Exemplar Global Certified Courses from USD 99. Ending Soon!

Addressing Risks and Opportunities Under ISO 42001 Clause 6.1.1

AW

Team @ Audit Workshop

13 min read
Addressing Risks and Opportunities Under ISO 42001 Clause 6.1.1

What Clause 6.1.1 Is Actually Asking You to Do

ISO 42001 is the international standard for AI management systems, and Clause 6.1.1 sits at the heart of its planning requirements. The clause asks organisations to determine the risks and opportunities that need to be addressed to give their AI management system a reasonable chance of achieving its intended outcomes, preventing or reducing undesired effects, and achieving continual improvement.

That sounds familiar because it is. The same structure appears in ISO 9001, ISO 14001, and ISO 45001 under their respective Clause 6.1.1 requirements. But do not let the familiar language lull you into treating this as a box-ticking exercise. AI systems carry a distinct category of risk that most organisations have never formally assessed before, and the standard expects you to take that seriously.

This article walks through what Clause 6.1.1 actually requires, how to approach it in practice, and what auditors will be looking for when they sit down to evaluate your AI management system.

The Foundation: Context, Interested Parties and Scope

Before you can address risks and opportunities under Clause 6.1.1, you need to have done the work in Clause 4. The standard is explicit about this. Your risk and opportunity assessment must consider the issues identified in Clause 4.1 (context of the organisation) and the requirements of interested parties identified in Clause 4.2.

In practice, this means your planning work is only as good as your context analysis. If your Clause 4 work was superficial, your Clause 6.1.1 output will reflect that. Auditors know this, and they will often trace backwards from your risk register to test whether the risks you have identified are genuinely connected to the context you described.

For AI systems specifically, the context questions matter enormously. What type of AI system does your organisation use or develop? Who interacts with it? What decisions does it influence or make? What data does it process? The answers to these questions shape the entire risk landscape. An organisation using a simple document classification tool faces a very different set of risks compared to one deploying a system that makes credit decisions or clinical recommendations.

If you want a thorough grounding in how Clause 4 feeds into planning, the article on What Clause 4 of ISO 42001 Asks About Your Organisation's AI Context covers that groundwork in detail.

What Counts as a Risk Under ISO 42001

The standard defines risk in the conventional ISO sense: effect of uncertainty on objectives. But in the AI context, the nature of that uncertainty is broader and more varied than in most other management systems.

Technical Risks

These include model performance degradation over time, training data that does not represent the population the system will serve, algorithmic bias that produces discriminatory outputs, and failures in the system's ability to generalise beyond its training conditions. These are not hypothetical concerns. They are documented failure modes that have caused real harm in deployed AI systems.

Ethical and Social Risks

ISO 42001 is one of the few management system standards that explicitly incorporates ethical considerations into its risk framework. Risks here include systems that produce outcomes that are unfair, opaque, or that erode human autonomy. The standard's Annex A provides controls specifically designed to address these concerns, including requirements around transparency, explainability, and human oversight.

Operational Risks

These are the risks that quality and compliance professionals are more accustomed to: supplier dependencies, competence gaps, inadequate testing before deployment, poor change management when models are updated, and insufficient monitoring once a system is live.

Legal and Regulatory Risks

Depending on your jurisdiction and sector, AI systems may be subject to specific regulatory requirements. In Australia, the government has been developing an AI governance framework, and certain uses of AI in regulated industries such as financial services, healthcare, and employment are already subject to existing legislation. Your risk assessment needs to capture these compliance obligations.

Reputational Risks

If an AI system produces outputs that harm customers, employees, or third parties, the reputational consequences can be severe. This is particularly true where the harm is discriminatory or where the organisation is seen to have deployed a system without adequate oversight.

What Counts as an Opportunity Under ISO 42001

Opportunities often get less attention than risks, but the standard treats them as equally important. An opportunity in this context is a set of circumstances that make it possible to achieve a favourable outcome that would not otherwise be achievable.

For AI systems, opportunities might include using AI to improve the consistency and speed of quality checks, reducing human error in repetitive decision-making tasks, enabling personalised services at scale, or identifying patterns in data that would be impossible to detect manually. The key is that these opportunities must be genuine and connected to your system's intended outcomes, not just aspirational statements about what AI might one day do.

