Clause 6 — planning: risk, impact, and the Statement of Applicability
Lesson 3 of 5 in ISO/IEC 42001 Clause by Clause: Building the AI Management System.
Clause 6 is where 42001 earns its keep — and where it departs furthest from its siblings. The planning chain has five links, and each produces a named artifact an auditor will read.
6.1.1 — Risks and opportunities. Starting from the clause 4 context, determine what could prevent the AIMS achieving its intended outcomes, and plan actions proportionally.
6.1.2 — AI risk assessment. Define and maintain AI risk criteria — including risk acceptance criteria and criteria for when assessments are performed — such that repeated assessments produce consistent, valid, and comparable results. Then identify risks that help or hinder your AI objectives, analyse their potential consequences and likelihood, and evaluate them against the criteria to prioritise treatment. The comparability requirement is the quiet killer: ad-hoc workshop scoring that changes scale every quarter fails it.
6.1.3 — AI risk treatment. Choose treatment options, determine the controls each requires — then perform the move 42001 borrowed from 27001’s playbook: compare your chosen controls against Annex A to verify nothing necessary was overlooked, and produce a Statement of Applicability: the document listing every Annex A control with a justification for including or excluding it. Formulate the risk treatment plan and obtain risk owners’ approval — including explicit acceptance of residual risk. Nobody accepts risk by silence.
6.1.4 — AI system impact assessment. The clause with no 27001 ancestor. You must define and run a process assessing the potential consequences of your AI systems for individuals, groups of individuals, and societies — not for your organisation. This is the affected-party lens: the loan applicant, the demographic group with elevated error rates, the labour market your automation touches. ISO/IEC 42005 supplies the how-to; the result must feed back into your risk assessment.
6.2 and 6.3 — Objectives and changes. Set measurable AI objectives at relevant functions and levels — monitored, communicated, updated — and make changes to the AIMS deliberately, never by drift.
The clause 6 planning chain
- Context & roles (clause 4)
Issues, interested parties, AI roles, scope — the raw material planning consumes.
- 6.1.1 Risks & opportunities
What threatens or advances the AIMS’s intended outcomes?
- 6.1.2 AI risk assessment
Criteria → identify → analyse → evaluate. Output: a prioritised, comparable risk register.
- 6.1.4 AI system impact assessment
The affected-party lens: consequences for individuals, groups, societies. Guidance: ISO/IEC 42005. Results feed the risk assessment.
- 6.1.3 Risk treatment
Select options, determine controls, compare against Annex A so nothing necessary is missed.
- Statement of Applicability
Every Annex A control: applicable or not, with justification. The audit’s master index.
- Risk treatment plan + residual risk sign-off
Risk owners approve the plan and explicitly accept what remains.
- 6.2 AI objectives
Measurable, monitored, communicated — the targets clause 9 will check performance against.
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.