AI Impact Assessment: A Step-by-Step Guide for ISO 42001

ISO Cloud Consulting editorial team
Magnifying glass over an AI network revealing faceless figures and ripples reaching homes, trees and buildings

An AI system impact assessment is a structured review of how an AI system could affect individuals, groups and society, and what you will do about it. ISO 42001 requires one for AI systems in scope. The method: describe the system, identify who it touches, rate potential harms, decide safeguards, record the result and revisit it when things change.

Key facts

  • Where it is required: ISO 42001 clause 6.1.4 (planning), clause 8.4 (doing it in operation) and Annex A controls A.5.2 to A.5.5.
  • Guidance standard: ISO/IEC 42005:2025 gives detailed guidance on AI system impact assessment (ISO page).
  • Who it looks at: individuals, groups and society, not only your own organization.
  • When: before deployment, after significant changes and at planned intervals.
  • Related law: the EU AI Act requires a fundamental rights impact assessment from certain deployers of high-risk systems; check the current text for scope and timing.

What is the difference between AI risk assessment and AI impact assessment?

AI risk assessment asks what could go wrong for your organization and its objectives. AI impact assessment asks what could happen to the people and communities affected by the system. ISO 42001 requires both, and they feed each other.

Question AI risk assessment (6.1.2) AI system impact assessment (6.1.4)
Whose harm? The organization: revenue, reputation, legal exposure, objectives Individuals, groups and society
Typical example "A biased model triggers a lawsuit" "Qualified applicants from one group are screened out"
Output Risk register and treatment plan Impact record with safeguards and residual concerns
How they connect Significant impacts become entries in the risk register, and risk treatments are checked for new impacts.

Keeping the two separate matters. A harm can be severe for a person yet small for the company, and a combined score tends to hide exactly those cases.

How do you run an AI system impact assessment, step by step?

Run it in eight steps, from a quick screen to a scheduled review. Each step produces a short written record, which becomes your audit evidence.

  1. Screen the system. Ask a few triage questions: does it make or support decisions about people, use personal or sensitive data, interact with the public, or operate where errors could cause physical, financial or legal harm? If every answer is no, record a light assessment and move on.
  2. Describe the system and its intended use. What it does, who uses it, what decisions it informs, what data it uses, whether it is built in-house or supplied, and what it must never be used for.
  3. Identify affected people. Direct users, the people the output is about, bystanders and groups who may be affected differently, such as people with disabilities, non-native speakers or older customers.
  4. Identify potential impacts. Work through fairness, privacy, safety, transparency and explainability, accessibility, economic effects, human autonomy and environmental effects. Consider both misuse and correct use that still goes wrong.
  5. Rate each impact. Score severity, likelihood and reversibility. Reversibility matters: a wrong movie recommendation is trivial; a wrongly denied benefit claim may not be easily undone.
  6. Decide safeguards. Human review points, testing across groups, clear notices to users, appeal routes, usage limits, monitoring thresholds and supplier commitments.
  7. Approve and connect. The system owner and an accountable manager sign off the residual impacts. Significant items go into the AI risk register with owners and dates.
  8. Revisit. Set triggers for reassessment: a model or vendor change, a new user group, new data sources, incidents or complaints, and a fixed review date.

What does a good impact assessment look like? A worked example

A good impact assessment is specific: it names real affected groups, links each harm to a concrete safeguard, and shows the assessment changed something. Here is a condensed example.

Harbor Lane Recruiting (fictional), a 60-person agency, plans to use a vendor's AI tool to rank incoming applications for warehouse roles.

Step What they recorded
Screening Supports decisions about people and uses personal data: full assessment needed.
Intended use Suggests a shortlist order; recruiters make every rejection decision. Not to be used for promotions or pay.
Affected people Applicants, especially those with career gaps, non-standard resumes or limited English; recruiters; client employers.
Key impacts Unfair ranking of applicants with career gaps (high severity, medium likelihood); applicants not knowing AI was used (medium); over-reliance by busy recruiters (medium).
Safeguards Quarterly comparison of shortlist rates across groups; notice to applicants that AI assists screening; recruiters must open every application in the bottom quarter before rejection; vendor to notify model changes.
What changed The original plan to auto-reject the lowest scores was dropped.
Review triggers Vendor model update, new client sector, any applicant complaint, and six months after go-live.

