AI impact assessment vs risk assessment is one of the first questions teams hit when they implement ISO/IEC 42001, because the standard asks for both and the two sound alike. They are not the same exercise. An AI risk assessment asks what could stop the organization achieving its objectives for AI. An AI system impact assessment asks what the system could do to the people, groups and society it touches. This guide sets out the differences, how the two connect, and how to run them without doing the work twice.

Free gap assessment
How much of ISO 42001 could you evidence today?
Score every clause and Annex A control of the AI management standard, free, and see where the programme really sits.
Run the free ISO 42001 gap assessment → or View premium report sample
AI Impact Assessment vs Risk Assessment: The Short Answer
Under ISO/IEC 42001, the AI risk assessment (clause 6.1.2) and risk treatment (clause 6.1.3) deal with risks to the organization and its AI objectives. The AI system impact assessment (clause 6.1.4) deals with the potential consequences of a specific AI system for individuals, groups and societies. ISO/IEC 23894 gives guidance on the first; ISO/IEC 42005:2025 gives guidance on the second. You need both, and each feeds the other.
AI Impact Assessment vs Risk Assessment: Side-by-Side
| AI risk assessment | AI system impact assessment | |
|---|---|---|
| ISO/IEC 42001 clause | 6.1.2 (assessment), 6.1.3 (treatment), 8.2 and 8.3 | 6.1.4 (assessment), 8.4, controls A.5.2 to A.5.5 |
| Guidance standard | ISO/IEC 23894 (with ISO 31000) | ISO/IEC 42005 |
| Whose perspective | The organization and its objectives | Individuals, groups and society |
| Unit of assessment | Usually the AI management system, across all AI | One AI system, or one use of it |
| Typical harms | Legal, financial, operational, reputational, security | Unfair outcomes, loss of autonomy, privacy, safety, effects on jobs and society |
| Benefits weighed? | Rarely | Yes: benefits and harms together |
| Output | Risk register, treatment plan, Statement of Applicability | Impact record, measures, a decision on the system |
| When | At planned intervals and on significant change | Before deployment, and on significant change to the system or its use |
What the AI Risk Assessment Covers
The AI risk assessment works like any management system risk assessment. The organization sets risk criteria, identifies risks that could prevent it achieving its AI objectives, analyses and evaluates them, and treats those above its appetite with controls, compared against Annex A and recorded in the Statement of Applicability. The risks are the organization’s: a biased model is a risk because it could lead to legal claims, lost customers or a regulator’s order, as well as because of the harm itself. Our AI risk assessment tool follows clauses 6.1.2 and 6.1.3.
What the AI System Impact Assessment Covers
The impact assessment starts from the other end. For one AI system, it documents what the system does, its intended and unintended uses, its data, its model, where it is deployed and who it can affect, then assesses the actual and reasonably foreseeable impacts on those people and groups, benefits and harms alike, including failures and misuse. The output is a decision about the system: go ahead, go ahead with measures, go ahead within limits, or stop. Our guide to the AI system impact assessment explains ISO/IEC 42005 in more depth.
How the Two Connect
ISO/IEC 42001 links them deliberately. The impacts identified for each AI system are an input to the risk assessment, because an impact on people is usually also a risk to the organization. And the measures chosen in the impact assessment are usually the same Annex A controls chosen in risk treatment. In practice:
- Keep an inventory of AI systems.
- Screen each one and run an impact assessment at the depth the screening calls for.
- Carry each significant impact into the AI risk register as a risk to the organization, with the same measures.
- Record the controls once, in the Statement of Applicability, referencing both.
- Review both when a system changes; review the risk assessment at planned intervals too.
One System, Both Views
A worked case makes the AI impact assessment vs risk assessment distinction concrete. Take an AI tool that ranks job applicants for a recruitment agency.
| Issue | In the AI risk assessment | In the AI impact assessment |
|---|---|---|
| Older applicants ranked lower | Discrimination claims, client loss, regulator action | Qualified people shut out of jobs; unequal treatment by age |
| No way to contest a ranking | Complaints and reputational damage | People cannot correct a wrong result or reach a human |
| Provider updates the model | Service disruption and loss of control over a supplier | Rankings change for thousands of applicants without anyone assessing why |
| Faster replies to applicants | Not usually recorded | A real benefit, weighed against the harms |
The measures are largely the same in both columns: bias testing, a review route, monitoring and supplier terms. What differs is who the harm lands on, how severe it is judged to be, and what decision it drives. Rated only from the organization’s side, the contest route might look like a low priority; rated from the applicants’ side, it is one of the most important measures. That is why the AI impact assessment vs risk assessment question matters: each rates the same issue on a different scale.
Where the AI Impact Assessment vs Risk Assessment Difference Shows
The difference is clearest in three situations:
- A small harm to the organization, a large one to people. A benefits-screening tool that wrongly denies support to a few thousand people may barely register as a business risk, yet be a serious impact.
- A large risk to the organization, little impact on people. An internal forecasting model that fails could cost money without affecting anyone outside.
- Benefits. Only the impact assessment asks what good the system does for the people affected, which is what a decision to deploy has to weigh.
Common Mistakes
- One document for both. A register rated only for the organization will miss impacts on people; a combined register needs both perspectives rated separately.
- Impact assessments only for “high-risk” systems. ISO/IEC 42001 expects an assessment for AI systems in scope, at a depth that fits the system.
- No link to the Statement of Applicability. Measures from impact assessments should appear there, or auditors will ask why.
- No trigger for re-assessment. A new use, new data or a new model should prompt both assessments.
Frequently Asked Questions
AI impact assessment vs risk assessment: does ISO/IEC 42001 certification require both?
Yes. Clauses 6.1.2, 6.1.3 and 6.1.4 are requirements, and an auditor will look for evidence of each.
Which comes first in the AI impact assessment vs risk assessment sequence?
Usually the impact assessment for each system, feeding the risk assessment. When a management system is new, both are often built together.
Is a fundamental rights impact assessment the same as an AI impact assessment?
No. The EU AI Act’s Article 27 assessment is a legal duty for certain deployers of high-risk systems, with its own content. An ISO/IEC 42005 assessment covers much of it. See our guide to the fundamental rights impact assessment.
Where does a DPIA fit?
Alongside both, where personal data is involved and the processing is likely to be high risk. Our comparison of AI impact assessment vs DPIA covers it.
To run the impact assessment for one system, use our free AI impact assessment template; for the organization-wide register, the free AI risk assessment. Both point measures at the same ISO/IEC 42001 Annex A controls, and the ISO 42001 Toolkit has the procedures and records around them. For a worked case, see our AI impact assessment example.