What matters in AI.

Subscribe

Learn / AI governance

Definition · AI governance

AI system impact assessment

An AI system impact assessment is a documented study of how an AI system and its foreseeable uses could affect individuals and societies. ISO/IEC 42005:2025 gives guidance on how and when to carry one out. The final draft of ISO/IEC 42001 has clauses on it, and Canada requires its own version for many federal automated decision systems.

Last reviewed

Key points

  • An AI system impact assessment looks outward, at the individuals, groups and societies an AI system can affect.
  • ISO/IEC 42005:2025 gives guidance on how and when to do one. NIST's crosswalk to the final draft of ISO/IEC 42001 lists clauses on AI system impact assessment alongside the one on AI risk assessment.
  • Canada requires one before an automated decision system that makes or supports administrative decisions about clients goes into production. Its questionnaire scores the system into one of four impact levels, and the level sets which extra safeguards apply.
  • A data protection impact assessment under the GDPR centres on processing personal data, and a fundamental rights impact assessment under the EU AI Act will be owed from 2 December 2027 by certain organisations using AI systems the Act classes as high-risk. The ISO/IEC 42005 scope covers impacts of any AI system.

The official page for ISO/IEC 42005 is on iso.org. This page draws on ISO’s open metadata and on what NIST, the Government of Canada, the EU and the Colorado General Assembly publish.

How it works

An AI system impact assessment asks what an AI system could do to the people and societies around it. ISO/IEC 42005:2025 is the international standard that gives guidance on it. Its published scope covers impacts “for individuals and societies that can be affected by an AI system and its foreseeable applications”. It also covers how and when to assess, at what stages of the life cycle, and how to document the result.

NIST’s crosswalk to the final draft of ISO/IEC 42001 lists annex items for the assessment process, its documentation, impacts on individuals and groups, and societal impacts. NIST’s framework adds size: its outcome MAP 5.1 is that the likelihood and magnitude of each identified impact, beneficial and harmful, are identified and documented, drawing on evidence such as public incident reports.

The assessment is tied to AI risk management but listed separately. The ISO/IEC 42005 scope says the process can be integrated into an organisation’s AI risk management. NIST’s crosswalk lists AI system impact assessment as its own clauses, 6.1.4 and 8.4, alongside AI risk assessment, 6.1.2.

Why it matters

NIST says impact assessment approaches can help AI actors understand potential impacts or harms within specific contexts. It lists the tasks as assessing accountability, combating harmful bias, examining impacts of AI systems, product safety, liability and security, among others.

The result can decide what happens next. In Canada, the score sets an impact level, and a higher level brings more demanding peer review and more human involvement in decisions. Baseline requirements, such as testing and recourse, apply at every level.

In practice

Canada has required its Algorithmic Impact Assessment since 2020 under the Directive on Automated Decision-Making. The directive covers automated decision systems in production that make or support administrative decisions about clients, in institutions subject to the Treasury Board’s Policy on Service and Digital, and excludes research and test systems. The official responsible must complete, approve and publish the final results on the Open Government Portal before the system goes into production. The tool is a questionnaire of 65 risk questions and 41 mitigation questions. Its impact questions cover rights and freedoms, equality, dignity, privacy and autonomy, health and well-being, economic interests, the environment, how long-lasting and reversible a decision is, and how the system performs for clients with different identity factors. It is filled in at the start of design, again before production, and updated when the system’s functionality or scope changes.

In the EU, two laws name their own assessments. A data protection impact assessment under the GDPR is required before processing personal data in a way likely to be high risk to people’s rights and freedoms. A fundamental rights impact assessment under the EU AI Act will be owed, from 2 December 2027, by public bodies, private entities providing public services, and some credit and insurance firms before they deploy AI systems the Act lists as high-risk.

Colorado wrote an impact assessment into law and then rewrote the law without one. Senate Bill 24-205 of 2024 required organisations using AI systems the act defined as high-risk, with some exceptions, to complete one at least annually and within 90 days of a substantial change. Its minimum contents included the system’s purpose, risks of algorithmic discrimination, input and output data, performance metrics, transparency measures and post-deployment monitoring. A 2025 law set its start at 30 June 2026. Senate Bill 26-189, approved on 14 May 2026, repeals and reenacts that part of Colorado law from 1 January 2027 around automated decision-making technology, and its text contains no impact assessment duty.

Questions and answers

What is an AI system impact assessment?

An AI system impact assessment is a documented study of how an AI system and its foreseeable uses could affect individuals and societies. ISO/IEC 42005:2025 gives guidance on performing one, including when to do it and at which stages of the system's life cycle.

What is ISO/IEC 42005?

ISO/IEC 42005:2025, "Information technology — Artificial intelligence (AI) — AI system impact assessment", is an ISO/IEC standard published on 28 May 2025; the committee responsible is ISO/IEC JTC 1/SC 42. According to its published scope it gives guidance to organisations that develop, provide or use AI systems on assessing impacts on individuals and societies, and on fitting that process into AI risk management and an AI management system.

How is an AI system impact assessment different from a DPIA or a FRIA?

A data protection impact assessment is required by GDPR Article 35 for processing of personal data likely to be high risk to people's rights and freedoms. A fundamental rights impact assessment is required by EU AI Act Article 27, from 2 December 2027 for the high-risk uses listed in the Act's Annex III, of certain organisations deploying those systems. The ISO/IEC 42005 scope covers the impacts of any AI system on individuals and societies, for any organisation that develops, provides or uses one.

Did Colorado require AI impact assessments?

Colorado Senate Bill 24-205 of 2024 required organisations using AI systems it defined as high-risk, with some exceptions, to complete one at least annually. A 2025 law set its start at 30 June 2026. Senate Bill 26-189, approved on 14 May 2026, repeals and reenacts that part of Colorado law from 1 January 2027 around automated decision-making technology, and its text contains no impact assessment duty.

Sources

  1. ISO Open Data, ISO deliverables metadata (JSON Lines, latest)ISO
  2. NIST AI RMF to ISO/IEC FDIS 42001 AI Management system CrosswalkNIST
  3. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1NIST, Jan 2023
  4. Directive on Automated Decision-MakingTreasury Board of Canada Secretariat, 24 Jun 2025
  5. Algorithmic Impact Assessment toolGovernment of Canada
  6. Colorado Senate Bill 24-205, Consumer Protections for Artificial Intelligence (signed act)Colorado General Assembly, May 2024
  7. SB25B-004, Colorado General Assembly bill pageColorado General Assembly, Aug 2025
  8. Senate Bill 26-189, Session Laws of Colorado 2026, chapter 131Colorado General Assembly, 14 May 2026
  9. Regulation (EU) 2016/679 (General Data Protection Regulation), Article 35Official Journal of the European Union, 4 May 2016
  10. Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text 27 July 2026, Article 27Publications Office of the European Union, 27 Jul 2026