Checklist for Clause 6.1.4 of ISO/IEC 42001 (AIMS): AI System Impact Assessment

1.        Introduction

Below is a certification-grade, auditor-ready tabular checklist for Clause 6.1.4 of ISO/IEC 42001 - AI System Impact Assessment, developed directly from the PECB auditing slides shared and expanded into clear, testable, evidence-based audit criteria aligned with PECB / IAS-accredited audit practice.

This checklist ensures AI impact assessments are defined, contextual, integrated with risk management, transparent to stakeholders where appropriate, and fully documented.

2.        ISO/IEC 42001 - Clause 6.1.4: AI System Impact Assessment

Audit Checklist (Process, Context, Integration & Transparency)

 

#

Clause 6.1.4 Requirement Area

Audit Objective

Audit Questions (Checklist)

Expected Evidence

Conformance (Y/N/Partial)

Findings / Gaps

Risk Rating

Improvement Actions

6.1.4-1

Impact Assessment Process

Confirm formal definition

Has the organization defined and documented a process for conducting AI system impact assessments?

Impact assessment procedure

       

6.1.4-2

Lifecycle Coverage

Validate completeness

Does the process assess impacts across development, deployment, use, and decommissioning of AI systems?

Lifecycle impact criteria

       

6.1.4-3

Scope Definition

Confirm applicability

Is the scope of AI system impact assessments clearly defined (systems, use cases, boundaries)?

Scope statements; system lists

       

6.1.4-4

Consequence Identification

Assess depth

Does the assessment identify potential consequences of AI systems for individuals, groups, organizations, and society?

Impact registers; consequence matrices

       

6.1.4-5

Intended & Foreseeable Misuse

Validate realism

Are impacts assessed for intended use, reasonably foreseeable misuse, and failure scenarios?

Use/misuse scenarios

       

6.1.4-6

Technical Context

Confirm contextual relevance

Does the assessment consider the technical context (model type, data sources, autonomy, accuracy, explainability)?

Technical assessment notes

       

6.1.4-7

Societal Context

Validate social considerations

Does the assessment consider societal, cultural, ethical, and legal context, including jurisdictions of deployment?

Societal impact analysis

       

6.1.4-8

Jurisdictional Considerations

Ensure regulatory awareness

Are applicable jurisdictions and regulatory environments considered in the impact assessment?

Legal context mapping

       

6.1.4-9

Availability of Results

Confirm transparency

Are AI system impact assessment results made available to relevant interested parties, where appropriate?

Disclosure records; summaries

       

6.1.4-10

Affected Persons Consideration

Validate inclusion

Are affected individuals or groups identified and considered in the impact assessment?

Stakeholder impact mapping

       

6.1.4-11

Integration with Risk Assessment

Confirm Clause 6.1.2 linkage

Are impact assessment outcomes integrated into the AI risk assessment process (Clause 6.1.2)?

Risk register updates

       

6.1.4-12

Risk & Impact Feedback Loop

Validate usefulness

Do impact assessment results inform risk analysis, prioritisation, and treatment decisions?

Treatment plan references

       

6.1.4-13

Discipline-Specific Assessments

Confirm specialised analysis

Where relevant, are discipline-specific impact assessments conducted (e.g. privacy, safety, security, bias)?

DPIAs; safety assessments

       

6.1.4-14

Control Alignment (Annex A)

Verify safeguards

Are controls for assessing and mitigating impacts aligned with Annex A (e.g. 5.5 Table A.1)?

Control mapping

       

6.1.4-15

Consistency of Application

Ensure repeatability

Is the impact assessment process applied consistently across AI systems and over time?

Assessment history

       

6.1.4-16

Documentation of Methodology

Confirm traceability

Is the methodology, assumptions, and criteria used for impact assessment documented?

Methodology documents

       

6.1.4-17

Documentation of Outcomes

Verify record keeping

Are impact assessment results documented, including identified impacts and conclusions?

Impact assessment reports

       

6.1.4-18

Decision Documentation

Confirm governance trail

Are decisions based on impact assessments (e.g. go/no-go, mitigation) documented?

Decision logs; approvals

       

6.1.4-19

Review & Update

Ensure currency

Are impact assessments reviewed and updated when AI systems, context, or deployment conditions change?

Review logs; change records

       

6.1.4-20

Management Oversight

Confirm accountability

Is there evidence of management oversight and review of AI system impact assessments?

Management review minutes

       


3.        Auditor's Conclusion - Clause 6.1.4

Assessment Area

Conclusion

Overall Conformance Status

☐ Conform ☐ Minor NC ☐ Major NC

Quality of Impact Assessment Process

☐ Robust ☐ Adequate ☐ Weak

Integration with Risk Management

☐ Strong ☐ Partial ☐ Weak

Risk of Unmitigated AI Harm

☐ Low ☐ Medium ☐ High

4.        Common Auditor Findings (Clause 6.1.4)

Auditors frequently raise findings where:

  • Impact assessments are ad-hoc or undocumented
  • Societal or jurisdictional impacts are ignored
  • Results are produced but not integrated into risk treatment
  • Affected individuals are not considered
  • Discipline-specific impacts (privacy, safety) are assumed but not assessed

This checklist explicitly prevents those nonconformities.

5.        ISOLTX Operational Alignment

Clause 6.1.4 is operationalised through:

  • ERMS → Impact-driven risk analysis
  • CAS/CAL → Jurisdictional and regulatory context
  • DMS → Impact assessment records
  • PERFORMANCE → Impact-related objectives & KPIs
  • I²MAS → Real-world incidents validating impact assumptions

It ensures AI impact assessment is defensible, repeatable, and governance-driven.

6.        Contact Us Today

Are you looking to grow into an Artificial Intelligence (AI) trusted company?

Contact Crest Advisory Africa today for expert guidance on implementing ISO 42001 frameworks tailored to your organization's needs.

Start your journey today. Visit crestadvisoryafrica.com or contact us at +27 (0) 764034307 or nico@crestadvisoryafrica.com.

Let's make 2026 the year of your professional breakthrough!