AI system impact assessment. Guidance and a guided platform for reasonably foreseeable impact on people, operations and rights.
ISO/IEC 42005 gives practical guidance for organisations that develop, provide or use AI systems. It is how reasonably foreseeable impacts - beneficial and harmful - on individuals, groups and societies are identified, analysed and treated. The useful question is not only whether the model is accurate. It is what impact the system can create. An accurate system can still create unacceptable impact on health, safety or fundamental rights.
For a South African organisation this page is the Union-market file. POPIA still requires a personal information impact assessment when personal information is processed. That work stays in the POPIA folder. ISO/IEC 42005 does not replace it. Where the system or its output is used in the Union, Article 9 (provider risk management) and, where Article 27 applies, a Fundamental Rights Impact Assessment sit on top. GDPR applies only to the populations and establishments that statute actually covers.
The standard looks at impact on people, business operations, privacy, security, human rights, society and regulatory compliance. It is written to sit with ISO/IEC 23894 risk management and ISO/IEC 42001. The assessment is run in a guided platform: system context, stakeholders, impact categories, visual risk mapping, controls, residual impact and a governance decision, with version control and multi-role review.
AI systems bring benefit and also reasonably foreseeable harm: unfair or discriminatory outcomes, environmental harm, and unwanted reductions in workforce. Under the EU AI Act, a high-risk system may be placed on the Union market or put into service there only when residual risk to health, safety and fundamental rights remains acceptable. ISO/IEC 42005 is the method that makes that determination visible, documented and governable.
Organisations developing, providing or using AI systems that must show an impact assessment to a board, an assessor or a Union authority. Providers running a continuous risk-management system. Deployers preparing an Article 27 FRIA. Quality, compliance, risk, legal and governance roles that have to sign residual impact before the system goes live.
AI impact assessment is not a one-time exercise. It is repeated across the lifecycle. The standard, run through the platform, is how residual impact on people and rights is identified, treated and formally accepted before the system is put into service or kept in operation.