AI risk and impact assessment
Clause 6 requires the organization to establish a systematic process for identifying, analyzing, and evaluating risks associated with AI systems. This includes assessing both the risk to the organization and the potential impact of the AI system on individuals, groups, and society.
What it means
Unlike traditional IT risk assessments that focus primarily on business continuity or data security, AI risk and impact assessments must address the unique nature of artificial intelligence. This involves evaluating risks such as algorithmic bias, lack of transparency (the "black box" problem), and potential societal harms.
The scope extends beyond internal operational risks to include external impacts. The organization must consider how its AI system affects stakeholders—including those who may be indirectly impacted by an AI-driven decision—and ensure these impacts are weighed against the intended benefits of the system.
In practice, this means implementing a lifecycle approach. Risk assessment is not a one-time event at the start of development but a continuous process that occurs during design, testing, deployment, and throughout the operational life of the AI system.
How to meet it
- Define an AI risk management framework that specifies how risks are identified, categorized, and scored based on severity and likelihood.
- Conduct a formal AI Impact Assessment (AIIA) to evaluate potential negative effects on human rights, fairness, and safety.
- Identify all relevant stakeholders, including end-users and marginalized groups who may be disproportionately affected by the system's output.
- Establish clear risk acceptance criteria to determine which risks are tolerable and which require mandatory mitigation before deployment.
- Create a Risk Treatment Plan that maps identified AI risks to specific technical or organizational controls (e.g., human-in-the-loop reviews, bias detection tools).
- Implement a recurring review cycle to re-assess risks as the AI model evolves through learning or as new data is introduced.
Evidence an auditor asks for
- An AI Risk Register documenting identified threats, their potential impacts on stakeholders, and assigned risk levels.
- Completed AI Impact Assessment reports detailing the analysis of societal and individual consequences.
- A documented Risk Treatment Plan showing how high-priority risks are being mitigated or managed.
- Records of stakeholder analysis used to determine who would be impacted by the AI system.
- Evidence of management approval for accepted residual risks.
Common pitfalls
- Using a generic IT risk template that fails to capture AI-specific issues like model drift, hallucination, or systemic bias.
- Treating the assessment as a "point-in-time" exercise rather than an iterative process integrated into the AI lifecycle.
- Focusing exclusively on organizational risks (e.g., financial loss) while ignoring external impacts on individuals and society.