Structured guidance for assessing AI impact under POPIA, King V and, where relevant, the EU AI Act
ISO/IEC 42005 provides practical guidance for organisations performing artificial intelligence (AI) system impact assessments. It helps organisations developing, providing or using AI systems systematically identify, analyse and address reasonably foreseeable impacts - both beneficial and harmful - on individuals, groups of individuals and societies.
The more important question is not only whether the model performs accurately, but "What impact can this AI system create?" An AI system can be technically accurate and still create unacceptable impact on people, privacy, dignity or organisational risk. Accuracy alone is not enough.
For South African organisations the legal duty is already in POPIA. Regulation 4(1)(b) requires the Information Officer to ensure that a personal information impact assessment is conducted so that adequate measures exist to comply with the conditions for lawful processing. King V expects the governing body to oversee data, information and technology risk, including third-party and emerging-technology risk. ISO/IEC 42005 does not replace those duties. It is a structured method that can make the assessment visible, documented and repeatable.
The standard focuses on structured evaluation of how AI systems may impact people, business operations, privacy, security, human rights, society and regulatory compliance. It supports integration with AI risk management (ISO/IEC 23894) and AI management systems (ISO/IEC 42001). Where the organisation also places systems on the EU market or acts as an EU deployer, the same method can inform the provider"s risk management system (Article 9) and a Fundamental Rights Impact Assessment under Article 27. Completing a 42005 assessment does not discharge the POPIA PIIA. Completing a PIIA does not discharge Article 27.
When following this guidance, the assessment can be performed through a professional-grade software platform that delivers a structured, auditable and collaborative workflow. Users are guided step-by-step through system context, stakeholder identification, impact categories, visual risk mapping, controls review, residual impact determination and governance decision-making. The platform generates documentation ready for review and approval, with version control and multi-role collaboration - producing evidence suitable for the Information Officer, the board, internal audit and, where relevant, conformity assessment.
The growing application of AI systems brings significant benefits. At the same time there are concerns about reasonably foreseeable negative effects, including potentially harmful, unfair or discriminatory outcomes, privacy harm, security compromise and unwanted effects on work. A system that is "accurate" can still process excessively, infer special personal information, or produce outcomes a person cannot see or challenge.
Under POPIA those outcomes sit inside the conditions for lawful processing: purpose limitation, minimisation, quality, openness, security and data-subject participation. Under King V they sit inside technology and information oversight. ISO/IEC 42005 provides a structured way to make the impact determination documented and governable - whether the organisation is assessing its own system, a supplier's AI feature, or a use that also has EU exposure.
The assessment process goes beyond technical testing. Operationalised in a guided digital environment, it includes seven structured steps:
The digital workflow is designed so the work can feed a POPIA PIIA file, operator and supplier assessments, notices and King V reporting, rather than sitting as a separate international paperwork exercise.
AI impact assessment is not a one-time exercise. It should be repeated across the AI lifecycle, when models change, when risks evolve, and when business context changes. ISO/IEC 42005, used through a guided digital platform, provides structure and traceability. In South Africa the purpose of that work is still POPIA applied to processing that moves, and King V applied to technology risk that is reported. The standard is the method. The Act and the Code are the duties.
ISO/IEC 42005:2025 is an International Standard available from ISO and national standards bodies. Applied through a structured digital assessment platform, it can deliver an auditable impact-assessment process that supports the standard's requirements and related obligations under POPIA, King V and, where they apply, the EU AI Act and data-protection law.