Running an AI Risk Assessment Against Clause 6 Requirements

ISO 42001 Clause 6 requires you to assess risks and opportunities related to your AI systems. This is not the same as a technical risk assessment of a model’s performance. Instead, you are assessing organisational risks: compliance risks, reputation risks, operational risks, and strategic risks that arise from deploying AI.
The Risk Assessment Process
A structured risk assessment under Clause 6 typically includes five steps. First, identify the sources of risk. These come from your AI inventory, your knowledge of regulations that apply to you, stakeholder feedback, and previous incidents or near-misses. Second, analyse each risk by assessing its likelihood and potential impact. A risk where an AI system makes inaccurate decisions affecting customers is high impact. A risk where a model degrades over months due to data drift might be medium impact but high likelihood. Third, evaluate risks against your risk criteria. Your organisation decides what level of risk is acceptable. Fourth, select controls and opportunities for improvement. High-risk items get more stringent controls. Fifth, document your assessment and review it regularly.
Sources of Risk in AI Systems
Common risk sources include: data quality and completeness problems, model drift or performance degradation, algorithmic bias or fairness issues, security vulnerabilities (prompt injection, model theft, data leakage), insufficient human oversight, inadequate documentation, and supply chain risks (reliance on a vendor or third-party model).
You identify these by analysing each system in your inventory. A recommendation engine has different risks than a fraud detection system, which has different risks than a generative AI application. Your assessment should be specific to each system you are managing.
Likelihood and Impact Assessment
Most organisations use a simple matrix: High, Medium, and Low likelihood, crossed with High, Medium, and Low impact. A risk with high likelihood and high impact gets immediate attention. A low likelihood, low impact risk might be accepted with minimal control.
Be realistic in your assessment. A risk of “our employees might ignore our AI governance policy” is probably medium to high likelihood and high impact if it results in non-conformity during audit. A risk of “a solar flare might disable all our systems” is extremely low likelihood and should not consume your time.
Documenting Your Risk Assessment
Your risk assessment becomes an audit reference document. Many organisations use a risk register that lists each identified risk, assesses likelihood and impact, and documents the control or opportunity planned to address it. A typical entry might read:
“Risk: Customer-facing recommendation engine produces biased recommendations. Likelihood: Medium. Impact: High (reputation, customer trust). Control: Conduct bias audit before production deployment and quarterly thereafter. Monitor rejection rates by demographic group. Escalate findings to governance committee.”
This level of specificity is what auditors expect to see.
Connecting Risk Assessment to Controls
Clause 6 does not prescribe specific controls. Instead, it requires that you have assessed risks and that your management system includes controls to address identified risks. If your risk assessment identifies a high-risk item around model drift, you implement monitoring controls to detect drift. If you identify a high-risk item around algorithmic bias, you implement bias testing controls. Your controls are evidence-based: they address risks you have actually identified.
Some organisations select controls from Annex A of ISO 42001. Others develop organisation-specific controls. Either approach is valid as long as your controls are proportionate to the risks you have identified.
Opportunity Assessment
Clause 6 also requires you to identify opportunities for improving your AI management system. This might be an opportunity to strengthen oversight, to improve data quality, or to extend your management system to new AI systems. Opportunities are not mandatory in the way that risk controls are, but documenting that you have considered opportunities shows mature thinking.
Regular Review and Update
Your risk assessment is not a one-time exercise. ISO 42001 assumes you will review and update your assessment periodically. Many organisations review formally every 12 months and update informally whenever a new system is added to your inventory or whenever an incident occurs. An incident is often a signal that your risk assessment was incomplete and needs refinement.
Auditors will assess whether your controls align with your documented risks. If your risk assessment does not mention data quality risks but you have no data quality controls, auditors will ask why. Similarly, if you implement extensive controls but your risk assessment does not justify them, auditors may question whether your resources are well directed.
A rigorous, evidence-based risk assessment is one of the most valuable documents in your ISO 42001 management system. It justifies your control choices and demonstrates that your governance is proportionate and rational.
