If Clause 5 gives the AI management system its mandate, Clause 6, “Planning,” is where that mandate gets spent. This is the engine room of ISO 42001: the clause where you actually identify AI risk, decide what to do about it, write down which controls apply, assess the impact your systems have on people, and set objectives you can be measured against. It is the most demanding clause in the standard, and the one a certification auditor will spend the most time inside, because it is where governance stops being aspiration and becomes a plan.
The shape of Clause 6
Clause 6 has three parts, and the first has four sub-parts:
- 6.1 Actions to address risks and opportunities (general, risk assessment, risk treatment, impact assessment)
- 6.2 AI objectives and planning to achieve them
- 6.3 Planning of changes
Most of the weight is in 6.1. Here is each piece.
6.1.1 Risks and opportunities
Before assessing anything in detail, 6.1.1 asks you to consider the issues from Clause 4.1 and the requirements from 4.2, and determine the risks and opportunities that need addressing to give assurance the system can achieve its outcomes, prevent or reduce undesired effects, and drive continual improvement. It is the framing step: it sets up why you are assessing risk at all and ties it back to your context.
6.1.2 AI risk assessment
Clause 6.1.2 requires you to establish and maintain an AI risk assessment process. The emphasis is on process, not a one-off spreadsheet. You define risk criteria up front (what counts as acceptable, what does not), then use them to consistently identify, analyse and evaluate the risks your AI systems carry.
The requirement the standard stresses is repeatability: the process must produce consistent, valid and comparable results. Two people assessing the same system should reach broadly the same conclusion, and the same system assessed twice should not swing wildly. This is also where AI risk differs from ordinary information-security risk: you consider risks to the organisation and risks to individuals and society. Classifying each system by risk is the practical front end of this process.
6.1.3 AI risk treatment and the Statement of Applicability
Once you have assessed risk, 6.1.3 requires a risk treatment process: choose how to handle each risk, determine the controls needed, and, crucially, compare your chosen controls against the reference controls in Annex A of the standard, to make sure you have not missed anything.
That comparison produces the Statement of Applicability (SoA), one of the most important documents in the whole system. The SoA lists the Annex A controls, states which you have applied, justifies any you have excluded, and confirms whether the applied ones are implemented. You also produce a risk treatment plan and get it approved by the relevant owners.
For an auditor, the SoA is a map of your entire control set: they use it to check that every control you claim is real and every exclusion is defensible. Our ISO 42001 checklist walks the Annex A control areas that feed it.
6.1.4 AI system impact assessment
This sub-clause is one of the things that makes ISO 42001 an AI standard rather than a generic one. Clause 6.1.4 requires a process to assess the impact of your AI systems on individuals, groups and society, across the system lifecycle. Where risk assessment often asks “what could go wrong for us,” impact assessment asks “who could this affect, and how,” including effects on rights, fairness, safety and wellbeing.
It overlaps heavily with the EU AI Act’s fundamental-rights impact assessment and with data-protection impact assessments, and many organisations run a single combined process. We cover the mechanics in how to run an AI impact assessment. Its output feeds both your risk treatment and your human oversight design.
6.2 AI objectives
Clause 6.2 requires measurable AI objectives, set at the relevant functions and levels and consistent with the AI policy from Clause 5.2. Objectives must be monitored, communicated and updated, and you must plan how to reach each one: what will be done, what resources are needed, who is responsible, when it completes, and how results are evaluated.
Objectives are what keep the system from going static. They give leadership something concrete to steer toward and give Clause 9 something real to measure. Vague objectives (“use AI responsibly”) fail the “measurable” test; useful ones look like “every high-risk system has a documented impact assessment and named oversight owner by Q3.”
6.3 Planning of changes
The short one. When you need to change the AI management system, 6.3 says do it in a planned, considered way, rather than letting the system drift through ad-hoc edits. Given how fast AI and its regulation move, this matters more here than in older standards: your systems, models and obligations will change, and the AIMS has to change with intent, not by accident.
