verified_user
Standardful
Homechevron_rightStandardschevron_rightISO/IEC 42005:2025
ActiveInternational Standardupdate Standard Updated: May 2025fact_check Fact checked: Sep 3, 2026

ISO/IEC 42005:2025

Information technology — Artificial intelligence (AI) — AI system impact assessment

apartmentPublishing Organization:International Organization for Standardization (ISO)

Standard Introduction

ISO/IEC 42005:2025 provides guidance for assessing how an artificial intelligence system and its foreseeable applications may affect individuals, groups, and society. It helps organizations define when to assess impacts and how to identify, evaluate, document, and revisit them across the AI system lifecycle.

The standard applies to organizations developing, providing, or using AI systems regardless of size or sector. It complements ISO/IEC 42001 and ISO/IEC 23894 by turning human and societal impact analysis into a repeatable governance process, but it is guidance rather than a standalone certification standard or substitute for legal analysis.

groups

Human and Societal Impact

Focuses the assessment on how an AI system and its foreseeable uses can affect individuals, groups, and society, including both beneficial and adverse outcomes.

sync

Lifecycle Assessment

Supports impact assessment from design and development through deployment and post-deployment monitoring, with reassessment when the system or its context changes.

account_tree

Governance Integration

Provides a repeatable impact-assessment process that can feed an organization's AI risk management and ISO/IEC 42001 artificial intelligence management system.

list_alt AI Impact Assessment Focus Areas

  • Assessment purpose and decision context
  • AI system and foreseeable-use boundaries
  • Affected individuals, groups, and societal stakeholders
  • Potential beneficial and adverse impacts
  • Impact evaluation criteria and prioritization
  • Treatment decisions, owners, and documented evidence
  • Lifecycle monitoring, triggers, and reassessment

Who Needs to Comply?

groups

Organizations developing, providing, procuring, deploying, or using AI systems that need a consistent way to assess and document effects on people and society. It is relevant across sectors and organization sizes, particularly where AI influences access, safety, rights, opportunities, or important decisions.

Key Requirements

1

Set Assessment Triggers

Define when an AI system impact assessment is required, who approves it, and which lifecycle events or material changes require reassessment.

2

Define System and Use Context

Document the AI system, intended and foreseeable uses, lifecycle stage, operating environment, dependencies, limitations, and relevant decisions.

3

Identify Affected Stakeholders

Determine which individuals, groups, communities, customers, workers, or other societal stakeholders may experience benefits or adverse effects.

4

Evaluate and Address Impacts

Use consistent criteria to analyse potential impacts, prioritize concerns, select actions, assign owners, and record accepted residual impacts.

5

Document, Monitor, and Reassess

Maintain traceable assessment records and refresh them after deployment, incidents, stakeholder feedback, performance changes, or changes in use and context.

Implementation Roadmap

1
Phase 1schedule Duration: 2-4 weeks

Set scope and assessment triggers

Define which AI systems and decisions require an impact assessment, the accountable owner, approval path, assessment timing, and the changes or incidents that trigger reassessment.

2
Phase 2schedule Duration: 2-6 weeks

Map context and stakeholders

Describe the system, intended and foreseeable uses, lifecycle stage, operating environment, dependencies, and limitations. Identify individuals, groups, and societal stakeholders who may be affected.

3
Phase 3schedule Duration: 3-8 weeks

Evaluate impacts and decide actions

Identify beneficial and adverse impacts, apply documented evaluation criteria, prioritize concerns, select treatment or design actions, assign owners, and record decisions and residual impacts.

4
Phase 4schedule Duration: Ongoing

Monitor and reassess

Track deployment evidence, performance, incidents, complaints, stakeholder feedback, and contextual change. Update the assessment and related governance records when a trigger occurs.

Compliance Checklist

0 / 12

checklist Scope and governance

checklist Impact analysis

checklist Decisions and lifecycle evidence

ISO/IEC 42005 Compared with Related AI Standards

These standards address different layers of AI governance and are often used together.

StandardPrimary purposeBest used forCertification role
ISO/IEC 42005:2025AI system impact assessmentEffects on individuals, groups, and society across the lifecycleGuidance; not standalone certifiable
ISO/IEC 42001:2023AI management systemOrganization-wide policies, processes, responsibilities, and continual improvementCertifiable management-system standard
ISO/IEC 23894:2023AI risk managementIntegrating AI-specific risks into organizational risk managementGuidance; not standalone certifiable

Common Misconceptions

cancel
Myth

An AI impact assessment is a one-time pre-launch document.

check_circle
Reality

Impact can change with data, models, users, deployment context, scale, or foreseeable use. The assessment process should define monitoring and reassessment triggers across the lifecycle.

cancel
Myth

Only AI developers need to assess impacts.

check_circle
Reality

The standard is intended for organizations developing, providing, or using AI systems. A deployer can create new impacts through its purpose, users, data, workflow, or operating context.

cancel
Myth

ISO/IEC 42005 certification proves an AI system is responsible.

check_circle
Reality

ISO/IEC 42005 is guidance and is not a standalone certification standard. Its value is a consistent, documented assessment process and better-informed governance decisions.

cancel
Myth

Completing the standard automatically satisfies every AI law.

check_circle
Reality

The process can support compliance evidence, but legal duties vary by jurisdiction, sector, system role, and use case and must be mapped separately.

Penalties & Enforcement

warning

ISO/IEC 42005:2025 is a voluntary guidance standard and does not create direct legal penalties or a standalone certification. Its assessment process can support evidence needed for laws, contracts, procurement reviews, and AI governance programs, whose consequences must be evaluated separately.

Frequently Asked Questions

What is ISO/IEC 42005:2025?

expand_more

ISO/IEC 42005:2025 is an international guidance standard for assessing and documenting how an AI system and its foreseeable applications may affect individuals, groups, and society across the AI system lifecycle.

Who should use ISO/IEC 42005?

expand_more

It is intended for organizations that develop, provide, or use AI systems and applies regardless of organization size, type, or sector. Procurement and deployment teams can use it as well as system developers.

Can an organization be certified to ISO/IEC 42005?

expand_more

ISO/IEC 42005 is a guidance standard, not a standalone certifiable management-system standard. ISO/IEC 42001 is the certifiable AI management-system standard; ISO/IEC 42005 can support its impact-assessment process and evidence.

When should an AI impact assessment be performed?

expand_more

The assessment should be considered throughout the AI system lifecycle, from design and development through deployment and post-deployment monitoring, and updated when changes in the system, use, stakeholders, evidence, or context could alter impacts.

Does ISO/IEC 42005 prove compliance with AI laws?

expand_more

No. It provides a consistent assessment method but does not replace jurisdiction-specific legal analysis. Organizations must separately map the assessment to applicable duties such as fundamental-rights, privacy, safety, employment, consumer-protection, or sector rules.

Official Documentation

View All

Related Categories