MSI's ISO QEM Risk management procedure template

Q/EMS Risk Management Procedure Template & Guide (ISO 9001 + ISO 14001)

$249
A complete, editable risk and aspect identification procedure for organizations holding both ISO 9001 and ISO 14001:2026, with the two scopes reconciled. Two identification routes feed one shared spine, because quality risk is not visible on a site walk. Sixteen integration decisions recorded.

The gap this closes

Quality risk and environmental aspects are not found the same way. An aspect is a property of work being done in a place, and you find it by going there and watching. A quality risk is not visible on a walkway.

A complete, editable risk and aspect identification procedure for an organization certified to both ISO 9001:2015 and ISO 14001:2026 — written as a finished working document, not an outline.

Most organizations holding both certificates run two identification exercises that never meet. Quality risk is discussed in a management meeting. Environmental aspects are found on a site walk. The two outputs live in two places, are rated on two scales nobody compares, and are reviewed on two cycles.

Combining them is not a matter of merging two spreadsheets, because the two exercises genuinely differ. Send the site-walk team to find quality risk and the quality column fills with housekeeping observations — a label peeling, a bin unlabeled — and the organization concludes its quality risk is low when it has simply not been looked for.

Two identification routes, one shared spine

This procedure runs Route A, observation of the work, for environmental aspects; and Route B, analysis of process performance, customer requirements, supplier behavior and nonconformity history, for quality risk. Both feed one shared assessment and treatment spine.

That is the integration, and it is real: one methodology, one threshold discipline, one action-tracking system, one review, one management review input. What is not integrated is the finding — because the finding genuinely differs.

Where the standards disagree, the decision is already made

ISO 14001:2026 is the stricter of the two almost everywhere the process itself is concerned. ISO 9001 requires the least at Clause 6.1 — no procedure, no criteria, no register — and contributes the obligation that makes the document necessary, at Clause 4.4.1 c): determined criteria and methods for the operation and control of every process. Risk identification is such a process.

Appendix D records sixteen divergences, each with what the two standards require, the position adopted as house standard, and the alternative rejected with its reasoning — followed by a sign-off table of decisions to confirm before adoption. It is the part a buyer cannot easily assemble alone, and it is what a certification body will ask about.

What is in it

  • Section 2.0 — scope reconciliation first, location by location. The two exclusions are set by different tests and rarely land in the same place.
  • Section 5.0 — Developing this process in your organization, covering both criteria sets, with a calibration exercise.
  • Two distinct rating scales, deliberately different in length and wording so a rating cannot be transcribed between them by accident.
  • Established significance criteria judged against the receptor an impact reaches, not against volume.
  • The separate Clause 6.1.4 register the 2026 edition requires, reaching external conditions acting on the organization.
  • Life cycle perspective across seven stages, with control and influence determined and recorded.
  • Communication of significant aspects among levels and functions, with the audience table and the record.
  • A quality risk register, kept even though ISO 9001 Clause 6.1 requires no documented information at all.
  • The ISO 9001 proportionality test — actions proportionate to the potential impact on conformity, reasoned and recorded.
  • Integration into QMS processes — every significant entry names the document its action changed.
  • Combinations of entries — shared dependencies that no single rating captures.
  • Figure 1 — process interaction map, required once ISO 9001 is in scope.
  • Appendix A — the registers, kept apart and linked. Appendix B — action and effectiveness record. Appendix C — desk-level work instruction with worked examples.
  • Appendix D — the integration decision record: sixteen divergences, sixteen decisions, one sign-off table.
  • Appendix E — determination worksheet, including the two-assessor calibration exercise.

Buying ahead of the ISO 9001:2026 launch

ISO has confirmed that ISO 9001:2026 launches on Wednesday 16 September 2026, with a three-year transition expected. Buy this template now and the aligned revision is sent to you free when MSI issues it. You get a working procedure today and the updated one when it matters, without buying twice.

Specification

StandardsISO 9001:2015 and ISO 14001:2026
ClausesISO 9001 Clauses 4.4.1 and 6.1; ISO 14001 Clause 6.1
Length62 pages
FormatMicrosoft Word (.docx), fully editable
DeliveryInstant download
LicensePerpetual, non-exclusive license for your organization to edit, rebrand and adopt across your own sites
UpdatesISO 9001:2026 launches 16 September 2026. Buy now and the aligned revision is sent to you free when MSI issues it — no second purchase, no upgrade fee

Who it is for

Quality and environmental managers, EHS leads carrying both systems, and consultants supporting dual-certified clients. Particularly useful for multi-site operations where the two scopes were never compared, for organizations transitioning to ISO 14001:2026 inside the three-year window, and anywhere the aspects register is thorough and the quality risk register was written from memory of last year's problems.

Written from what repeats. Diana Lynn has attended more than 200 certification and surveillance audits across 28 years, supporting more than 80 certifications and training more than 600 professionals. These templates encode the structural weaknesses that show up again and again, not one organization's approach generalized. Management Systems International is veteran-owned and female-owned. Questions: 760-434-9141.

Prefer to be invoiced? If your organization buys on a purchase order rather than by card, email info@msi-international.com or call 760-434-9141 and we will raise an invoice. Tell us which templates or package you need and we will send payment terms the same working day.


Other options in this family

If this is not the right combination

Every variant covers one certification combination, so you buy the one document that matches your certificates rather than assembling it from singles.

The full documentation package

This procedure is one document in a wider system. If you are building or rebuilding the whole documentation set rather than filling a single gap, the packages below collect the procedures and guides for each standard, and work out considerably cheaper than buying them individually.