Checklist for Clause 6.1.4 of ISO/IEC 42001 (AIMS): AI System Impact Assessment
1. Introduction
Below is a certification-grade, auditor-ready tabular checklist for Clause 6.1.4 of ISO/IEC 42001 - AI System Impact Assessment, developed directly from the PECB auditing slides shared and expanded into clear, testable, evidence-based audit criteria aligned with PECB / IAS-accredited audit practice.
This checklist ensures AI impact assessments are defined, contextual, integrated with risk management, transparent to stakeholders where appropriate, and fully documented.
2. ISO/IEC 42001 - Clause 6.1.4: AI System Impact Assessment
Audit Checklist (Process, Context, Integration & Transparency)
|
# |
Clause 6.1.4 Requirement Area |
Audit Objective |
Audit Questions (Checklist) |
Expected Evidence |
Conformance (Y/N/Partial) |
Findings / Gaps |
Risk Rating |
Improvement Actions |
|
6.1.4-1 |
Impact Assessment Process |
Confirm formal definition |
Has the organization defined and documented a process for conducting AI system impact assessments? |
Impact assessment procedure |
||||
|
6.1.4-2 |
Lifecycle Coverage |
Validate completeness |
Does the process assess impacts across development, deployment, use, and decommissioning of AI systems? |
Lifecycle impact criteria |
||||
|
6.1.4-3 |
Scope Definition |
Confirm applicability |
Is the scope of AI system impact assessments clearly defined (systems, use cases, boundaries)? |
Scope statements; system lists |
||||
|
6.1.4-4 |
Consequence Identification |
Assess depth |
Does the assessment identify potential consequences of AI systems for individuals, groups, organizations, and society? |
Impact registers; consequence matrices |
||||
|
6.1.4-5 |
Intended & Foreseeable Misuse |
Validate realism |
Are impacts assessed for intended use, reasonably foreseeable misuse, and failure scenarios? |
Use/misuse scenarios |
||||
|
6.1.4-6 |
Technical Context |
Confirm contextual relevance |
Does the assessment consider the technical context (model type, data sources, autonomy, accuracy, explainability)? |
Technical assessment notes |
||||
|
6.1.4-7 |
Societal Context |
Validate social considerations |
Does the assessment consider societal, cultural, ethical, and legal context, including jurisdictions of deployment? |
Societal impact analysis |
||||
|
6.1.4-8 |
Jurisdictional Considerations |
Ensure regulatory awareness |
Are applicable jurisdictions and regulatory environments considered in the impact assessment? |
Legal context mapping |
||||
|
6.1.4-9 |
Availability of Results |
Confirm transparency |
Are AI system impact assessment results made available to relevant interested parties, where appropriate? |
Disclosure records; summaries |
||||
|
6.1.4-10 |
Affected Persons Consideration |
Validate inclusion |
Are affected individuals or groups identified and considered in the impact assessment? |
Stakeholder impact mapping |
||||
|
6.1.4-11 |
Integration with Risk Assessment |
Confirm Clause 6.1.2 linkage |
Are impact assessment outcomes integrated into the AI risk assessment process (Clause 6.1.2)? |
Risk register updates |
||||
|
6.1.4-12 |
Risk & Impact Feedback Loop |
Validate usefulness |
Do impact assessment results inform risk analysis, prioritisation, and treatment decisions? |
Treatment plan references |
||||
|
6.1.4-13 |
Discipline-Specific Assessments |
Confirm specialised analysis |
Where relevant, are discipline-specific impact assessments conducted (e.g. privacy, safety, security, bias)? |
DPIAs; safety assessments |
||||
|
6.1.4-14 |
Control Alignment (Annex A) |
Verify safeguards |
Are controls for assessing and mitigating impacts aligned with Annex A (e.g. 5.5 Table A.1)? |
Control mapping |
||||
|
6.1.4-15 |
Consistency of Application |
Ensure repeatability |
Is the impact assessment process applied consistently across AI systems and over time? |
Assessment history |
||||
|
6.1.4-16 |
Documentation of Methodology |
Confirm traceability |
Is the methodology, assumptions, and criteria used for impact assessment documented? |
Methodology documents |
||||
|
6.1.4-17 |
Documentation of Outcomes |
Verify record keeping |
Are impact assessment results documented, including identified impacts and conclusions? |
Impact assessment reports |
||||
|
6.1.4-18 |
Decision Documentation |
Confirm governance trail |
Are decisions based on impact assessments (e.g. go/no-go, mitigation) documented? |
Decision logs; approvals |
||||
|
6.1.4-19 |
Review & Update |
Ensure currency |
Are impact assessments reviewed and updated when AI systems, context, or deployment conditions change? |
Review logs; change records |
||||
|
6.1.4-20 |
Management Oversight |
Confirm accountability |
Is there evidence of management oversight and review of AI system impact assessments? |
Management review minutes |
3. Auditor's Conclusion - Clause 6.1.4
|
Assessment Area |
Conclusion |
|
Overall Conformance Status |
☠Conform ☠Minor NC ☠Major NC |
|
Quality of Impact Assessment Process |
☠Robust ☠Adequate ☠Weak |
|
Integration with Risk Management |
☠Strong ☠Partial ☠Weak |
|
Risk of Unmitigated AI Harm |
☠Low ☠Medium ☠High |
4. Common Auditor Findings (Clause 6.1.4)
Auditors frequently raise findings where:
- Impact assessments are ad-hoc or undocumented
- Societal or jurisdictional impacts are ignored
- Results are produced but not integrated into risk treatment
- Affected individuals are not considered
- Discipline-specific impacts (privacy, safety) are assumed but not assessed
This checklist explicitly prevents those nonconformities.
5. ISOLTX Operational Alignment
Clause 6.1.4 is operationalised through:
- ERMS → Impact-driven risk analysis
- CAS/CAL → Jurisdictional and regulatory context
- DMS → Impact assessment records
- PERFORMANCE → Impact-related objectives & KPIs
- I²MAS → Real-world incidents validating impact assumptions
It ensures AI impact assessment is defensible, repeatable, and governance-driven.
6. Contact Us Today
Are you looking to grow into an Artificial Intelligence (AI) trusted company?
Contact Crest Advisory Africa today for expert guidance on implementing ISO 42001 frameworks tailored to your organization's needs.
Start your journey today. Visit crestadvisoryafrica.com or contact us at +27 (0) 764034307 or nico@crestadvisoryafrica.com.
Let's make 2026 the year of your professional breakthrough!