3.6 AI System Impact Assessment (Clause 6.1.4 & Annex A.5)

Key Takeaways

  • ISO/IEC 42001 Clause 6.1.4 mandates that organizations conduct AI System Impact Assessments to evaluate potential adverse effects on individuals, groups, society, and the environment.
  • Impact assessments differ fundamentally from risk assessments by focusing on external stakeholder impacts rather than internal enterprise risk.
  • Clause 6.1.4 aligns directly with mandatory Fundamental Rights Impact Assessments (FRIA) under EU AI Act Article 27.
  • Re-assessments are strictly required whenever there are significant modifications to model architecture, training data distribution, or operational deployment context.
Last updated: July 2026

3.6 AI System Impact Assessment (Clause 6.1.4 & Annex A.5)

One of the most defining innovations of ISO/IEC 42001 is Clause 6.1.4, which mandates that organizations perform an AI System Impact Assessment (AISIA). While traditional management standards focus almost exclusively on internal risks to the business, ISO/IEC 42001 requires organizations to systematically evaluate how their AI systems affect external stakeholders, individuals, vulnerable populations, society at large, and the environment. This requirement aligns directly with control objectives in Annex A.5 (AI System Life Cycle).


Distinguishing Risk Assessment from Impact Assessment

Understanding the fundamental distinction between Clause 6.1.2 (Risk Assessment) and Clause 6.1.4 (Impact Assessment) is essential for AIMS implementers:

  • AI Risk Assessment (Clause 6.1.2): Focuses primarily on threats to the organization's objectives (e.g., operational failure, financial loss, regulatory penalties, IP leakage, reputational damage).
  • AI System Impact Assessment (Clause 6.1.4): Focuses explicitly on potential harm to external entities (e.g., individuals denied credit due to bias, workers displaced by automation, environmental degradation from massive compute workloads, erosion of civil liberties).
+-----------------------------------------------------------------------+
|                   CLAUSE 6.1.2 vs CLAUSE 6.1.4 FOCUS                  |
|                                                                       |
|   +--------------------------+       +----------------------------+   |
|   |   Clause 6.1.2 Risk      |       |  Clause 6.1.4 Impact       |   |
|   |   (Internal Enterprise)  |       |  (External Stakeholders)   |   |
|   |  - Revenue Loss          |       |  - Human Rights Violations |   |
|   |  - Regulatory Fines      |       |  - Algorithmic Bias        |   |
|   |  - IP Leakage            |       |  - Physical Safety Hazards |   |
|   |  - System Downtime       |       |  - Environmental Carbon    |   |
|   +--------------------------+       +----------------------------+   |
+-----------------------------------------------------------------------+

Fundamental Rights Impact Assessment (FRIA) & EU AI Act Alignment

Clause 6.1.4 creates direct alignment with emerging international regulations, most notably Article 27 of the European Union AI Act, which mandates a Fundamental Rights Impact Assessment (FRIA) for deployers of high-risk AI systems. An ISO/IEC 42001 AISIA satisfies FRIA requirements by systematically evaluating:

  • Impact on fundamental rights protected under international charters (privacy, non-discrimination, freedom of expression).
  • Specific categories of persons or groups likely to be affected (e.g., job applicants, loan borrowers, patients).
  • Specific human oversight measures deployed to prevent automated harm.
  • Verification of post-deployment monitoring mechanisms.

Core Impact Assessment Dimensions

An ISO/IEC 42001 compliant impact assessment must evaluate potential effects across four primary dimensions:

1. Human Rights & Civil Liberties

Evaluating potential infringements on personal privacy, freedom of expression, human dignity, and protection against automated profiling or mass surveillance. For example, deploying facial recognition in public spaces requires rigorous evaluation under this dimension.

2. Algorithmic Equity & Non-Discrimination

Assessing whether model predictions disproportionately penalize protected demographic groups (e.g., bias in hiring algorithms, tenant screening tools, or loan approval models). Assessments must verify data representativeness and test for disparate impact.

