2.3 AI Risk Taxonomy & Societal Impact Dimensions
Key Takeaways
Risk is the effect of uncertainty on objectives and can include positive or negative effects.
Clause 6.1.2 establishes an AI risk assessment process; Clause 8.2 performs assessments at planned intervals and when significant changes are proposed or occur.
Clause 6.1.4 addresses potential consequences for individuals, groups of individuals, and societies, including intended use and foreseeable misuse.
Impact-assessment results feed into AI risk assessment rather than forming an isolated track.
Risk responses and technical mitigations are selected in context; ISO/IEC 42001 does not prescribe one exhaustive four-option list.
AI risks, opportunities, and system impacts
Risk and impact are connected concepts in ISO/IEC 42001, but they are not synonyms. A strong Foundation answer begins with the standard definition of risk: the effect of uncertainty on objectives. An effect can be positive, negative, or both. Clause 6.1.1 also requires planning for risks and opportunities relevant to the AIMS and its intended outcomes.
Clause 6.1.1 risk criteria and the 6.1.2 assessment process
Clause 6.1.1 establishes and maintains AI risk criteria that support distinguishing acceptable from non-acceptable risks, performing assessment, conducting treatment, and assessing impacts. Those criteria are an input to—not a product of—the Clause 6.1.2 process.
Clause 6.1.2 defines and establishes an AI risk-assessment process informed by and aligned with the AI policy and objectives. It is designed so repeated assessments can produce consistent, valid, and comparable results. It identifies risks that can aid or prevent achievement of AI objectives, analyzes potential consequences to the organization, individuals, and societies, assesses realistic likelihood where applicable, determines risk levels, compares them with the criteria, and prioritizes assessed risks for treatment. The organization retains documented information about the process.
This scope is broader than “risks to the company.” Objectives may concern responsible development and use, safety, fairness, legal obligations, service performance, stakeholder trust, or societal outcomes. Financial loss, operational disruption, discrimination, unsafe behavior, and missed beneficial opportunities can all matter because they affect relevant objectives.
A practical risk record can include a risk description, affected objective, causes, consequences, existing controls, likelihood, consequence level, risk owner, treatment, residual risk, and review trigger. That structure is an implementation example, not a mandated template.
Operational assessment under Clause 8.2
Clause 6.1.2 defines the process. Clause 8.2 requires the organization to perform AI risk assessments according to that process at planned intervals and whenever significant changes are proposed or occur. Results are documented.
A significant change might involve purpose, data source, model architecture, user population, supplier, geography, automation level, integration, or applicable law. Not every patch is automatically significant, and not every model retraining has identical consequences. The organization applies its defined criteria.
AI system impact assessment under Clause 6.1.4
Clause 6.1.4 requires a process for assessing potential consequences for:
- individuals;
- groups of individuals; and
- societies.
The assessment considers consequences arising from development, provision, or use of AI systems. It addresses deployment, intended use, and foreseeable misuse, and it takes account of the technical and societal context and applicable jurisdictions. Results are documented and, where appropriate, may be made available to relevant interested parties.
The standard does not define “the environment” as a fourth mandatory recipient category in Clause 6.1.4. Environmental effects can still be relevant: they may be societal impacts, applicable requirements, organizational objectives, or risk sources. Present them through the correct pathway rather than changing the clause’s three stated categories.
Clause 6.1.4 explicitly connects the processes: the organization considers impact-assessment results in the Clause 6.1.2 risk assessment. That prevents a false split in which “risk” concerns only the organization and “impact” concerns everyone else.
Operational impact assessment under Clause 8.4
Clause 8.4 performs AI system impact assessments in accordance with the defined process at planned intervals or when significant changes are proposed. The organization retains documented information about results.
An assessment can examine positive and negative consequences, affected groups, severity, scale, duration, reversibility, likelihood, distribution, and the effectiveness of safeguards. ISO/IEC 42001 specifies the process and categories of consequence; it does not impose one universal scoring formula.
Risk treatment and the Statement of Applicability
Clause 6.1.3 requires a risk-treatment process. The organization selects appropriate options, determines necessary controls, compares them with Annex A, considers relevant Annex A controls, identifies additional controls, considers Annex B guidance, produces the SoA, and formulates a treatment plan. Designated management approves the plan and residual-risk acceptance. Necessary controls are aligned with AI objectives and have documentation and communication duties.
Avoid presenting “avoid, reduce, share, accept” as the only four ISO/IEC 42001 treatment choices. Those are familiar risk-management strategies and can be useful, but the clause requires appropriate options rather than publishing that fixed exhaustive list.
Typical risk sources and treatments
| Risk source | Possible consequence | Illustrative controls |
|---|---|---|
| Unrepresentative data | Unequal error rates or poor generalization | Data-quality criteria, subgroup evaluation, acquisition changes |
| Purpose drift | System used beyond validation limits | Intended-use documentation, access control, monitoring, user information |
| Supplier change | Output format or behavior changes | Responsibility allocation, supplier process, regression testing |
| Weak logging | Inability to investigate incidents | Event logs, retention controls, access protection |
| Automation bias | Reviewers defer to incorrect outputs | Competence, interface design, workload controls, override paths |
| Prompt injection | Unauthorized action or disclosure | Isolation, least privilege, input/output controls, testing |
These are examples. The appropriate treatment depends on role, context, intended use, applicable requirements, and residual risk.
A worked distinction
Suppose a hiring model produces more false negatives for a protected group. The impact assessment examines consequences for applicants, affected groups, and potentially society. The risk assessment considers how that evidence affects objectives such as fair treatment, legal conformity, trustworthy service, and reputation. Risk treatment may involve data changes, model redesign, revised decision procedures, independent validation, human review, or discontinuing the use case. Monitoring tests whether the chosen measures work.
Important
Accuracy alone is not a complete risk or impact assessment. An accurate aggregate result can conceal subgroup harm, misuse, security weaknesses, or failure to meet an applicable requirement.
Which definition best matches risk in ISO management-system terminology?
The effect of uncertainty on objectives
Any financial loss caused by a computer
Only a realized harmful event
A list of Annex A controls
Which categories are expressly named in Clause 6.1.4 for potential consequences?
Organizations, regulators, and suppliers
Individuals, groups of individuals, and societies
Models, datasets, and networks
Customers, employees, and the environment as four fixed groups
How do the impact-assessment and risk-assessment processes connect?
They must be kept completely separate
The risk assessment replaces impact assessment
Impact-assessment results are considered in the AI risk assessment
Only the certification body may connect them
Sections you finish are checked off in the contents.