ISO/IEC 42005: The New Standard for AI System Impact Assessments
ISO/IEC 42005 is a standard from ISO/IEC JTC 1/SC 42 that provides guidance for assessing how an AI system may affect individuals, groups, and society. It is designed to operationalize the impact assessment expectations referenced in ISO/IEC 42001 rather than function as a separate certifiable standard, and it requires organizations to document assessment scope, methodology, findings, and mitigation decisions on an ongoing basis.
ISO/IEC 42005 at a Glance
A quick summary of what the standard covers, how it relates to ISO/IEC 42001, and what enterprises are expected to produce.
Standard Focus
Guidance for assessing societal and stakeholder impact of AI systems, not just technical risk.
Relationship to 42001
Operationalizes impact assessment provisions referenced in the ISO/IEC 42001 management system standard.
Assessment Model
Applied per system or use case, iteratively across the AI lifecycle rather than once before deployment.
Documentation Expectation
Auditable records of scope, methodology, findings, and mitigation, not narrative reporting alone.
What to Document, and What to Ask First
ISO/IEC 42005 style impact assessments center on a defined set of documented elements, plus a set of readiness questions organizations should answer before scaling the practice across multiple AI systems.
Documentation Elements
- Intended use and deployment context of the AI system
- Affected stakeholder groups, including indirect or downstream populations
- Foreseeable societal and operational effects of the system
- Likelihood and severity of identified harms, consistent with a risk based approach
- Mitigation decisions and the rationale behind them
- Assessment scope and methodology as a standalone auditable record
Readiness Questions Before Scaling
- Does the organization already have an ISO/IEC 42001 aligned AI management system that assessments need to integrate with?
- Who owns each impact assessment from initial completion through periodic review?
- What documentation format and repository will keep assessments auditable and accessible to compliance and legal teams?
- How is production behavior of deployed AI agents monitored and logged to verify assessment assumptions remain valid?
- What process triggers re-assessment when a system's model, data, or use context changes materially?
ISO/IEC 42005 Explained
ISO/IEC 42005 is a standard from ISO/IEC JTC 1/SC 42 that provides guidance for assessing how an AI system may affect individuals, groups, and society. It operationalizes the impact assessment expectations referenced in ISO/IEC 42001 rather than functioning as a separate certifiable standard, and it requires organizations to document assessment scope, methodology, findings, and mitigation decisions on an ongoing basis.
What ISO/IEC 42005 Covers
ISO/IEC 42005, issued by ISO/IEC JTC 1/SC 42, is titled Information technology, Artificial intelligence, AI system impact assessment. It provides organizations with guidance for identifying and evaluating the potential consequences an AI system may have on individuals, groups, and society. This is distinct from a purely technical risk assessment, which typically focuses on model performance, security, or reliability. The standard addresses a gap many enterprises face today: AI systems are frequently deployed without a standardized, auditable method for evaluating their broader operational and stakeholder impact. For AI governance leaders, this means impact assessment moves from an informal or ad hoc exercise to a structured process with defined expectations for documentation and review.
How ISO/IEC 42005 Relates to ISO/IEC 42001
ISO/IEC 42001, published in 2023 by the same committee, specifies requirements for an AI management system, commonly referred to as an AIMS. It already includes provisions that reference impact assessment as part of AI risk management. ISO/IEC 42005 is positioned as a supporting document that operationalizes those provisions rather than replacing them or standing on its own as a certifiable standard. In practical terms, an organization that has built or is building an ISO/IEC 42001 aligned management system should treat ISO/IEC 42005 as the mechanism for executing the impact assessment component of that system, not as a separate compliance track. Organizations without an existing AIMS should still be able to apply ISO/IEC 42005 guidance to individual AI systems, but will need to determine how assessment outputs feed into whatever governance structure they do have.
Assessment Lifecycle: Not a One-Time Exercise
Impact assessment guidance in this standards family is generally designed to be applied iteratively across the AI system lifecycle rather than as a single exercise completed before launch. This has direct implications for how enterprises assign ownership. Each assessment needs a defined owner and a review cadence so that it remains current as models, data, or deployment context change. Completing a credible assessment typically requires cross-functional input from legal, compliance, engineering, data governance, and business stakeholders, since no single function has full visibility into intended use, technical behavior, and downstream impact. Before scaling this process across multiple AI systems, organizations benefit from establishing a repeatable template and workflow, since assessments should be scoped per system or use case rather than applied generically across an entire AI portfolio.
Where Runtime Monitoring Supports Continuous Compliance
An impact assessment records assumptions at a point in time: intended use, affected populations, and planned mitigations. Those assumptions can drift once a system is in production, particularly for AI agents that take actions or interact with tools and data beyond their original scope. Runtime monitoring and logging of AI agent behavior can provide evidentiary support that the assumptions documented in an impact assessment continue to hold after deployment. This is where the assessment process connects to operational controls. Trussed AI's runtime governance and audit logging capabilities are built to capture agent actions, tool use, and permission boundaries in production, which can serve as supporting evidence when an organization needs to demonstrate that a system is still operating within the scope described in its impact assessment. The specific evidentiary requirements for this are not detailed in ISO/IEC 42005 itself and should be confirmed against the published standard text, but the general principle, that documentation alone does not verify ongoing behavior, holds regardless of which standard an organization is aligning to.
Operationalize AI Impact Assessment in Production
Documentation defines what an AI system is supposed to do. Runtime governance helps verify what it actually does in production.
Explore Runtime Governance