Assessing Impacts of AI Systems - ISO 42001 Annex A Controls

ISO 42001 Annex A.5

The impact assessment is the most distinctive AI-specific concept in the standard. Annex A.5 makes it operational.

ISO 42001 Annex A.5 - Assessing Impacts of AI Systems Explained

Annex A.5 operationalises the impact assessment requirement in Clause 6.1.4. The four controls cover the impact assessment process, the documentation of results, and the assessment of impacts on individuals or groups and on societies.

Control A.5.2 - AI system impact assessment process

The organisation must establish a process to assess the potential consequences for individuals, groups of individuals and societies that can result from the AI system throughout its life cycle. The implementation guidance under Annex B.5.2 sets out the elements the process should include - the circumstances under which an impact assessment is performed, the elements of the assessment (identification, analysis, evaluation, treatment, documentation), who performs the assessment, how the results are used, and the individuals and societies potentially impacted.

Control A.5.3 - Documentation of AI system impact assessments

The organisation must document the results of AI system impact assessments and retain results for a defined period. The implementation guidance lists the items typically documented - the intended use of the AI system and reasonably foreseeable misuse, positive and negative impacts on relevant individuals or groups and societies, predictable failures and their impacts, demographic groups the system applies to, system complexity, the role of humans in the system, and employment and skilling considerations.

Control A.5.4 - Assessing AI system impact on individuals or groups of individuals

The organisation must assess and document the potential impacts of AI systems on individuals or groups of individuals throughout the system's life cycle. The implementation guidance highlights areas to consider - fairness, accountability, transparency and explainability, security and privacy, safety and health, financial consequences, accessibility, and human rights. Specific protection needs of groups such as children, impaired persons, elderly persons and workers should be taken into account.

Control A.5.5 - Assessing societal impacts of AI systems

The organisation must assess and document the potential societal impacts of its AI systems throughout their life cycle. Examples in the implementation guidance include environmental sustainability, economic impacts including access to financial services and employment, government and democratic processes, health and safety access, and norms, traditions, culture and values.

The A.5.4 and A.5.5 distinction matters. A.5.4 is about how the AI system affects identifiable individuals or groups - the people who use it, are subject to its decisions, or are otherwise directly touched. A.5.5 is about the wider societal effects - the second-order consequences for the economy, the environment, democratic processes or social norms. Many impact assessments focus on A.5.4 and underweight A.5.5. Both deserve attention.

The impact assessment is also where the management system intersects most directly with ethics. The standard does not prescribe an ethical framework, but it asks the organisation to consider the human and societal consequences of its AI use. The answer to those questions reveals what the organisation actually values, not just what its policies claim.

When auditing Annex A.5, I look for impact assessments that are specific to each high-impact AI system rather than generic exercises. The assessment should name the affected individuals and groups, describe the impacts considered, and record the conclusions and any mitigations applied.

The integration with the AI risk assessment under Clause 6.1.2 is critical. The impact assessment feeds the risk assessment, and the risk assessment feeds the Statement of Applicability. An impact assessment that is documented but not connected to the rest of the management system is a gap.

For the inspection AI, the impact assessment focused on the line operators and the customer. For the generative tool, it focused on staff using the tool, the customers receiving content drafted with the tool, and the wider effects of AI-drafted communication. Different AI systems, different impact pictures, different control sets.

Practical Compliance Guidance

The IMS1 Manual Section 2.5 Risk Management/IMS1-2-5 Risk Management provides the integrated framework for assessing risks and impacts. The dedicated F-Q110 AI System Impact Assessment template is the operational document for satisfying the four Annex A.5 controls.

The following alphaZ documents support compliance with ISO 42001 Annex A.5.

alphaZ document How to use it
ISO 42001 AI Management System Toolkit The full toolkit containing the AI management system documentation including the impact assessment template.
F-Q113 AI System Impact Assessment The dedicated AI system impact assessment template covering the process, documentation, and assessment of impacts on individuals, groups and societies.
F-IMS70 Annex A Controls Records the Statement of Applicability including the four A.5 controls with the implementation status and supporting evidence.
F-IMS40 AI Process Register Records the AI systems within scope and links each to its impact assessment, providing the audit trail across systems.

Note - all the above files can be downloaded with an alphaZ subscription.

Frequently Asked Questions

The standard requires the organisation to define the circumstances under which an impact assessment is performed. Most organisations conclude that high-impact AI systems need individual assessments, while lower-impact AI systems can be grouped. The decision should be deliberate, documented and consistent with the risk picture.
The data protection impact assessment is a UK GDPR requirement and focuses specifically on personal data processing risks. The AI system impact assessment under ISO 42001 is broader - it covers all impacts on individuals and societies, including but not limited to privacy. Where an AI system processes personal data, both assessments are needed but can be aligned and conducted together to avoid duplication.
Clause 8.4 requires impact assessments to be performed at planned intervals or when significant changes occur. Annual review aligned with the management review cycle is the standard cadence. Interim review is triggered by significant changes to the AI system, its use, the regulatory environment, or the affected individuals and groups.

UK Legislation

The following UK legislation is directly relevant to the assessment of AI system impacts. Organisations outside the UK should identify the equivalent legislation applicable in their jurisdiction.

Further Resources

payment logos