Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

AI impact assessment example: screening, safeguards and impacts for an AI tool that ranks job applicants

AI Impact Assessment Example: A Complete 2026 Walkthrough for ISO 42005

An AI impact assessment example is the quickest way to see what a finished assessment should say, because ISO/IEC 42005 gives guidance on what to consider, not a form to fill in. This guide walks through a complete AI impact assessment example for a fictional recruitment agency about to use an AI tool that ranks job applicants, step by step, from the screening to the decision.

Each section follows the documentation elements of ISO/IEC 42005:2025, published in May 2025, and shows how the results feed an AI management system under ISO/IEC 42001, whose clause 6.1.4 asks for an AI system impact assessment. Our guide to the AI system impact assessment and ISO 42005 covers the method; this is the worked version.

AI impact assessment example: screening, safeguards and impacts for an AI tool that ranks job applicants

What an AI Impact Assessment Must Show

ISO/IEC 42005 asks the organization to document, for one AI system:

  • the system itself: what it does, its purpose, and its intended and unintended uses, including reasonably foreseeable misuse;
  • the data it is built and run on, and its quality;
  • the algorithm and model, including components from third parties;
  • the deployment environment;
  • the people and groups who can be affected, directly or indirectly;
  • the actual and reasonably foreseeable impacts on them, benefits as well as harms, including failures and misuse;
  • the measures that address those impacts.

It also expects the assessment to be reviewed, approved and repeated when the system changes. ISO/IEC 42001 turns this into controls: A.5.2 (the assessment process), A.5.3 (documenting it), A.5.4 (impacts on individuals and groups) and A.5.5 (impacts on society).

The Organization in This AI Impact Assessment Example

Brightwell Recruitment (a fictional company) screens about 60,000 applications a year for 40 client employers in the UK, Ireland and Germany. It has fine-tuned a general-purpose language model from an AI provider on five years of its own placements. The tool reads CVs and application answers, scores each applicant against the job and ranks them; recruiters see the top 20 per role. A three-month pilot with two clients has just finished.

Step 1: Screening

The first question in any AI impact assessment example is how deep the assessment needs to go. Brightwell’s screening:

ThresholdAnswerWhy
Could it be a prohibited practice?NoEmotion recognition in interviews was considered and ruled out
Does it shape decisions about access to jobs?YesIt ranks applicants before any person sees them
Is it high-risk under the EU AI Act?YesRecruitment and selection is listed in Annex III
Context factors4 of 6Many people, personal data, a third-party model, and applicants cannot opt out

Verdict: a full impact assessment before deployment. Because the system is high-risk under the EU AI Act, Brightwell also noted the provider and deployer duties that follow, which the Digital Omnibus has pushed back to December 2027 for Annex III systems.

Step 2: Describe the AI System

ElementWhat Brightwell recorded
PurposeRank applicants against job requirements so recruiters see the strongest first
Intended useRecruiters shortlist; every shortlist and hiring decision is made by a person
Foreseeable misuseClients using the ranking to reject automatically; recruiters shortlisting only from the top 20; AI-written CVs gaming the score
Data180,000 past applications and outcomes, which under-represent applicants over 50 and those with career gaps
ModelA provider’s general-purpose model, fine-tuned in-house; model card available, training data not
DeploymentEU-hosted; recruiters see reasons and can move anyone onto the shortlist; can be switched off per client
People affectedApplicants (including older applicants, applicants with disabilities and career gaps), recruiters, client employers
BenefitsReplies in 48 hours instead of two weeks; more consistent criteria; recruiter time moved to interviews

Recording the benefits matters. ISO/IEC 42005 asks for benefits and harms together, so the decision at the end weighs one against the other rather than looking at harms alone.

Step 3: Safeguards in This AI Impact Assessment Example

SafeguardAnswerNote
Outcomes tested for unfair differencesPartlyTested by sex and age; not by disability, where data is sparse
People told AI is involvedYesStated on the application page
Meaningful explanation availablePartlyRecruiters see reasons; applicants get a general explanation
Human can override or stopYesRecruiters can add anyone; overrides reviewed weekly
People can contest and reach a humanNoNo review route for applicants
Accuracy and fairness monitored in useNoMeasured in the pilot only

Two “no” answers became two of the measures below. The safeguard questions are a quick way to find gaps before rating individual impacts.

Step 4: Impacts and Measures

Impacts are rated for the applicants and recruiters, not for Brightwell, on 1 to 5 scales:

ImpactLevel beforeMeasures (ISO 42001 Annex A)Level after
Older applicants and those with career gaps ranked lower16 HighRemove proxy features; test outcomes by group before launch and quarterly (A.7.4, A.6.2.4, A.5.4)8 Medium
Historical data carries past discrimination16 HighReview training data; drop outcomes from clients with skewed hiring (A.7.4, A.7.5)6 Medium
Applicants cannot contest a ranking12 HighReview link in every decision email, answered in five working days (A.9.2, A.8.5)6 Medium
Recruiters rubber-stamp the ranking12 HighShow a sample from below the cut-off on every role; training (A.9.2, A.4.6)8 Medium
Performance drifts after launch12 HighMonthly dashboard of shortlisting rates by group and client (A.6.2.6)6 Medium

Pointing each measure at an Annex A control is what connects the impact assessment to the rest of the AI management system: the same controls appear in the AI risk treatment plan and the Statement of Applicability.

Step 5: Review and Decision

The AI governance committee advised against launch until outcomes were tested by disability and an applicant review route existed. Brightwell followed part of that advice and recorded why: disability testing needs more data, so the tool launches with the two pilot clients only, with recruiters reviewing every application from applicants who declare a disability. A survey of 412 pilot applicants found most welcomed faster replies, while several older applicants raised fairness concerns.

The decision: proceed only within stated limits (two clients, the extra human review), approved by the Managing Director, with the next review in six months or before any new client is added.

Common Mistakes This AI Impact Assessment Example Avoids

  • Rating impact on the organization. Brand and fines matter, but an impact assessment is about the people affected.
  • Ignoring foreseeable misuse. Clients asking to reject automatically was the most likely misuse, and the contract now forbids it.
  • Treating human review as a safeguard by default. A review nobody uses is not oversight.
  • Leaving out the benefits. Without them, the decision has nothing to weigh the harms against.
  • Doing it once. Adding clients, retraining the model or a provider update all call for a review.

Frequently Asked Questions

Can I reuse this AI impact assessment example as a template?

Reuse the structure of this AI impact assessment example, not the answers. The impacts depend on your system, your data and who it affects.

Is an AI impact assessment mandatory?

ISO/IEC 42005 is guidance, but an organization certified to ISO/IEC 42001 must carry out AI system impact assessments under clause 6.1.4. Some deployers of high-risk systems also owe a fundamental rights impact assessment under the EU AI Act.

How does it relate to the AI risk assessment?

The impact assessment looks at consequences for people and society; the AI risk assessment looks at risks to the organization and its objectives. ISO/IEC 42001 asks for both, and each informs the other.

Do I still need a DPIA?

If the system processes personal data and is likely to be high risk, yes. Brightwell completed one for the same tool.

To build your own in the same order, use our free AI impact assessment template, which screens the system, checks the safeguards, rates the impacts and records the decision. For the policies and records around it, see the ISO 42001 Toolkit.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.