An ISO 42001 risk assessment is the process clause 6.1.2 of ISO/IEC 42001:2023 requires for identifying, analysing and evaluating the risks an organization runs by developing, providing or using AI. It is not the same thing as the AI system impact assessment in clause 6.1.4, though the two feed each other, and it is not an ISO 27001 risk assessment with “AI” written in the asset column — a mistake that produces a register full of data breaches and nothing about bias, drift or automation.
This guide sets out what the clause requires, the AI-specific objectives and risk sources the standard’s own Annex C gives you to work from, how the assessment relates to the impact assessment, and a method that produces the “consistent, valid and comparable results” the clause insists on.

What clause 6.1.2 requires of an ISO 42001 risk assessment
The clause is compact. For the ISO 42001 risk assessment, the organization shall define and establish an AI risk assessment process that:
- is informed by and aligned with the AI policy (5.2) and AI objectives (6.2) — so the objectives come first, and the risks are risks to them;
- is designed so that repeated assessments produce consistent, valid and comparable results — the requirement that rules out ad-hoc workshops with no fixed scale;
- identifies risks that aid or prevent achieving the AI objectives — note “aid”: opportunities are in scope, not only threats;
- analyses the risks — assessing the potential consequences to the organization, individuals and societies if the risk materialised, the realistic likelihood where applicable, and the resulting level of risk;
- evaluates the risks — comparing the analysis with the risk criteria set under 6.1.1 and prioritising for treatment.
The organization shall retain documented information about the process. A note under a) adds the connection that most teams miss: when assessing consequences under d) 1), the organization can use the AI system impact assessment from 6.1.4. The impact assessment is, in other words, an input to the consequence analysis — the place where “harm to individuals and societies” gets its content.
Clause 6.1.1 sits above the ISO 42001 risk assessment and requires AI risk criteria that support distinguishing acceptable from non-acceptable risk, performing assessments, conducting treatment and assessing impacts. Without written criteria, requirement 2 of the ISO 42001 risk assessment cannot be met, because two assessors will score the same risk differently and neither can be shown to be wrong.
ISO 42001 risk assessment vs impact assessment: two subjects, one evidence base
| AI risk assessment (6.1.2) | AI system impact assessment (6.1.4 / 8.4) | |
|---|---|---|
| Question | What could stop us achieving our AI objectives — or help us? | What could this AI system do to individuals, groups and societies? |
| Subject of harm | The organization, and through it individuals and societies | Individuals or groups of individuals, and societies — including effects the organization is untroubled by |
| Unit | The management system, and each AI system or grouping within it (6.1.1 Note 2) | Each AI system, across its deployment, intended use and foreseeable misuse |
| Output | Prioritised risks → treatment plan → Statement of Applicability | Documented impacts, considered in the risk assessment; may be shared with interested parties |
| When repeated | At planned intervals and when new risks appear (8.2, 8.3) | At planned intervals or when significant changes are proposed (8.4) |
| Guidance standard | ISO/IEC 23894:2023 (AI risk management, built on ISO 31000) | ISO/IEC 42005:2025 (AI system impact assessment) |
Run the ISO 42001 risk assessment and the impact assessment as one evidence-gathering exercise and two documents. The impact assessment tells you the consequence side of each AI risk; the risk assessment adds likelihood, applies your criteria and decides what to treat. Our guide to the AI system impact assessment covers the other half.
What to assess against: the objectives and risk sources in Annex C
ISO 42001’s informative Annex C is the part of the standard that stops an ISO 42001 risk assessment collapsing into a security exercise. It lists AI-related organizational objectives and AI-specific risk sources, and says plainly that it is neither exhaustive nor applicable to everyone — the organization decides which are relevant. Used as a prompt list, it makes the identification step repeatable.
Eleven objectives (C.2)
Accountability; AI expertise; availability and quality of training and test data; environmental impact; fairness; maintainability; privacy; robustness; safety; security; transparency and explainability. Each is a thing the AI can undermine. “Fairness” in the annex’s words: the inappropriate application of AI systems for automated decision-making can be unfair to specific persons or groups of persons. That sentence alone generates risks no ISMS register contains.
Seven risk sources (C.3)
- Complexity of environment — broad ranges of situation create performance uncertainty (autonomous driving is the annex’s example).
- Lack of transparency and explainability — inability to give interested parties appropriate information, with trustworthiness and accountability consequences.
- Level of automation — affecting safety, fairness and security.
- Risk sources related to machine learning — data quality and collection processes, including data poisoning.
- System hardware issues — defective components, or moving trained models between systems.
- System life cycle issues — flaws in design, inadequate deployment, lack of maintenance, decommissioning.
