Skip to main content
AI Controls Catalog
AI-CTRL-005 AI Risk Management directive v1.0.0

AI Risk Assessment and Impact Assessment

Authored by Emmanuel Guilherme Jr. · Last reviewed 2026-05-01

Objective

Ensure that each AI system is subject to a documented risk assessment and AI System Impact Assessment (AIIA) aligned with ISO/IEC 23894 and ISO/IEC 42005, completed prior to production deployment and refreshed on material change or annually.

Applicability

AI types
LLM, Agentic AI, Traditional ML, Computer Vision, Generative AI, Multi-modal, Recommender
Deployment models
SaaS, Self-hosted, Hybrid, Edge, Embedded
Lifecycle stages
Strategy & Planning, Evaluation & Testing, Deployment
Risk domains
Governance, Model, Data
Regulatory regimes
EU AI Act, ISO 42001, ISO 23894, ISO 42005, NIST AI RMF
Company size
SMB, MidMarket, Enterprise

Rationale

EU AI Act, ISO/IEC 42001, and NIST AI RMF all require AI-specific risk treatment — generic enterprise risk frameworks miss model-specific risks (hallucination, drift, prompt injection, fairness, autonomy). A structured AIIA per ISO/IEC 42005 surfaces stakeholder, misuse, fairness, transparency, oversight, and lifecycle considerations that conventional ERM does not. Without this assessment, residual risks are unmeasured and treatment is undocumented.

Control narrative

Each AI system completes a two-stage assessment before production: (1) an AI Risk Assessment identifying threats, vulnerabilities, likelihood, and impact across the model lifecycle, aligned with ISO/IEC 23894; and (2) an AI System Impact Assessment (AIIA) aligned with ISO/IEC 42005 Annex A covering purpose, stakeholders, data, foreseeable misuse, fairness, transparency, oversight, robustness, environmental and social impact, and lifecycle considerations. The AIIA is signed off by the AI Governance lead and the business owner. Findings feed the AI Risk Register; treatment plans drive remediation. Reassessment is triggered by material change (model version, expanded scope, new data sources, new geography) or at minimum annually.

Test of Design

Procedures

  1. Obtain the AI Risk Assessment and AIIA standards and confirm coverage of ISO/IEC 23894 risk-management concepts and ISO/IEC 42005 Annex A topics.
  2. Confirm policy requires both assessments to be completed before production deployment.
  3. Confirm trigger criteria for re-assessment (material change list, annual minimum).
  4. Confirm sign-off requirements (AI Governance + business owner; Legal/Privacy for personal-data-processing systems).
  5. Confirm linkage from AIIA findings to the AI Risk Register and to controls applied.

Inquiries

  • Who facilitates the AIIA workshop or process?
  • How are stakeholder-impact considerations gathered for systems whose users are external customers or the public?
  • How are 'foreseeable misuse' scenarios identified and validated?
  • What happens if the assessment cannot be completed in time for the planned deployment date?

Inspections

  • AI Risk Assessment and AIIA standards.
  • AIIA template aligned to ISO/IEC 42005.
  • Sign-off workflow and approval records.
  • Sample of completed AIIA reports.

Test of Operating Effectiveness

Procedures

  1. From the AI System Inventory, select a sample of AI systems newly deployed to production in the audit period.
  2. For each sampled system, confirm an AI Risk Assessment and AIIA were completed prior to production deployment.
  3. Inspect the AIIA and confirm all ISO/IEC 42005 Annex A topics are addressed substantively (not boilerplate).
  4. Confirm sign-off by AI Governance and business owner with date pre-dating deployment.
  5. Trace 3 AIIA findings to entries in the AI Risk Register and confirm treatment plans with owners and target dates.
  6. For systems that experienced a material change in the audit period, confirm re-assessment occurred.

Sample-size guidance

Population AI systems newly deployed or materially changed in audit period
Low risk 5 systems
Moderate risk 10 systems
High risk 25 systems or 100% of EU AI Act high-risk classifications

Evidence requirements

Required

  • AI Risk Assessment standard PDF/Word · At fieldwork
  • AIIA standard and template (ISO/IEC 42005-aligned) PDF/Word · At fieldwork
  • Completed AIIA reports for sampled systems PDF/Word · Per sample
  • Sign-off records System / email · Per sample
  • Risk Register entries traced from AIIA findings Excel/system export · Per sample

Supporting

  • Material-change re-assessment records PDF/Word · Per change

Retention: Lifetime of the AI system + 7 years after retirement (regulated); + 3 years (otherwise)

Framework mappings

Framework References
ISO 42001 6.1, 6.2, 8.3
NIST AI RMF MAP-1.1, MAP-3.1, MAP-5.1, MEASURE-1.1
EU AI Act Article 9, Article 27
OWASP DSGAI DSGAI02
SOC 2 CC3.1, CC3.2, CC3.4
osfi_e21 Principle 1
nydfs_500 500.02, 500.09

Related controls

Changelog
  • v1.0.0 · 2026-05-01 · Initial publication.

References