[{"data":1,"prerenderedAt":14},["ShallowReactive",2],{"article:en:the-iso-42001-ai-system-impact-assessment-what-clause-6-1-4-asks-for-the-three-levels-where-it-meets-the-ai-act-the-mistakes-an-auditor-flags-and-a-page-that-writes-it":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"answer":9,"body":13},"en","the-iso-42001-ai-system-impact-assessment-what-clause-6-1-4-asks-for-the-three-levels-where-it-meets-the-ai-act-the-mistakes-an-auditor-flags-and-a-page-that-writes-it","The ISO 42001 AI system impact assessment: what Clause 6.1.4 asks for, the three levels of consequence, where it meets the AI Act, the mistakes an auditor flags, and a page that writes it","Clause 6.1.4 of ISO\u002FIEC 42001 has the company assess what each AI system could do to the individuals and groups it touches and to society, keep the result as documented information, and act on it through the system's life cycle; Clause 8.4 runs the process and four Annex A controls ask for the process, the retention, the harm to individuals and groups, and the harm beyond the users. It is the record the standard has and ISO 27001 does not. An assessment an auditor accepts names the purpose and the foreseeable misuse, the people, the consequences at the three levels with a likelihood and a severity each, the benefits, the measures, a result and a review date; under the AI Act it is the input to the Article 27 fundamental rights impact assessment and the place the company's own reading of the system is recorded. A free page writes it for one system.","2026-09-13",{"who":10,"when":11,"do":12},"A company that builds an AI system into its product or runs someone else's AI system in its work and holds or plans ISO 42001; the impact assessment is the record the certification auditor opens per system, and the one the AI Act's deployer duties reach for first.","Before an AI system is built or first used, again when its purpose, its data, its users or its outputs change, when an incident touches it, and at a review date set in the assessment itself; the first assessments before the first internal audit, since the inventory and the assessments are what the audit reads.","List the systems, and for each write the purpose and the foreseeable misuse, name the people it touches, rate the consequences to individuals, to groups and to society for likelihood and severity and describe them, weigh the benefits, set the measures and the human oversight, record a result and a review date, record the AI Act reading beside it, and keep the record; the free page writes it in that order.","\nEvery ISO management system has a risk assessment, and a company that already runs ISO 27001 expects the AI standard to ask for the same thing with a new noun. It does ask for that, at Clause 6.1.2, and then it asks for something the security standard has no version of: an assessment, per AI system, of what the system could do to the people it touches and to society, not to the company. That is Clause 6.1.4, the AI system impact assessment, and it is the clause that makes ISO 42001 a different standard rather than ISO 27001 with the word \"AI\" inserted. This article reads the clause and the controls behind it, sets out the three levels of consequence and what a rating at each looks like, shows where the assessment meets the AI Act, lists the mistakes an auditor flags, and points to the [free page](\u002Fiso-42001\u002Fimpact-assessment) that writes the assessment for one system in the clause's order.\n\n## What the clause asks for, and why it has no counterpart in ISO 27001\n\nClause 6.1.4 asks the company to define a process for assessing the potential consequences of its AI systems for individuals, for groups of individuals and for society, to run that process, to keep the results as documented information, and to use them: the impacts feed the risk assessment of 6.1.2, the treatment of 6.1.3 and the life cycle of Clause 8, where 8.4 performs the assessment in operation as 6.1.4 planned it. Four controls in Annex A carry the same subject: one asks for the process and when it must run, one for the retention of each result, one for the assessment of harm to individuals and to identifiable groups, and one for the harm beyond the people who use the system, to society. The reason there is no counterpart in ISO 27001 is the direction of the harm. A security risk is a harm to the company's information and, through it, to the company; the register asks how likely and how bad for us. An AI impact is a harm the company's system does to someone else, a person refused, misclassified, profiled or misinformed, a group treated worse on average, a public that loses something it depended on, and the company may not feel it at all. The standard therefore asks for a second register with a different subject, and an auditor who finds the impacts written as lines in the security risk register, with the company as the only party at risk, writes a finding on 6.1.4 and on the two harm controls at once.