← AI security in plain English

Clause 6

ISO/IEC 42001 / Planning and AI risk

The organization identifies what could go wrong with its AI, decides which risks matter most, plans how to treat them, and sets measurable objectives to steer the program.

Think of it likeChildproofing the house before the baby crawls: you walk room to room spotting hazards, decide which to fix first, and plan the safety gates and outlet covers.

In plain English

The organization runs an AI risk assessment, chooses treatments for the risks it finds, and sets concrete goals so the plan can be tracked over time.