Skip to main content
Services
Audit & Certification
ISO Gap AnalysisInternal AuditAudit PreparationAfter the AuditClose Nonconformities
Standards
ISO 9001 Quality ManagementISO 9001:2026 TransitionISO 14001 Environmental ManagementISO 45001 Occupational Health & SafetyISO 27001 Information SecurityISO 42001 AI ManagementISO 13485 Medical Devices
Industries & Support
Industry SolutionsMedical DevicesMechanical Engineering & ProductionIT, SaaS & AIManagement System MaintenanceExternal QMRQM Training
Industries
All IndustriesMechanical Engineering & ProductionAutomotive SuppliersLaser Optics, Photonics & SemiconductorsIndustrial Service ProvidersMedical DevicesIT, SaaS & AI
FundingFAQKnowledgeAboutContactSend emailCall now
DE/EN
Free Consultation
ISO 42001, AI & CompliancePublished: 10 July 2026

AI Risk Assessment and Impact Assessment under ISO 42001

Assess AI risks and impacts systematically: criteria, affected people, controls, human oversight and traceable evidence.

An AI risk assessment examines events and uncertainty affecting the organisation. An impact assessment broadens the view to individuals, groups and society. For ISO 42001, both perspectives should connect traceably to the use case, data, stakeholders, controls, owners and review decisions.

Distinguishing risk and impact

Table 1: AI Risk Assessment and Impact Assessment under ISO 42001
PerspectiveExample question
Organisational riskWhat financial, legal, security or reputational harm could occur?
Impact on individualsCould output affect a person's rights, access, opportunities or treatment?
Societal effectCould scale, bias or incentives affect wider groups?
Technical uncertaintyHow robust, explainable and monitorable is the system in its intended context?

An eight-step assessment

  1. Describe the use case and intended purpose
  2. Identify affected stakeholders and foreseeable misuse
  3. Record data sources, model, supplier and dependencies
  4. Build scenarios for error, bias, privacy, security and over-reliance
  5. Assess likelihood, severity, duration and reversibility
  6. Evaluate existing controls and human oversight
  7. Set actions, owners, acceptance and residual risk
  8. Define testing, monitoring and review triggers

Practical example

For AI-assisted applicant screening, model accuracy alone is not enough. Data representativeness, potential discrimination, explainability, human review, complaint routes, supplier changes and automation bias all matter.

Measures may include data and fairness testing, dual approval, exclusion of selected attributes, logged overrides, periodic sampling and clear escalation routes.

When reassessment is needed

  • Change of purpose, user group or decision context
  • New model, version or material supplier change
  • New data sources or altered training data
  • Incidents, complaints or unusual monitoring results
  • New legal or contractual obligations

How Sternberg Consulting supports you

We structure AI inventory, risks, roles, evidence and internal review into a pragmatic AIMS. Learn more about ISO 42001 consulting.

Discuss your project

Frequently asked questions

Is a data protection impact assessment the same thing?

No. It may be relevant but does not automatically cover all AI-specific impacts and organisational risks.

Does every small use case need a long report?

Depth should be risk-based, but even a simple tool needs a documented classification.

Who accepts residual risk?

An authorised role with sufficient technical and business context; high-impact decisions should be escalated.

Sources and further guidance

Next step

Let's talk.

Tell me where you stand and what you need.

Within 24 hours you receive a first assessment and a concrete meeting proposal — free and without commitment.

  • Reply within 24 hours
  • Personal assessment of your project
  • Funding eligibility checked on request

By submitting you agree to the processing of your details for answering your enquiry.