AI Risk Assessment and Impact Assessment under ISO 42001
Assess AI risks and impacts systematically: criteria, affected people, controls, human oversight and traceable evidence.
An AI risk assessment examines events and uncertainty affecting the organisation. An impact assessment broadens the view to individuals, groups and society. For ISO 42001, both perspectives should connect traceably to the use case, data, stakeholders, controls, owners and review decisions.
Distinguishing risk and impact
| Perspective | Example question |
|---|---|
| Organisational risk | What financial, legal, security or reputational harm could occur? |
| Impact on individuals | Could output affect a person's rights, access, opportunities or treatment? |
| Societal effect | Could scale, bias or incentives affect wider groups? |
| Technical uncertainty | How robust, explainable and monitorable is the system in its intended context? |
An eight-step assessment
- Describe the use case and intended purpose
- Identify affected stakeholders and foreseeable misuse
- Record data sources, model, supplier and dependencies
- Build scenarios for error, bias, privacy, security and over-reliance
- Assess likelihood, severity, duration and reversibility
- Evaluate existing controls and human oversight
- Set actions, owners, acceptance and residual risk
- Define testing, monitoring and review triggers
Practical example
For AI-assisted applicant screening, model accuracy alone is not enough. Data representativeness, potential discrimination, explainability, human review, complaint routes, supplier changes and automation bias all matter.
Measures may include data and fairness testing, dual approval, exclusion of selected attributes, logged overrides, periodic sampling and clear escalation routes.
When reassessment is needed
- Change of purpose, user group or decision context
- New model, version or material supplier change
- New data sources or altered training data
- Incidents, complaints or unusual monitoring results
- New legal or contractual obligations
How Sternberg Consulting supports you
We structure AI inventory, risks, roles, evidence and internal review into a pragmatic AIMS. Learn more about ISO 42001 consulting.
Frequently asked questions
Is a data protection impact assessment the same thing?
No. It may be relevant but does not automatically cover all AI-specific impacts and organisational risks.
Does every small use case need a long report?
Depth should be risk-based, but even a simple tool needs a documented classification.
Who accepts residual risk?
An authorised role with sufficient technical and business context; high-impact decisions should be escalated.