3.6 AI System Impact Assessment (Clause 6.1.4 & Annex A.5)
Key Takeaways
- ISO/IEC 42001 Clause 6.1.4 mandates that organizations conduct AI System Impact Assessments to evaluate potential adverse effects on individuals, groups, society, and the environment.
- Impact assessments differ fundamentally from risk assessments by focusing on external stakeholder impacts rather than internal enterprise risk.
- Clause 6.1.4 aligns directly with mandatory Fundamental Rights Impact Assessments (FRIA) under EU AI Act Article 27.
- Re-assessments are strictly required whenever there are significant modifications to model architecture, training data distribution, or operational deployment context.
3.6 AI System Impact Assessment (Clause 6.1.4 & Annex A.5)
One of the most defining innovations of ISO/IEC 42001 is Clause 6.1.4, which mandates that organizations perform an AI System Impact Assessment (AISIA). While traditional management standards focus almost exclusively on internal risks to the business, ISO/IEC 42001 requires organizations to systematically evaluate how their AI systems affect external stakeholders, individuals, vulnerable populations, society at large, and the environment. This requirement aligns directly with control objectives in Annex A.5 (AI System Life Cycle).
Distinguishing Risk Assessment from Impact Assessment
Understanding the fundamental distinction between Clause 6.1.2 (Risk Assessment) and Clause 6.1.4 (Impact Assessment) is essential for AIMS implementers:
- AI Risk Assessment (Clause 6.1.2): Focuses primarily on threats to the organization's objectives (e.g., operational failure, financial loss, regulatory penalties, IP leakage, reputational damage).
- AI System Impact Assessment (Clause 6.1.4): Focuses explicitly on potential harm to external entities (e.g., individuals denied credit due to bias, workers displaced by automation, environmental degradation from massive compute workloads, erosion of civil liberties).
+-----------------------------------------------------------------------+
| CLAUSE 6.1.2 vs CLAUSE 6.1.4 FOCUS |
| |
| +--------------------------+ +----------------------------+ |
| | Clause 6.1.2 Risk | | Clause 6.1.4 Impact | |
| | (Internal Enterprise) | | (External Stakeholders) | |
| | - Revenue Loss | | - Human Rights Violations | |
| | - Regulatory Fines | | - Algorithmic Bias | |
| | - IP Leakage | | - Physical Safety Hazards | |
| | - System Downtime | | - Environmental Carbon | |
| +--------------------------+ +----------------------------+ |
+-----------------------------------------------------------------------+
Fundamental Rights Impact Assessment (FRIA) & EU AI Act Alignment
Clause 6.1.4 creates direct alignment with emerging international regulations, most notably Article 27 of the European Union AI Act, which mandates a Fundamental Rights Impact Assessment (FRIA) for deployers of high-risk AI systems. An ISO/IEC 42001 AISIA satisfies FRIA requirements by systematically evaluating:
- Impact on fundamental rights protected under international charters (privacy, non-discrimination, freedom of expression).
- Specific categories of persons or groups likely to be affected (e.g., job applicants, loan borrowers, patients).
- Specific human oversight measures deployed to prevent automated harm.
- Verification of post-deployment monitoring mechanisms.
Core Impact Assessment Dimensions
An ISO/IEC 42001 compliant impact assessment must evaluate potential effects across four primary dimensions:
1. Human Rights & Civil Liberties
Evaluating potential infringements on personal privacy, freedom of expression, human dignity, and protection against automated profiling or mass surveillance. For example, deploying facial recognition in public spaces requires rigorous evaluation under this dimension.
2. Algorithmic Equity & Non-Discrimination
Assessing whether model predictions disproportionately penalize protected demographic groups (e.g., bias in hiring algorithms, tenant screening tools, or loan approval models). Assessments must verify data representativeness and test for disparate impact.
3. Health, Safety & Physical/Psychological Wellbeing
Evaluating physical safety hazards (e.g., AI-driven autonomous robotics, medical diagnostic software) and psychological impacts (e.g., addictive social media recommendation algorithms or conversational AI inducing emotional distress).
4. Environmental & Ecological Sustainability
Quantifying compute energy usage, carbon emissions, and resource consumption associated with training and hosting large-scale AI models under Annex A.5 controls.
End-to-End AISIA Execution Workflow
Impact assessments must not be treated as a single static checkmark. They must be executed dynamically across five key workflow steps:
| Assessment Step | Key Operational Activities | Deliverables & Artifacts |
|---|---|---|
| Step 1: System Profiling | Define AI system purpose, intended users, deployment context, and underlying model technology. | AI System Profile Document. |
| Step 2: Stakeholder Identification | Map affected populations, including end-users, subject individuals, and vulnerable demographic groups. | Stakeholder Impact Map. |
| Step 3: Impact Analysis | Identify potential adverse outcomes across human rights, fairness, safety, and environmental dimensions. | Impact Hazard Matrix. |
| Step 4: Control Mapping & Mitigation | Select Annex A controls (e.g., A.6 data sanitization, A.7 transparency, A.8 human oversight) to mitigate harm. | Impact Mitigation Plan. |
| Step 5: Sign-Off & Lifecycle Triggers | Obtain formal approval from AI Ethics Board; schedule re-assessments upon model retraining or context shift. | Approved AISIA Report. |
Mandatory Triggers for Impact Re-Assessment
Clause 6.1.4 explicitly mandates that impact assessments be kept up to date. Re-assessments are strictly required whenever any of the following triggers occur:
- Model Architecture Updates: Transitioning from a domain-specific model to a multi-modal foundation model or altering hyperparameter weightings.
- Training Data Distribution Shifts: Ingesting new dataset sources or retraining models on significantly altered demographic distributions.
- Operational Context Change: Deploying an internal decision-support model directly into a customer-facing automated execution channel.
- Discovery of Incidents or Anomalies: Uncovering algorithmic bias, unexpected hallucination rates, or safety near-misses in production.
Worked Implementation Scenario: HR Recruitment AI Impact Assessment
Context: An enterprise enterprise deploys an automated resume screening algorithm to rank job applicants.
Execution Steps:
- Stakeholder Mapping: The team identifies job applicants—specifically protected demographic groups—as affected stakeholders.
- Impact Identification: The AISIA reveals a severe risk of gender bias because historical hiring data used for training contained 80% male resumes.
- Mitigation Mapping: The team implements Annex A.6 controls (re-balancing dataset, masking gender indicators) and Annex A.8 controls (requiring HR recruiters to manually review all rejected resumes).
- Sign-Off: The AI Ethics Board approves the AISIA, establishing a quarterly re-assessment schedule.
Lead Implementer Exam Tips
- Internal vs External Focus: Master the distinction: Clause 6.1.2 = Internal enterprise risk; Clause 6.1.4 = External stakeholder impact.
- Environmental Inclusion: Remember that environmental sustainability (carbon emissions, energy compute tracking) is explicitly included within Clause 6.1.4 impact assessments under Annex A.5.
- FRIA Alignment: Understand that an AISIA under Clause 6.1.4 directly satisfies EU AI Act Article 27 FRIA requirements.
What is a fundamental distinction between an AI Risk Assessment (Clause 6.1.2) and an AI System Impact Assessment (Clause 6.1.4)?
How does ISO/IEC 42001 Clause 6.1.4 align with regulatory requirements under Article 27 of the EU AI Act?
Under ISO/IEC 42001 Clause 6.1.4 and Annex A.5, how are environmental impacts incorporated into the AI System Impact Assessment?
Which event MUST trigger a re-assessment of an AI system's impact under Clause 6.1.4?