ISO 42001 Risk Assessment: Methodology, Register, and Treatment
The Clause 6.1.2 risk assessment is one of the most-scrutinised parts of the AIMS. This is what auditors test, what good looks like, and how risk assessment relates to (but is distinct from) AI impact assessment.
What ISO 42001 requires
Clause 6.1.2 requires you to define and apply an AI risk assessment process that:
- Establishes and maintains AI risk criteria (risk appetite, risk tolerance)
- Ensures risk assessments produce consistent, valid, comparable results
- Identifies AI risks that could affect individuals, groups, society, or the organisation
- Analyses risks (potential consequences and likelihood)
- Evaluates risks (compare against criteria, prioritise for treatment)
Clause 6.1.3 then requires a risk-treatment process: select options, determine necessary controls, produce the Statement of Applicability, formulate the risk-treatment plan, and obtain risk-owner sign-off.
AI risk vs information-security risk
If you have ISO 27001, you already have a risk-assessment methodology. ISO 42001 risk assessment shares structure but expands scope:
- ISO 27001 focus: confidentiality, integrity, availability of information. Threat → vulnerability → asset → impact.
- ISO 42001 focus: effects of AI on individuals, groups, and society, bias, fairness, safety, privacy, explainability, autonomy, environmental impact. Plus organisational risk from AI behaviour.
A good ISO 42001 risk methodology extends your ISO 27001 methodology rather than replacing it. The Risk Register can be unified (with AI-specific tags) or separate.
Structure of a defensible methodology
1. Scope and scale
Which AI systems are covered? Which organisational units? Which lifecycle phases?
2. Criteria
- Likelihood scale (usually 1–5: rare to certain)
- Impact scales, typically three: on individuals, on organisation, on society
- Combined risk matrix producing a risk level (Low / Moderate / High / Critical or 1–25)
- Risk appetite (what level is acceptable without treatment)
- Risk tolerance (how much variance from appetite is acceptable)
3. Process
- Trigger events (new system, change, incident, periodic review)
- Participants (risk owner, AI system owner, domain expert, legal/compliance)
- Identification methods (checklists, structured brainstorm, red-teaming, literature review)
- Analysis and evaluation
- Documentation and sign-off
4. Integration points
- How risk assessment informs impact assessment (6.1.4)
- How it feeds into the risk treatment plan (6.1.3)
- How it updates the Statement of Applicability
- Link to nonconformity and CAPA when risks materialise as incidents
Typical AI risks to consider
- Bias and discrimination in AI outputs
- Hallucination producing factually incorrect information at scale
- Training-data leakage or privacy breach
- Model drift degrading performance silently
- Prompt injection / adversarial input compromising system behaviour
- Supply-chain risk from third-party models, datasets, APIs
- Over-reliance on AI output by human decision-makers
- Lack of explainability in consequential decisions
- Misuse by users (intended and foreseeable)
- Societal effects (displacement, information-ecosystem effects)
- Environmental impact of training/inference at scale
- Intellectual-property and copyright risks in generated content
- Regulatory non-compliance (EU AI Act, Colorado AI Act, sector regulation)
AIMS-05 in the Starter tier comes pre-seeded with 20 example risks across these categories. Adapt to your context, add missing categories, remove irrelevant ones.
Risk vs impact, the important distinction
Clause 6.1.2 risk assessment is organisation-centric: what risks affect our objectives?
Clause 6.1.4 AI system impact assessment is stakeholder-centric: how does this specific AI system affect individuals, groups, and society?
You need both. They inform each other. A high-impact AI system typically elevates several risk-register entries.
How auditors test risk assessment
Expect questions like:
- "Show me your risk criteria. Who approved them?"
- "For this risk in your register, walk me through the likelihood and impact scoring."
- "When did this risk last get reviewed? Who?"
- "This AI system is in your inventory, where are its risks in the register?"
- "Show me a risk that's been treated. Where's the residual-rating evidence?"
Auditors aren't checking whether your scores are "right", there's no objective answer to "is bias risk a 3 or a 4". They're checking that the methodology is applied consistently, the results are documented, the risk owner agrees, and treatment has followed.