What Is ISO/IEC 42005?
ISO/IEC 42005:2025 (Information technology — Artificial intelligence — AI system impact assessment) is a guidance standard published by ISO/IEC JTC 1/SC 42, the same subcommittee that developed ISO/IEC 42001. Its purpose is to give a practical methodology for identifying, evaluating, and documenting the impacts an AI system can have on individuals, groups, and society.
Risk Assessment vs. Impact Assessment: The Difference Almost Everyone Confuses
Many organizations believe they've already covered "assessing impact" because they ran an AI risk assessment. These are two distinct, complementary exercises.
Who Should Run It, and When
- Before deployment — every medium- or high-risk AI system should go through impact assessment before reaching production
- When purpose or context of use changes — a model retrained for a new use case requires a new assessment
- After an incident — a detected bias, a complaint, or a significant error requires reviewing the existing assessment
- On periodic review — at least annually for high-risk systems, aligned with the ISO 42001 internal audit cycle
The 7 Steps of an AI Impact Assessment
What the system does, what decisions it makes or supports, and what process it's integrated into. This input should come straight from your AI systems inventory.
Who does the system impact, directly or indirectly? Individuals (customers, employees, candidates), groups (communities, protected categories), and, for large-scale systems, society at large.
For each stakeholder, what type of impact could they suffer? Fundamental rights, health and safety, economic, psychological, environmental, or social — see the category table below.
For each identified impact: how severe would it be if it occurs? How likely is it to occur? And, above all, how reversible is it for the affected person?
Technical controls (confidence thresholds, human review), organizational controls (escalation, complaint channel), or design controls (excluding proxy variables for protected categories).
The final document should be signed off by the system owner and, for high-risk systems, reviewed by an independent function (risk, legal, or the AI governance committee).
The assessment is not a one-time document. Review it on significant system changes, incidents, or, at minimum, on the annual audit cycle.
Impact Categories You Need to Assess
Relationship With ISO/IEC 42001
Within its planning process (clause 6.1.4, AI system impact assessment), ISO/IEC 42001 requires the organization to establish, document, and maintain a process for assessing the impact of its AI systems. The standard says what must exist; it doesn't say how to do it in detail. ISO/IEC 42005 fills exactly that gap: it's the methodology an auditor would expect to see applied as evidence for that clause.
Relationship With the EU AI Act: The FRIA
Article 27 of the EU AI Act requires a Fundamental Rights Impact Assessment (FRIA) before putting a high-risk system into use, from two categories of deployers: (1) public-law bodies and private entities providing essential services — education, healthcare, social services, housing, or the administration of justice — when they deploy an Annex III high-risk system; and (2) any deployer, public or private, using AI to evaluate creditworthiness (credit scoring) or to price life and health insurance risk.
ISO/IEC 42005 doesn't formally replace that legal obligation, but its methodology is compatible: the stakeholder-identification, impact-category, and mitigation steps described in this guide can be adapted directly to the specific requirements Article 27 asks for, avoiding the need to build two parallel processes for the same thing.
How SoberanIA Supports Your Impact Assessment
SoberanIA's Assessments module connects the AI systems inventory with the impact assessment: every system classified as medium or high risk automatically generates an assessment template (AIIA/FRIA) with impact categories, the stakeholder register, mitigation measures, and the review history — all with traceability and digital signature ready for audit.
Frequently Asked Questions
No. ISO/IEC 42005:2025 is a guidance standard, not a certifiable requirement. You are not audited against ISO 42005 directly — you use it as the methodology to satisfy the impact-assessment obligation that ISO/IEC 42001 (and, in the EU, the AI Act) does require.
Risk assessment (ISO 42001 §6.1) looks inward: what could go wrong for the organization? Impact assessment (ISO/IEC 42005) looks outward: who does this system affect, and how? A system can carry low operational risk for the company while still having high impact on the people it evaluates — which is why both assessments are needed and neither replaces the other.
ISO 42005 recommends proportionality: low-risk systems can go through a simplified assessment, while high-risk systems — those affecting rights, access to essential services, or decisions about people — require a full, documented assessment.
It doesn't formally replace it, but the methodology is compatible. Article 27 of the EU AI Act requires a FRIA from two groups: public bodies (and private entities providing essential services) deploying Annex III high-risk systems, and any deployer using AI to evaluate creditworthiness or to price life and health insurance risk. You can use the ISO 42005 process as the methodological base and adapt it to the specific requirements Article 27 asks for.
It shouldn't be done by the technical team alone. ISO 42005 recommends involving whoever understands the context of use: the business owner of the process, legal/compliance, and, where possible, representatives of the people affected or of groups that represent them.
Run your AI impact assessment with SoberanIA
Impact assessment templates (AIIA/FRIA) connected to your AI systems inventory, with impact categories, mitigations, and digital signature.
You might also be interested in: AI Systems Inventory · ISO 42001 Roadmap · ISO 42001 vs NIST AI RMF