ISO 42005 AI Impact Assessment | TLY

AI Regulation Tracker  /  Standards and governance

ISO Publishes the First International Standard for AI Impact Assessments

ISO/IEC 42005:2025 is the first international standard that gives organizations a structured, documentable method for assessing how an AI system affects the people and the society around it, across the full lifecycle. It is voluntary guidance, not a law and not a certification, and it is best understood as the operational companion to ISO/IEC 42001. If your clients are building an AI governance program, this is the yardstick that tells them what a real impact assessment should actually contain.

The Leveraged Years AI Regulation News

Here is the problem this standard was built to solve. For a few years now, "do an AI impact assessment" has been the answer everyone gives and no one defines. The EU AI Act references impact and fundamental-rights assessments. State and sector regulators in the US gesture at algorithmic assessments. Boards ask for one. And when you sit down to actually produce the document, there is no agreed picture of what belongs in it. People reach for privacy impact assessments, or a risk register, or a one-page memo, and call it done. ISO/IEC 42005 is the first international attempt to say, in one place, here is what an AI system impact assessment is and here is how you run one.

What the standard actually gives you

Strip away the standards language and 42005 is a process. It tells an organization how to decide when an impact assessment is needed, how to scope it, who is responsible for it, how to weigh potential benefits against potential harms to individuals and to society, what to write down, and how to review and approve the result. It covers the timing question directly, so the assessment is not a box you tick at launch but something tied to points across the lifecycle, from initial design through deployment and ongoing monitoring. The output is a documented, defensible record rather than a gut call.

Two things are worth being precise about. First, this is a guidance standard. It gives recommendations and a structure, not a pass-fail bar, and there is no certification body issuing 42005 certificates. Second, it is not a standalone island. It is written to sit inside a broader governance stack, and it explicitly integrates with ISO/IEC 42001, the AI management system standard, and with ISO/IEC 23894 on AI risk management. An annex in 42005 maps how it aligns with 42001, so a firm running a 42001 program can wire the impact assessment straight into the management system it already has.

Why this is the companion to 42001

If you have followed the ISO AI standards at all, you know ISO/IEC 42001 is the headline act. It is the certifiable AI management system standard, the one an organization can be audited and certified against, the one that shows up in RFP requirements. But 42001 tells you to have processes for assessing AI impacts without spelling out, in operational detail, what that assessment looks like. That is the gap 42005 fills. Think of 42001 as the management system that says you must assess impacts, and 42005 as the manual for how to do it. One is the certifiable frame, the other is the operational content that lives inside it.

For a firm building an AI governance program, that pairing is the practical takeaway. You do not have to argue from first principles about what your impact assessment should contain or defend a homegrown template. You can adopt a named international standard, align it to your 42001 work, and hand auditors, clients, and regulators a recognizable reference instead of a bespoke document they have never seen.

Where it touches the EU AI Act

Be careful with this one, because it is easy to overstate. ISO/IEC 42005 is not an EU instrument and conforming to it does not, by itself, satisfy any legal obligation. But the connection is real. The EU AI Act pushes certain deployers toward impact-style assessments, including the fundamental rights impact assessment (FRIA) that Article 27 requires of some high-risk deployers, and impact assessments are increasingly expected under emerging AI regulation generally. A standard that structures how you document AI impacts is a natural scaffold for that work. It does not replace the legal FRIA analysis, and no one should tell a client that a 42005 assessment discharges an Article 27 duty. What it does is give the compliance team a disciplined, repeatable method to build the underlying record that regulatory assessments draw on.

Why a US professional should care

There is no US mandate here, so the honest framing is that 42005 is a tool, not a rule. But it is a tool that solves a recurring headache. If you advise companies deploying AI, you have seen the moment where a client, a customer, or a regulator asks for the AI impact assessment and everyone in the room realizes there is no agreed format. Now there is a shared answer. For a general counsel or a compliance lead, adopting 42005 turns "we assessed the risks" into a documented process with defined triggers, ownership, thresholds, and sign-off, which is exactly the kind of record that holds up when someone later asks what you did and when.

The concrete moves are straightforward. If a client is already pursuing ISO/IEC 42001, fold 42005 in as the impact-assessment methodology and use the annex mapping so the two fit together rather than duplicating effort. If a client is not doing 42001 but keeps getting asked for impact assessments in contracts or procurement, 42005 gives you a standalone framework you can name and adopt. And when you draft or review vendor terms, watch for conformance to these standards showing up as a contractual ask, because that is the channel through which a voluntary standard starts to bind in practice. None of this is required by law. All of it is a way to give a fuzzy expectation a real spine.

Questions professionals are asking

What is ISO/IEC 42005?

It is the first international standard dedicated to AI system impact assessments, published in 2025 by ISO and IEC. It gives organizations a structured method for assessing and documenting how an AI system, and its foreseeable applications, can affect individuals, groups, and society across the lifecycle, from design and development through deployment and monitoring.

Is ISO 42005 mandatory, and can you get certified to it?

No on both counts. It is voluntary guidance, not a law or regulation, and unlike ISO/IEC 42001 it is not a certifiable management-system standard, so there is no audit or certificate against 42005 itself. Its practical force comes from clients, procurement, and counsel choosing to require or adopt it.

How does it relate to ISO 42001?

ISO/IEC 42001 is the certifiable AI management system standard that requires you to assess AI impacts; ISO/IEC 42005 is the operational guidance for how to actually run and document those assessments. An annex in 42005 maps its alignment with 42001, so a firm running a 42001 program can integrate the impact assessment directly into the management system.

Does conforming to ISO 42005 satisfy the EU AI Act?

No. Conforming to 42005 does not by itself discharge any legal obligation, including the Article 27 fundamental rights impact assessment (FRIA) for certain high-risk deployers. It is a useful, disciplined scaffold for the impact-assessment record that the EU AI Act and other emerging rules increasingly expect, but the legal analysis still has to be done on its own terms.

Why should a US firm adopt a voluntary international standard?

Because it solves a recurring problem: clients, regulators, and boards ask for an AI impact assessment, and there has been no agreed definition of what one contains. ISO 42005 gives you a named framework with defined triggers, ownership, thresholds, documentation, and sign-off, which is far more defensible than a homegrown template when someone later asks what you assessed and when.

RELATED BRIEFINGS

Browse the full AI Regulation News tracker

Informational analysis for working professionals, not legal advice. ISO/IEC 42005:2025 is a voluntary international standard; adopting it does not by itself satisfy any legal or regulatory obligation. Confirm how any standard or regulation applies to your situation with qualified counsel.