In practice, organisations often identify opportunities through the same process they use to identify risks. When you examine a particular AI application and ask what could go wrong, you naturally also surface what could go right if the system is well-designed and well-governed. Document both.

How to Structure Your Risk and Opportunity Assessment

The standard does not prescribe a specific methodology, but it does require that the process be systematic and proportionate to the nature of your AI systems. Here is a practical approach that works in most organisational contexts.

Step 1: Inventory Your AI Systems

You cannot assess risks you have not identified. Start with a clear inventory of every AI system your organisation uses, develops, or deploys. This includes systems you have built internally, systems you have procured from vendors, and systems embedded in other tools you use. Many organisations are surprised by how extensive this list is once they look carefully.

For each system, document what it does, what data it uses, who it affects, and what decisions or actions it influences. This inventory becomes the foundation for everything that follows.

Step 2: Assess Each System Against Your Context

For each AI system, work through the risks and opportunities systematically. Consider the technical, ethical, operational, legal, and reputational dimensions described above. Think about who could be harmed if the system fails or behaves in an unintended way. Consider the likelihood and severity of those harms. Think about what opportunities the system creates and under what conditions those opportunities can be realised.

The AI system impact assessment, which ISO 42001 introduces as a distinct concept in Annex A.5, is closely related to this work. While the impact assessment is a separate documented process, the findings from it should feed directly into your Clause 6.1.1 risk register.

Step 3: Determine What Needs to Be Addressed

Not every risk requires the same response. Some risks will be low enough in likelihood or severity that you accept them without specific action. Others will require controls, monitoring, or changes to how the system is designed or deployed. Opportunities will require action plans to realise them. Document your reasoning clearly. Auditors want to see that you have made deliberate, informed decisions, not just listed everything and done nothing.

Step 4: Integrate With the Rest of Your AIMS

The risks and opportunities you identify in Clause 6.1.1 should flow through into your objectives (Clause 6.2), your operational controls (Clause 8), your monitoring and measurement arrangements (Clause 9.1), and your continual improvement processes (Clause 10). If your risk register sits in isolation with no visible connection to these other elements, that is a gap an auditor will find.

The Role of AI-Specific Considerations

One of the things that makes ISO 42001 genuinely different from other management system standards is its recognition that AI systems have characteristics that create risks not typically encountered in conventional quality, environmental, or safety management contexts.

Opacity is one of these. Many AI systems, particularly those based on machine learning, do not produce outputs that are easily explainable in human terms. This creates risks around accountability and makes it harder to identify when a system is behaving in an unintended way. Your risk assessment should explicitly address how your organisation manages this opacity.

Data dependency is another. AI systems are only as good as the data they are trained and operated on. Risks related to data quality, data bias, data privacy, and data security are not just technical concerns. They are fundamental to whether the system can achieve its intended outcomes without causing harm. The standard's Annex A.7 addresses data controls specifically, but the underlying risks need to be captured in your Clause 6.1.1 assessment.

The dynamic nature of AI systems also matters. Unlike a piece of equipment that behaves consistently until it breaks, AI systems can drift over time as the data they encounter changes. A model that performed well at deployment may perform poorly six months later without any obvious trigger. Your risk assessment should address how you will detect and respond to this kind of drift.

Documented Information Requirements

Clause 6.1.1 does not explicitly require a specific documented output, but in practice you will need documented evidence of your risk and opportunity assessment to demonstrate conformity. This is because Clause 6.1.2 (AI risk assessment) and Clause 6.1.3 (AI risk treatment) build directly on Clause 6.1.1, and those clauses do have documented information requirements.

At a minimum, you should be able to show an auditor a document or set of documents that identifies the risks and opportunities you have determined, explains how you arrived at those determinations, and shows how they connect to your context and interested party analysis. A well-structured risk register that references your Clause 4 outputs and feeds into your Clause 6.2 objectives is usually sufficient.

Keep the documentation proportionate. A small organisation using a single AI-assisted tool does not need the same level of documentation as a technology company with dozens of AI systems across multiple product lines. The standard's principle of proportionality applies here as it does throughout.

