ReadSafety.com

ISO 42001 Questions, Answered

What is an AI impact assessment?

Quick answer

An AI system impact assessment is the structured evaluation of what an AI system could do to people: individuals, groups, and society, not just to your organization. It examines fairness, safety, privacy, rights, transparency, and the consequences of failure or misuse, and its findings drive controls. ISO 42001 makes it a core requirement, and regulations like the EU AI Act require closely related assessments.

How it differs from risk assessment

Classic risk assessment asks what could harm the organization: financial, legal, operational, reputational exposure. Impact assessment turns the lens outward: who is affected by this system's decisions and behavior, what harms could reach them (denied opportunities, discriminatory outcomes, unsafe recommendations, privacy intrusions, manipulation), how severe and reversible those harms would be, and whether the people affected have recourse. ISO 42001 requires both, feeding one treatment process, because a system can be low-risk to you and high-impact to others, and that combination is precisely where governance failures live.

What a competent assessment covers

  • Purpose and context: intended use, foreseeable misuse, and deployment environment; the same model is a different risk in triage than in marketing.
  • Affected parties: users, subjects of decisions, groups statistically affected, and society-level effects (information quality, labor, environment) where relevant.
  • Harm analysis: failure modes and their consequences for those parties, including performance disparities across demographic groups.
  • Data lineage: what the system learned from, its representativeness, and the rights and quality attached to it.
  • Oversight and recourse: where humans sit in the loop, what they can actually see and override, and how an affected person contests an outcome.
  • Findings into controls: each significant impact maps to a treatment: design change, restriction of use, monitoring, disclosure, or the decision not to deploy.
Key factThe most important output of an impact assessment is sometimes "no": documented cases where an organization assessed a proposed AI use and declined or constrained it are the strongest evidence any auditor or regulator can see that the process is real. An assessment archive containing only approvals reads as a rubber stamp.

When to perform and refresh it

Before deployment, at significant change (new model, new data, new use case, new population), and periodically in operation, because drift and scope creep are how yesterday's assessed system becomes today's unassessed one. Proportionality applies: a spam filter and a hiring screen do not deserve the same depth, and tiering your inventory by potential impact is itself part of a mature process.

An auditor's marker of quality

Read any impact assessment and check one thing: does it name specific harms to specific people and connect each to a specific control, or does it recite principles ("we value fairness") without operational consequence. The first survives audit, regulator scrutiny, and incident retrospectives. The second is the template everyone can smell, and in this field, the template is the risk.

Ready to take the next step?

USQC - United Safety Quality Council is an ASC-accredited certification body providing third-party ISO 42001 and management system certification audits, internal and supplier audit services, and auditor training. Since 2015, USQC has automated audit planning, reporting, and decision support, cutting audit man-days that other certification bodies bill for and placing USQC pricing in the lower quartile, with highly experienced lead auditors on every audit.

Talk to USQC