Exemplar Global Certified Courses from USD 99. Ending Soon!

AI System Impact Assessment: The Concept That Sets ISO 42001 Apart

AW

Team @ Audit Workshop

14 min read
AI System Impact Assessment: The Concept That Sets ISO 42001 Apart

Why Impact Assessment Is Not Just Another Risk Tool

If you have spent time working with ISO 9001, ISO 14001, or ISO 45001, you are already familiar with risk assessment. You identify hazards or risks, evaluate their likelihood and consequence, and put controls in place. ISO 42001 does all of that too, through its Clause 6.1.2 AI risk assessment process. But it introduces something additional that none of those other standards require in the same way: a formal AI system impact assessment.

This is not a duplicate of the risk assessment. It sits alongside it, addresses different questions, and covers territory that a conventional risk register simply cannot reach. Understanding the difference between the two is one of the most important conceptual steps for anyone working with ISO 42001, whether you are implementing an AI management system, auditing one, or advising an organisation on what the standard actually demands.

This article explains what an AI system impact assessment is, why ISO 42001 requires it, how it connects to the rest of the management system, and what auditors and quality managers need to look for when reviewing one.

The Core Idea: Harms Beyond the Organisation

Most management system risk assessments focus inward. ISO 9001 asks about risks to product quality and customer satisfaction. ISO 45001 focuses on risks to workers. ISO 14001 broadens the lens to environmental impacts, but even then the process is grounded in the organisation's own operations and aspects.

AI systems are different. An AI model used to screen job applications, assess loan eligibility, triage medical symptoms, or predict recidivism in criminal justice settings does not just create operational risk for the organisation deploying it. It creates the potential for real harm to the people it is applied to. Those people are often not customers in any conventional sense. They may have no relationship with the organisation at all. They may not even know an AI system has been used to make a decision about them.

ISO 42001 recognises this explicitly. The standard requires organisations to assess the impacts of their AI systems on individuals, groups, and society, not just on the organisation's own objectives and operations. That is the fundamental shift that the impact assessment introduces. It is outward facing, not inward facing.

This connects directly to the broader concept of responsible AI. If you want to understand how ISO 42001 frames the ethical and societal dimensions of AI governance, the article on Responsible AI: What It Means and How ISO 42001 Makes It Operational provides useful context before working through the impact assessment requirements in detail.

Where the Impact Assessment Sits in ISO 42001

The AI system impact assessment is introduced in Clause 6.1.2 of ISO 42001, which covers AI risk assessment. However, the standard does not treat impact assessment as a subset of risk assessment. It treats them as related but distinct activities. The risk assessment addresses uncertainty and potential negative outcomes for the organisation. The impact assessment addresses the broader effects of the AI system on people and society.

The requirement to conduct impact assessments at planned intervals is addressed in Clause 8.4, which sits within the operational section of the standard. This placement is deliberate. It signals that impact assessment is not just a planning exercise done once at the start. It is an operational control that must be repeated throughout the life of the AI system.

Annex A of ISO 42001 reinforces this through its control set. Annex A.5 specifically addresses the assessment of impacts of AI systems, and the controls within it cover areas such as fairness, transparency, human oversight, and the potential for AI systems to affect vulnerable populations. These annex controls feed directly into the Statement of Applicability, which means an organisation cannot simply ignore impact assessment by declaring it not applicable without a documented justification.

What an AI Impact Assessment Actually Covers

The scope of an AI system impact assessment is broader than most quality or safety professionals initially expect. It is not just about whether the AI system produces the right output. It is about what happens to the people affected by that output.

Fairness and Discrimination

One of the most significant impact areas is whether the AI system treats people fairly. This includes whether the system produces outputs that are systematically biased against particular groups based on characteristics such as age, gender, ethnicity, disability, or socioeconomic status. An AI hiring tool trained on historical data from a workforce that was predominantly male may learn to deprioritise female applicants. A credit scoring model trained on postcode data may effectively discriminate against people from lower income areas. The impact assessment needs to examine whether these patterns exist, how they are detected, and what the organisation does about them.

Privacy and Data Rights

AI systems often process large volumes of personal data. The impact assessment should consider whether the AI system respects individuals' privacy, whether data is used in ways that people have consented to, and whether the outputs of the system could expose private information. In Australia, this intersects with obligations under the Privacy Act 1988 and the Australian Privacy Principles. Organisations certified to ISO 42001 cannot treat the impact assessment as separate from their legal compliance obligations.