What Auditors Will Actually Check

When an auditor sits down to evaluate your Clause 6.1.1 compliance, they are not just looking for a risk register. They are asking a series of questions that test whether your process is genuine and effective.

First, they will check whether your risks and opportunities are actually connected to your context. If your Clause 4 analysis identified that your organisation operates in a regulated sector where AI decisions affect vulnerable populations, they will expect to see risks related to fairness, oversight, and regulatory compliance in your register. If those are absent, that is a gap.

Second, they will look for evidence that the assessment was done systematically, not just assembled to satisfy the audit. This means looking at who was involved, what inputs were used, and whether the process was documented in a way that would allow it to be repeated or reviewed.

Third, they will trace the outputs forward. Do your objectives address the risks you identified? Do your operational controls correspond to the treatment decisions you made? Is there monitoring in place for the risks you decided to accept? If the risk register is an island disconnected from the rest of the system, that is a significant finding.

Fourth, they will assess whether you have addressed AI-specific risks, not just generic management system risks. A risk register that could equally apply to an ISO 9001 system without modification is unlikely to satisfy an ISO 42001 auditor. The risks of opacity, bias, data dependency, and model drift need to appear somewhere.

For a deeper look at how this clause connects to the risk assessment and treatment processes that follow, the article on AI Risk Assessment Under ISO 42001: A Clause 6.1.2 Walkthrough is worth reading alongside this one.

Common Mistakes to Avoid

The most common mistake organisations make with Clause 6.1.1 is treating it as a generic risk management exercise. They pull out a standard risk register template, populate it with generic risks, and consider the job done. This approach will not survive scrutiny from a competent auditor, and more importantly, it will not actually protect your organisation or the people affected by your AI systems.

The second common mistake is failing to update the assessment when circumstances change. AI systems evolve. Regulations change. The data environment shifts. Your Clause 6.1.1 assessment is not a one-time exercise. It needs to be reviewed at planned intervals and whenever significant changes occur. Build this into your management system from the start.

The third mistake is separating the risk and opportunity assessment from the people who actually understand the AI systems. This work cannot be done by the compliance team alone. It requires input from the technical people who build or configure the systems, the operational people who use them, and the people who understand the regulatory and ethical landscape. If your risk register was produced by one person in isolation, it is probably incomplete.

Understanding how the planning requirements in Clause 6.1.1 connect to the broader structure of risk-based thinking across ISO standards is also useful context. The article on Risk Based Thinking With Practical Examples provides that broader perspective in a practical way.

Connecting Clause 6.1.1 to Your AI Objectives

One of the clearest tests of whether your Clause 6.1.1 work is effective is whether it drives meaningful objectives under Clause 6.2. If your risk assessment identifies that a particular AI system poses a significant risk of producing biased outputs in hiring decisions, your objectives should include something measurable related to detecting and reducing that bias. If your assessment identifies an opportunity to improve customer service response times through AI, your objectives should reflect a commitment to realising that opportunity in a measurable way.

The connection between risk identification and objective-setting is where many organisations fall short. They do the risk assessment, they set the objectives, but the two documents have no visible relationship. Auditors will look for this connection explicitly. Make it easy for them to find.

Building Competence for This Work

Addressing risks and opportunities under ISO 42001 requires a combination of skills that not many organisations currently have in one place. You need people who understand AI systems technically, people who understand management system requirements, and people who can think through ethical and social implications. Building that competence takes deliberate effort.

Training is part of the answer. If you are responsible for implementing or auditing an AI management system and want to build a solid foundation in how ISO 42001 works in practice, Audit Workshop offers training courses that cover ISO 42001 alongside the broader auditing skills you need. The courses are built around real audit practice, not just theory, and are designed for practitioners who need to apply this knowledge in the real world. You can explore the available options at auditworkshop.com.

Frequently Asked Questions

Not necessarily. If your organisation already has a risk management framework or risk register for other ISO standards, you can integrate your AI-related risks and opportunities into that existing structure, provided the AI-specific risks are clearly identified and addressed. What matters is that the assessment is systematic, documented, and connected to your AI management system's context and objectives. A combined register can work well as long as it captures the distinct characteristics of AI risk, including bias, opacity, data dependency, and model drift.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.