What Clause 6.1.1 Is Actually Asking You to Do
ISO 42001 is the international standard for AI management systems, and Clause 6.1.1 sits at the heart of its planning requirements. The clause asks organisations to determine the risks and opportunities that need to be addressed to give their AI management system a reasonable chance of achieving its intended outcomes, preventing or reducing undesired effects, and achieving continual improvement.
On this page
That sounds familiar because it is. The same structure appears in ISO 9001, ISO 14001, and ISO 45001 under their respective Clause 6.1.1 requirements. But do not let the familiar language lull you into treating this as a box-ticking exercise. AI systems carry a distinct category of risk that most organisations have never formally assessed before, and the standard expects you to take that seriously.
This article walks through what Clause 6.1.1 actually requires, how to approach it in practice, and what auditors will be looking for when they sit down to evaluate your AI management system.
The Foundation: Context, Interested Parties and Scope
Before you can address risks and opportunities under Clause 6.1.1, you need to have done the work in Clause 4. The standard is explicit about this. Your risk and opportunity assessment must consider the issues identified in Clause 4.1 (context of the organisation) and the requirements of interested parties identified in Clause 4.2.
In practice, this means your planning work is only as good as your context analysis. If your Clause 4 work was superficial, your Clause 6.1.1 output will reflect that. Auditors know this, and they will often trace backwards from your risk register to test whether the risks you have identified are genuinely connected to the context you described.
For AI systems specifically, the context questions matter enormously. What type of AI system does your organisation use or develop? Who interacts with it? What decisions does it influence or make? What data does it process? The answers to these questions shape the entire risk landscape. An organisation using a simple document classification tool faces a very different set of risks compared to one deploying a system that makes credit decisions or clinical recommendations.
If you want a thorough grounding in how Clause 4 feeds into planning, the article on What Clause 4 of ISO 42001 Asks About Your Organisation's AI Context covers that groundwork in detail.
Exemplar Global Recognised Training ProviderRTP No. 310970What Counts as a Risk Under ISO 42001
The standard defines risk in the conventional ISO sense: effect of uncertainty on objectives. But in the AI context, the nature of that uncertainty is broader and more varied than in most other management systems.
Technical Risks
These include model performance degradation over time, training data that does not represent the population the system will serve, algorithmic bias that produces discriminatory outputs, and failures in the system's ability to generalise beyond its training conditions. These are not hypothetical concerns. They are documented failure modes that have caused real harm in deployed AI systems.
Ethical and Social Risks
ISO 42001 is one of the few management system standards that explicitly incorporates ethical considerations into its risk framework. Risks here include systems that produce outcomes that are unfair, opaque, or that erode human autonomy. The standard's Annex A provides controls specifically designed to address these concerns, including requirements around transparency, explainability, and human oversight.
Operational Risks
These are the risks that quality and compliance professionals are more accustomed to: supplier dependencies, competence gaps, inadequate testing before deployment, poor change management when models are updated, and insufficient monitoring once a system is live.
Legal and Regulatory Risks
Depending on your jurisdiction and sector, AI systems may be subject to specific regulatory requirements. In Australia, the government has been developing an AI governance framework, and certain uses of AI in regulated industries such as financial services, healthcare, and employment are already subject to existing legislation. Your risk assessment needs to capture these compliance obligations.
Reputational Risks
If an AI system produces outputs that harm customers, employees, or third parties, the reputational consequences can be severe. This is particularly true where the harm is discriminatory or where the organisation is seen to have deployed a system without adequate oversight.
What Counts as an Opportunity Under ISO 42001
Opportunities often get less attention than risks, but the standard treats them as equally important. An opportunity in this context is a set of circumstances that make it possible to achieve a favourable outcome that would not otherwise be achievable.
For AI systems, opportunities might include using AI to improve the consistency and speed of quality checks, reducing human error in repetitive decision-making tasks, enabling personalised services at scale, or identifying patterns in data that would be impossible to detect manually. The key is that these opportunities must be genuine and connected to your system's intended outcomes, not just aspirational statements about what AI might one day do.