3. Health, Safety & Physical/Psychological Wellbeing

Evaluating physical safety hazards (e.g., AI-driven autonomous robotics, medical diagnostic software) and psychological impacts (e.g., addictive social media recommendation algorithms or conversational AI inducing emotional distress).

4. Environmental & Ecological Sustainability

Quantifying compute energy usage, carbon emissions, and resource consumption associated with training and hosting large-scale AI models under Annex A.5 controls.


End-to-End AISIA Execution Workflow

Impact assessments must not be treated as a single static checkmark. They must be executed dynamically across five key workflow steps:

Assessment StepKey Operational ActivitiesDeliverables & Artifacts
Step 1: System ProfilingDefine AI system purpose, intended users, deployment context, and underlying model technology.AI System Profile Document.
Step 2: Stakeholder IdentificationMap affected populations, including end-users, subject individuals, and vulnerable demographic groups.Stakeholder Impact Map.
Step 3: Impact AnalysisIdentify potential adverse outcomes across human rights, fairness, safety, and environmental dimensions.Impact Hazard Matrix.
Step 4: Control Mapping & MitigationSelect Annex A controls (e.g., A.6 data sanitization, A.7 transparency, A.8 human oversight) to mitigate harm.Impact Mitigation Plan.
Step 5: Sign-Off & Lifecycle TriggersObtain formal approval from AI Ethics Board; schedule re-assessments upon model retraining or context shift.Approved AISIA Report.

Mandatory Triggers for Impact Re-Assessment

Clause 6.1.4 explicitly mandates that impact assessments be kept up to date. Re-assessments are strictly required whenever any of the following triggers occur:

  1. Model Architecture Updates: Transitioning from a domain-specific model to a multi-modal foundation model or altering hyperparameter weightings.
  2. Training Data Distribution Shifts: Ingesting new dataset sources or retraining models on significantly altered demographic distributions.
  3. Operational Context Change: Deploying an internal decision-support model directly into a customer-facing automated execution channel.
  4. Discovery of Incidents or Anomalies: Uncovering algorithmic bias, unexpected hallucination rates, or safety near-misses in production.

Worked Implementation Scenario: HR Recruitment AI Impact Assessment

Context: An enterprise enterprise deploys an automated resume screening algorithm to rank job applicants.

Execution Steps:

  1. Stakeholder Mapping: The team identifies job applicants—specifically protected demographic groups—as affected stakeholders.
  2. Impact Identification: The AISIA reveals a severe risk of gender bias because historical hiring data used for training contained 80% male resumes.
  3. Mitigation Mapping: The team implements Annex A.6 controls (re-balancing dataset, masking gender indicators) and Annex A.8 controls (requiring HR recruiters to manually review all rejected resumes).
  4. Sign-Off: The AI Ethics Board approves the AISIA, establishing a quarterly re-assessment schedule.

Lead Implementer Exam Tips

  • Internal vs External Focus: Master the distinction: Clause 6.1.2 = Internal enterprise risk; Clause 6.1.4 = External stakeholder impact.
  • Environmental Inclusion: Remember that environmental sustainability (carbon emissions, energy compute tracking) is explicitly included within Clause 6.1.4 impact assessments under Annex A.5.
  • FRIA Alignment: Understand that an AISIA under Clause 6.1.4 directly satisfies EU AI Act Article 27 FRIA requirements.
Test Your Knowledge

What is a fundamental distinction between an AI Risk Assessment (Clause 6.1.2) and an AI System Impact Assessment (Clause 6.1.4)?

A
B
C
D
Test Your Knowledge

How does ISO/IEC 42001 Clause 6.1.4 align with regulatory requirements under Article 27 of the EU AI Act?

A
B
C
D
Test Your Knowledge

Under ISO/IEC 42001 Clause 6.1.4 and Annex A.5, how are environmental impacts incorporated into the AI System Impact Assessment?

A
B
C
D
Test Your Knowledge

Which event MUST trigger a re-assessment of an AI system's impact under Clause 6.1.4?

A
B
C
D