Clause 8 is where the AIMS moves from planning into controlled operation. It requires the organisation to operate the processes needed to meet AIMS requirements, manage AI risk, perform AI system impact assessment and control operational change.
This clause is the practical delivery layer of ISO 42001. It is where AI governance is applied to real AI systems, real users, real data and real organisational decisions.
The organisation must plan, implement and control the processes needed to meet AIMS requirements and implement the actions identified in Clause 6.
Operational control means the organisation has defined how AI governance activities are performed, who performs them, what evidence is retained and how deviations are handled.
Operational controls may include:
- AI system inventory management
- AI risk assessment before development, deployment or significant change
- Approval gates for AI systems
- Data quality and data governance checks
- Testing, validation and evaluation processes
- Human oversight arrangements
- Supplier and third-party AI due diligence
- User information and transparency processes
- Monitoring of deployed AI systems
- Incident, issue and escalation processes
- Retirement or decommissioning controls
Operational planning should define:
| Planning area | Example evidence |
|---|---|
| Process criteria | Standards, procedures, approval rules |
| Control implementation | Workflows, checklists, system records |
| Documented information | Risk assessments, approvals, test results |
| Change control | Change records, impact reviews, approvals |
| Outsourced processes | Supplier assessments, contracts, monitoring |
Operational control should apply across the AI lifecycle, not only at the point of deployment. Many AI risks are created during design, data selection, development, procurement or configuration.
The organisation must perform AI risk assessments at planned intervals and when significant changes occur.
AI risk assessment identifies, analyses and evaluates risks associated with AI systems and the AIMS. It should consider the intended use of AI systems, reasonably foreseeable misuse, affected parties and potential consequences.
AI risk assessment should consider:
- The purpose and context of the AI system
- Who may be affected by the system
- Potential harms to individuals, groups, society or the organisation
- Data quality, representativeness and suitability
- Bias, fairness and discrimination risks
- Accuracy, robustness and reliability
- Human oversight and decision authority
- Security and misuse risks
- Transparency and explainability needs
- Legal, regulatory and contractual obligations
- Third-party dependencies
Risk assessment outputs should include:
- Identified risks
- Risk owners
- Assessment of likelihood and impact
- Treatment decisions
- Required controls
- Residual risk evaluation
- Approval or escalation decisions
- Records retained as documented information
The assessment method should be repeatable and proportionate. Higher-risk AI systems need deeper analysis, stronger controls and more senior approval.
The organisation must implement risk treatment actions based on the AI risk assessment.
Risk treatment is the step where assessment becomes action. It determines which controls will be used to reduce, avoid, transfer or accept AI-related risks.
Risk treatment options may include:
- Avoiding a high-risk AI use case
- Changing system design or intended use
- Adding human oversight or approval steps
- Improving data quality or data controls
- Applying testing, validation or monitoring controls
- Restricting access or use
- Adding transparency or user information
- Strengthening supplier contractual requirements
- Escalating residual risk for senior acceptance
Good risk treatment evidence shows:
- The link between risk and treatment action
- The control owner
- Implementation status
- Evidence of implementation
- How residual risk is evaluated
- Who accepted any remaining risk
A treatment plan is not enough on its own. Auditors will look for evidence that controls are implemented and operating.
The organisation must assess the potential consequences of AI systems for individuals, groups and society where relevant.
AI system impact assessment is broader than organisational risk. It asks who may be affected, how they may be affected and whether the AI system could create or amplify harm.
Impact assessment should consider:
- The intended purpose of the AI system
- The deployment context
- Affected individuals or groups
- Potential benefits and adverse impacts
- Fairness, accessibility and inclusion concerns
- Privacy and data protection impacts
- Human rights and societal impacts where relevant
- Transparency and contestability needs
- Dependence on automated outputs
- The effectiveness of mitigation measures
Examples of impact questions:
- Could the AI system affect access to important services or opportunities?
- Could errors create material harm?
- Could some groups be affected differently from others?
- Can affected people understand, challenge or seek review of outcomes?
- Is there meaningful human oversight?
- Are benefits and risks proportionate to the intended use?
Impact assessment should be revisited when the system, context, data, users or intended use changes.
- What operational processes control AI system development, deployment and use?
- How does the organisation maintain an inventory of in-scope AI systems?
- When are AI risk assessments required, and who approves them?
- How are risk treatment actions selected, implemented and tracked?
- How are AI system impact assessments performed and reviewed?
- How are outsourced or third-party AI processes controlled?
- What evidence shows that operational controls are followed in practice?
| Clause 8 output | Used by |
|---|---|
| Operational processes | Clause 9 (monitoring, audit), Clause 10 (improvement) |
| AI risk assessments | Annex A control selection, Statement of Applicability |
| Risk treatment plans | Clause 6 objectives, Clause 9 performance evaluation |
| AI system impact assessments | Interested party management, transparency and oversight controls |
| Operational records | Certification audit evidence |
Clause 8 is where AI governance is operated. It turns risks, objectives and controls into day-to-day processes for real AI systems.
Reference catalogue entry — use this as source material for matching funny and professional infographic cards.