AI Assurance Logo
AI Assurance aiassurance.co.za
Get In Touch

ISO/IEC 42005:2025

AI system impact assessment. Guidance and a guided platform for reasonably foreseeable impact on people, operations and rights.

ISO/IEC 42005 gives practical guidance for organisations that develop, provide or use AI systems. It is how reasonably foreseeable impacts - beneficial and harmful - on individuals, groups and societies are identified, analysed and treated. The useful question is not only whether the model is accurate. It is what impact the system can create. An accurate system can still create unacceptable impact on health, safety or fundamental rights.

For a South African organisation this page is the Union-market file. POPIA still requires a personal information impact assessment when personal information is processed. That work stays in the POPIA folder. ISO/IEC 42005 does not replace it. Where the system or its output is used in the Union, Article 9 (provider risk management) and, where Article 27 applies, a Fundamental Rights Impact Assessment sit on top. GDPR applies only to the populations and establishments that statute actually covers.

The standard looks at impact on people, business operations, privacy, security, human rights, society and regulatory compliance. It is written to sit with ISO/IEC 23894 risk management and ISO/IEC 42001. The assessment is run in a guided platform: system context, stakeholders, impact categories, visual risk mapping, controls, residual impact and a governance decision, with version control and multi-role review.

Why this matters

AI systems bring benefit and also reasonably foreseeable harm: unfair or discriminatory outcomes, environmental harm, and unwanted reductions in workforce. Under the EU AI Act, a high-risk system may be placed on the Union market or put into service there only when residual risk to health, safety and fundamental rights remains acceptable. ISO/IEC 42005 is the method that makes that determination visible, documented and governable.

Seven steps

  1. Define the system context. Nature, scope, purpose, intended and unintended uses, data, models, deployment environment and AI Act role (provider or deployer).
  2. Identify affected stakeholders. Individuals, groups, societies and other interested parties, including vulnerable persons, workers and data subjects.
  3. Assess impact categories. People, operations, privacy, security, human rights, society and regulatory compliance, using the standard's harms and benefits taxonomy.
  4. Evaluate severity and likelihood. Visual mapping so each impact can be positioned and prioritised.
  5. Review controls and mitigations. Existing and planned measures, including those relevant to EU AI Act essential requirements and data-protection principles where they apply.
  6. Determine residual impact. Remaining impact after controls, compared with organisational thresholds, with an acceptance statement for management.
  7. Governance review and decision. Preparer, reviewer and approver. The record of residual-impact acceptance and the trigger for the next review.

What the platform does

  • Guided modules for all seven steps.
  • Visual severity and likelihood mapping across accountability, transparency, fairness, privacy, reliability, safety, explainability and environmental dimensions.
  • Traceability from answers to the standard, and one-click reports, residual-impact statements and action plans.
  • Role-based access, version history and exchange with internal and external parties.
  • A knowledge base of recommended controls inside the workflow.
  • Reassessment triggers when the model, the risk or the business context changes.

Who it is for

Organisations developing, providing or using AI systems that must show an impact assessment to a board, an assessor or a Union authority. Providers running a continuous risk-management system. Deployers preparing an Article 27 FRIA. Quality, compliance, risk, legal and governance roles that have to sign residual impact before the system goes live.

AI impact assessment is not a one-time exercise. It is repeated across the lifecycle. The standard, run through the platform, is how residual impact on people and rights is identified, treated and formally accepted before the system is put into service or kept in operation.