How it differs from risk assessment
Classic risk assessment asks what could harm the organization: financial, legal, operational, reputational exposure. Impact assessment turns the lens outward: who is affected by this system's decisions and behavior, what harms could reach them (denied opportunities, discriminatory outcomes, unsafe recommendations, privacy intrusions, manipulation), how severe and reversible those harms would be, and whether the people affected have recourse. ISO 42001 requires both, feeding one treatment process, because a system can be low-risk to you and high-impact to others, and that combination is precisely where governance failures live.
What a competent assessment covers
- Purpose and context: intended use, foreseeable misuse, and deployment environment; the same model is a different risk in triage than in marketing.
- Affected parties: users, subjects of decisions, groups statistically affected, and society-level effects (information quality, labor, environment) where relevant.
- Harm analysis: failure modes and their consequences for those parties, including performance disparities across demographic groups.
- Data lineage: what the system learned from, its representativeness, and the rights and quality attached to it.
- Oversight and recourse: where humans sit in the loop, what they can actually see and override, and how an affected person contests an outcome.
- Findings into controls: each significant impact maps to a treatment: design change, restriction of use, monitoring, disclosure, or the decision not to deploy.
When to perform and refresh it
Before deployment, at significant change (new model, new data, new use case, new population), and periodically in operation, because drift and scope creep are how yesterday's assessed system becomes today's unassessed one. Proportionality applies: a spam filter and a hiring screen do not deserve the same depth, and tiering your inventory by potential impact is itself part of a mature process.
An auditor's marker of quality
Read any impact assessment and check one thing: does it name specific harms to specific people and connect each to a specific control, or does it recite principles ("we value fairness") without operational consequence. The first survives audit, regulator scrutiny, and incident retrospectives. The second is the template everyone can smell, and in this field, the template is the risk.