2.4 Clause 6 & 7: Planning & Support Infrastructure for AIMS
Key Takeaways
- Clause 6.1 requires establishing a formal AI risk assessment and treatment framework, evaluating likelihood and impact, and formulating a Statement of Applicability (SOA).
- Clause 6.2 mandates defining measurable AI Objectives aligned with the AI Policy, while Clause 6.3 establishes structured planning for AIMS changes.
- Clause 7.1 through 7.4 define support infrastructure requirements: allocating resources, ensuring data science and governance competence, promoting awareness, and managing communications.
- Clause 7.5 establishes strict controls for Documented Information, covering creation, updating, versioning, access control, and retention of AIMS artifacts and model documentation.
- The Statement of Applicability (SOA) serves as the critical normative artifact linking Clause 6 risk treatments to Annex A operational safeguards.
2.4 Clause 6 & 7: Planning & Support Infrastructure for AIMS
Moving from executive governance to operational execution requires structured planning and robust supporting infrastructure. ISO/IEC 42001 Clause 6 (Planning) defines how an organization identifies AI risks and opportunities, sets measurable AI objectives, and manages system changes. Complementing this, Clause 7 (Support) provisions the vital infrastructure—human competence, technical resources, awareness, communication, and documented information—necessary to sustain the Artificial Intelligence Management System (AIMS).
Subclause 6.1: Actions to Address Risks and Opportunities
Risk management is the core engine of ISO/IEC 42001. Clause 6.1 requires the organization to consider context issues (Clause 4.1) and interested party requirements (Clause 4.2) to determine risks and opportunities that must be addressed.
1. AI Risk Assessment Process (6.1.2)
The organization must define and apply an AI risk assessment process that:
- Establishes AI risk criteria, including risk acceptance criteria and criteria for performing assessments.
- Ensures that repeated assessments produce consistent, valid, and comparable results.
- Identifies AI risks associated with loss of confidentiality, integrity, availability, safety, fairness, transparency, explainability, and accountability across the AI system lifecycle.
- Assesses the potential impacts and estimates the likelihood of identified AI risks to determine risk levels.
2. AI Risk Treatment Process (6.1.3)
Following risk assessment, the organization must select appropriate risk treatment options (mitigate, avoid, transfer, or accept) and:
- Formulate an AI Risk Treatment Plan.
- Determine all controls necessary to implement the risk treatment options.
- Compare selected controls against Annex A (Normative Controls) to ensure no necessary control has been omitted.
- Produce a Statement of Applicability (SOA) stating selected controls, justifications for inclusions/exclusions, and implementation status.
- Obtain risk owners' approval for the risk treatment plan and acceptance of residual AI risks.
Subclause 6.2 & 6.3: AI Objectives & Planning of Changes
Establishing AI Objectives (6.2)
Clause 6.2 requires establishing documented, measurable AI Objectives at relevant functions and levels. Objectives must be:
- Consistent with the AI Policy.
- Measurable (if practicable) using defined key performance indicators (KPIs).
- Monitored, communicated, and updated as appropriate.
- Accompanied by plans defining what will be done, what resources are required, who is responsible, when it will be completed, and how results will be evaluated.
Planning of Changes (6.3)
When the organization determines the need for changes to the AIMS or AI systems (e.g., retraining a foundation model, switching cloud AI providers, or modifying data pipelines), changes must be carried out in a planned and systematic manner, considering potential consequences and resource availability.
Clause 7: Support Infrastructure
Clause 7 outlines the enabling infrastructure required to operationalize AIMS plans across five key subclauses:
+---------------------------+
| CLAUSE 7 SUPPORT |
+---------------------------+
|
+----------+----------+------------+------------+----------+
| | | | |
v v v v v
+-------+ +--------+ +---------+ +---------+ +------------+
| 7.1 | | 7.2 | | 7.3 | | 7.4 | | 7.5 |
|Resour-| |Compe- | |Awareness| |Comms | |Documented |
| ces | | tence | | | | | | Information|
+-------+ +--------+ +---------+ +---------+ +------------+
Subclause 7.1: Resources
The organization must determine and provide the resources needed for the establishment, implementation, maintenance, and continual improvement of the AIMS. This includes compute infrastructure, secure data storage, specialized testing tools, and adequate funding.
Subclause 7.2: Competence
Personnel affecting AIMS performance must be competent on the basis of appropriate education, training, or experience. For AI, competence spans:
- Data science and machine learning engineering.
- Algorithmic fairness and bias testing methodologies.
- AI security, adversarial attack mitigation, and privacy protection.
- Regulatory compliance and AI ethics. The organization must retain appropriate documented information as evidence of competence.
Subclause 7.3: Awareness
Personnel doing work under the organization’s control must be aware of:
- The AI Policy and ethical principles.
- Their contribution to the effectiveness of the AIMS, including benefits of improved AI safety.
- The implications of not conforming to AIMS requirements.
Subclause 7.4: Communication
The organization must determine internal and external communications relevant to the AIMS, specifying what to communicate, when, with whom, how, and who is authorized to communicate (crucial for disclosing AI incidents or external transparency reports).
Subclause 7.5: Documented Information
The AIMS must include documented information required by ISO/IEC 42001 and determined by the organization as necessary for effectiveness. Controls must cover:
- Creation and updating (identification, format, media, review, approval).
- Control of documented information (distribution, access, retrieval, storage, protection, version control, and disposition).
- Special AI artifacts: Model Cards, dataset lineage logs, model evaluation reports, and SOA versions.
Summary Comparison: Clause 6 Planning vs. Clause 7 Support
| Dimension | Clause 6: Planning | Clause 7: Support |
|---|---|---|
| Primary Purpose | Identify risks/opportunities and define measurable targets. | Provide human, technical, and informational capabilities. |
| Key Deliverables | Risk Treatment Plan, SOA, AI Objectives, Change Plans. | Competence matrix, awareness training, Documented Information procedures. |
| Audit Focus | Methodological rigor of risk assessments and SOA justification. | Evidence of staff competence, resource adequacy, and document control. |
What is the primary role of the Statement of Applicability (SOA) produced under Subclause 6.1.3?
Under ISO/IEC 42001 Subclause 7.2 (Competence), what action must an organization take regarding personnel whose work affects AIMS performance?
Which of the following artifacts represents a specialized form of 'Documented Information' (Subclause 7.5) commonly managed within an AIMS?
When an organization plans a major retrain of a core AI model that alters data processing pipelines, which clause mandates systematic management of this process?