Transparency and Explainability

When an AI system makes a decision that affects a person, can that person understand why the decision was made? Can they challenge it? Many AI systems, particularly those based on complex machine learning models, produce outputs that are difficult to explain even to technical experts. The impact assessment should consider whether the level of transparency is appropriate for the context. A system that recommends a movie is different from one that determines whether a person receives a welfare payment. The stakes determine how much explainability is required.

Human Oversight and the Right to Contest

ISO 42001 places significant weight on human oversight of AI systems. The impact assessment should evaluate whether humans are genuinely in the loop at critical decision points, or whether the AI system is effectively making final decisions without meaningful human review. It should also consider whether affected individuals have a mechanism to contest or seek review of AI-driven decisions that affect them.

Impacts on Vulnerable Populations

Some groups face greater risk of harm from AI systems. Children, people with disabilities, elderly individuals, and people from marginalised communities may be disproportionately affected by AI systems that have not been designed or tested with their needs in mind. The impact assessment should specifically consider whether the AI system is likely to interact with or affect vulnerable populations, and what additional safeguards are needed.

Broader Societal Effects

At the widest scale, the impact assessment should consider whether the AI system could have effects on society beyond the individuals it directly affects. This might include effects on employment in a sector, on public trust in institutions, or on the concentration of power or information. For most organisations deploying AI in commercial settings, this level of analysis will be proportionate to the scale and reach of the system. A small business using AI to schedule appointments is unlikely to need the same depth of societal analysis as a government agency using AI to prioritise welfare claims.

The Proportionality Principle

ISO 42001 does not require every organisation to conduct the same level of impact assessment regardless of context. The standard builds in proportionality. The depth and rigour of the impact assessment should reflect the nature of the AI system, the context in which it is deployed, and the potential severity of harm to those affected.

This is practically important. An organisation using a simple AI tool to categorise incoming emails by topic does not need the same impact assessment process as one using AI to make credit decisions or to support clinical diagnosis. Auditors reviewing impact assessments need to assess whether the level of analysis is appropriate to the risk and context, not just whether a document exists.

This is where the connection to Clause 4 of ISO 42001 becomes important. The organisation's AI context, including its role as a provider or deployer of AI systems, the nature of the systems in scope, and the characteristics of the affected populations, should inform how the impact assessment is scoped and conducted. The article on What Clause 4 of ISO 42001 Asks About Your Organisation's AI Context explains how that foundational context-setting feeds into the rest of the management system, including the impact assessment process.

The Relationship Between Impact Assessment and Risk Treatment

Once the impact assessment has identified potential harms, the organisation needs to decide what to do about them. ISO 42001 Clause 6.1.3 addresses AI risk treatment, and the controls selected through that process should address both the risks identified through the risk assessment and the harms identified through the impact assessment.

In practice, this means the impact assessment is not a standalone document that sits in a drawer. It needs to feed into the organisation's control selection process, influence the Statement of Applicability, and drive operational controls under Clause 8. If the impact assessment identifies a risk of discriminatory outputs from an AI hiring tool, the organisation needs to implement controls such as regular bias testing, human review of borderline cases, and a process for applicants to seek review of decisions. Those controls need to be documented, implemented, and auditable.

The Annex A controls in ISO 42001 provide a structured framework for this. Annex A.5 on impact assessment, Annex A.6 on the AI system life cycle, Annex A.7 on data controls, and Annex A.9 on responsible use all contain controls that are directly relevant to managing the harms identified through an impact assessment. Organisations should not treat these annexes as optional extras. They are the mechanism through which the impact assessment findings are translated into operational practice.

Conducting the Impact Assessment: Practical Steps

For quality managers and management system practitioners who are new to ISO 42001, the impact assessment can feel abstract. Here is a practical approach to structuring one.

Step 1: Define the AI System in Scope

Be specific about what system is being assessed. Name the system, describe its function, identify the data it uses, and describe the outputs it produces. Vague descriptions produce vague assessments. If the system is a third-party tool, you still need to assess its impacts. The fact that you did not build the system does not remove your responsibility for how it affects people in your context.

