When should High Risk AI be reviewed under ISO/IEC 42001?
Repeat ISO risk assessments at planned intervals and when significant changes are proposed or occur; repeat impact assessments at planned intervals or when significant changes are proposed. Revisit legal classification when intended purpose, functionality, integration, operator role, branding, market, affected population, decision influence, profiling, Annex coverage, product law, guidance, or application date changes.
A name or trademark change, substantial modification, or changed intended purpose can make a distributor, importer, deployer, or other party the provider of a high-risk system under Article 25. Review before the change is released, not only after an incident.
Keep the AIMS reassessment date and the legal-classification review date separately visible because the triggers, approvers, evidence tests, and consequences differ. If either analysis changes, update controls, technical documentation, instructions, registration, conformity-assessment planning, monitoring, and customer or supplier allocations as applicable.
- Use separate change triggers for AIMS risk and legal classification.
- Update controls and evidence when either analysis changes.
- Escalate conflicts between accepted organisational risk and binding law.
Clauses 8.2-8.4 set planned and significant-change triggers for risk, treatment, and impact reassessment.
Article 6 makes classification depend on the system and its intended purpose; Articles 25 and 43 address role changes and substantial modification in relevant cases.