FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
32of32items
Across 8 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
ISO/IEC 42001 Risk Controls

Who should approve Risk Controls decisions under ISO/IEC 42001?

Control owners design, implement, operate, and monitor controls within their authority. Risk owners evaluate the remaining exposure. The designated management authority approves the risk-treatment plan and accepts residual AI risk. AIMS governance can check coverage and consistency, while top management addresses resources or risk decisions outside delegated authority.

Security, privacy, safety, supplier, legal, product, and business owners should approve matters within their authority. Acceptance of residual AI risk under the AIMS cannot waive a binding legal, contractual, or sector requirement.

  • Name the control owner, risk owner, evidence owner, residual-risk approver, and escalation authority.
  • Separate control design and testing from residual-risk acceptance where practical.
  • Keep approval records with the evidence rather than in disconnected email threads.
Citations
ISO/IEC 42001:2023 standard page

ISO/IEC 42001:2023 Clauses 5.3 and 6.1.3 require assigned authorities and designated management approval of treatment and residual AI risks.

ISO/IEC 42001 Risk Controls

When should Risk Controls be reviewed under ISO/IEC 42001?

Review controls through planned monitoring and whenever risks, impacts, intended purpose, users, affected populations, data, model or system design, suppliers, deployment context, incidents, performance, or applicable requirements change. Review before a significant planned change and after an unintended change or control failure.

When a treatment option is ineffective, ISO/IEC 42001 requires review and revalidation through the treatment process and an updated plan. Determine whether to redesign, add, replace, or withdraw controls; reassess the risk and impact; update the statement of applicability; obtain approval; and verify the revised treatment.

After a nonconformity, control and correct it, deal with consequences, examine causes and similar potential failures where applicable, implement corrective action, and review effectiveness. Keep the remaining risk open until the relevant approval authority accepts it against current criteria.

  • Reassess residual risk after material change or control failure.
  • Add, replace, or redesign controls when the necessary treatment is not covered or the existing control is ineffective.
  • Verify corrective-action effectiveness and update management-review inputs.
Citations
ISO/IEC 42001:2023 standard page

ISO/IEC 42001:2023 Clauses 8.2-8.4 and 10.2 require change-triggered reassessment, revalidation of ineffective treatment, updated plans, and review of corrective-action effectiveness.

Page 3 of 3