ISO/IEC 42005 — Information technology — Artificial intelligence — AI system impact assessment
An international standard specifying guidance and methodologies for conducting impact assessments of artificial intelligence systems.
Systematic impact assessments demonstrate accountability to regulators, safeguard human rights, and inform risk mitigation strategies before AI systems enter production.
An insurer applies ISO/IEC 42005 to assess how an automated claims underwriting algorithm impacts policyholder rights, financial vulnerability, and accessibility prior to rollout.
Impact assessment provides structured evaluation methodology but does not eliminate risk or substitute for legal compliance, technical verification, or ongoing operational monitoring.
The standard outlines processes for assessing the potential impacts of AI systems on individuals, groups, organizations, and society. It provides guidance on context definition, stakeholder engagement, severity and likelihood scoring, mitigation treatment identification, and continual post-deployment impact evaluation.
Cybersecurity, Systems Architecture
ISO — ISO/IEC 42005:2025 — https://www.iso.org/standard/42005; ISO — Responsible AI governance and impact standards package — https://www.iso.org/publication/PUB200420.html
