An AI impact assessment example is the quickest way to see what a finished assessment should say, because ISO/IEC 42005 gives guidance on what to consider, not a form to fill in. This guide walks through a complete AI impact assessment example for a fictional recruitment agency about to use an AI tool that ranks job applicants, step by step, from the screening to the decision.
Each section follows the documentation elements of ISO/IEC 42005:2025, published in May 2025, and shows how the results feed an AI management system under ISO/IEC 42001, whose clause 6.1.4 asks for an AI system impact assessment. Our guide to the AI system impact assessment and ISO 42005 covers the method; this is the worked version.

What an AI Impact Assessment Must Show
ISO/IEC 42005 asks the organization to document, for one AI system:
- the system itself: what it does, its purpose, and its intended and unintended uses, including reasonably foreseeable misuse;
- the data it is built and run on, and its quality;
- the algorithm and model, including components from third parties;
- the deployment environment;
- the people and groups who can be affected, directly or indirectly;
- the actual and reasonably foreseeable impacts on them, benefits as well as harms, including failures and misuse;
- the measures that address those impacts.
It also expects the assessment to be reviewed, approved and repeated when the system changes. ISO/IEC 42001 turns this into controls: A.5.2 (the assessment process), A.5.3 (documenting it), A.5.4 (impacts on individuals and groups) and A.5.5 (impacts on society).
The Organization in This AI Impact Assessment Example
Brightwell Recruitment (a fictional company) screens about 60,000 applications a year for 40 client employers in the UK, Ireland and Germany. It has fine-tuned a general-purpose language model from an AI provider on five years of its own placements. The tool reads CVs and application answers, scores each applicant against the job and ranks them; recruiters see the top 20 per role. A three-month pilot with two clients has just finished.
Step 1: Screening
The first question in any AI impact assessment example is how deep the assessment needs to go. Brightwell’s screening:
| Threshold | Answer | Why |
|---|---|---|
| Could it be a prohibited practice? | No | Emotion recognition in interviews was considered and ruled out |
| Does it shape decisions about access to jobs? | Yes | It ranks applicants before any person sees them |
| Is it high-risk under the EU AI Act? | Yes | Recruitment and selection is listed in Annex III |
| Context factors | 4 of 6 | Many people, personal data, a third-party model, and applicants cannot opt out |
Verdict: a full impact assessment before deployment. Because the system is high-risk under the EU AI Act, Brightwell also noted the provider and deployer duties that follow, which the Digital Omnibus has pushed back to December 2027 for Annex III systems.
Step 2: Describe the AI System
| Element | What Brightwell recorded |
|---|---|
| Purpose | Rank applicants against job requirements so recruiters see the strongest first |
| Intended use | Recruiters shortlist; every shortlist and hiring decision is made by a person |
| Foreseeable misuse | Clients using the ranking to reject automatically; recruiters shortlisting only from the top 20; AI-written CVs gaming the score |
| Data | 180,000 past applications and outcomes, which under-represent applicants over 50 and those with career gaps |
| Model | A provider’s general-purpose model, fine-tuned in-house; model card available, training data not |
| Deployment | EU-hosted; recruiters see reasons and can move anyone onto the shortlist; can be switched off per client |
| People affected | Applicants (including older applicants, applicants with disabilities and career gaps), recruiters, client employers |
| Benefits | Replies in 48 hours instead of two weeks; more consistent criteria; recruiter time moved to interviews |
Recording the benefits matters. ISO/IEC 42005 asks for benefits and harms together, so the decision at the end weighs one against the other rather than looking at harms alone.
Step 3: Safeguards in This AI Impact Assessment Example
| Safeguard | Answer | Note |
|---|---|---|
| Outcomes tested for unfair differences | Partly | Tested by sex and age; not by disability, where data is sparse |
| People told AI is involved | Yes | Stated on the application page |
| Meaningful explanation available | Partly | Recruiters see reasons; applicants get a general explanation |
| Human can override or stop | Yes | Recruiters can add anyone; overrides reviewed weekly |
| People can contest and reach a human | No | No review route for applicants |
| Accuracy and fairness monitored in use | No | Measured in the pilot only |
Two “no” answers became two of the measures below. The safeguard questions are a quick way to find gaps before rating individual impacts.
Step 4: Impacts and Measures
Impacts are rated for the applicants and recruiters, not for Brightwell, on 1 to 5 scales:
| Impact | Level before | Measures (ISO 42001 Annex A) | Level after |
|---|---|---|---|
| Older applicants and those with career gaps ranked lower | 16 High | Remove proxy features; test outcomes by group before launch and quarterly (A.7.4, A.6.2.4, A.5.4) | 8 Medium |
| Historical data carries past discrimination | 16 High | Review training data; drop outcomes from clients with skewed hiring (A.7.4, A.7.5) | 6 Medium |
| Applicants cannot contest a ranking | 12 High | Review link in every decision email, answered in five working days (A.9.2, A.8.5) | 6 Medium |
| Recruiters rubber-stamp the ranking | 12 High | Show a sample from below the cut-off on every role; training (A.9.2, A.4.6) | 8 Medium |
| Performance drifts after launch | 12 High | Monthly dashboard of shortlisting rates by group and client (A.6.2.6) | 6 Medium |
Pointing each measure at an Annex A control is what connects the impact assessment to the rest of the AI management system: the same controls appear in the AI risk treatment plan and the Statement of Applicability.
Step 5: Review and Decision
The AI governance committee advised against launch until outcomes were tested by disability and an applicant review route existed. Brightwell followed part of that advice and recorded why: disability testing needs more data, so the tool launches with the two pilot clients only, with recruiters reviewing every application from applicants who declare a disability. A survey of 412 pilot applicants found most welcomed faster replies, while several older applicants raised fairness concerns.
The decision: proceed only within stated limits (two clients, the extra human review), approved by the Managing Director, with the next review in six months or before any new client is added.
Common Mistakes This AI Impact Assessment Example Avoids
- Rating impact on the organization. Brand and fines matter, but an impact assessment is about the people affected.
- Ignoring foreseeable misuse. Clients asking to reject automatically was the most likely misuse, and the contract now forbids it.
- Treating human review as a safeguard by default. A review nobody uses is not oversight.
- Leaving out the benefits. Without them, the decision has nothing to weigh the harms against.
- Doing it once. Adding clients, retraining the model or a provider update all call for a review.
Frequently Asked Questions
Can I reuse this AI impact assessment example as a template?
Reuse the structure of this AI impact assessment example, not the answers. The impacts depend on your system, your data and who it affects.
Is an AI impact assessment mandatory?
ISO/IEC 42005 is guidance, but an organization certified to ISO/IEC 42001 must carry out AI system impact assessments under clause 6.1.4. Some deployers of high-risk systems also owe a fundamental rights impact assessment under the EU AI Act.
How does it relate to the AI risk assessment?
The impact assessment looks at consequences for people and society; the AI risk assessment looks at risks to the organization and its objectives. ISO/IEC 42001 asks for both, and each informs the other.
Do I still need a DPIA?
If the system processes personal data and is likely to be high risk, yes. Brightwell completed one for the same tool.
To build your own in the same order, use our free AI impact assessment template, which screens the system, checks the safeguards, rates the impacts and records the decision. For the policies and records around it, see the ISO 42001 Toolkit.