Common mistakes
- A risk register, not a risk process. A one-time spreadsheet is not what 6.1.2 asks for; it wants a repeatable process with defined criteria.
- Skipping the Annex A comparison. Choosing controls without checking them against Annex A, so the SoA is incomplete and exclusions are unjustified.
- Conflating risk and impact. Assessing risk to the business but never assessing impact on the people the AI affects, which 6.1.4 specifically requires.
- Unmeasurable objectives. Aspirations with no metric, which then cannot be evaluated in Clause 9.
- A static plan. Treating Clause 6 as a launch activity rather than a living one, and never revisiting it as systems and rules change.
The short version
Clause 6 is where ISO 42001 does its hardest work. You establish a repeatable AI risk assessment process with defined criteria (6.1.2), treat those risks and record your control decisions against Annex A in a Statement of Applicability (6.1.3), assess the impact of your systems on individuals and society (6.1.4), set measurable AI objectives with real plans behind them (6.2), and commit to changing the system deliberately rather than by drift (6.3). This is the clause that turns your leadership mandate into an actual plan, and it is the clause an auditor examines most closely, because it is where risk is genuinely dealt with rather than merely acknowledged.
Working toward certification? The ISO 42001 guide walks the full standard, the checklist covers the Annex A controls your SoA draws on, and our ISO 42001 consulting builds the risk and impact processes with you. For a quick baseline, the free AI governance check takes about ten minutes, no email.
Previous: Clause 5, leadership. Next: Clause 7, support.
Frequently asked questions
What is Clause 6 of ISO 42001?
Clause 6, "Planning", is where an ISO 42001 AI management system turns intent into a plan. It covers risks and opportunities (6.1.1), the AI risk assessment process (6.1.2), AI risk treatment including the Statement of Applicability against Annex A (6.1.3), the AI system impact assessment (6.1.4), setting measurable AI objectives (6.2), and planning changes to the system (6.3). It is the most technically demanding clause and the one certification auditors examine most closely, because it is where risk is actually identified and dealt with.
What is an AI risk assessment under ISO 42001?
Under Clause 6.1.2, an AI risk assessment is a defined, repeatable process for identifying, analysing and evaluating the risks associated with your AI systems against criteria you set in advance. "Repeatable" is the key word: the process must produce consistent, valid and comparable results, so that two people assessing the same system reach broadly the same conclusion. It considers risks to the organisation and, distinctively for AI, risks to individuals and society. The output feeds risk treatment.
What is a Statement of Applicability in ISO 42001?
A Statement of Applicability (SoA) is a documented record, required by Clause 6.1.3, that lists the reference controls in Annex A of ISO 42001, states which ones you have applied, justifies any you have excluded, and confirms whether the applied controls are implemented. It is the bridge between your risk assessment and the actual controls you run, and it is a central artefact in a certification audit: the auditor uses it to check that every control you claim is real and every exclusion is justified.
What is an AI system impact assessment?
Clause 6.1.4 requires a process to assess the potential consequences of your AI systems for individuals, groups of individuals and society, across the system lifecycle. It goes beyond risk to the organisation and asks who could be affected and how, including impacts on rights, fairness, safety and wellbeing. It is closely related to the EU AI Act's fundamental-rights impact assessment and to data-protection impact assessments, and in practice many organisations run one combined process. The output informs both risk treatment and human oversight.
What are AI objectives under Clause 6.2?
Clause 6.2 requires you to set AI objectives at relevant functions and levels, consistent with the AI policy. They must be measurable (where practicable), monitored, communicated and updated as needed, and you must plan how to achieve them: what will be done, what resources are needed, who is responsible, when it will be complete, and how results will be evaluated. Objectives are what stop the management system being static; they give it something concrete to improve toward and to measure in Clause 9.
Building something you need to govern?
Start with a fixed-scope AI Opportunity & Risk Audit.
Meet an Expert