In ISO9001 sections 4.1, 4.2, 4.3 and 6.1, the organization must determine its context, its external and internal issues, its interested parties and their needs, and finally, determine the risks associated with all of these.
Try this simple lean Six Sigma tool to get started!