Step 2: Identify Affected Parties

Who does this system make decisions about or produce outputs that affect? Be comprehensive. Consider direct users, people who are the subject of AI-driven decisions, third parties who may be indirectly affected, and any vulnerable populations who may interact with the system.

Step 3: Assess Each Impact Domain

Work through the relevant impact domains: fairness, privacy, transparency, human oversight, contestability, and broader societal effects. For each domain, assess the nature and severity of potential harm, the likelihood that harm will occur, and any existing controls that mitigate the risk.

Step 4: Document Findings and Link to Controls

Record the findings clearly. For each identified harm or risk of harm, document what controls are in place or will be implemented. Link these to the relevant Annex A controls and to the organisation's operational procedures.

Step 5: Review at Planned Intervals

The impact assessment is not a one-time exercise. AI systems change over time. The data they are trained on changes. The context in which they are deployed changes. Clause 8.4 requires the assessment to be repeated at planned intervals. Organisations should define how frequently this occurs and what triggers an unplanned review, such as a significant change to the AI system, a new deployment context, or an incident involving the system.

What Auditors Look for in an Impact Assessment

If you are auditing an AI management system, the impact assessment is one of the most substantive areas to examine. Here is what to focus on.

First, does the assessment actually exist as documented information, and does it cover the AI systems within the scope of the management system? A common gap is an organisation that has conducted a risk assessment but has not conducted a separate impact assessment addressing harms to individuals and society.

Second, is the depth of the assessment proportionate to the context? A superficial assessment for a high-risk AI system is a significant gap. An overly detailed assessment for a low-risk application is less of a concern but may indicate the organisation does not understand the proportionality principle.

Third, does the assessment identify specific harms and link them to specific controls? Generic statements about commitment to fairness are not sufficient. Auditors should look for evidence that the organisation has thought concretely about how harm could occur and what it has done to prevent or mitigate it.

Fourth, is there evidence that the assessment has been reviewed at planned intervals? Check the documented information for version history, review dates, and any changes made following review. If the AI system has changed significantly since the last assessment, that is a red flag.

Fifth, does the impact assessment feed into the Statement of Applicability and the operational controls? If the impact assessment identifies a need for human oversight but there is no operational procedure requiring human review of AI outputs, there is a gap between assessment and implementation.

For those looking to develop their skills in auditing AI management systems, including the impact assessment process, the Auditing Operational Controls and Impact Assessments Under Clause 8 article provides a detailed walkthrough of what to examine during an ISO 42001 audit.

Why This Concept Matters Beyond ISO 42001

Even if your organisation is not currently pursuing ISO 42001 certification, the concept of AI system impact assessment is worth understanding. Regulatory pressure on AI governance is increasing in Australia and globally. The Australian Government's AI Ethics Framework, the EU AI Act, and emerging guidance from bodies such as the Office of the Australian Information Commissioner all point in the same direction: organisations deploying AI systems need to demonstrate that they have assessed and managed the impacts of those systems on people.

ISO 42001 provides a structured, internationally recognised framework for doing exactly that. The impact assessment requirement is at the heart of what makes it a genuine governance tool rather than just another management system checkbox exercise. It is the mechanism through which the standard moves from managing internal risk to taking responsibility for external harm.

For quality managers and auditors who want to build credibility in this space, understanding the impact assessment process in depth is essential. It is also one of the areas where practical auditing skills translate directly. The same discipline of evidence gathering, proportionate assessment, and linking findings to controls that makes a good ISO 9001 or ISO 45001 auditor also makes a good ISO 42001 auditor. The subject matter is different, but the methodology is recognisable.

If you are considering building your ISO 42001 auditing credentials, Audit Workshop offers training that covers the full scope of the standard, including the impact assessment requirements, with instruction from practitioners who have conducted audits across a wide range of industries and management system standards. The practical focus means you leave with the ability to actually conduct an ISO 42001 audit, not just describe what the standard says.

Frequently Asked Questions

An AI system impact assessment is a structured evaluation of the potential harms that an AI system could cause to individuals, groups, and society. It goes beyond a conventional risk assessment by focusing on external impacts such as fairness, privacy, transparency, and human oversight, rather than just internal operational risks. ISO 42001 requires organisations to conduct these assessments and to repeat them at planned intervals throughout the life of the AI system.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
ISO 45001:2018 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
ISO 14001:2026 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.