Checklist for Clause 6.1.3 of ISO/IEC 42001 (AIMS): AI Risk Treatment
1. Introduction
Below is a certification-grade, auditor-ready tabular checklist for Clause 6.1.3 of ISO/IEC 42001 - AI Risk Treatment, developed directly from the PECB auditing slides expanded into clear, testable, evidence-based audit criteria aligned with PECB / IAS-accredited audit practice.
This checklist ensures AI risk treatment is methodical, justified, standards-aligned, approved, communicated, implemented, and traceable.
2. ISO/IEC 42001 - Clause 6.1.3: AI Risk Treatment
Audit Checklist (Treatment Selection, Controls, SoA & Execution)
| # | Clause 6.1.3 Requirement Area | Audit Objective | Audit Questions (Checklist) | Expected Evidence | Conformance (Y/N/Partial) | Findings / Gaps | Risk Rating | Improvement Actions |
|---|---|---|---|---|---|---|---|---|
| 6.1.3-1 | Risk Treatment Process | Confirm structured approach | Has the organization established a defined process to select AI risk treatment options based on risk assessment results? | Risk treatment procedure | ||||
| 6.1.3-2 | Treatment Option Selection | Validate appropriateness | Are appropriate AI risk treatment options selected (avoid, reduce, share, accept) for each non-acceptable risk? | Risk treatment decisions; rationale | ||||
| 6.1.3-3 | Risk-Treatment Traceability | Ensure linkage | Is there clear traceability between identified AI risks and selected treatment options? | Risk register ↔ treatment mapping | ||||
| 6.1.3-4 | Necessary Controls Identification | Confirm completeness | Has the organization identified all necessary controls required to implement selected treatment options? | Control lists; design documents | ||||
| 6.1.3-5 | Annex A Consideration | Verify mandatory review | Have relevant controls from Annex A been considered when selecting AI risk treatments? | Annex A mapping matrix | ||||
| 6.1.3-6 | Annex A Omission Check | Prevent control gaps | Has the organization verified that no necessary Annex A controls are omitted without justification? | Omission analysis | ||||
| 6.1.3-7 | Additional Controls | Identify beyond Annex A | Has the organization identified additional controls beyond Annex A where Annex A controls are insufficient? | Custom control definitions | ||||
| 6.1.3-8 | Annex B Guidance | Confirm best-practice use | Has guidance from Annex B been considered when designing and implementing controls? | Annex B references; design notes | ||||
| 6.1.3-9 | Statement of Applicability (SoA) | Confirm SoA existence | Has the organization developed a Statement of Applicability for AI risk controls? | Approved SoA document | ||||
| 6.1.3-10 | SoA Justification | Validate rationale | Does the SoA include justifications for inclusion or exclusion of each control (Annex A or otherwise)? | SoA justification fields | ||||
| 6.1.3-11 | SoA Completeness | Ensure defensibility | Does the SoA cover all relevant AI risks and control objectives? | SoA vs risk comparison | ||||
| 6.1.3-12 | AI Risk Treatment Plan | Confirm planning | Has the organization formulated an AI risk treatment plan? | Risk treatment plan | ||||
| 6.1.3-13 | Treatment Plan Detail | Validate executability | Does the treatment plan define actions, responsibilities, timelines, and resources? | Action plans; RACI | ||||
| 6.1.3-14 | Approval of Treatment | Confirm governance | Has the AI risk treatment plan been reviewed and approved by appropriate management? | Approval records | ||||
| 6.1.3-15 | Communication of Treatment | Verify awareness | Have risk treatment decisions and responsibilities been communicated to relevant parties? | Communication records | ||||
| 6.1.3-16 | Implementation Status | Confirm execution | Are AI risk treatment actions implemented as planned, not only documented? | Implementation evidence | ||||
| 6.1.3-17 | Residual Risk Acceptance | Validate acceptance | Are residual risks evaluated and formally accepted by authorized risk owners? | Residual risk approvals | ||||
| 6.1.3-18 | Documentation Control | Confirm traceability | Is the AI risk treatment process and outcomes documented and controlled? | DMS records; version history | ||||
| 6.1.3-19 | Effectiveness Monitoring | Assess control performance | Is the effectiveness of AI risk treatments monitored and evaluated? | KPIs; monitoring reports | ||||
| 6.1.3-20 | Review & Update | Ensure adaptability | Are AI risk treatments reviewed and updated when risks, systems, or context change? | Review logs; change records |
3. Auditor's Conclusion - Clause 6.1.3
| Assessment Area | Conclusion |
|---|---|
| Overall Conformance Status | ☠Conform ☠Minor NC ☠Major NC |
| Robustness of AI Risk Treatment | ☠Strong ☠Adequate ☠Weak |
| Statement of Applicability Quality | ☠Defensible ☠Partial ☠Not Defensible |
| Risk of Untreated AI Harm | ☠Low ☠Medium ☠High |
4. Common Auditor Findings (Clause 6.1.3)
Auditors frequently raise findings where:
- Risk treatment options are chosen without clear justification
- Annex A controls are not systematically reviewed
- SoA exists but lacks rationale for exclusions
- Treatment plans are approved but not implemented
- Residual risks are not formally accepted
5. Effectiveness of controls is not monitored
This checklist explicitly prevents those nonconformities.
6. ISOLTX Operational Alignment
Clause 6.1.3 is operationalised through:
- ERMS → AI risk treatment planning & residual risk tracking
- CAS/CAL → Annex A / B control alignment
- DMS → Statement of Applicability & approvals
- PERFORMANCE → Control effectiveness KPIs
- AUDIT → Treatment and SoA verification
- I²MAS → Incidents validating treatment effectiveness
It turns AI risk treatment into a governed, auditable, and defensible control system.
7. Contact Us Today
Are you looking to grow into an Artificial Intelligence (AI) trusted company?
Contact Crest Advisory Africa today for expert guidance on implementing ISO 42001 frameworks tailored to your organization's needs.
Start your journey today. Visit crestadvisoryafrica.com or contact us at +27 (0) 764034307 or nico@crestadvisoryafrica.com.
Let's make 2026 the year of your professional breakthrough!