4.2 Clause 6.1.4: AI System Impact Assessment
Key Takeaways
Clause 6.1.4 requires a process for potential consequences to individuals, groups of individuals, and societies.
The process considers deployment, intended use, foreseeable misuse, technical and societal context, and applicable jurisdictions.
Results are documented and considered in the Clause 6.1.2 AI risk assessment.
Clause 8.4 performs assessments at planned intervals or when significant changes are proposed and retains all results.
ISO/IEC 42001 does not prescribe one universal method, score, approval committee, or separate environmental category.
Clauses 6.1.4 and 8.4: AI system impact assessment
AI system impact assessment is one of ISO/IEC 42001’s distinctive requirements. It directs attention to consequences beyond technical performance or organizational loss. The organization must understand how an AI system can affect individuals, groups of individuals, and societies in its real context.
What Clause 6.1.4 requires
The organization defines a process for assessing potential consequences that can result from the development, provision, or use of AI systems. The process covers consequences to:
- individuals;
- groups of individuals, or both individuals and groups; and
- societies.
It determines potential consequences of an AI system’s deployment, intended use, and foreseeable misuse. It takes account of the specific technical and societal context in which the system is deployed and the applicable jurisdictions.
The assessment result is documented. Where appropriate, the organization can make the result available to relevant interested parties it has identified. The organization also considers the result in the Clause 6.1.2 AI risk assessment.
This language establishes the minimum process boundary without prescribing one scoring table, report template, committee, or software tool.
What the clause does not say
Avoid several common additions:
- It does not create four mandatory impact categories of “individual, group, society, environment.” Environmental consequences may be relevant societal impacts, organizational objectives, legal requirements, or risk sources, but the clause names individuals, groups, and societies.
- It does not require publication of every assessment. Results may be made available where appropriate.
- It does not require top management to sign every system assessment. The organization should allocate suitable roles and approval authority through its processes.
- It does not prescribe a five-step methodology, numerical matrix, or named stakeholder panel.
Designing an effective process
A useful process usually answers these questions:
- What is being assessed? Define the system, version, components, purpose, boundaries, and organizational role.
- What is the context? Identify users, affected people, geographic and sector setting, technical dependencies, and applicable jurisdictions.
- What uses are in view? Include intended use and reasonably foreseeable misuse, not arbitrary science-fiction possibilities.
- Who can be affected? Consider individuals, relevant groups, and societal institutions or conditions.
- What can happen? Identify positive and negative consequences, their distribution, severity, duration, scale, and reversibility as appropriate.
- What controls exist? Record preventive, detective, corrective, and communication measures and their limitations.
- How will results be used? Feed findings into risk assessment, requirements, control selection, deployment decisions, monitoring, and communication.
Those steps are an implementation pattern. An organization can use another method if it meets the requirements and produces useful, repeatable evidence.
Sources of impact
Potential impacts depend on the system. Examples include:
| Area | Questions to ask |
|---|---|
| Access and fairness | Are benefits, errors, or burdens distributed unjustifiably? |
| Privacy and autonomy | Does the system enable intrusive inference, manipulation, or loss of choice? |
| Safety and health | Can outputs contribute to physical or psychological harm? |
| Livelihood and rights | Can decisions affect employment, credit, education, benefits, or legal interests? |
| Information environment | Can the system amplify deception, misinformation, or loss of trust? |
| Accessibility | Are disabled people or language groups excluded? |
| Society and environment | Can scale affect institutions, labor, resources, or environmental conditions? |
An assessment should also identify benefits and opportunities. Impact assessment is not limited to cataloguing harms, although potential adverse consequences need effective treatment.
Relationship to risk assessment
A false “inward risk versus outward impact” diagram can be too rigid. Clause 6.1.2 assesses risks affecting organizational objectives, and those objectives can include responsible use, legal conformity, fairness, safety, and stakeholder outcomes. Clause 6.1.4 supplies focused evidence about consequences for people and society. The standard explicitly requires the impact result to be considered in risk assessment.
For example, unequal denial rates in a credit model are impacts on applicants and groups. They also create risk to objectives concerning fair service, legal compliance, trust, and model effectiveness. Treatment decisions should reflect both views.
Clause 8.4: performing the assessment
Clause 6.1.4 defines the process; Clause 8.4 operates it. The organization performs AI system impact assessments in accordance with its process:
- at planned intervals; or
- when significant changes are proposed.
It retains documented information on all assessment results.
The standard’s trigger language does not say “continuously,” and it does not list development and procurement as the only triggers. An organization can schedule assessments at lifecycle gates and add event triggers. Examples of potentially significant change include a new intended purpose, user population, jurisdiction, data source, automation level, supplier model, interface, or decision authority. The organization applies its defined significance criteria.
Third-party systems
Using a vendor model does not make impact assessment irrelevant. The organization may lack access to training details, but it controls or influences intended use, integration, users, data supplied, communications, monitoring, and response. Supplier information and testing limitations become inputs to the assessment.
Documented result
A useful result can identify system and version, intended use, context, affected parties, foreseeable misuse, potential consequences, evidence, assumptions, controls, unresolved uncertainty, decisions, and review triggers. Consultation records and residual-impact ratings can be useful when appropriate, but ISO/IEC 42001 does not state that every report must contain one universal set of fields.
Tip
In an exam scenario, “define the process” points to 6.1.4; “perform at planned intervals or significant proposed change” points to 8.4; “assess individuals/groups and society through controls” often points to Annex A.5.
Which set exactly matches the consequence recipients named in Clause 6.1.4?
Individuals, the environment, and certification bodies only
Employees, customers, suppliers, and shareholders
The organization, its competitors, and ISO
Individuals, groups of individuals, and societies
When does Clause 8.4 require operational impact assessments?
At planned intervals or when significant changes are proposed
Only after an incident has caused public harm
Once, when the organization is incorporated
Only when a regulator supplies a template
What must happen to impact-assessment results under Clause 6.1.4?
They must always be published in full
They are documented and considered in the AI risk assessment
They must be sent to ISO for approval
They replace the SoA
Sections you finish are checked off in the contents.