You Cannot Govern What You Have Not Assessed
ISO/IEC 42001 Clause 6.1 requires two distinct assessments. AI risk asks what could go wrong for the organisation. AI impact asks what could go wrong for everyone else. Confusing them is the most common gap we find.
Traditional enterprise risk management is, quite legitimately, self-interested. AI governance requires that, and then requires something further. An AI system can perform exactly as designed, present negligible risk to the organisation, and still cause serious harm to the people it acts upon. A screening model that quietly disadvantages a protected group may never produce an incident — while doing consistent damage at scale.
AI Risk Assessment (AIRA)
Organisational exposure, assessed with an AI-aware methodology: likelihood × impact × AI-specific factors. Those factors include autonomy, opacity, data sensitivity, drift exposure, reversibility, and scale. That last factor deserves emphasis — a model with a systematic flaw makes the same poor decision every time, at volume, consistently, until someone notices. Scale converts a small error rate into a large aggregate harm.
AI Impact Assessment (AIIA)
External consequence: the effect on individuals, groups, society, and the environment. A workable AIIA covers, per system: affected populations, fairness measured across relevant groups, transparency to affected individuals, contestability of outcomes, safety implications, and societal effects at population scale.
Fairness cannot be asserted
The most common weakness: a bias section that states an intention rather than a measurement. "The model was trained on representative data and does not consider protected characteristics." Neither clause survives contact with an auditor. A defensible fairness assessment states the metric used, the measured disparity across groups, the threshold at which action is triggered, what was done, and when it will be re-measured.