Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

AI impact assessment vs risk assessment: risks to the organization compared with impacts on people and society

AI Impact Assessment vs Risk Assessment: The Essential 2026 Guide for ISO 42001

AI impact assessment vs risk assessment is one of the first questions teams hit when they implement ISO/IEC 42001, because the standard asks for both and the two sound alike. They are not the same exercise. An AI risk assessment asks what could stop the organization achieving its objectives for AI. An AI system impact assessment asks what the system could do to the people, groups and society it touches. This guide sets out the differences, how the two connect, and how to run them without doing the work twice.

AI impact assessment vs risk assessment: risks to the organization compared with impacts on people and society

Free gap assessment

How much of ISO 42001 could you evidence today?

Score every clause and Annex A control of the AI management standard, free, and see where the programme really sits.

Run the free ISO 42001 gap assessment →  or  View premium report sample

AI Impact Assessment vs Risk Assessment: The Short Answer

Under ISO/IEC 42001, the AI risk assessment (clause 6.1.2) and risk treatment (clause 6.1.3) deal with risks to the organization and its AI objectives. The AI system impact assessment (clause 6.1.4) deals with the potential consequences of a specific AI system for individuals, groups and societies. ISO/IEC 23894 gives guidance on the first; ISO/IEC 42005:2025 gives guidance on the second. You need both, and each feeds the other.

AI Impact Assessment vs Risk Assessment: Side-by-Side

AI risk assessmentAI system impact assessment
ISO/IEC 42001 clause6.1.2 (assessment), 6.1.3 (treatment), 8.2 and 8.36.1.4 (assessment), 8.4, controls A.5.2 to A.5.5
Guidance standardISO/IEC 23894 (with ISO 31000)ISO/IEC 42005
Whose perspectiveThe organization and its objectivesIndividuals, groups and society
Unit of assessmentUsually the AI management system, across all AIOne AI system, or one use of it
Typical harmsLegal, financial, operational, reputational, securityUnfair outcomes, loss of autonomy, privacy, safety, effects on jobs and society
Benefits weighed?RarelyYes: benefits and harms together
OutputRisk register, treatment plan, Statement of ApplicabilityImpact record, measures, a decision on the system
WhenAt planned intervals and on significant changeBefore deployment, and on significant change to the system or its use

What the AI Risk Assessment Covers

The AI risk assessment works like any management system risk assessment. The organization sets risk criteria, identifies risks that could prevent it achieving its AI objectives, analyses and evaluates them, and treats those above its appetite with controls, compared against Annex A and recorded in the Statement of Applicability. The risks are the organization’s: a biased model is a risk because it could lead to legal claims, lost customers or a regulator’s order, as well as because of the harm itself. Our AI risk assessment tool follows clauses 6.1.2 and 6.1.3.

What the AI System Impact Assessment Covers

The impact assessment starts from the other end. For one AI system, it documents what the system does, its intended and unintended uses, its data, its model, where it is deployed and who it can affect, then assesses the actual and reasonably foreseeable impacts on those people and groups, benefits and harms alike, including failures and misuse. The output is a decision about the system: go ahead, go ahead with measures, go ahead within limits, or stop. Our guide to the AI system impact assessment explains ISO/IEC 42005 in more depth.

How the Two Connect

ISO/IEC 42001 links them deliberately. The impacts identified for each AI system are an input to the risk assessment, because an impact on people is usually also a risk to the organization. And the measures chosen in the impact assessment are usually the same Annex A controls chosen in risk treatment. In practice:

  1. Keep an inventory of AI systems.
  2. Screen each one and run an impact assessment at the depth the screening calls for.
  3. Carry each significant impact into the AI risk register as a risk to the organization, with the same measures.
  4. Record the controls once, in the Statement of Applicability, referencing both.
  5. Review both when a system changes; review the risk assessment at planned intervals too.

One System, Both Views

A worked case makes the AI impact assessment vs risk assessment distinction concrete. Take an AI tool that ranks job applicants for a recruitment agency.

IssueIn the AI risk assessmentIn the AI impact assessment
Older applicants ranked lowerDiscrimination claims, client loss, regulator actionQualified people shut out of jobs; unequal treatment by age
No way to contest a rankingComplaints and reputational damagePeople cannot correct a wrong result or reach a human
Provider updates the modelService disruption and loss of control over a supplierRankings change for thousands of applicants without anyone assessing why
Faster replies to applicantsNot usually recordedA real benefit, weighed against the harms

The measures are largely the same in both columns: bias testing, a review route, monitoring and supplier terms. What differs is who the harm lands on, how severe it is judged to be, and what decision it drives. Rated only from the organization’s side, the contest route might look like a low priority; rated from the applicants’ side, it is one of the most important measures. That is why the AI impact assessment vs risk assessment question matters: each rates the same issue on a different scale.

Where the AI Impact Assessment vs Risk Assessment Difference Shows

The difference is clearest in three situations:

  • A small harm to the organization, a large one to people. A benefits-screening tool that wrongly denies support to a few thousand people may barely register as a business risk, yet be a serious impact.
  • A large risk to the organization, little impact on people. An internal forecasting model that fails could cost money without affecting anyone outside.
  • Benefits. Only the impact assessment asks what good the system does for the people affected, which is what a decision to deploy has to weigh.

Common Mistakes

  • One document for both. A register rated only for the organization will miss impacts on people; a combined register needs both perspectives rated separately.
  • Impact assessments only for “high-risk” systems. ISO/IEC 42001 expects an assessment for AI systems in scope, at a depth that fits the system.
  • No link to the Statement of Applicability. Measures from impact assessments should appear there, or auditors will ask why.
  • No trigger for re-assessment. A new use, new data or a new model should prompt both assessments.

Frequently Asked Questions

AI impact assessment vs risk assessment: does ISO/IEC 42001 certification require both?

Yes. Clauses 6.1.2, 6.1.3 and 6.1.4 are requirements, and an auditor will look for evidence of each.

Which comes first in the AI impact assessment vs risk assessment sequence?

Usually the impact assessment for each system, feeding the risk assessment. When a management system is new, both are often built together.

Is a fundamental rights impact assessment the same as an AI impact assessment?

No. The EU AI Act’s Article 27 assessment is a legal duty for certain deployers of high-risk systems, with its own content. An ISO/IEC 42005 assessment covers much of it. See our guide to the fundamental rights impact assessment.

Where does a DPIA fit?

Alongside both, where personal data is involved and the processing is likely to be high risk. Our comparison of AI impact assessment vs DPIA covers it.

To run the impact assessment for one system, use our free AI impact assessment template; for the organization-wide register, the free AI risk assessment. Both point measures at the same ISO/IEC 42001 Annex A controls, and the ISO 42001 Toolkit has the procedures and records around them. For a worked case, see our AI impact assessment example.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.