6.3 Controls A.4 (Resources) & A.5 (AI Impact Assessment)

Key Takeaways

  • A.4 controls run from A.4.2 resource documentation through A.4.6 human resources.

  • A.4 documents relevant resources; it does not universally require GPUs, named MLOps products, or environmental telemetry.

  • A.5 has four controls: process, documentation, individual/group impacts, and societal impacts.

  • A.5.5 addresses societal impacts; there is no separate Annex A.5 environmental-impact control.

  • Clause 6.1.4 and 8.4 remain mandatory AIMS requirements even when individual Annex A controls are selected through the SoA.

Last updated: October 2026

Annex A.4 and A.5: resources and impact controls

A.4 ensures the organization accounts for resources needed across AI activities. A.5 ensures potential impacts on individuals, groups, and societies are assessed throughout the lifecycle. Both groups are commonly miscounted and shifted by one control number.

A.4 Resources for AI systems

The objective is to account for resources, including system components and assets, so risks and impacts can be understood and addressed.

A.4.2 Resource documentation

The organization identifies and documents relevant resources required for activities at AI lifecycle stages and other relevant AI activities.

This is the umbrella control. A useful inventory can connect resources to system, lifecycle stage, owner, version, dependency, criticality, and risk. It is not a “general budget” control numbered A.4.1; A.4.1 is the objective row.

A.4.3 Data resources

As part of resource identification, the organization documents information about data resources used for the AI system.

Information can include source, purpose, ownership, access, relevant characteristics, constraints, and lifecycle associations. Detailed data management controls appear in A.7.

A.4.4 Tooling resources

The organization documents information about tooling resources used for the AI system. Tools can support data preparation, development, testing, deployment, monitoring, logging, or documentation.

PyTorch, model registries, fairness libraries, and labeling platforms are examples. The control does not mandate named products or require specialized machine-learning tooling when it is not relevant.

A.4.5 System and computing resources

The organization documents information about system and computing resources used for the AI system. This can include hardware, cloud services, storage, networks, interfaces, platforms, and dependencies.

GPUs and auto-scaling can matter for some systems; they are not universal requirements. Reliability, capacity, security, location, energy, and supplier dependence can be relevant attributes depending on context.

A.4.6 Human resources

The organization documents information about human resources and competencies used for development, deployment, operation, change management, maintenance, transfer, decommissioning, verification, and integration.

This complements Clause 7.2 competence. It helps identify where expertise or authority is needed across the lifecycle.

A.5 Assessing impacts of AI systems

The objective is to assess impacts on individuals or groups of individuals, or both, and societies affected throughout the lifecycle.

A.5.2 AI system impact-assessment process

The organization establishes a process to assess potential consequences for individuals, groups, and societies throughout the lifecycle.

This control supports Clause 6.1.4. A defined process can address scope, roles, criteria, evidence, affected parties, review triggers, reporting, and use of results. No single numerical method is prescribed.

A.5.3 Documentation of impact assessments

The organization documents results and retains them for a defined period.

The organization should determine retention based on needs and requirements. The control does not impose one number of years. Useful records can include system/version, context, affected parties, findings, evidence, decisions, and review date.

A.5.4 Impacts on individuals or groups

The organization assesses and documents potential impacts on individuals or groups throughout the system lifecycle.

Examples include safety, health, privacy, autonomy, accessibility, discrimination, financial consequences, employment, education, or access to services. Relevant groups may require particular attention because aggregate results can conceal unequal burdens.

A.5.5 Societal impacts

The organization assesses and documents potential societal impacts throughout the lifecycle.

Societal effects can concern democratic processes, information ecosystems, labor patterns, public trust, cultural conditions, critical services, economic concentration, or environmental consequences at scale. Environment can therefore be relevant, but it is not a separate fourth recipient category in Clause 6.1.4 or a fifth A.5 control.

Relationship to mandatory clauses

Annex A controls are selected through risk treatment, but Clauses 6.1.4 and 8.4 are mandatory requirements for an AIMS. An organization cannot simply exclude A.5 controls and thereby erase the clause-level duty to define and perform impact assessment.

The controls deepen implementation:

RequirementRelated A.5 control
Define impact processA.5.2
Document resultA.5.3
Assess people and groupsA.5.4
Assess societal impactsA.5.5

Risk assessment versus impact assessment

Do not reduce Clause 6.1.2 to “financial risk to the organization.” Risk is the effect of uncertainty on objectives, and objectives can concern responsible AI. A.5 supplies focused impact evidence. Clause 6.1.4 then requires those results to be considered in risk assessment.

Example

A municipality considers an AI system for benefit-fraud prioritization. A.4 documentation identifies datasets, vendor tools, cloud resources, caseworkers, and integration dependencies. A.5 assessment considers false positives for individuals, patterns across disability or language groups, and societal effects such as trust in public services. Controls and objectives are then selected based on the combined evidence.

A prescribed “disparate impact ratio,” GPU cluster, stakeholder panel, or executive signature might be useful in a particular context but is not an automatic requirement of A.4 or A.5.

Accurate numbering

  • A.4.2 resource documentation
  • A.4.3 data resources
  • A.4.4 tooling resources
  • A.4.5 system and computing resources
  • A.4.6 human resources
  • A.5.2 process
  • A.5.3 documentation
  • A.5.4 individual/group impact
  • A.5.5 societal impact

Tip

If a question offers “A.5.1 impact process” or says A.5 has only three controls, the numbering is wrong.

Test Your Knowledge

What is A.4.2?

A

Data quality

B

Supplier allocation

C

Human oversight

D

Resource documentation

Test Your Knowledge

Which A.5 control specifically addresses societal impacts?

A

A.5.5

B

A.5.3

C

A.5.4

D

A.5.2

Test Your Knowledge

How many controls are in A.5?

A

Three

B

Four

C

Five

D

Nine

Sections you finish are checked off in the contents.