An AI risk assessment asks what could go wrong with the AI you build, buy or use, and who would be hurt if it did. ISO/IEC 42001 builds an AI management system on that question: criteria set in advance, an owner for every AI risk, a rating you can explain, consequences weighed for the individuals and groups a system affects and for society as well as for the organization, and a treatment decision for every risk you are not prepared to accept.
This tool takes you through it in that order. List your AI systems, the models and data behind them and the use cases they serve, pick risks from a library of 38 AI risk scenarios, each mapped to the ISO/IEC 42001:2023 Annex A controls that usually treat it, rate them against your own scales and decide what to do about each one. It is free, and your answers save as you go.
Premium report
See what the premium AI risk assessment report looks like
A worked sample for a fictional organization: the ranked register of AI risks, heat maps before and after treatment, the treatment plan with ISO 42001 Annex A references, every finding with the document that closes it, an AI-assisted analysis with a 30/60/90-day roadmap, plus the live Excel workbook with a Statement of Applicability starter.
Other free risk assessments: Information Security Risk Assessment (ISO 27001) Privacy Risk Assessment (ISO 27701) Business Continuity Risk Assessment (ISO 22301) Enterprise Risk Assessment (ISO 31000) Data Protection Impact Assessment (GDPR) Transfer Impact Assessment (GDPR) AI System Impact Assessment (ISO 42005) Legitimate Interests Assessment (GDPR) Third-Party Risk Assessment (ISO 27001)
What this AI risk assessment covers
- Scope and criteria. Your likelihood and impact scales, with impact described for the people an AI system affects as well as for the organization, and the appetite line.
- What is in scope. AI systems, models, datasets, use cases, AI providers and the people affected, each with how much harm it could do if it fails or behaves wrongly.
- Risks. Scenarios from the library, from biased outcomes, poor training data and made-up answers to prompt injection, data leaking into public AI tools, weak human oversight and third-party models nobody checked, or your own. Each is tagged with the objectives at risk: fairness, transparency, safety, robustness, privacy, security and accountability.
- Analysis. Likelihood and impact for each risk, with the controls already in place and the reason for the rating.
- Treatment. Modify, avoid, share or retain, the ISO 42001 Annex A controls the treatment relies on, an owner, a date, a target level and the risk owner’s acceptance.
What you get from the AI risk assessment, free
Your heat map against your own appetite line, the highest AI risks in priority order, a process score out of 100 that shows how complete and defensible the assessment is, and the findings an auditor would raise, such as a risk above the line with no decision or a risk with no owner. Sign in and it stays in your account, ready for next year’s review.
The full report adds the complete register, heat maps before and after treatment, the treatment plan by owner and due date, an AI-assisted analysis with a 30/60/90-day roadmap, and an ISO 42001 Statement of Applicability starter, with the register as a live Excel workbook.
Where this fits
The controls you choose here carry straight into your ISO 42001 Statement of Applicability, and one click sends them to our free SoA generator. If you have already run the ISO 42001 gap assessment, import it and every open Annex A gap becomes a suggested risk. For the method in full, read our guide to the ISO 42001 risk assessment; for the assessment of effects on people that sits beside it, see the AI system impact assessment, and for keeping the results, the AI risk register.
Rolling out chatbots, writing assistants or AI coding tools? Our generative AI risk assessment guide covers the risks to look for and walks through a worked example register mapped to Annex A.
Frequently asked questions
Is this the same as an AI system impact assessment?
No. ISO/IEC 42001 asks for both. The AI risk assessment in clause 6.1.2 covers risks to the organization and to the people and society its AI affects, and feeds the treatment plan. The AI system impact assessment in clause 6.1.4 looks in depth at the consequences of a particular system for individuals, groups and society. The risks you rate high here show where an impact assessment is most needed.
Which controls does it use?
The 38 controls in ISO/IEC 42001:2023 Annex A, from AI policy and roles to data, the AI system life cycle, information for interested parties, responsible use and suppliers. Each scenario suggests the ones that usually treat it, and you can add any other.
Does it cover generative AI and third-party models?
Yes. The library includes made-up answers, prompt injection, confidential data pasted into public AI tools, models changed or withdrawn by their provider and third-party models used without due diligence, alongside the risks of models you build yourself.
Does this satisfy the EU AI Act?
It helps you show structured, documented risk decisions, which the EU AI Act and ISO/IEC 42001 both expect, but no tool makes an organization compliant. It is a self-assessment built from the information you enter, and Governance Docs does not review or verify it.
What happens to the information I enter?
It is stored with your assessment so you can come back to it, and it is never shared. Describe systems and data by name and category rather than entering any real personal data. You can delete an assessment permanently from your account at any time.
