How to Maintain an ISO 9001 Risk Register
Risk-Based Auditing
August 31, 202610 Min Read
Back To Blog

How to Maintain an ISO 9001 Risk Register: Keeping Risk Management Current and Actionable

TL;DR

  • Maintaining an ISO 9001 risk register means keeping risk information current, relevant and connected to the QMS, not simply updating a document.
  • Review the register when processes, suppliers, equipment, customer requirements, responsibilities or other significant conditions change.
  • Check that each risk still applies, controls remain effective, actions have been completed and ownership is still correct.
  • Use audit findings, nonconformities and corrective actions as evidence when reassessing risks and controls.
  • A spreadsheet can work for simple risk registers, but multiple files, manual updates and disconnected actions can make risk management difficult to maintain.
  • A well-maintained register should connect risks, actions, audits, evidence, findings and effectiveness reviews.
  • For complex audit programmes, iAudit connects evidence capture, findings and corrective-action tracking to make risk information more actionable.

An ISO 9001 risk register can look perfectly complete on paper. Every risk has a score, an owner and an action. The problem is what happens after it has been completed.

Processes change. Suppliers change. People change. Customer requirements change. Audits uncover new problems. Corrective actions are raised. Yet the risk register can remain exactly as it was six months earlier.

That is why how to maintain an ISO 9001 risk register is more important than simply knowing how to create one.

A risk register should reflect what is actually happening in the organisation. If it becomes a document that is updated only before an audit, it can create the appearance of control without helping people manage risk.

What Does ISO 9001 Require from a Risk Register?

Team reviewing an ISO 9001 risk register

ISO 9001:2015 does not require organisations to use a specific risk register, spreadsheet or software application.

Clause 6.1 requires organisations to determine the risks and opportunities that need to be addressed, plan actions to address them, integrate those actions into the management system processes and evaluate their effectiveness.

That distinction matters.

The requirement is not to maintain a particular type of document. It is to make risk-based thinking part of how the management system operates.

A register can help provide structure and documented information, but it should support decisions and actions rather than become the end result.

This is where risk-based thinking in ISO 9001 becomes important. Risk should influence how processes are planned, controlled, monitored and improved, rather than sitting separately in a table.

When Should an ISO 9001 Risk Register Be Updated?

Risk and performance information being reviewed

There is no single review interval that will suit every organisation. An annual review may be appropriate for some risks, but relying on an annual calendar alone can leave important changes unrecorded.

A risk register should be reviewed when something changes that could affect the organisation’s risks or the effectiveness of its controls.

For example:

  • A new product, service or process is introduced
  • Equipment, technology or facilities change
  • A significant supplier changes
  • Customer or regulatory requirements change
  • Responsibilities or resources change
  • Audit findings identify weaknesses
  • A nonconformity occurs repeatedly
  • A corrective action changes an existing control
  • Performance data shows that a control is not working as expected
  • A new internal or external issue affects the organisation

The point is not to update the register for the sake of updating it. The point is to make sure the organisation’s current understanding of risk reflects current conditions.

How to Maintain an ISO 9001 Risk Register

Management system review and risk register maintenance

Maintaining the register involves more than changing risk scores. Each risk should be tested against what is actually happening.

1

Check whether the risk is still relevant

Some risks become less significant. Others become more important. Ask whether the circumstances that created the original risk still exist. If they have changed, the risk description or assessment may need to change with them.

2

Review the controls

A risk score should not remain unchanged simply because nobody has edited the spreadsheet. Look at the controls that are supposed to manage the risk. Are they still in place? Are they being followed? Are they producing the intended result?

3

Check whether actions were completed

An action marked as “complete” is not necessarily an effective action. There should be evidence that the action was implemented and, where appropriate, that it achieved its intended result. This is particularly important when audit findings or corrective actions have been used to address a risk.

4

Confirm ownership

People move roles. Responsibilities change. Departments are reorganised. A risk with an owner who no longer has responsibility for the relevant process is not properly managed, even if the register itself is up to date.

5

Look at what the audits are telling you

Internal audits provide information that can change your understanding of risk. If the same weakness appears repeatedly, the organisation should question whether the existing risk assessment and controls are adequate.

Effective auditing risk-based thinking means looking beyond whether a risk register exists and asking whether risk-based decisions can actually be seen in the way processes are managed.

