DoAIRight
ISO/IEC 42001

AI Impact Assessment Under ISO 42001: Guide

PUBLISHED 06 AUG 2026

An AI impact assessment under ISO/IEC 42001:2023 (specifically addressed in Clause 6.1.4 and Annex A.5) is a structured methodology used to identify, evaluate, and mitigate the potential consequences that an artificial intelligence system may impose on individuals, groups, and society throughout its lifecycle. Unlike conventional IT risk management—which primarily addresses organizational risks like operational downtime or financial loss—ISO 42001 requires organizations to evaluate external and societal harm. Performing rigorous impact assessments allows organizations to build trustworthy AI, uphold fundamental human rights, and achieve certification readiness under an ISO/IEC 42001 Artificial Intelligence Management System (AIMS).

Understanding ISO 42001 6.1.4 and Annex A.5

ISO/IEC 42001 makes a clear distinction between internal organizational risk assessments and external AI system impact assessments. While Clause 6.1.2 focuses on risks to the organization's objectives, ISO 42001 6.1.4 mandates that organizations establish a process for assessing the potential impacts of AI systems.

The framework recognizes that AI systems can generate downstream effects far beyond the boundaries of the organization that built or deployed them. Therefore, Annex A domain A.5 (Assessing impacts of AI systems) provides specific control objectives to ensure organizations analyze potential ethical, legal, and societal disruptions before, during, and after deployment.

Three Levels of Impact: Individuals, Groups, and Society

When conducting an AI impact assessment under ISO 42001, your organization must systematically evaluate consequences across three distinct tiers:

1. Impact on Individuals

Assessments must analyze how the AI system directly affects individual rights, well-being, and autonomy. Key considerations include:

  • Human rights and dignity: Does the system restrict individual decision-making, freedom, or privacy?
  • Fairness and non-discrimination: Could automated decisions produce biased outcomes in hiring, lending, or law enforcement?
  • Physical and psychological safety: Can model outputs cause mental distress or bodily harm?

2. Impact on Groups

AI models frequently perform differently across demographic or socio-economic cohorts. Your impact assessment must examine collective effects on marginalized or vulnerable populations, such as:

  • Demographic bias: Disparate impact on specific ethnic, gender, or age groups.
  • Economic exclusion: Systematic denial of essential services (e.g., healthcare, credit) to specific communities.
  • Power dynamics: Shifts in bargaining power between workers and automated management software.

3. Impact on Society

At the broadest level, organizations must analyze macro-level societal consequences, including:

  • Democratic processes and public discourse: Spread of synthetic deepfakes, disinformation, or political manipulation.
  • Environmental footprint: Energy consumption and carbon emissions resulting from model training and execution.
  • Labor market disruption: Long-term displacement of skilled or unskilled labor forces.

Step-by-Step Guide to Conducting an AI Impact Assessment

To fulfill the requirements of ISO 42001 6.1.4, follow this five-step process:

  1. Define Context and Intended Use: Document the scope of the AI system, its intended operational context, user roles, and potential reasonably foreseeable misuses (linking Clause 4 and Annex A.6).
  2. Identify Affected Stakeholders: List all internal and external parties—including individuals, groups, and societal elements—who could be impacted by system outputs.
  3. Analyze Potential Negative Consequences: Evaluate potential harms across privacy, fairness, safety, and ethics. Determine both the severity and likelihood of each impact.
  4. Implement Mitigation Controls: Select and execute Annex A controls (such as data governance controls in A.7 or operational oversight in A.9) to reduce unacceptable impacts to an tolerable level.
  5. Document and Re-evaluate: Maintain clear records of assessment findings and trigger re-assessments whenever significant changes occur in the AI system or operational environment (Clause 8 and Clause 10).

Preparing for ISO 42001 Certification

To achieve formal certification, an independent accredited certification body will conduct a human-led audit (under ISO/IEC 42006 guidelines) to verify that your AIMS meets all standard requirements. Auditors will expect documented evidence that your Clause 6.1.4 AI impact assessments are systematically executed and integrated into your lifecycle processes.

Platforms like DoAIRight help organizations design, implement, and track ISO 42001-compliant processes—including automated workflows for AI impact assessments. While DoAIRight prepares your team to be certification-ready, formal certificates are issued exclusively by accredited external certification bodies.

Ready to evaluate your current AIMS controls? Start with DoAIRight's free readiness assessment to baseline your organization against ISO 42001 requirements today.

Frequently asked

What is the primary difference between Clause 6.1.2 and Clause 6.1.4 in ISO 42001?

Clause 6.1.2 addresses risk management focused on risks to the organization itself (such as financial or reputational risk), whereas Clause 6.1.4 specifically focuses on assessing the potential impacts of AI systems on external entities, including individuals, groups, and society.

Is an AI impact assessment mandatory for ISO 42001 compliance?

Yes. ISO 42001 6.1.4 requires organizations to establish and maintain a process for assessing the potential impact of AI systems throughout their lifecycle.

Who grants ISO 42001 certification?

Certification is granted exclusively by independent, accredited certification bodies using qualified human auditors operating under ISO/IEC 42006 standards. Software platforms like DoAIRight prepare organizations for certification but do not issue accredited certificates.

When should an AI impact assessment be updated?

Assessments should be conducted during initial design and updated whenever there are significant modifications to the model, changes in data sources, shifts in operational context, or newly identified societal risks.

See where you stand on ISO 42001.

A free readiness assessment scores you against every clause and control.

Get your score