In practice, organisations often identify opportunities through the same process they use to identify risks. When you examine a particular AI application and ask what could go wrong, you naturally also surface what could go right if the system is well-designed and well-governed. Document both.
How to Structure Your Risk and Opportunity Assessment
The standard does not prescribe a specific methodology, but it does require that the process be systematic and proportionate to the nature of your AI systems. Here is a practical approach that works in most organisational contexts.
Step 1: Inventory Your AI Systems
You cannot assess risks you have not identified. Start with a clear inventory of every AI system your organisation uses, develops, or deploys. This includes systems you have built internally, systems you have procured from vendors, and systems embedded in other tools you use. Many organisations are surprised by how extensive this list is once they look carefully.
For each system, document what it does, what data it uses, who it affects, and what decisions or actions it influences. This inventory becomes the foundation for everything that follows.
Step 2: Assess Each System Against Your Context
For each AI system, work through the risks and opportunities systematically. Consider the technical, ethical, operational, legal, and reputational dimensions described above. Think about who could be harmed if the system fails or behaves in an unintended way. Consider the likelihood and severity of those harms. Think about what opportunities the system creates and under what conditions those opportunities can be realised.
The AI system impact assessment, which ISO 42001 introduces as a distinct concept in Annex A.5, is closely related to this work. While the impact assessment is a separate documented process, the findings from it should feed directly into your Clause 6.1.1 risk register.
Step 3: Determine What Needs to Be Addressed
Not every risk requires the same response. Some risks will be low enough in likelihood or severity that you accept them without specific action. Others will require controls, monitoring, or changes to how the system is designed or deployed. Opportunities will require action plans to realise them. Document your reasoning clearly. Auditors want to see that you have made deliberate, informed decisions, not just listed everything and done nothing.
Step 4: Integrate With the Rest of Your AIMS
The risks and opportunities you identify in Clause 6.1.1 should flow through into your objectives (Clause 6.2), your operational controls (Clause 8), your monitoring and measurement arrangements (Clause 9.1), and your continual improvement processes (Clause 10). If your risk register sits in isolation with no visible connection to these other elements, that is a gap an auditor will find.
The Role of AI-Specific Considerations
One of the things that makes ISO 42001 genuinely different from other management system standards is its recognition that AI systems have characteristics that create risks not typically encountered in conventional quality, environmental, or safety management contexts.
Opacity is one of these. Many AI systems, particularly those based on machine learning, do not produce outputs that are easily explainable in human terms. This creates risks around accountability and makes it harder to identify when a system is behaving in an unintended way. Your risk assessment should explicitly address how your organisation manages this opacity.
Data dependency is another. AI systems are only as good as the data they are trained and operated on. Risks related to data quality, data bias, data privacy, and data security are not just technical concerns. They are fundamental to whether the system can achieve its intended outcomes without causing harm. The standard's Annex A.7 addresses data controls specifically, but the underlying risks need to be captured in your Clause 6.1.1 assessment.
The dynamic nature of AI systems also matters. Unlike a piece of equipment that behaves consistently until it breaks, AI systems can drift over time as the data they encounter changes. A model that performed well at deployment may perform poorly six months later without any obvious trigger. Your risk assessment should address how you will detect and respond to this kind of drift.
Documented Information Requirements
Clause 6.1.1 does not explicitly require a specific documented output, but in practice you will need documented evidence of your risk and opportunity assessment to demonstrate conformity. This is because Clause 6.1.2 (AI risk assessment) and Clause 6.1.3 (AI risk treatment) build directly on Clause 6.1.1, and those clauses do have documented information requirements.
At a minimum, you should be able to show an auditor a document or set of documents that identifies the risks and opportunities you have determined, explains how you arrived at those determinations, and shows how they connect to your context and interested party analysis. A well-structured risk register that references your Clause 4 outputs and feeds into your Clause 6.2 objectives is usually sufficient.
