7.4 A.5 Assessing Impacts of AI Systems
Key Takeaways
- A.5 provides four controls: impact assessment process (A.5.2), documentation of assessments (A.5.3), impacts on individuals or groups (A.5.4), and societal impacts (A.5.5).
- Clause 6.1.4 requires AI system impact assessment as a management-system planning requirement; A.5 supplies reference controls that operationalize assessing and documenting impacts on people and society.
- Impact assessment focuses on effects on individuals, groups, and society (and related external consequences), which is complementary to—not identical with—enterprise AI risk assessment under Clause 6.1.2.
- Auditors evaluate process completeness, documentation quality, coverage of individual/group and societal dimensions, and lifecycle timing (before deployment and after material change).
- Typical NCs: no process; template never completed for high-impact systems; assessments only internal brand risk; one-time go-live assessment never updated after major model or use-context change.
7.4 A.5 Assessing Impacts of AI Systems
Auditor focus: A.5 is where ISO/IEC 42001 most clearly differs from a pure information-security standard. You are checking whether the organization systematically assesses who can be harmed or affected—individuals, groups, and society—and whether that work is documented and refreshed across the AI life cycle.
Control objective (intent): Identify and assess potential consequences of AI systems for individuals, groups, and society so that impacts can be addressed through the AIMS.
A.5 Control Map
| Control | Name | Auditor essence |
|---|---|---|
| A.5.2 | AI system impact assessment process | Defined, repeatable process for performing assessments |
| A.5.3 | Documentation of AI system impact assessments | Results retained as documented information |
| A.5.4 | Assessing impact on individuals or groups of individuals | Explicit analysis of effects on people/groups |
| A.5.5 | Assessing societal impacts of AI systems | Explicit analysis of broader societal effects |
Linkage to Clause 6.1.4
Clause 6.1.4 requires the organization to assess the potential consequences of AI systems for individuals and societies (AI system impact assessment) as part of planning. Annex A.5 provides the detailed control set for process, documentation, and the individual/group vs societal dimensions.
| Element | Clause 6.1.4 (planning requirement) | Annex A.5 (controls) |
|---|---|---|
| Mandate to assess impacts | Management system shall perform AISIA as specified | A.5.2–A.5.5 structure how |
| Scope of effects | Individuals and societies (and related consequences per the clause text) | A.5.4 people/groups; A.5.5 society |
| Records | Documented information as required by the clause | A.5.3 documentation control |
| Audit citation | Use when planning process missing at AIMS level | Use when control design/implementation of impact assessment fails |
In practice, Stage 1/2 findings often cite 6.1.4 and A.5 together when no credible impact assessments exist for in-scope high-impact systems.
Impact assessment vs risk assessment
| AI risk assessment (6.1.2 family) | AI system impact assessment (6.1.4 / A.5) | |
|---|---|---|
| Primary focus | Risks to organizational objectives (operations, finance, compliance, reputation, security of the org) | Effects on external parties—individuals, groups, society |
| Example | Model outage causes revenue loss | Model bias denies credit to a protected group |
| Example | IP leakage of model weights | Mass profiling chills free expression |
| Relationship | Inputs treatment and SoA | Inputs treatment, controls, human oversight, transparency |
Trap: A risk register that only lists “regulatory fine” and “brand damage” without analyzing harms to affected persons is not a complete impact assessment—even if enterprise risk scores are sophisticated.
A.5.2 — Impact Assessment Process
Expect a defined process covering at least:
- Triggers — new system, new intended use, major model/data/context change, periodic review, incident-driven reassessment
- Roles — who drafts, who reviews, who accepts residual impact
- Method — steps to identify stakeholders, impacts, severity/likelihood or qualitative scales, mitigations
- Inputs — system description, intended use, reasonably foreseeable misuse, data categories, automation level, human oversight design
- Outputs — decisions feeding risk treatment, design controls, deployment gates, monitoring
- Integration — link to SoA, life-cycle gates (A.6), transparency (A.8), use controls (A.9)
Interview probes:
- When is an assessment mandatory before production?
- Who can waive an assessment, and is waiver allowed for high-impact systems?
- How is “significant change” defined for re-assessment?
Weak process signs: one-page “ethics checklist” with yes/no boxes and no stakeholder analysis; process owned solely by marketing; no deployment gate dependency.
A.5.3 — Documentation
Documented impact assessments should be retrievable, complete enough to reconstruct reasoning, and controlled.
