What Is ISO/IEC 42005?

ISO/IEC 42005:2025 (Information technology — Artificial intelligence — AI system impact assessment) is a guidance standard published by ISO/IEC JTC 1/SC 42, the same subcommittee that developed ISO/IEC 42001. Its purpose is to give a practical methodology for identifying, evaluating, and documenting the impacts an AI system can have on individuals, groups, and society.

It is not a certifiable standard. Unlike ISO/IEC 42001 (which is certified through third-party audit), ISO/IEC 42005 is technical guidance. You use it as the methodology to satisfy the impact-assessment obligation your AI management system requires — and, in the European Union, to structure the AI Act's Fundamental Rights Impact Assessment (FRIA).

Risk Assessment vs. Impact Assessment: The Difference Almost Everyone Confuses

Many organizations believe they've already covered "assessing impact" because they ran an AI risk assessment. These are two distinct, complementary exercises.

Aspect
Risk Assessment (ISO 42001 §6.1)
Impact Assessment (ISO/IEC 42005)
Central question
What could go wrong for the organization?
Who does this system affect, and how?
Focus
Inward — continuity, reputation, compliance
Outward — people, groups, society
Example
"If the model fails, which business process breaks?"
"If the model gets it wrong, which person is unfairly denied credit?"
A system can carry low operational risk for the company (cheap to replace, doesn't affect revenue) while still having high impact on the people it evaluates. That's why both assessments are necessary — neither replaces the other.

Who Should Run It, and When

  • Before deployment — every medium- or high-risk AI system should go through impact assessment before reaching production
  • When purpose or context of use changes — a model retrained for a new use case requires a new assessment
  • After an incident — a detected bias, a complaint, or a significant error requires reviewing the existing assessment
  • On periodic review — at least annually for high-risk systems, aligned with the ISO 42001 internal audit cycle
ISO 42005 recommends proportionality: a low-autonomy internal chatbot can go through a simplified assessment, while a system deciding on access to credit, employment, or public services requires a full, documented one.

The 7 Steps of an AI Impact Assessment

STEP 1
Describe the system and its context of use

What the system does, what decisions it makes or supports, and what process it's integrated into. This input should come straight from your AI systems inventory.

STEP 2
Identify affected stakeholders

Who does the system impact, directly or indirectly? Individuals (customers, employees, candidates), groups (communities, protected categories), and, for large-scale systems, society at large.

STEP 3
Identify potential impacts by category

For each stakeholder, what type of impact could they suffer? Fundamental rights, health and safety, economic, psychological, environmental, or social — see the category table below.

STEP 4
Assess severity and likelihood

For each identified impact: how severe would it be if it occurs? How likely is it to occur? And, above all, how reversible is it for the affected person?

STEP 5
Define mitigation measures

Technical controls (confidence thresholds, human review), organizational controls (escalation, complaint channel), or design controls (excluding proxy variables for protected categories).

STEP 6
Document and submit for approval

The final document should be signed off by the system owner and, for high-risk systems, reviewed by an independent function (risk, legal, or the AI governance committee).

STEP 7
Review and update

The assessment is not a one-time document. Review it on significant system changes, incidents, or, at minimum, on the annual audit cycle.

Impact Categories You Need to Assess

Category
What it assesses
Example
Fundamental rights and freedoms
Discrimination, privacy, due process, freedom of expression
A CV-screening model that indirectly penalizes on gender or age
Health and safety
Direct physical or psychological risk from an erroneous decision
A clinical triage system that underestimates the severity of a case
Economic / financial
Access to credit, employment, insurance, or benefits; financial loss
A credit score that denies financing without a clear explanation
Psychological
Anxiety, manipulation, dependency, or emotional harm
A chatbot that generates manipulative or addictive responses
Environmental
Energy consumption and compute footprint of the system in production
Frequent retraining of a large model with no clear business justification
Social / democratic
Disinformation, polarization, concentration of algorithmic power
A content recommendation system that amplifies disinformation

Relationship With ISO/IEC 42001

Within its planning process (clause 6.1.4, AI system impact assessment), ISO/IEC 42001 requires the organization to establish, document, and maintain a process for assessing the impact of its AI systems. The standard says what must exist; it doesn't say how to do it in detail. ISO/IEC 42005 fills exactly that gap: it's the methodology an auditor would expect to see applied as evidence for that clause.

In practice: your AI systems inventory (Annex A) feeds the risk assessment (§6.1), and medium/high-risk systems additionally go through impact assessment following the ISO/IEC 42005 methodology. The three pieces — inventory, risk, impact — fit together.

Relationship With the EU AI Act: The FRIA

Article 27 of the EU AI Act requires a Fundamental Rights Impact Assessment (FRIA) before putting a high-risk system into use, from two categories of deployers: (1) public-law bodies and private entities providing essential services — education, healthcare, social services, housing, or the administration of justice — when they deploy an Annex III high-risk system; and (2) any deployer, public or private, using AI to evaluate creditworthiness (credit scoring) or to price life and health insurance risk.

Timeline update: the Digital Omnibus on AI (adopted 29 June 2026) pushed the high-risk application date the FRIA depends on from 2 August 2026 to 2 December 2027 for stand-alone Annex III systems. Always check the current timeline before setting internal deadlines.

ISO/IEC 42005 doesn't formally replace that legal obligation, but its methodology is compatible: the stakeholder-identification, impact-category, and mitigation steps described in this guide can be adapted directly to the specific requirements Article 27 asks for, avoiding the need to build two parallel processes for the same thing.

How SoberanIA Supports Your Impact Assessment

SoberanIA's Assessments module connects the AI systems inventory with the impact assessment: every system classified as medium or high risk automatically generates an assessment template (AIIA/FRIA) with impact categories, the stakeholder register, mitigation measures, and the review history — all with traceability and digital signature ready for audit.

Frequently Asked Questions

No. ISO/IEC 42005:2025 is a guidance standard, not a certifiable requirement. You are not audited against ISO 42005 directly — you use it as the methodology to satisfy the impact-assessment obligation that ISO/IEC 42001 (and, in the EU, the AI Act) does require.

Risk assessment (ISO 42001 §6.1) looks inward: what could go wrong for the organization? Impact assessment (ISO/IEC 42005) looks outward: who does this system affect, and how? A system can carry low operational risk for the company while still having high impact on the people it evaluates — which is why both assessments are needed and neither replaces the other.

ISO 42005 recommends proportionality: low-risk systems can go through a simplified assessment, while high-risk systems — those affecting rights, access to essential services, or decisions about people — require a full, documented assessment.

It doesn't formally replace it, but the methodology is compatible. Article 27 of the EU AI Act requires a FRIA from two groups: public bodies (and private entities providing essential services) deploying Annex III high-risk systems, and any deployer using AI to evaluate creditworthiness or to price life and health insurance risk. You can use the ISO 42005 process as the methodological base and adapt it to the specific requirements Article 27 asks for.

It shouldn't be done by the technical team alone. ISO 42005 recommends involving whoever understands the context of use: the business owner of the process, legal/compliance, and, where possible, representatives of the people affected or of groups that represent them.

Run your AI impact assessment with SoberanIA

Impact assessment templates (AIIA/FRIA) connected to your AI systems inventory, with impact categories, mitigations, and digital signature.

See free demo

You might also be interested in: AI Systems Inventory · ISO 42001 Roadmap · ISO 42001 vs NIST AI RMF