How to audit risk-based thinking in ISO 9001
ISO 9001 Auditing
August 19, 202612 Min Read
Back To Blog

How to Audit Risk-based Thinking in ISO 9001

Auditing risk-based thinking is one of the more challenging aspects of an ISO 9001 internal audit.

Most audit competencies focus on evidence. Show me the procedure. Show me the record. Show me the certificate.

Risk-based thinking does not work that way.

You cannot ask an auditee to “show you their risk-based thinking” and expect a document to tell the whole story. It is a mindset. It should be visible in how an organisation plans, decides and responds, not just in what it files.

I have sat through many ISO 9001 audits where the auditor asked for the risk register, reviewed it briefly and moved on. That approach misses the point entirely.

This blog explains how to audit risk-based thinking properly, what evidence to look for and where to find it across the standard.

Why Auditing Risk-based Thinking Is Different

Why auditing ISO 9001 risk-based thinking is different from traditional audits

Traditional ISO auditing is relatively straightforward.

A clause requires a procedure. You find the procedure. You verify it is followed.

Risk-based thinking does not produce a single document you can review in isolation. It produces a pattern of decisions, process designs and operational responses that should be visible across the management system.

As Kevin Brown notes in his analysis of auditing risk-based thinking, the auditor's job is to look for evidence that people understand why controls exist, not just that they exist. That distinction requires a different approach to questioning and observation.

For context on what risk-based thinking actually requires under ISO 9001:2015, see our earlier article on risk-based thinking in ISO 9001.

What Auditors Should Look for Beyond the Risk Register

Audit evidence beyond the ISO 9001 risk register

A risk register is useful. It is also only one piece of evidence.

When auditing risk-based thinking, I look across several sources.

Meeting Minutes and Operational Decisions

Do meeting records show risk discussions?
Are decisions traceable to risk reasoning?
If a process was changed or a supplier was removed, is there a documented rationale?

The ISO Certification Group notes that risk-based thinking should be visible across multiple organisational touchpoints, including meeting records, process changes and resource decisions. Look for evidence that risk awareness shaped decisions, not just that risks were listed somewhere.

Process Design as Evidence

Why were certain controls chosen?

The 9000 Store makes an important point here: process design is itself evidence of risk thinking. If a process has no visible rationale for its controls, risk-based thinking may be absent. Ask the process owner why steps exist. If they cannot explain the risk rationale, the control may have been inherited rather than designed.

Resource Allocation

Did leadership direct resources toward high-risk processes?
If Clause 6.1 identified a significant risk, was it reflected in budget, training or staffing decisions?

Kevin Brown identifies resource allocation as one of the clearest indicators of whether risk-based thinking is genuinely embedded or simply documented.

Supplier and Subcontractor Controls

Are higher-risk suppliers monitored more frequently?
Is there a visible rationale for how supplier oversight is tiered?

Risk-based thinking should inform supply chain decisions. If all suppliers receive identical oversight regardless of their risk profile, the approach may be compliance-driven rather than risk-driven. Where corrective actions arise from supplier failures, it is also worth examining whether they address root cause.

How to Audit Risk-based Thinking Across ISO 9001 Clauses

Auditing risk-based thinking across ISO 9001 clauses

One of the most important insights from Ideagen's analysis of ISO 9001:2015 is that risk-based thinking is not confined to Clause 6.1. It is distributed across the standard.

When auditing risk-based thinking, I examine multiple clauses.

Clause 4 – Context of the Organisation

Is there evidence that internal and external issues were genuinely identified? Are interested parties and their requirements documented with a clear connection to risk?

Clause 5 – Leadership

Does leadership demonstrate risk awareness in their decisions? Clause 5 requires top management to promote risk-based thinking. Look for evidence in management review outputs, resource decisions and communication.

Clause 8 – Operational Control

Are operational controls proportionate to identified risks? If a high-risk process has minimal controls, that is a gap. If a low-risk process is over-controlled, that suggests the approach may not be risk-driven.

Clause 9 – Performance Evaluation

Is monitoring focused on high-risk processes? Are the right metrics being tracked? Monitoring should be concentrated where risk is greatest.

Clause 10 – Improvement

Does corrective action genuinely eliminate root cause? Clause 10 is where risk-based thinking is tested most directly. If the same nonconformities return, root cause analysis may be superficial.

