Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 42001 impact assessment: clause 6.1.4, clause 8.4 and Annex A.5 requirements

ISO 42001 Impact Assessment: The Essential 2026 Guide to Clauses 6.1.4 and 8.4

An ISO 42001 impact assessment is one of the requirements auditors probe hardest, because it is where an AI management system either touches real people or stays a paper exercise. ISO/IEC 42001:2023 asks you to assess how each AI system could affect individuals, groups and society, to keep records, and to redo the assessment when things change. Many first-time implementers treat it as a variant of the risk assessment and fail the audit question that follows.

This guide explains exactly where the ISO 42001 impact assessment sits in the standard, how it differs from the risk assessment in clause 6.1.2, what the Annex A.5 controls add, and what evidence a certification auditor will ask to see.

Free gap assessment

How much of ISO 42001 could you evidence today?

Score every clause and Annex A control of the AI management standard, free, and see where the programme really sits.

Run the free ISO 42001 gap assessment →  or  View premium report sample

Where the ISO 42001 impact assessment appears in the standard

The requirement shows up in two clauses and one control group. Clause 6.1.4 sits in the planning section and requires you to define a process for assessing the consequences of your AI systems for individuals and society, taking both intended use and misuse into account. Clause 8.4 sits in the operation section and requires you to carry that assessment out, keep records of it and repeat it, particularly after significant changes to the system. Annex A.5 then lists controls on assessing the impacts of AI systems, which you must consider when preparing your Statement of Applicability.

WhereWhat it doesWhat you produce
Clause 6.1.4Sets up the impact assessment processA documented procedure with criteria, roles and timing
Clause 8.4Runs the process and repeats itCompleted assessments per AI system, with review records
Annex A.5Control group on assessing AI system impactsStatement of Applicability entries and supporting evidence

Annex A of ISO 42001 contains 38 controls in total. You are not required to implement all of them, but you must justify any you exclude in the Statement of Applicability. For the wider structure of the standard, see our overview of ISO 42001 requirements.

ISO 42001 impact assessment vs risk assessment

This is the distinction that catches teams out. The risk assessment in clause 6.1.2 asks what could go wrong for the organization in meeting its objectives. The ISO 42001 impact assessment asks what could happen to the people and communities the system affects, even when the organization itself would suffer no loss.

Free AI risk assessment

Which of your AI systems could harm people, or you?

List your AI systems, models and data, pick from 38 AI risk scenarios, rate them for the people affected and for you, and plan treatment with ISO 42001 Annex A controls. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free AI risk assessment →  or  View premium report sample

A resume-screening model is a good test. The risk assessment might rate the chance of a discrimination claim. The impact assessment asks who is disadvantaged by the ranking, how severely, and whether they can appeal. The two outputs feed each other, and a finding in one should appear in the other. Our guide to the ISO 42001 risk assessment under clause 6.1.2 covers the organizational side in detail, and the side-by-side comparison shows how to keep the two consistent.

What the Annex A.5 controls cover

The Annex A.5 group breaks the ISO 42001 impact assessment into four practical controls: a defined process for assessing AI system impact, documentation of the results, assessment of impact on individuals or groups of individuals, and assessment of wider societal impact. Treat them as a checklist for your procedure. If your process covers individual impact but never mentions society, an auditor will notice, and so will anyone reading your Statement of Applicability. Confirm the exact wording of each control against your licensed copy of the standard before you publish your own mapping.

What auditors ask to see for the impact assessment

Certification auditors work from evidence, so prepare the following before Stage 1 rather than after.

  • A documented process. Criteria for when an assessment is required, who performs it, who approves it and how often it is reviewed.
  • One completed assessment per in-scope AI system. Not a template, the real thing, with dates and named owners.
  • Evidence of misuse thinking. The standard expects you to consider foreseeable misuse as well as intended use.
  • Links to risk treatment. Impacts above your tolerance should appear in the risk register with a treatment.
  • Review records. Proof the assessment was revisited after a model update, new data source or new user group.
  • Statement of Applicability entries. A justification for each Annex A.5 control, whether included or excluded.

