ISO/IEC 42005:2025 — AI System Impact Assessment
The published international standard providing guidance for organisations that conduct impact assessments of artificial intelligence systems.
The standard gives organisations a repeatable basis for documenting stakeholder impacts, informing deployment decisions, selecting treatments, and demonstrating accountable AI governance to customers, regulators, and assurance functions.
Before deploying an AI decision-support system, an organisation uses ISO/IEC 42005 to define scope, identify affected groups, assess beneficial and adverse impacts, assign treatments and owners, and establish monitoring triggers.
ISO/IEC 42005 is guidance for AI system impact assessment; it is not interchangeable with an AI risk assessment, data protection impact assessment, or algorithmic impact assessment. Applying it does not itself establish legal compliance or certify the system.
The first edition was published in May 2025. It provides a structured approach for identifying, analysing, evaluating, and documenting the impacts of an individual AI system across its lifecycle and affected stakeholders. It complements organisation-level AI governance under ISO/IEC 42001 by providing system-level impact-assessment guidance.
Cybersecurity
ISO — ISO/IEC 42005:2025 — https://www.iso.org/standard/42005; ISO — Responsible AI governance and impact standards package — https://www.iso.org/publication/PUB200420.html
