Risk assessment is not a bureaucratic exercise in ISO 42001 — it is the engine that drives the entire Artificial Intelligence Management System. Get it right, and your AIMS becomes a genuinely effective tool for managing AI responsibly. Get it wrong, and you end up with documentation that satisfies auditors on paper while leaving real AI risks unaddressed. This practical guide shows you how to conduct AI risk assessment that is both ISO 42001-compliant and actually useful.
What Is AI Risk Assessment Under ISO 42001?
ISO 42001's Clause 6.1 requires organizations to identify and assess risks related to their AI activities. This is not the same as a general enterprise risk assessment — it specifically focuses on risks arising from the development, deployment, use, and management of AI systems. The standard requires that this assessment be systematic, documented, and regularly reviewed.
ISO 42001 risk assessment operates at two levels:
- AIMS-level risk assessment: Risks that could prevent the AI Management System itself from achieving its objectives — governance failures, resource constraints, regulatory changes.
- AI system risk assessment: Risks specific to individual AI systems within scope — the potential harms the system could cause if it fails, behaves unexpectedly, or is misused.
The standard also requires an AI system impact assessment — a structured evaluation of the potential impact of AI systems on individuals, groups, and society that goes beyond technical risk to address broader ethical and societal concerns.
Step 1: Identify AI Risks
Risk identification requires a systematic approach to uncovering all the things that could go wrong with your AI systems. Structure your risk identification around these key dimensions:
Bias and Fairness Risks
AI systems learn patterns from historical data. If that data reflects historical discrimination or underrepresentation, the model can perpetuate and amplify those patterns. Bias risks include:
- Training data that underrepresents certain demographic groups
- Proxy variables that correlate with protected characteristics (e.g., zip code as a proxy for race)
- Model performance gaps across demographic subgroups
- Feedback loops that reinforce existing disparities
- Deployment contexts where the model's training distribution differs from the real-world population
Safety Risks
For AI systems that influence physical processes or make recommendations in safety-critical contexts, failure can cause physical harm. Safety risks include:
- Model errors in autonomous or semi-autonomous physical systems
- Overreliance on AI recommendations without appropriate human verification
- Distribution shift causing model performance to degrade in production
- Failure modes not anticipated during development and testing
- Adversarial inputs designed to cause unexpected behavior
Privacy Risks
AI systems frequently process large quantities of personal data. Privacy risks include:
- Inclusion of personal data in training datasets without appropriate consent or legal basis
- Model inversion attacks that allow adversaries to reconstruct training data
- Membership inference attacks that reveal whether specific individuals were in the training set
- Inference of sensitive attributes not present in input data
- Cross-context data use that violates contextual integrity expectations
Security Risks
AI systems introduce novel attack surfaces beyond traditional software security concerns:
- Data poisoning — deliberate manipulation of training data to corrupt model behavior
- Model stealing — extraction of model architecture or parameters by adversaries
- Adversarial examples — inputs crafted to cause misclassification
- Prompt injection — in LLM-based systems, inputs designed to override instructions
- Supply chain attacks on AI components, pre-trained models, or datasets
Transparency and Explainability Risks
When AI systems cannot explain their decisions, the inability to understand, challenge, or improve them creates governance risks:
- Inability to detect or diagnose bias or error sources
- Regulatory non-compliance where explainability is required (e.g., credit decisions under GDPR)
- Inability to provide meaningful human oversight
- Reputational risk from unexplainable high-impact decisions
Step 2: Assess Risk Likelihood and Impact
Once risks are identified, assess each one for:
- Likelihood: How probable is it that this risk will materialize? Consider the design of the system, the deployment context, and any controls already in place.
- Impact: If the risk materializes, how severe are the consequences? Consider impacts on individuals, the organization, and society. Severity includes both the magnitude of harm and the number of people affected.
- Risk level: Combine likelihood and impact to determine overall risk level. Most organizations use a simple matrix (Low/Medium/High or 1-5 scales).
Document your assessment methodology and apply it consistently across all AI systems. Auditors will look for consistency and defensibility in your assessment approach.
Step 3: Determine Risk Treatment
For each identified risk, determine the appropriate treatment option:
- Mitigate: Implement controls to reduce likelihood and/or impact. This is the most common treatment for AI risks.
- Accept: For low-level risks where the cost of mitigation exceeds the expected harm, document the decision to accept the risk and the reasoning.
- Transfer: Shift some or all of the risk to another party (e.g., through contractual provisions with AI system vendors).
- Avoid: Modify or discontinue the AI activity to eliminate the risk entirely.
Risk treatment options should be selected from Annex A controls where applicable. Document your risk treatment plan with clear ownership, timelines, and success criteria.
Step 4: Documentation — What Auditors Look For
ISO 42001 auditors will look for evidence that your risk assessment is:
- Systematic: You have a defined methodology applied consistently, not ad hoc assessments done differently for each system.
- Documented: Risk assessments are recorded in sufficient detail to demonstrate the assessment was genuine and considered all relevant factors.
- Current: Risk assessments are reviewed and updated regularly, and when significant changes occur (new AI system, change in deployment context, incident).
- Acted upon: Identified risks have a documented treatment plan, and evidence exists that treatments have been implemented.
- Integrated: Risk assessment results feed into management decisions, AIMS objectives, and control selection.
Common audit findings in AI risk assessment include risk registers that are too generic (listing risks without sufficient specificity to the actual AI systems), risk assessments that were conducted once and never updated, and treatment plans without clear ownership or completion evidence.
Step 5: Monitor and Review
AI risk is not static. Risks change as AI systems evolve, as deployment contexts change, as new vulnerabilities are discovered, and as regulatory requirements develop. Your risk assessment process must include regular review cycles and triggers for unscheduled reassessment:
- Significant change to AI system architecture or training data
- AI-related incident or near-miss
- New regulatory requirement or guidance
- Change in deployment context or user population
- Evidence of model drift or performance degradation
Build risk review into your AIMS calendar as a standing activity, not a one-time event. The most mature AI governance programs treat risk assessment as a continuous activity, not a periodic project.
Ready to Get Certified?
AICerty provides end-to-end ISO 42001, EU AI Act, and ISO 27001 certification services for AI companies worldwide. 100% online, 6-10 weeks, powered by BALTUM Bureau.
Visit aicerty.io