Typical content auditors look for (scaled to risk):
| Content element | Why it matters |
|---|---|
| System identity & version / date | Traceability to deployed model |
| Intended purpose & users | Bounds analysis |
| Affected individuals/groups | A.5.4 completeness |
| Societal considerations | A.5.5 completeness |
| Positive and adverse impacts | Balanced analysis |
| Foreseeable misuse | Abuse cases |
| Measures to address impacts | Link to treatment |
| Residual concerns & acceptance | Accountability |
| Approvals | Authority |
NC example: Process document exists (A.5.2 appears designed) but zero completed assessments for three production high-impact systems → A.5.3 / 6.1.4 implementation failure.
A.5.4 — Individuals or Groups of Individuals
Assess impacts on people, including groups who may be differentially affected:
| Impact theme | Examples |
|---|---|
| Rights & dignity | Privacy intrusion, unjust automated decisions, lack of contestability |
| Discrimination / fairness | Disparate error rates across demographic groups |
| Safety & wellbeing | Incorrect medical triage, unsafe recommendations |
| Economic | Unfair denial of jobs, credit, insurance |
| Vulnerable groups | Children, elderly, disabled users, marginalized communities |
Sampling: For a hiring model, expect analysis of candidates as affected individuals, subgroup performance considerations, and human review pathways—not only “improves HR efficiency.”
A.5.5 — Societal Impacts
Societal lens looks beyond single-transaction harm:
| Theme | Examples |
|---|---|
| Labor & economy | Large-scale workforce displacement patterns |
| Public discourse | Amplification of misinformation via generative systems |
| Environment | Material energy/water impacts of large-scale training where relevant to context |
| Public services & trust | Erosion of trust in institutions from opaque public-sector AI |
| Collective rights | Community-level surveillance effects |
Not every system has dramatic societal effects—but the assessment should consider the dimension and document why effects are limited when that is the conclusion. Blank silence on society for a city-wide camera analytics platform is a red flag.
Lifecycle Timing and Completeness Evaluation
Lead auditors test when assessments occur relative to decisions that can harm people:
| Lifecycle point | Expectation |
|---|---|
| Concept / design | Early impact framing informs requirements |
| Pre-deployment | Completed assessment before high-impact go-live |
| Material change | Re-assessment after major model, data, or use-context change |
| Periodic | Planned refresh for long-lived high-impact systems |
| Post-incident | Update after harms or near-misses |
Completeness scorecard:
- Process defined and known (A.5.2)?
- Records exist for sampled systems (A.5.3)?
- Individual/group analysis substantive (A.5.4)?
- Societal analysis considered (A.5.5)?
- Timing correct relative to deployment/change?
- Outputs visible in treatment, monitoring, and oversight design?
- Alignment with Clause 6.1.2 risks without collapsing into pure enterprise risk?
Scenario — InsurTech claims automation
System auto-denies low-value claims with optional human appeal. Impact assessment from two years ago covers “customer satisfaction” only. Model and fraud features changed three times; denial rates rose for a regional language minority. No re-assessment. Findings: A.5.2 trigger failure; A.5.3 stale/incomplete docs; A.5.4 inadequate group analysis; possible 6.1.4 and monitoring (9.1) gaps.
Scenario — Internal code assistant
Low external individual impact if scoped to internal developers with IP controls. Assessment may be lighter but should still exist if the AIMS/SoA applies A.5; document limited external impact with rationale. Do not accept “internal = never assess” if the tool can leak personal data or generate unsafe operational scripts affecting third parties.
Evidence Pack and NC Patterns
| Evidence / NC pattern | Notes |
|---|---|
| Procedure + completed AISIA reports | A.5.2 design; A.5.3–A.5.5 substance |
| Deployment gates & change-linked re-assessment | Lifecycle timing |
| Treatment/SoA/management-review linkage | Process effectiveness |
| No process / no records | 6.1.4 + A.5.2 / A.5.3 |
| Only enterprise risk language | A.5.4/A.5.5 substance missing |
| One-time ethics essay; blanket product waivers | Timing and integrity failures |
Bottom line: A.5 forces the organization to look outward at human and societal consequences, document that look, and repeat it when systems change. With A.2–A.5, governance policy, organization, resources, and impact foundations are in place for the life-cycle and data controls that follow.
Which statement best distinguishes Clause 6.1.4 AI system impact assessment from typical enterprise AI risk assessment?
Which set lists the four Annex A.5 controls?
A high-impact lending model was impact-assessed at initial launch. Eighteen months later the model architecture, training data mix, and geographic market all changed, but no re-assessment was performed. Which evaluation best fits A.5?
What documentation package best supports A.5.3 for a high-risk public-sector benefits eligibility AI system?