ISO/IEC 42001:2023 / clause 6

Planning

Plan how the organisation will assess AI risks and opportunities, set measurable objectives, and manage changes to the AIMS.

AIMSEVIDENCEDATAEVIDENCEMODELEVIDENCEHUMANEVIDENCEAI GOVERNANCEClause 6 AI ControlsPOLICY / CONTROL / EVIDENCE / REVIEW

How to implement it

  1. 01Define an AI risk assessment method that covers harm, bias, privacy, safety, security, reliability, explainability, misuse, and legal impact.
  2. 02Run an AI impact assessment for systems that affect people, customers, regulated decisions, safety, or material business outcomes.
  3. 03Maintain a risk treatment plan that links each risk to controls, accountable owners, due dates, and residual risk approval.
  4. 04Set AIMS objectives such as inventory coverage, assessment completion, incident response time, model monitoring coverage, and training completion.
  5. 05Define how changes to models, prompts, datasets, providers, or intended use trigger reassessment.

Evidence to keep

  • - AI risk methodology
  • - AI risk register
  • - AI impact assessments
  • - Risk treatment plan
  • - AIMS objectives and progress reports

Common mistakes

  • - Assessing only cybersecurity risk
  • - Ignoring foreseeable misuse
  • - Failing to reassess when a model is repurposed

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map