Checklist for Clause 6.1 of ISO/IEC 42001 (AIMS): Actions to address Risks and Opportunities
1. Introduction
Below is a certification-grade, auditor-ready tabular checklist for Clause 6.1 of ISO/IEC 42001 - Actions to Address Risks and Opportunities, built directly from the PECB auditing slide provided and expanded into auditor-testable, evidence-based criteria consistent with PECB / IAS-accredited audit practice.
This checklist ensures AI risk management is structured, risk-based, standards-aligned, implemented, and demonstrably effective—not theoretical.
2. ISO/IEC 42001 - Clause 6.1: Actions to Address Risks and Opportunities
Audit Checklist (Risk Criteria, Planning, Integration & Effectiveness)
| # | Clause 6.1 Requirement Area | Audit Objective | Audit Questions (Checklist) | Expected Evidence | Conformance (Y/N/Partial) | Findings / Gaps | Risk Rating | Improvement Actions |
|---|---|---|---|---|---|---|---|---|
| 6.1-1 | Context Consideration (4.1) | Confirm linkage to context | Has the organization considered internal and external issues identified in Clause 4.1 when planning actions for the AIMS? | Context analysis; planning records | ||||
| 6.1-2 | Interested Parties (4.2) | Confirm stakeholder linkage | Have the needs and expectations of interested parties (Clause 4.2) been considered when identifying AI risks and opportunities? | Stakeholder requirements matrix | ||||
| 6.1-3 | Risk & Opportunity Process | Verify formal process | Has the organization established a defined and repeatable process to identify AI-related risks and opportunities? | Risk management procedure; methodology | ||||
| 6.1-4 | Intended Outcomes Assurance | Validate purpose | Does the risk process ensure the AIMS can achieve intended results, prevent undesired effects, and enable continual improvement? | Risk objectives; performance criteria | ||||
| 6.1-5 | AI Risk Criteria | Confirm criteria establishment | Has the organization established and documented AI risk criteria? | Risk criteria document; scoring model | ||||
| 6.1-6 | Risk Acceptability | Validate thresholds | Do the AI risk criteria clearly distinguish acceptable vs non-acceptable risks? | Risk appetite; tolerance thresholds | ||||
| 6.1-7 | AI Risk Assessment | Confirm assessment execution | Are AI risk assessments performed in accordance with defined criteria and methodology? | AI risk register; assessment records | ||||
| 6.1-8 | Impact Assessment | Validate depth | Do risk assessments include impact analysis (ethical, legal, safety, societal, operational)? | Impact scoring; consequence analysis | ||||
| 6.1-9 | Risk Treatment | Confirm treatment planning | Has the organization planned and implemented AI risk treatment actions for non-acceptable risks? | Risk treatment plans; controls | ||||
| 6.1-10 | Opportunity Identification | Balance risk & value | Are AI opportunities identified alongside risks (e.g. innovation, performance, resilience)? | Opportunity register; improvement plans | ||||
| 6.1-11 | Standards Alignment | Verify external guidance | Is the AI risk approach aligned with ISO/IEC 38507 and ISO/IEC 23894 guidance? | Mapping analysis; methodology references | ||||
| 6.1-12 | Domain & Use Context | Confirm contextual accuracy | Are risks and opportunities determined based on the AI system's domain, application context, and intended use? | Use-case definitions; AI system profiles | ||||
| 6.1-13 | Multi-AI Scoping | Verify scalability | Where multiple AI systems exist, are risks and opportunities determined per AI system or defined groupings? | System-level risk registers | ||||
| 6.1-14 | Planning Actions | Confirm action definition | Have specific actions been planned to address identified AI risks and opportunities? | Action plans; roadmaps | ||||
| 6.1-15 | Integration | Validate operational embedding | Are planned actions integrated into AIMS processes and business operations? | Process updates; control integration | ||||
| 6.1-16 | Implementation | Confirm execution | Are risk and opportunity actions implemented as planned, not only defined? | Implementation evidence; records | ||||
| 6.1-17 | Effectiveness Evaluation | Assess results | Is the effectiveness of actions evaluated to ensure AI risks are controlled and opportunities realised? | Monitoring results; KPIs | ||||
| 6.1-18 | Review & Update | Confirm adaptability | Are AI risks, opportunities, and actions reviewed and updated when context, systems, or regulation changes? | Review logs; change records |
3. Auditor's Conclusion - Clause 6.1
| Assessment Area | Conclusion |
|---|---|
| Overall Conformance Status | ☠Conform ☠Minor NC ☠Major NC |
| AI Risk Management Maturity | ☠Initial ☠Defined ☠Implemented ☠Optimised |
| Alignment with ISO/IEC 38507 & 23894 | ☠Strong ☠Partial ☠Weak |
| Risk of Uncontrolled AI Impacts | ☠Low ☠Medium ☠High |
4. Common Auditor Findings (Clause 6.1)
Auditors frequently raise findings where:
- AI risks are identified but no formal risk criteria exist
- Risk assessments ignore ethical or societal impacts
- Risk treatment actions are not integrated into operations
- Multiple AI systems are covered by one generic risk register
- Effectiveness of actions is not measured or reviewed
This checklist explicitly prevents those nonconformities.
5. ISOLTX Operational Alignment
Clause 6.1 is enabled through:
- ERMS → AI risk & opportunity registers
- CAS/CAL → Legal & regulatory risk alignment
- PERFORMANCE → Risk-driven objectives & KPIs
- AUDIT → Risk effectiveness testing
- I²MAS → AI incident feedback into risk reviews
It operationalises risk-based thinking across the full AI lifecycle.
6. Contact Us Today
Are you looking to grow into an Artificial Intelligence (AI) trusted company?
Contact Crest Advisory Africa today for expert guidance on implementing ISO 42001 frameworks tailored to your organization's needs.
Start your journey today. Visit crestadvisoryafrica.com or contact us at +27 (0) 764034307 or nico@crestadvisoryafrica.com.
Let's make 2026 the year of your professional breakthrough!