Keep the documentation proportionate. A small organisation using a single AI-assisted tool does not need the same level of documentation as a technology company with dozens of AI systems across multiple product lines. The standard's principle of proportionality applies here as it does throughout.
What Auditors Will Actually Check
When an auditor sits down to evaluate your Clause 6.1.1 compliance, they are not just looking for a risk register. They are asking a series of questions that test whether your process is genuine and effective.
First, they will check whether your risks and opportunities are actually connected to your context. If your Clause 4 analysis identified that your organisation operates in a regulated sector where AI decisions affect vulnerable populations, they will expect to see risks related to fairness, oversight, and regulatory compliance in your register. If those are absent, that is a gap.
Second, they will look for evidence that the assessment was done systematically, not just assembled to satisfy the audit. This means looking at who was involved, what inputs were used, and whether the process was documented in a way that would allow it to be repeated or reviewed.
Third, they will trace the outputs forward. Do your objectives address the risks you identified? Do your operational controls correspond to the treatment decisions you made? Is there monitoring in place for the risks you decided to accept? If the risk register is an island disconnected from the rest of the system, that is a significant finding.
Fourth, they will assess whether you have addressed AI-specific risks, not just generic management system risks. A risk register that could equally apply to an ISO 9001 system without modification is unlikely to satisfy an ISO 42001 auditor. The risks of opacity, bias, data dependency, and model drift need to appear somewhere.
For a deeper look at how this clause connects to the risk assessment and treatment processes that follow, the article on AI Risk Assessment Under ISO 42001: A Clause 6.1.2 Walkthrough is worth reading alongside this one.
Common Mistakes to Avoid
The most common mistake organisations make with Clause 6.1.1 is treating it as a generic risk management exercise. They pull out a standard risk register template, populate it with generic risks, and consider the job done. This approach will not survive scrutiny from a competent auditor, and more importantly, it will not actually protect your organisation or the people affected by your AI systems.
The second common mistake is failing to update the assessment when circumstances change. AI systems evolve. Regulations change. The data environment shifts. Your Clause 6.1.1 assessment is not a one-time exercise. It needs to be reviewed at planned intervals and whenever significant changes occur. Build this into your management system from the start.
The third mistake is separating the risk and opportunity assessment from the people who actually understand the AI systems. This work cannot be done by the compliance team alone. It requires input from the technical people who build or configure the systems, the operational people who use them, and the people who understand the regulatory and ethical landscape. If your risk register was produced by one person in isolation, it is probably incomplete.
Understanding how the planning requirements in Clause 6.1.1 connect to the broader structure of risk-based thinking across ISO standards is also useful context. The article on Risk Based Thinking With Practical Examples provides that broader perspective in a practical way.
Exemplar Global Recognised Training ProviderRTP No. 310970Connecting Clause 6.1.1 to Your AI Objectives
One of the clearest tests of whether your Clause 6.1.1 work is effective is whether it drives meaningful objectives under Clause 6.2. If your risk assessment identifies that a particular AI system poses a significant risk of producing biased outputs in hiring decisions, your objectives should include something measurable related to detecting and reducing that bias. If your assessment identifies an opportunity to improve customer service response times through AI, your objectives should reflect a commitment to realising that opportunity in a measurable way.
The connection between risk identification and objective-setting is where many organisations fall short. They do the risk assessment, they set the objectives, but the two documents have no visible relationship. Auditors will look for this connection explicitly. Make it easy for them to find.
Building Competence for This Work
Addressing risks and opportunities under ISO 42001 requires a combination of skills that not many organisations currently have in one place. You need people who understand AI systems technically, people who understand management system requirements, and people who can think through ethical and social implications. Building that competence takes deliberate effort.
Training is part of the answer. If you are responsible for implementing or auditing an AI management system and want to build a solid foundation in how ISO 42001 works in practice, Audit Workshop offers training courses that cover ISO 42001 alongside the broader auditing skills you need. The courses are built around real audit practice, not just theory, and are designed for practitioners who need to apply this knowledge in the real world. You can explore the available options at auditworkshop.com.













