ISO 42001 AI Risk Assessment: Guide & Worked Example
An AI risk assessment under ISO 42001 Clause 6.1.2 is a systematic process to identify, analyze, and evaluate potential harms and operational risks across the artificial intelligence lifecycle. Unlike traditional IT security frameworks that focus almost exclusively on organizational assets, ISO 42001 requires organizations to evaluate risk by calculating likelihood and impact on business operations as well as on individuals, specific demographics, and broader society. Establishing a repeatable risk assessment methodology allows organizations to apply targeted controls from Annex A, lower residual risk to acceptable levels, and demonstrate governance maturity to accredited certification auditors.
Understanding ISO 42001 Clause 6.1.2 Requirements
Clause 6.1.2 of ISO/IEC 42001:2023 defines how an organization must structure its AI risk assessment process. To comply with the standard, your AI Management System (AIMS) must establish criteria for evaluating risk that reflect your organization's context (Clause 4) and stakeholder expectations.
Key requirements under Clause 6.1.2 include:
- Consistent Risk Criteria: Defining measurable standards for risk estimation, including how likelihood and impact are scored.
- Comprehensive Risk Identification: Identifying risks associated with data quality, model behavior, system misuse, lack of transparency, and regulatory non-compliance.
- Multi-Domain Impact Analysis: Assessing potential harms across four distinct domains: individuals, groups, society, and the organization itself.
- Control Mapping: Linking identified risks to control objectives in Annex A (such as A.5 Impact Assessments, A.6 AI System Lifecycle, and A.7 Data for AI Systems) to formulate a Risk Treatment Plan (Clause 6.1.3).
The ISO 42001 Risk Calculation Model: Likelihood and Impact
To perform an objective AI risk assessment, organizations typically apply a qualitative or semi-quantitative scoring matrix combining likelihood and impact.
1. Estimating Likelihood
Likelihood represents the probability or frequency of a risk event occurring during the AI system's lifecycle. Typical scale levels include:
- 1 - Rare: Highly unlikely; requires multiple systemic failures.
- 2 - Unlikely: Could occur under specific, non-standard conditions.
- 3 - Moderate: Likely to happen occasionally during normal operations.
- 4 - High: Expected to happen regularly without intervention.
- 5 - Almost Certain: Continuous or guaranteed occurrence given current system design.
2. Evaluating Impact Domains
ISO 42001 expands traditional impact scoring beyond financial or reputational loss. Impact must be scored (e.g., 1 to 5) across multiple dimensions:
- Individual Impact: Physical safety, psychological harm, loss of rights, financial loss, or unfair discrimination.
- Group Impact: Systemic bias or disproportionate harm targeting protected classes or demographic groups.
- Societal Impact: Erosion of public trust, environmental cost of compute, or dissemination of mass misinformation.
- Organizational Impact: Regulatory fines, operational downtime, intellectual property loss, and legal liability.
Risk Score Formula: Inherent Risk = Likelihood x Highest Impact Score
Worked Example: Customer Service Generative AI Assistant
To visualize how ISO 42001 6.1.2 functions in practice, consider a financial services company deploying a Generative AI chatbot to provide automated customer support.
Step 1: Risk Identification
- Risk ID: R-04
- Risk Event: The AI chatbot generates inaccurate financial advice ("hallucinations") or leaks sensitive customer PII present in its fine-tuning context.
- System Lifecycle Stage: Operation and Use (Annex A.9).
Step 2: Assessment of Inherent Risk
Before applying specialized ISO 42001 controls, the risk team evaluates the unmitigated system:
- Likelihood: 4 (High — Large Language Models inherently carry a baseline rate of hallucination without guardrails).
- Impact Analysis:
- Individual: 4 (High — Customers could act on bad financial advice, leading to direct monetary loss).
- Group: 2 (Low — Harm is not targeted at a specific protected class, but affects individual query types).
- Societal: 2 (Low — Limited to company customer base).
- Organizational: 4 (High — Severe regulatory penalties under financial conduct rules and loss of consumer trust).
- Max Impact Score: 4
- Inherent Risk Rating: 4 (Likelihood) x 4 (Impact) = 16 / 25 (High Risk)
Step 3: Risk Treatment & Annex A Control Mapping
Because a score of 16 exceeds the organization's risk acceptance threshold (set at 9), the team selects controls from ISO 42001 Annex A:
- A.5.2 AI Impact Assessment: Formal impact study conducted before deployment to analyze downstream consequences on customer financial health.
- A.6.2.2 AI System Design & Architecture: Implement Retrieval-Augmented Generation (RAG) to ground answers exclusively in vetted company documentation, alongside prompt-filtering guardrails.
- A.7.3 Data Quality for AI Systems: Sanitize training and context data to strip PII before input into the model context window.
- A.9.2 Human Oversight: Define automatic fallback triggers routing high-risk financial queries to human agents.
Step 4: Residual Risk Re-Evaluation
After implementing these Annex A controls, the team re-assesses the risk:
- Residual Likelihood: 1 (Rare — Grounding mechanisms and fallbacks minimize hallucination rates).
- Residual Impact: 2 (Minor — Guardrails prevent unverified advice from reaching the end user).
- Residual Risk Rating: 1 x 2 = 2 / 25 (Low Risk / Acceptable)
How to Build Audit-Ready AI Risk Documentation
When preparing for certification, independent auditors accredited under ISO/IEC 42006 will look for clear evidence that your risk assessments are non-static and fully integrated into operational workflows. Ensure your records contain:
- A documented methodology showing clear definitions for likelihood and multi-domain impact.
- An up-to-date Risk Register capturing AI asset inventories, risk scores, and assigned risk owners.
- Direct links between risk assessment outcomes and your Statement of Applicability (SoA).
To ensure your risk assessment process fulfills ISO 42001 requirements before your formal external audit, you can benchmark your operational readiness using DoAIRight's free AI Management System readiness assessment. While software tools help you organize controls and prepare documentation, formal ISO 42001 certification is awarded exclusively through independent audits conducted by accredited certification bodies.
Frequently asked
What is the primary objective of ISO 42001 Clause 6.1.2?
Clause 6.1.2 requires organizations to establish a repeatable AI risk assessment process that identifies AI-specific risks, evaluates likelihood and impact across multiple domains (including individuals and society), and determines whether risk treatment is required.
How does ISO 42001 risk assessment differ from traditional ISO 27001 risk assessments?
While ISO 27001 focuses primarily on confidentiality, integrity, and availability of information assets, ISO 42001 expands risk criteria to include societal impacts, individual fairness, bias, transparency, and safety issues unique to artificial intelligence.
Does ISO 42001 mandate a specific 5x5 matrix for scoring likelihood and impact?
No. ISO 42001 mandates that you define clear criteria for risk estimation, but allows organizations to choose qualitative, semi-quantitative, or quantitative methodologies (such as 3x3, 5x5, or numerical scoring) suited to their context.
Can DoAIRight grant an official ISO 42001 certificate after we complete our risk assessment?
No. DoAIRight provides tools and readiness assessments to help organizations implement their AI Management System and prepare for audit. Accredited ISO 42001 certificates are issued solely by independent certification bodies following an audit governed by ISO/IEC 42006.