Auditen
Home / Frameworks / ISO 42001 / AI risk and impact assessment
ISO 42001 · Clause 6

AI risk and impact assessment

Clause 6 requires the organization to establish a systematic process for identifying, analyzing, and evaluating risks associated with AI systems. This includes assessing both the risk to the organization and the potential impact of the AI system on individuals, groups, and society.

What it means

Unlike traditional IT risk assessments that focus primarily on business continuity or data security, AI risk and impact assessments must address the unique nature of artificial intelligence. This involves evaluating risks such as algorithmic bias, lack of transparency (the "black box" problem), and potential societal harms.

The scope extends beyond internal operational risks to include external impacts. The organization must consider how its AI system affects stakeholders—including those who may be indirectly impacted by an AI-driven decision—and ensure these impacts are weighed against the intended benefits of the system.

In practice, this means implementing a lifecycle approach. Risk assessment is not a one-time event at the start of development but a continuous process that occurs during design, testing, deployment, and throughout the operational life of the AI system.

How to meet it

Evidence an auditor asks for

  • An AI Risk Register documenting identified threats, their potential impacts on stakeholders, and assigned risk levels.
  • Completed AI Impact Assessment reports detailing the analysis of societal and individual consequences.
  • A documented Risk Treatment Plan showing how high-priority risks are being mitigated or managed.
  • Records of stakeholder analysis used to determine who would be impacted by the AI system.
  • Evidence of management approval for accepted residual risks.

Common pitfalls

  • Using a generic IT risk template that fails to capture AI-specific issues like model drift, hallucination, or systemic bias.
  • Treating the assessment as a "point-in-time" exercise rather than an iterative process integrated into the AI lifecycle.
  • Focusing exclusively on organizational risks (e.g., financial loss) while ignoring external impacts on individuals and society.