AI Assurance Logo
AI Assurance aiassurance.co.za
Get In Touch

ISO/IEC 42005:2025 AI System Impact Assessment

Structured guidance for assessing AI impact under POPIA, King V and, where relevant, the EU AI Act

Overview

ISO/IEC 42005 provides practical guidance for organisations performing artificial intelligence (AI) system impact assessments. It helps organisations developing, providing or using AI systems systematically identify, analyse and address reasonably foreseeable impacts - both beneficial and harmful - on individuals, groups of individuals and societies.

The more important question is not only whether the model performs accurately, but "What impact can this AI system create?" An AI system can be technically accurate and still create unacceptable impact on people, privacy, dignity or organisational risk. Accuracy alone is not enough.

For South African organisations the legal duty is already in POPIA. Regulation 4(1)(b) requires the Information Officer to ensure that a personal information impact assessment is conducted so that adequate measures exist to comply with the conditions for lawful processing. King V expects the governing body to oversee data, information and technology risk, including third-party and emerging-technology risk. ISO/IEC 42005 does not replace those duties. It is a structured method that can make the assessment visible, documented and repeatable.

The standard focuses on structured evaluation of how AI systems may impact people, business operations, privacy, security, human rights, society and regulatory compliance. It supports integration with AI risk management (ISO/IEC 23894) and AI management systems (ISO/IEC 42001). Where the organisation also places systems on the EU market or acts as an EU deployer, the same method can inform the provider"s risk management system (Article 9) and a Fundamental Rights Impact Assessment under Article 27. Completing a 42005 assessment does not discharge the POPIA PIIA. Completing a PIIA does not discharge Article 27.

When following this guidance, the assessment can be performed through a professional-grade software platform that delivers a structured, auditable and collaborative workflow. Users are guided step-by-step through system context, stakeholder identification, impact categories, visual risk mapping, controls review, residual impact determination and governance decision-making. The platform generates documentation ready for review and approval, with version control and multi-role collaboration - producing evidence suitable for the Information Officer, the board, internal audit and, where relevant, conformity assessment.

Why This Matters

The growing application of AI systems brings significant benefits. At the same time there are concerns about reasonably foreseeable negative effects, including potentially harmful, unfair or discriminatory outcomes, privacy harm, security compromise and unwanted effects on work. A system that is "accurate" can still process excessively, infer special personal information, or produce outcomes a person cannot see or challenge.

Under POPIA those outcomes sit inside the conditions for lawful processing: purpose limitation, minimisation, quality, openness, security and data-subject participation. Under King V they sit inside technology and information oversight. ISO/IEC 42005 provides a structured way to make the impact determination documented and governable - whether the organisation is assessing its own system, a supplier's AI feature, or a use that also has EU exposure.

Systematic Assessment Process

The assessment process goes beyond technical testing. Operationalised in a guided digital environment, it includes seven structured steps:

  1. Defining AI system context - Capturing the nature, scope, purpose, intended and unintended uses, data, algorithms, models, deployment environment and the organisation's role (responsible party, operator, provider or deployer) through interactive description modules.
  2. Identifying affected stakeholders - Systematically identifying individuals, groups, societies and other interested parties that can be affected, including employees, customers, applicants, vulnerable persons and those whose privacy or other rights may be engaged.
  3. Assessing impact categories - Evaluating impacts across people, business operations, privacy, security, human rights, society and regulatory compliance, including accountability, transparency, fairness, reliability, safety, explainability and environmental dimensions.
  4. Evaluating severity and likelihood - Using visual risk mapping to position each identified impact and prioritise attention.
  5. Reviewing controls and mitigations - Assessing existing or planned measures, selecting recommended controls, and documenting how safeguards address identified harms - including POPIA measures and, where applicable, EU AI Act and data-protection expectations.
  6. Determining residual impact - Calculating remaining impact after controls, comparing against organisational thresholds, and generating residual-risk acceptance statements suitable for formal management or board-level approval.
  7. Governance review and decision-making - Routing the completed assessment through multi-role collaboration (preparer, reviewer, approver) for formal review, approval and continual improvement - creating the auditable record the Information Officer and governing body need.

The digital workflow is designed so the work can feed a POPIA PIIA file, operator and supplier assessments, notices and King V reporting, rather than sitting as a separate international paperwork exercise.

Key Features of the Guided Assessment

Benefits

Target Users

Key Takeaway

AI impact assessment is not a one-time exercise. It should be repeated across the AI lifecycle, when models change, when risks evolve, and when business context changes. ISO/IEC 42005, used through a guided digital platform, provides structure and traceability. In South Africa the purpose of that work is still POPIA applied to processing that moves, and King V applied to technology risk that is reported. The standard is the method. The Act and the Code are the duties.

Availability

ISO/IEC 42005:2025 is an International Standard available from ISO and national standards bodies. Applied through a structured digital assessment platform, it can deliver an auditable impact-assessment process that supports the standard's requirements and related obligations under POPIA, King V and, where they apply, the EU AI Act and data-protection law.

Book a Demonstration Explore the Platform