- Technology readiness — immature technology with unknown limits, and mature technology that breeds complacency.
A practical identification method for the ISO 42001 risk assessment is a matrix: objectives down the side, risk sources across the top, and for each AI system in scope a pass through the cells asking “can this source undermine this objective here?” It is mechanical, which is the point — 6.1.2 b) wants results that are comparable between assessors and between years.
An ISO 42001 risk assessment method that produces comparable results
- Fix the criteria first (6.1.1). Define consequence scales separately for the organization, for individuals and for societies — a regulatory fine and a wrongly denied loan are not the same axis. Define a likelihood scale, and define the level of risk at which treatment is mandatory. Get management to sign the criteria; they will be asked to accept residual risk against them later (6.1.3).
- Set the units. Note 2 to 6.1.1 allows assessment per AI system or per grouping of systems. Group systems only where they share technology, data, use and affected people; otherwise you average away the risk that matters.
- Identify, using Annex C. For each unit, walk the objectives-by-sources matrix, and add anything from context (4.1), interested parties (4.2) and the impact assessment.
- Analyse. Consequence from the impact assessment where it exists; likelihood from monitoring data, incident history and vendor documentation where it exists, and expert judgement labelled as such where it does not. Record the reasoning, not just the score.
- Evaluate and prioritise. Apply the criteria, rank, and pass everything above the treatment threshold into 6.1.3.
- Record and version. The ISO 42001 risk assessment clause requires documented information about the process; auditors will also expect the results, the date, the assessors and the criteria version used.
Where a first-year ISO 42001 risk assessment goes wrong
| Symptom | Cause | Fix |
|---|---|---|
| Every risk is a confidentiality, integrity or availability risk | The ISMS template was reused | Rebuild identification on Annex C objectives; keep security as one objective of eleven |
| Same risk scored 3 by one assessor and 9 by another | No written criteria, or criteria without worked examples | Add anchored examples to each level of each scale; re-score the disputed items together |
| No opportunities recorded | Teams read ‘risk’ as ‘threat’ | 6.1.2 c) says risks that aid objectives are in scope; add at least the opportunities that justify the AI system’s existence |
| Consequences to individuals and societies are blank | Impact assessment not done, or done after the risk assessment | Sequence them: impact assessment feeds consequence analysis (note to 6.1.2 a)) |
| Register never changes between years | Assessment is an annual document, not a process | Add triggers under 8.2: new system, model change, new jurisdiction, monitoring anomaly, incident |
Frequently asked questions
Is an ISO 42001 risk assessment mandatory?
Yes. Clause 6.1.2 requires a defined AI risk assessment process with retained documented information, and clause 8.2 requires it to be performed at planned intervals and when significant changes occur.
Can we reuse our ISO 27001 risk assessment?
Reuse the method and the scales if they work; do not reuse the results. The AI assessment must be aligned to the AI policy and objectives and cover consequences to individuals and societies, which an ISMS assessment does not. See our ISO 27001 risk assessment guide for what does transfer.
Does ISO 42001 require a particular risk methodology?
No. It requires criteria, a process that gives consistent results, and the identify–analyse–evaluate structure. ISO/IEC 23894:2023 is the referenced guidance and follows ISO 31000.
How does the risk assessment produce the Statement of Applicability?
Prioritised risks go into risk treatment (6.1.3); the controls chosen to implement the treatment options, checked against Annex A, are recorded in the Statement of Applicability with justifications.
How often should it be repeated?
At planned intervals — annually is typical — and whenever a significant change is proposed or new risks are identified. Model changes, new uses and new jurisdictions are the usual triggers.
Where this leaves you
Write the risk criteria before the register, identify against Annex C’s eleven objectives and seven risk sources rather than a security taxonomy, take consequences to people from the impact assessment, and make the process repeatable enough that a different assessor next year would land in the same place. That is what clause 6.1.2 is testing, and it is also what makes the AI risk register worth reading once the certificate is on the wall.
References
- ISO/IEC 42001:2023 — clause 6.1.2 sets the AI risk assessment requirement; Annex C lists objectives and risk sources.
- ISO/IEC 23894:2023 — guidance on AI risk management, the reference ISO 42001 cites for implementing the process.
More on AI governance
- The ISO 42001 risk assessment — you are here
- ISO 42001 explained: the AI management system standard
- The AI system impact assessment
- The ISO 42001 Statement of Applicability
- The ISO 27001 risk assessment
The AI risk management policy, the risk and impact assessment procedure, the risk treatment procedure and the AI risk assessment form are included in the ISO 42001 Toolkit (68 templates), or start with the free ISO templates.