Clause 6.1
Actions to address risks and opportunities
Clause 6.1 requires the organization to plan its AIMS around identified risks and opportunities. It contains the two signature planning requirements of the standard: Clause 6.1.2, an AI risk assessment with documented criteria that identifies and analyzes risks from the organization's use of AI, and Clause 6.1.4, an AI system impact assessment that evaluates consequences for individuals, groups, and society. Clause 6.1.3 then requires a treatment plan selecting controls, justified in a Statement of Applicability.
For an organization whose employees use external AI tools, the 6.1.2 risk assessment must cover the data those tools receive: prompts containing client records, health information, financials, or source code are a documented risk category, not an edge case. The 6.1.4 impact assessment forces a harder question: what happens to the actual people whose personal information an employee pastes into a chatbot? IBM found in 2025 that 63% of organizations have no AI governance policy at all, which means most organizations have not started what Clause 6.1 requires them to finish.
Clause 8.2
AI risk assessment in operation
Clause 8.2 moves the risk assessment from planning into operations: the organization must perform AI risk assessments at planned intervals and when significant changes occur, using the criteria defined under Clause 6.1.2, and retain documented results.
This clause is why a one-time workshop does not satisfy the standard. New AI tools appear in browsers monthly, and employees adopt them without asking: LayerX measured in 2025 that organizations have no insight into roughly 89% of AI usage. A recurring risk assessment that never looks at actual, current AI usage across the workforce is assessing a fiction. Auditors will expect evidence that the inputs to each assessment reflect reality, which requires visibility into which tools are used and what data reaches them.
Clause 8.4
AI system impact assessment in operation
Clause 8.4 requires the organization to perform AI system impact assessments in accordance with Clause 6.1.4 at planned intervals and on significant change, and to keep documented information as evidence of the results.
Impact assessments look outward at the people affected. When personal or confidential data about clients, patients, students, or employees flows into external AI tools, the impact assessment must account for that exposure: who could be harmed, how severely, and what reduces the likelihood. An organization that redacts sensitive data before it enters AI tools can document a materially lower residual impact than one relying on a policy memo, and Clause 8.4 is where that difference gets written down.
Annex A, Control A.7
Data for AI systems
Annex A is the standard's control catalogue, selected and justified through the Statement of Applicability. The A.7 control family addresses data for AI systems: documenting data provenance, quality, preparation, and management across the AI lifecycle. Neighbouring families cover impact assessment processes (A.5), the AI system lifecycle (A.6), information for interested parties (A.8), and responsible use of AI (A.9, including acceptable-use direction).
A.7 obliges the organization to know and document what data its AI systems consume. Read together with the A.9 responsible-use controls, this covers the everyday case: employees feeding organizational data into AI tools. Evidence that sensitive data types are identified and controlled before entering AI tools, and that usage is monitored against a defined acceptable-use policy, is exactly the kind of documented operation of controls an ISO 42001 auditor samples.