AI Assurance Institute Logo AI Assurance Institute

ISO/IEC 42005:2025
AI System Impact Assessment

Guidance and practical support for conducting AI system impact assessments

Overview

ISO/IEC 42005 provides practical guidance for organisations performing artificial intelligence (AI) system impact assessments. It helps organisations developing, providing or using AI systems systematically identify, analyse and address reasonably foreseeable impacts - both beneficial and harmful - on individuals, groups of individuals and societies.

While studying the standard, a fundamental realisation emerges: the more important question is not merely whether the model performs accurately, but "What impact can this AI system create?" This shift completely changes how AI governance is approached. An AI system can be technically accurate and still create unacceptable impact on health, safety or fundamental rights. Accuracy alone is not enough.

The standard focuses on structured evaluation of how AI systems may impact: People, Business operations, Privacy, Security, Human rights, Society, and Regulatory compliance. It supports seamless integration with AI risk management (ISO/IEC 23894) and AI management systems (ISO/IEC 42001), and aligns closely with EU AI Act obligations - in particular the provider's risk management system (Article 9) and the deployer's Fundamental Rights Impact Assessment (FRIA) under Article 27 - as well as GDPR Data Protection Impact Assessments where personal data is processed. In doing so, it fosters transparency, trustworthiness and accountability across the AI system lifecycle.

When following this guidance, the assessment is performed through a professional-grade software platform that delivers a structured, auditable and collaborative workflow. Users are guided step-by-step through interactive modules covering system context, stakeholder identification, impact categories, visual risk mapping, controls review, residual impact determination and governance decision-making. The platform generates complete documentation ready for review and approval, with full version control and multi-role collaboration - producing evidence suitable for internal governance, conformity assessment and regulatory scrutiny.

Why This Matters

The growing application of AI systems brings significant benefits. At the same time, there are concerns about reasonably foreseeable negative effects, including potentially harmful, unfair or discriminatory outcomes, environmental harm and unwanted reductions in workforce. An AI system can be technically accurate and still create unacceptable impact. Accuracy alone is not enough.

Under the EU AI Act, high-risk AI systems may only be placed on the market or put into service when residual risks to health, safety and fundamental rights remain acceptable. ISO/IEC 42005 provides the structured methodology to make that determination visible, documented and governable - whether you are a provider operating a continuous risk management system or a deployer preparing a Fundamental Rights Impact Assessment.

Systematic Assessment Process

The assessment process goes beyond technical testing. Operationalised in a guided digital environment, it includes seven structured steps that ensure impacts are fully considered:

  1. Defining AI system context Capturing the nature, scope, purpose, intended and unintended uses, data, algorithms, models, deployment environment and AI Act role (provider or deployer) through interactive description modules.
  2. Identifying affected stakeholders Systematically identifying individuals, groups of individuals, societies and other interested parties that can be affected, including vulnerable persons, workers, data subjects and those whose fundamental rights may be engaged.
  3. Assessing impact categories Evaluating impacts across People, Business operations, Privacy, Security, Human rights, Society and Regulatory compliance, using the standard's harms and benefits taxonomy (including accountability, transparency, fairness, reliability, safety, explainability and environmental dimensions).
  4. Evaluating severity & likelihood Using visual risk mapping (severity versus likelihood) within the platform to position each identified impact and prioritise attention.
  5. Reviewing controls & mitigations Assessing existing or planned measures, selecting recommended controls from the knowledge base, and documenting how safeguards address identified harms - including measures relevant to EU AI Act essential requirements and GDPR principles where applicable.
  6. Determining residual impact Calculating remaining impact after controls, comparing against organisational thresholds for sensitive or restricted uses, and generating residual risk acceptance statements suitable for formal management approval.
  7. Governance review & decision making Routing the completed assessment through multi-role collaboration (preparer, reviewer, approver) for formal review, approval and continual improvement decisions - creating the auditable record required for residual impact acceptance and ongoing monitoring.

The digital workflow ensures every requirement of the standard is addressed systematically while supporting multi-disciplinary input and generating auditable evidence for conformity assessment and regulatory readiness under both ISO/IEC 42005 and the EU AI Act.

Key Features of the Guided Assessment

Benefits

Target Users

Key Takeaway

AI Impact Assessment is not a one-time exercise. It should be repeated across the AI lifecycle, when models change, when risks evolve, and when business context changes. The standard, operationalised through a guided digital platform, provides the structure, tools and traceability needed for continuous, responsible governance - ensuring that residual impacts on people and fundamental rights are identified, treated and formally accepted before an AI system is put into service or continues in operation.

Availability

ISO/IEC 42005:2025 is an International Standard available from ISO and national standards bodies. When applied through a structured digital assessment platform, it delivers a complete, efficient and auditable impact assessment process that supports both the standard's requirements and related obligations under the EU AI Act and data protection law.

Get Started Today. Complete The Assessment Online

Adopt ISO/IEC 42005 today. Perform your AI system impact assessments through a guided, collaborative digital workflow that fully implements the standard's requirements for documentation, analysis, risk visualisation, residual impact determination and continual improvement.