That final "what changed" line is what auditors like to see. It proves the assessment influenced a real decision rather than decorating one already made.

What should an AI impact assessment record contain?

A complete record lets someone who was not in the room understand what the system does, who it affects, what could go wrong and what was decided. Most good records fit on a few pages and contain the same core fields.

  • System name, owner, version and link to its inventory entry.
  • Intended use, known limits and uses that are out of bounds.
  • Affected individuals and groups, including any affected differently.
  • Each potential impact with its severity, likelihood and reversibility rating.
  • Safeguards, owners and due dates, with links to risk register entries.
  • Residual impacts accepted, and who accepted them.
  • Participants, approval date, review triggers and next review date.
  • Retention period for the record, as control A.5.3 expects results to be kept.

How does this relate to the EU AI Act?

An ISO 42001 impact assessment is not a legal assessment, but it covers much of the same ground as the EU AI Act's fundamental rights impact assessment, which applies to certain deployers of high-risk systems.

Under the 2026 Digital Omnibus, most high-risk obligations now apply from 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products. If you may fall in scope, design your impact template so it can be extended into the legal assessment later instead of starting again. Confirm your obligations against the current AI Act guidance with legal advice.

Who should be involved in an AI impact assessment?

Involve the system owner, a technical lead who understands how the model behaves, someone who represents the affected people, and a privacy or legal reviewer. One person filling in a form alone produces a weak assessment.

The "affected people" voice is the one most often missing. It might be a customer service lead who hears complaints, an HR partner, or, for high-impact systems, direct feedback from a sample of users. Engineers are good at predicting how a model fails on test data. They are less good at predicting how a real applicant feels when a system they did not know existed rejects them.

What are the most common impact assessment mistakes?

The most common mistake is treating the impact assessment as a privacy form, which misses harms such as unfair outcomes, over-reliance and lack of recourse that do not involve personal data at all.

  • Doing it after launch, when the design can no longer change.
  • Only considering the average user and missing groups affected differently.
  • Listing harms with no safeguard or owner against each one.
  • No reassessment trigger, so the record describes a model that no longer exists.
  • Skipping vendor-supplied AI because "the supplier handles that". You remain accountable for how you use it.

How do you get started with AI impact assessments?

Start with your AI system inventory, screen every system, and run a full assessment on the one with the most direct effect on people. Use it to refine your method before rolling it out further.

The AI System Impact Assessment Template ($49) gives you a structured format for screening, rating and recording impacts. If you also need the inventory, risk register and Annex A gap assessment, the ISO 42001 Starter Bundle ($129) combines them. For how impact assessment fits the wider control set, see ISO 42001 Annex A controls explained, or return to the ISO 42001 guide.

Last reviewed: 29 September 2026

Back to blog

Frequently asked questions

How is an AI impact assessment different from a DPIA?

A data protection impact assessment under privacy law focuses on risks to individuals from processing personal data. An AI system impact assessment is broader. It covers fairness, safety, transparency, accessibility and societal effects, and applies even when no personal data is involved. Where both are needed, run them together and cross-reference, so the same facts are not described twice in different ways.

How long does an AI system impact assessment take?

A low-risk internal tool can be screened and documented in an hour or two. A system that makes or supports decisions about people typically needs several working sessions across a couple of weeks, because you need input from the system owner, a technical lead, someone who understands the affected people, and legal or privacy. Reassessments after changes are usually quicker.

Does ISO 42001 require a separate impact assessment for every AI system?

The standard expects impact assessment for the AI systems in your scope, with depth proportionate to the potential consequences. In practice, organizations use a short screening step for every system and a full assessment only where screening shows meaningful potential impact. Record the screening outcome either way, because it is your evidence that the decision was deliberate.

Is ISO/IEC 42005 required for ISO 42001 certification?

No. ISO/IEC 42005:2025 is a guidance standard, so you are not audited against it. It is a helpful reference for designing your impact assessment method, and aligning with it shows auditors you took a recognized approach. Your certification audit checks your process against ISO 42001 itself, especially clause 6.1.4 and controls A.5.2 to A.5.5.

Templates that do this job

Editable Word and Excel files. Instant download. Licensed for one organization.