Checklist for Clause 6.1.2 of ISO/IEC 42001 (AIMS): AI Risk Assessment

1. Introduction

Below is a certification-grade, auditor-ready tabular checklist for Clause 6.1.2 of ISO/IEC 42001 - AI Risk Assessment, built directly from the PECB auditing slides provided and expanded into clear, testable, evidence-based audit criteria consistent with PECB / IAS-accredited audit practice.

This checklist ensures AI risk assessments are policy-aligned, methodologically sound, repeatable, documented, and decision-driving.

2. ISO/IEC 42001 - Clause 6.1.2: AI Risk Assessment

Audit Checklist (Alignment, Methodology, Analysis & Documentation)


# Clause 6.1.2 Requirement Area Audit Objective Audit Questions (Checklist) Expected Evidence Conformance (Y/N/Partial) Findings / Gaps Risk Rating Improvement Actions
6.1.2-1 Alignment with AI Policy Confirm policy consistency Is the AI risk assessment process informed by and aligned with the AI Policy? AI Policy; risk methodology references
6.1.2-2 Alignment with AI Objectives Verify objective linkage Are AI risks assessed in relation to the organization's AI objectives? AI objectives register; risk linkage
6.1.2-3 Defined Risk Assessment Method Confirm structured approach Has the organization defined and documented an AI risk assessment methodology? Risk assessment procedure; methodology
6.1.2-4 Consistency of Method Ensure repeatability Is the methodology applied consistently across assessments and AI systems? Historical risk assessments
6.1.2-5 Validity & Reliability Confirm robustness Is the AI risk assessment process designed to produce valid, reliable, and comparable results? Validation records; peer reviews
6.1.2-6 Risk Identification Scope Confirm completeness Does the process identify a comprehensive range of AI risks relevant to objectives and use cases? AI risk taxonomy; risk register
6.1.2-7 Objective Impact Identification Validate relevance Are risks identified that could hinder or support achievement of AI objectives? Risk-objective mapping
6.1.2-8 Consequence Analysis Assess impact analysis Are potential consequences assessed for the organization, individuals, and society if risks materialise? Impact analysis; consequence scales
6.1.2-9 Likelihood Assessment Validate realism Where applicable, is the likelihood of AI risks realistically assessed? Likelihood criteria; scoring
6.1.2-10 Risk Level Determination Confirm risk scoring Are risk levels determined using defined criteria and scoring models? Risk matrices; scoring results
6.1.2-11 Risk Criteria Application Verify threshold use Are assessed risks evaluated against established AI risk criteria? Risk appetite; tolerance thresholds
6.1.2-12 Risk Prioritisation Confirm treatment focus Are risks prioritised for treatment based on significance and potential impact? Prioritised risk register
6.1.2-13 Decision Support Validate usability Do risk assessment results support decision-making for risk treatment and controls? Decision logs; treatment plans
6.1.2-14 Multi-AI System Coverage Ensure scalability Where multiple AI systems exist, are risk assessments performed per system or logical grouping? System-specific risk records
6.1.2-15 Documentation of Process Confirm traceability Is the AI risk assessment process documented, including methodology, criteria, and steps? Procedure documents
6.1.2-16 Documentation of Outcomes Verify record keeping Are risk assessment outcomes documented, including identified risks and scores? Risk assessment reports
6.1.2-17 Documentation of Decisions Confirm governance trail Are decisions made regarding identified risks documented, including rationale? Decision records; approvals
6.1.2-18 Review & Update Confirm currency Are AI risk assessments reviewed and updated when AI systems, context, or risks change? Review logs; change records


3. Auditor's Conclusion - Clause 6.1.2

Assessment Area Conclusion
Overall Conformance Status ☐ Conform ☐ Minor NC ☐ Major NC
AI Risk Assessment Maturity ☐ Basic ☐ Defined ☐ Consistent ☐ Optimised
Consistency & Validity of Results ☐ Strong ☐ Moderate ☐ Weak
Risk of Undetected AI Harm ☐ Low ☐ Medium ☐ High

4. Common Auditor Findings (Clause 6.1.2)

Auditors frequently raise findings where:

· Risk assessments are not aligned with AI objectives or policy

· Methodology exists but is applied inconsistently

· Ethical, societal, or individual impacts are not analysed

· Risk scoring is performed but not compared to risk criteria

· Assessments are documented, but decisions are not traceable

This checklist explicitly prevents those failures.

5. ISOLTX Operational Alignment

Clause 6.1.2 is operationalised through:

· ERMS → AI risk identification, analysis, evaluation

· CAS/CAL → Regulatory and ethical risk drivers

· PERFORMANCE → Risk-driven objectives and KPIs

· AUDIT → Methodology and consistency testing

· I²MAS → Incident feedback into reassessment

It ensures AI risk assessment is repeatable, defensible, and audit-proof.

6. Contact Us Today

Are you looking to grow into an Artificial Intelligence (AI) trusted company?

Contact Crest Advisory Africa today for expert guidance on implementing ISO 42001 frameworks tailored to your organization's needs.

Start your journey today. Visit crestadvisoryafrica.com or contact us at +27 (0) 764034307 or nico@crestadvisoryafrica.com.

Let's make 2026 the year of your professional breakthrough!