← All articles
AI RiskImpact AssessmentISO/IEC 42001

You Cannot Govern What You Have Not Assessed

ISO/IEC 42001 Clause 6.1 requires two distinct assessments. AI risk asks what could go wrong for the organisation. AI impact asks what could go wrong for everyone else. Confusing them is the most common gap we find.

16 Jul 2026·5 min read

Traditional enterprise risk management is, quite legitimately, self-interested. AI governance requires that, and then requires something further. An AI system can perform exactly as designed, present negligible risk to the organisation, and still cause serious harm to the people it acts upon. A screening model that quietly disadvantages a protected group may never produce an incident — while doing consistent damage at scale.

AI Risk Assessment (AIRA)

Organisational exposure, assessed with an AI-aware methodology: likelihood × impact × AI-specific factors. Those factors include autonomy, opacity, data sensitivity, drift exposure, reversibility, and scale. That last factor deserves emphasis — a model with a systematic flaw makes the same poor decision every time, at volume, consistently, until someone notices. Scale converts a small error rate into a large aggregate harm.

AI Impact Assessment (AIIA)

External consequence: the effect on individuals, groups, society, and the environment. A workable AIIA covers, per system: affected populations, fairness measured across relevant groups, transparency to affected individuals, contestability of outcomes, safety implications, and societal effects at population scale.

The two assessments can disagree. A system may be low risk to you and high impact on the people it affects. Under ISO 42001 — and under any serious reading of the AI Act — the second finding governs.

Fairness cannot be asserted

The most common weakness: a bias section that states an intention rather than a measurement. "The model was trained on representative data and does not consider protected characteristics." Neither clause survives contact with an auditor. A defensible fairness assessment states the metric used, the measured disparity across groups, the threshold at which action is triggered, what was done, and when it will be re-measured.

2Distinct assessments required
AIRAOrg risk
AIIAHuman impact

Ready to build AI systems the world can trust?

Book a complimentary 45-minute AI Governance Readiness Assessment with our Senior Lead Auditor team.

contact@gnaan.ai +91 6282 552 995