ISO/IEC 42005 is an international guidance standard for conducting AI impact assessments (AI IAs): formal, documented processes by which an organization developing, providing, or using AI considers the impacts to individuals, groups, and societies across the AI life cycle. First published in 2024 by ISO/IEC JTC 1/SC 42, it serves as the companion guidance to ISO/IEC 42001 — AI Management System and provides the detailed method for the impact assessment that 42001 requires.
Published: 2024 Publisher: ISO/IEC JTC 1/SC 42 Type: International guidance standard (companion to ISO/IEC 42001 — AI Management System)
Scope
The standard provides a framework for AI impact assessments, the documented processes by which the impacts to individuals, groups, and societies are considered by an organization developing, providing, or using AI.
Core process structure
The standard organizes the assessment into a sequence of documented steps mapped to its clauses.
Planning (Clause 5) establishes the IA process and documentation expectations, allocates responsibilities (scope, resources, liaison, approvals, reviews), defines thresholds for sensitive and restricted uses (based on legal requirements, stakeholder expectations, state of the art, cultural norms, and ethical frameworks), and defines impact scales (magnitude × likelihood) and how they map to acceptable or unacceptable risk.
Documentation of the AI system (Clause 6.3) covers the system description (capabilities, architecture, operating environment), the system purpose (why AI is being used, the value proposition, and tradeoffs), intended uses (by use case or scenario), and unintended uses (foreseeable misuses and additional beneficial uses).
Documentation of data (Clause 6.4) covers data provenance, quantity, and quality; known or potential bias; whether datasets are real, synthetic, or semi-synthetic; and data quality life-cycle management. Documentation of algorithms and models (Clause 6.5) records the AI algorithms used by the organization.
Impact identification and evaluation identifies foreseeable impacts, both beneficial and harmful, on all affected parties, assesses the magnitude and likelihood of each impact, compares them against the established thresholds, and develops an action plan for impacts exceeding thresholds.
Recording and reporting (Clause 5.10) covers internal reporting (to management, personnel, and AI partners) and external reporting (to authorities, customers, and affected individuals, groups, and societies). The approval process (Clause 5.11) addresses when approvals are required (a threshold exceeded, an IA completed), who approves, and whether external approvals are needed. Monitoring and review (Clause 5.12) covers the ongoing cadence, triggering events, who performs the review, and the review outputs (continual improvement, changes to IA planning, and changes to thresholds).
Impact categories
The standard draws its impact categories from ISO/IEC 42001 guidance. Impacts on individuals and groups (from ISO/IEC 42001, Annex B.5.4) cover fairness; accountability; transparency and explainability; security and privacy; safety and health; financial consequences; accessibility; and human rights.
Impacts on society (from ISO/IEC 42001, Annex B.5.5) cover environmental sustainability; economic impacts; government impacts; health and safety (including access to healthcare); and norms, traditions, culture, and values.
Relation to other frameworks
42005 elaborates the AI impact assessment control in ISO/IEC 42001 (Clause 6.1.4 and Annex A.5). An organization implementing 42001 uses 42005 as the detailed guidance for how to conduct the IA that 42001 requires. The standard provides a documentation structure for organizations needing to demonstrate AI impact assessment to regulators, auditors, or stakeholders, and it aligns with the EU AI Act's Fundamental Rights Impact Assessment (FRIA) requirements for high-risk AI. Among available international AI impact-assessment specifications, it is the most detailed.
Adoption
ISO published an updated IEC 42005:2026 on AI impact assessments on April 22, 2026. Early adopters identified by ISO and in reporting include Novo Nordisk, Siemens, and ING, three large European organizations spanning healthcare, industrial, and financial-services contexts, providing initial reference implementations across regulated EU industries. (Source: iso.org)
Relationships
- depends-on: ISO/IEC 42001 — AI Management System (parent management-system standard).
- supports: Algorithmic Accountability and Bias Audits, EU AI Act (Regulation 2024/1689) (FRIA alignment), Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) (impact-assessment requirements).
- related: NIST AI Risk Management Framework (AI RMF 1.0) (complementary), Frontier Compliance Framework (February 2026), AI Compliance Industry / Regulatory Fragmentation.
Sources
- ISO/IEC 42005 standard text
- ISO/IEC 42001 Annex B.5 guidance (impact assessment)