revisit the risk assessment and treatment when scope, context, or the threat environment changes and at planned intervals, keeping documented information current for certification body review.