A frequent weakness is a single assessment written at launch and never updated. Clause 8.4 exists to stop that, so build a change trigger into your change management process, not just your calendar.

Scoping which AI systems need an assessment

Auditors will ask how you decided which systems are in scope, so settle this early. Start from your AI inventory and include anything that makes, recommends or materially influences a decision about a person: credit scoring, hiring filters, fraud flags, content moderation, triage tools, pricing engines and customer-facing chatbots. Internal productivity tools with no effect on individuals, such as a code assistant used by your own engineers, will usually screen out quickly, but write down why.

Third-party AI is the trap. If a supplier’s model drives a decision you are accountable for, it belongs in your inventory and your assessment, even though you cannot see inside it. Ask the supplier for documentation on intended use, known limitations and testing, and record what you received. When a supplier will not share anything, that gap is itself a finding to carry into your risk treatment.

Common audit findings on impact assessments

Weak impact assessments tend to share the same flaws. The assessment describes benefits only and skips harms. Affected parties are listed as “customers” with no thought for the people scored but never served. Ratings have no written scale, so two assessors would score the same system differently. Mitigations have no owner or date. Sign-off is by a group email address. And the record carries a launch date with no review since, even though the model has been retrained twice.

None of these is hard to fix, but each one is easier to prevent than to explain to an auditor. Read your own records against this list before the certification body does.

How ISO 42005 helps with the ISO 42001 impact assessment

ISO/IEC 42005:2025, published in May 2025, is guidance on performing AI system impact assessments. It is not a certification standard and uses “should” rather than “shall”, so you cannot be audited against it directly. It is still the best available reference for how to run the assessment that ISO 42001 requires: how to set thresholds, who to involve, how to record results and how to monitor afterwards. You can read the official listing for ISO/IEC 42005:2025 on iso.org.

For a deeper walkthrough of the guidance itself, our guide to AI system impact assessment under ISO 42005 is the place to start, and the worked AI impact assessment example shows a finished record.

A practical sequence for your first ISO 42001 impact assessment

  1. List your AI systems. Include third-party tools that make or influence decisions about people.
  2. Screen each one. Use a short set of questions on decision impact, sensitive data, human oversight and vulnerable groups.
  3. Assess the systems that pass the screen. Record affected parties, benefits, harms, severity, likelihood and reversibility.
  4. Agree mitigations and owners. Rate the residual impact after controls.
  5. Get sign-off. A named person with authority accepts the residual impact.
  6. Feed the results into the risk register and Statement of Applicability.
  7. Set review triggers. Model changes, new use cases, incidents and a fixed annual review.

Most organizations complete the first round faster than they expect once the screening questions and rating scale are agreed. The slow part is usually getting affected-party input from teams who have never been asked.

Speeding up the ISO 42001 impact assessment with a finished structure

If you would rather not design the record from scratch, the AI Impact Assessment Report and Workbook provides a structured report with screening, safeguards, impacts on people and society, measures and a live workbook, built around ISO/IEC 42005. Whether you use it or your own form, apply the same structure to every system so results stay comparable across the portfolio.

ISO 42001 impact assessment FAQ

Is an impact assessment mandatory for ISO 42001 certification?

Yes. Clauses 6.1.4 and 8.4 require an AI system impact assessment process and records of its use. Auditors will ask for completed assessments, not just a procedure.

Do I need a separate assessment for every AI system?

You need to assess each in-scope system, but your screening step can show that some systems have limited impact and need only a short record. The decision itself must be documented.

Can our DPIA count as the ISO 42001 impact assessment?

Partly. A DPIA covers privacy risk to individuals, which is only one dimension. It can supply evidence, but the ISO 42001 impact assessment must also cover wider individual and societal effects.

How often must the assessment be repeated?

The standard expects reassessment after significant changes, so define triggers for model updates, new data sources and new users. Many organizations also review annually as a baseline.

Who should own the ISO 42001 impact assessment?

Give ownership to the person accountable for the AI system, with input from legal, privacy, security and the teams whose customers or staff are affected. The AI management system owner should own the process, while each system owner owns that system’s completed assessment and its review dates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.