\n\n## The three levels, and what a rating at each looks like\n\nThe standard names the three levels; the company decides how to rate them, and a likelihood and a severity per level is the smallest rating that still lets a result be read. Individuals: what the system does to one person, a customer, an applicant, an employee, a patient, a reader, and to their data, safety, rights, money and standing. A support ticket classifier that rates a ticket low priority in error makes one customer wait; a credit model that scores one applicant wrong refuses one loan; the severity differs by orders of magnitude, and the rating says so. Groups: effects that appear only across a population, which is where most of the harm AI systems actually do lives, a language, a region, an age, a disability, a gender, a customer segment treated worse on average because the training data or the thresholds treat it worse. The individual cases look fine one by one; the group rating is the line that makes the company measure accuracy by group instead of overall. Society: the consequences beyond the users and the company, the environment, public discourse, employment in a sector, trust in a service people depend on, and for most internal systems the honest rating is low with a sentence saying why, which is a better record than a level left blank. The assessment then weighs the benefits to the same people, because a result that reads only the harm cannot say why the system runs at all, sets the measures that limit the harm and the human oversight that catches what the measures miss, and reads the highest of the six ratings against them: acceptable as the system stands, acceptable with the measures, which then become actions with an owner and a date, or not acceptable, in which case the purpose, the design or the measures change and the assessment is written again.\n\n## Where the assessment meets the AI Act\n\nThe AI Act does not ask for an ISO 42001 impact assessment and ISO 42001 does not ask for AI Act compliance; the two meet in the record. Under Article 27, some deployers of high-risk AI systems, public bodies and private operators of public services among them, and the deployers of the credit and insurance systems the Annex lists, assess the impact on fundamental rights before first use, naming the process, the period, the people affected, the risks of harm, the human oversight and what happens if the harm materialises. Every one of those elements is a section of the 6.1.4 assessment already written, so the management-system record is the input to the legal one, and the company that has the first writes the second in an afternoon. Under Article 50, a system that interacts with people or generates content carries a transparency duty, and the measure line of the assessment is where the company records how the people affected are told. And whether a system is high-risk at all is a reading of the Regulation's lists that the company makes and records, with its date, so that the assessment carries the reading beside the impacts without pretending to be legal advice. The free page records four readings, not yet read, high-risk, transparency duty, neither, and writes the consequence of each into the result; the [Article 27 page](\u002Fai-act\u002Ffundamental-rights-impact-assessment) decides whether the fundamental rights assessment is owed at all, and the [high-risk page](\u002Fai-act\u002Fhigh-risk) reads a system against the lists.\n\n## The mistakes an auditor flags\n\nThe assessment written as a risk register line, with the company as the only party at risk, which fails the clause's subject. Consequences written for individuals only, so that the group level, where the standard's own control lives, is missing. Every level rated without a sentence saying what the harm is, so the rating cannot be checked. The benefits left out, so the result is a list of harms and no balance. The measures written as intentions rather than actions with an owner and a date, so the next audit finds them unchanged. Assessed once, at launch, and never again, though the model, the data and the users changed. No inventory of AI systems, so nobody can say which systems have an assessment and which do not, and the auditor samples the one that does not. Human oversight named in the assessment and absent in practice, the agent who reviews every draft under normal load and none under peak. And the AI Act reading decided inside the assessment as if it were a legal determination, or missing from it as if the Regulation did not apply; the record wants the company's reading, dated, with the reasoning, and nothing more. Each of these is avoided by writing the assessment in the clause's order and by leaving a level empty rather than skipping it, because an empty level is visible and a skipped one is not.\n\n## What to do with it\n\nEnter the system on the [free page](\u002Fiso-42001\u002Fimpact-assessment): the company, the system, the company's role, where the system is, the owner and the dates; the intended purpose and the reasonably foreseeable misuse; the people it touches; for each of the three levels a likelihood, a severity and what the harm is; the benefits, the measures and the human oversight; the result and the AI Act reading. The page writes the assessment in the clause's order, with the facts and the ratings in the link and the free text kept on the page, and leaves an empty level as a gap to fill. Copy it, have the owner and someone who did not build the system read it, file it as the documented information of the system, and put the review date in the calendar. StandardOS keeps one assessment per AI system in the inventory, with the affected groups, the purpose, the foreseeable misuse and the consequences as fields, the measures as actions, the review date on the calendar and the AI Act reading beside it, so that the Annex A controls on impact assessment are evidenced by the record itself; the [AI policy](\u002Fiso-42001\u002Fai-policy) promises the assessments, and the [controls list](\u002Fiso-42001\u002Fcontrols) is where the four controls behind this one sit.\n",1789383982972]