AI impact assessments under ISO 42001: a working template
As artificial intelligence moves from speculative hype to core infrastructure, the regulatory net is tightening. ISO 42001 provides the global blueprint for managing AI risks, but its most critical component—the AI Impact Assessment—remains a mystery to many founders. This article provides a clinical, step-by-step template for conducting assessments that satisfy auditors and protect your reputation.
Michael McCarroll— Founder · 20+ yrs GRC, ISO 27001 lead implementer 16 min read Updated June 2026
The New Reality of AI Governance
The publication of ISO/IEC 42001:2023 marked a shift in how we approach technology governance. It is no longer sufficient to treat AI as a subset of Information Security under ISO 27001; the unique challenges of transparency, non-determinism, and bias require a dedicated management system. Annex B of the standard specifically highlights the need for impact assessments that go beyond basic risk management.
An Artificial Intelligence Impact Assessment (AIIA) is the cornerstone of this new regime. It serves as documented evidence that your organisation has considered the 'downstream' consequences of its algorithms. For a founder, this isn't just a compliance box-ticking exercise; it is a mechanism to prevent catastrophic PR failures and ensure that your product remains viable as the EU AI Act and similar global regulations come online.
Phase One: Defining System Boundaries and Intended Use
Every effective assessment starts with a clear 'Scope and Context' definition. Under ISO 42001 Clause 6.1.2, you are required to define the AI system's boundaries. You cannot assess impact if you haven't defined exactly what the system does and, more importantly, what it is prohibited from doing. This section should include a rigorous definition of the intended use case.
I often see firms making the mistake of being too vague here. Saying 'we use AI to improve customer service' is useless for an auditor. You must specify: 'We use a fine-tuned GPT-4 model to provide automated responses to tier-1 support queries regarding billing and account access.' Precision in the description allows for precision in the risk identification.
Once the system is defined, you must map the stakeholders. This includes not just your customers, but the individuals who might be impacted by the AI’s decisions without ever interacting with it directly. If your AI determines creditworthiness, the stakeholder is the applicant; if it optimises delivery routes, the stakeholders include the drivers and the local community.
The intended purpose and stated objectives of the AI system.
A detailed Technical Description, including model types (e.g., Transformer, CNN) and data sources.
Stakeholders identified, categorising them into internal users, external subjects, and society at large.
The physical and digital environment where the AI will operate.
Phase Two: Assessing Trustworthiness and Societal Impact
ISO 42001 deviates from traditional security standards by placing a heavy emphasis on ethics and societal impact. Your assessment must evaluate the 'Trustworthiness' of the AI system. This isn't a nebulous concept; it's a technical requirement. You need to document how you are mitigating 'algorithmic bias' and what measures are in place to ensure the system behaves predictably.
A practical approach is to use the 'Four Pillars of AI Trust': Fairness, Accountability, Transparency, and Safety. For each pillar, you must identify potential adverse impacts. For instance, in the 'Fairness' pillar, you should ask if your training data over-represents a certain demographic, leading to skewed results that could lead to legal challenges under equality legislation.
Fairness and Non-discrimination: Assessing for historical bias in training sets.
Transparency and Explainability: Can a human understand why a specific output was generated?
Safety and Security: Resilience against adversarial attacks or 'jailbreaking'.
Environmental Impact: The compute resources required and their carbon footprint.
Phase Three: Risk Quantification and Categorisation
Not all AI systems are created equal. You should implement a scoring matrix similar to a traditional risk heat map, but tailored for AI. An AI that organises internal meeting notes carries a significantly lower impact profile than an AI that filters CVs for the HR department. Your assessment must reflect this gradient.
For high-impact systems, ISO 42001 expects a deeper level of scrutiny. You will need to demonstrate that you have considered the 'Residual Risk'—the risk that remains after you have applied all your controls. If you are deploying a high-impact system, the auditor will look for evidence of external validation or 'red-teaming' to prove your impact claims are accurate.
Low Impact: Internal productivity tools with 'human-in-the-loop' oversight.
Medium Impact: Customer-facing tools that do not make life-altering decisions.
High Impact: Systems involving recruitment, healthcare, credit, or legal standing.
Prohibited: Systems that cross clear ethical lines, such as social scoring or real-time biometric ID in public.
Phase Four: Continuous Monitoring and Documentation
Documentation is the only way to survive an ISO 42001 audit. Your AIIA should be a living document, version-controlled and stored within your Management System. I recommend a templated approach where every AI project within the firm triggers a 'Gate 0' impact assessment. No code should go to production without a completed and signed-off assessment.
A common failure point is the lack of 'Human Oversight' documentation. Annex A of ISO 42001 specifically mentions the requirement for human intervention. Your assessment must detail who is responsible for overriding the AI, under what conditions they should do so, and how those overrides are logged. If you can't show who is in control, you aren't compliant.
Design Phase: Initial impact scoping and 'Go/No-Go' ethical review.
Testing Phase: Quantitative testing for bias and error rates (Model Validation).
Deployment Phase: Sign-off by the AI Management Representative.
Review Phase: Monthly or quarterly monitoring of system performance in the wild.
Automate your AI Governance today
Bridge the gap between AI innovation and regulatory compliance. Use ISO-STANDARD.app to automate your ISO 42001 evidence collection, manage AI risk registers, and generate boardroom-ready impact assessments that win enterprise trust.
ISO-STANDARD.app ships a ready-to-adopt ISO 42001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.
Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.
Frequently asked questions
What is an AI impact assessment under ISO 42001?
An AI impact assessment (AIIA) is a systematic evaluation required by ISO 42001 to identify and mitigate risks related to AI systems, specifically focusing on societal impacts, ethics, and safety. Unlike a standard risk assessment which focuses on the business, an AIIA prioritises the impact on individuals and stakeholders. It is a mandatory component for organisations aiming for ISO 42001 certification.
How does an AIIA differ from a Data Protection Impact Assessment (DPIA)?
While there is overlap, a DPIA focuses on data privacy under GDPR, whereas an AIIA covers broader systemic issues like algorithmic bias, safety, environmental impact, and societal shifts. If your AI processes personal data, you will likely need to perform both or create a hybrid assessment that satisfies the requirements of both ISO 42001 and GDPR.
How often should I conduct an AI impact assessment?
ISO 42001 does not mandate a specific frequency, but best practice suggests performing an assessment during the design phase, before deployment, and whenever significant changes are made to the model or data inputs. For high-risk systems, a quarterly review of the impact assessment is recommended to account for 'model drift' and evolving societal expectations.
Is the assessment only for companies building their own LLMs?
No. ISO 42001 applies to any organisation providing or using AI systems. If you are a 'deployer' (using third-party AI), your assessment will focus on how that tool integrates into your business processes and the risks it poses to your specific users. If you are a 'provider' (building the AI), your assessment must be more technical and cover the entire development lifecycle.
Action checklist PDF
Mirrors this guide with owners, artefacts & a 30/60/90-day plan.