Why Spreadsheets Can Make Risk-Register Maintenance Difficult

Risk information managed across spreadsheets and dashboards

There is nothing inherently wrong with using Excel for a risk register. For a small organisation with a limited number of risks, it may be perfectly practical.

The difficulty comes when the spreadsheet becomes disconnected from everything around it.

The risk may be recorded in Excel. The action may be tracked in an email. Evidence may sit in a shared folder. An audit finding may be recorded somewhere else. Corrective action may have its own tracker.

The information exists, but the connection between it becomes difficult to follow.

This is where what could be called “ghost compliance” appears. The organisation has the records needed to show that risks have been considered, but those records are no longer driving action.

Version control can add another problem. Different sites or departments may maintain different copies of the same register. By the time someone brings them together for management review, the information may already be out of date.

The bigger issue is therefore not the spreadsheet itself. It is the gap between recording risk and actively managing risk.

Your Audit Findings Should Influence Your Risk Register

Manufacturing audit evidence informing risk management

A maintained risk register should learn from what happens inside the management system.

Consider a manufacturing process where an internal audit identifies repeated problems with inspection records. If the finding is closed but the risk register remains unchanged, an opportunity has been missed.

The organisation should ask whether:

  • The original risk assessment was accurate
  • The existing control is effective
  • The action addressed the underlying cause
  • Additional resources are required
  • The process needs stronger controls
  • The risk level should be reassessed

This is also why audit information needs to reach the people responsible for managing risk while it is still useful. When audit data arrives too late, findings can become historical information rather than input into current decisions.

In manufacturing environments, this becomes even more important because operational conditions can change quickly. Risk-based auditing in manufacturing can help focus audit attention where changes, failures and operational risks are most significant.

What Does a Well-Maintained ISO 9001 Risk Register Look Like?

A useful risk register should be current, owned and connected to the management system.

It should help answer straightforward questions:

  • What could go wrong?
  • What are we doing about it?
  • Who is responsible?
  • What evidence shows that the control is working?
  • What has changed?
  • What have our audits and performance data told us?
  • Does the risk need to be reassessed?

If answering these questions requires searching through several spreadsheets, emails and folders, the register may be documenting risk without really helping to manage it.

For organisations with multiple sites, larger audit programmes or significant numbers of corrective actions, a connected digital system can make these relationships easier to maintain.

From a Risk Register to Live Risk Management

Connected risk management and audit workflow

The useful shift is not simply from Excel to software. It is from a static risk record to connected risk information.

A risk can lead to an action. An action can be checked through an audit. The audit can generate evidence and findings. Findings can lead to corrective actions. Those actions can then be reviewed for effectiveness, and the results can inform the next assessment of risk.

Risk → Action → Audit → Evidence → Finding → Corrective Action → Effectiveness → Review

This is where a platform such as iAudit can support the process. Its findings dashboard, evidence capture and corrective-action tracking bring information that is often scattered across separate files into a more connected audit workflow.

The aim is not to create another place to store a risk register. It is to make the information around risk more visible and actionable.

If your organisation is finding it difficult to keep risks, findings, evidence and corrective actions connected, you can try iAudit free for 14 days and explore the workflow for yourself.

Support

Frequently asked questions

Keep Risk Information Current and Connected

An ISO 9001 risk register is most useful when it reflects current conditions and supports real decisions.

Review it when things change, test whether controls work, use audit evidence and make sure actions and ownership remain clear.

When risk information connects to audits, evidence, findings and corrective actions, it becomes part of an active management cycle rather than a document maintained for the next audit.

Try iAudit free for 14 days
Ready to upgrade?

Ready To Upgrade Your
Audit Process?

Join the global community of auditors who have moved beyond spreadsheets. Create oversight in days, not months.

Just pay what you see
No hidden fees
iAuditGLOBAL
OVERVIEW
Dashboard
MANAGEMENT
Company
Users
Self Assessment
Gap Analysis
Audit Program
Findings

Audit Summary

Overall compliance status

49%
Requires Improvement
Comply
OFI
NC

Clause Breakdown

Compliance by ISO clause

4. Context
11%
5. Leadership
90%
6. Planning
33%
7. Support
0%
8. Operation
50%
9. Performance
50%
10. Improvement
60%
Start free trial