Our ISO 9001 audit management software is structured around these clauses to ensure audit coverage reflects the full standard.

Interview Techniques for Auditing Risk-based Thinking

Interview techniques for auditing ISO 9001 risk-based thinking

How to audit risk-based thinking effectively depends heavily on questioning technique.

Closed questions produce limited evidence.

“Do you have a risk register?” will get you a yes or no.

Open questions produce richer insight.

“How did you decide which risks to prioritise?” tells you whether risk-based thinking is genuinely embedded.

Kevin Brown emphasises that auditors should listen for whether people understand the purpose behind controls, not just their existence.

Strong audit questions for risk-based thinking include:

?

Why was this control introduced?

?

How do you decide which suppliers receive closer oversight?

?

What changed operationally after the last audit finding?

?

How was this process designed to address identified risks?

?

Who was involved in identifying these risks?

The answers reveal whether risk awareness is a management system feature or a lived operational reality.

Proportionality: The Forgotten Element

Proportionate risk-based thinking for small businesses

Effivity's analysis of risk-based thinking makes a point that auditors sometimes overlook.

The standard does not require the same level of risk sophistication from every organisation.

A small business with straightforward processes does not need a complex risk matrix or formal scoring system. What it needs is a proportionate, considered approach to risk that fits its context.

When auditing risk-based thinking in smaller organisations, I adjust my expectations accordingly. The question is not whether the organisation has a sophisticated framework. The question is whether risk awareness is visible in how they operate.

This is also where platform design matters. We built audit management software built by auditors to support organisations at different levels of audit maturity, not just those with formal risk management infrastructure.

Effectiveness: The Final Test

Verifying effectiveness of ISO 9001 risk-based thinking

The most important question when auditing risk-based thinking is simple.

Has it worked?

Auditors should look for performance data. Are monitored metrics improving? Have previously identified risks led to actual incidents or nonconformities? Has the same issue recurred after corrective action?

If risks were identified and actions were taken but the situation has not improved, the effectiveness of risk-based thinking must be questioned.

This connects directly to the Act phase of PDCA. Our PDCA cycle audit software links findings to verified corrective actions so that effectiveness is tracked rather than assumed.

How iAudit Supports Risk-based Audit Planning

iAudit Global risk-based ISO audit planning

When I was developing iAudit, one of the core design principles was that audit programmes should reflect risk, not just calendars.

iAudit supports how to audit risk-based thinking by providing:

Clause-aligned checklists that cover the full standard
Evidence attached directly to findings and clauses
Cross-site trend analysis to identify recurring risks
Corrective action tracking through to verified closure
Dashboards that show compliance performance by site and department

Audit effort should follow risk. The platform is designed to make that possible.

If you are reviewing how your internal audit programme addresses risk-based thinking, you can explore iAudit Global with a 14-day free trial at iaudit.global.

Ensuring Risk-based Thinking Works in Practice

How to audit risk-based thinking in ISO 9001 requires more than reviewing a risk register.

It requires looking across clauses, meeting records, process designs, resource decisions and supplier controls.

It requires open interview questions that reveal whether people understand why controls exist.

It requires proportionate expectations that reflect the organisation's context.

And it requires a final effectiveness check that confirms risk controls are actually working.

Risk-based thinking should be visible in how an organisation operates, not just in what it documents.

Plan audits around risk, not just calendars

Explore iAudit Global with a 14-day free trial and see how clause-aligned audits, evidence and verified actions support risk-based thinking in practice.

Start your free trial
Support

Frequently asked questions

Ready to upgrade?

Ready To Upgrade Your
Audit Process?

Join the global community of auditors who have moved beyond spreadsheets. Create oversight in days, not months.

Just pay what you see
No hidden fees
iAuditGLOBAL
OVERVIEW
Dashboard
MANAGEMENT
Company
Users
Self Assessment
Gap Analysis
Audit Program
Findings

Audit Summary

Overall compliance status

49%
Requires Improvement
Comply
OFI
NC

Clause Breakdown

Compliance by ISO clause

4. Context
11%
5. Leadership
90%
6. Planning
33%
7. Support
0%
8. Operation
50%
9. Performance
50%
10. Improvement
60%
Start free trial