
ISO/IEC 42005
ISO/IEC 42005 AI system impact assessment support
ISO/IEC 42005 consulting helps businesses assess how AI affects individuals, groups and society. Vosurein starts with the intended use and the people affected, then documents possible consequences, information gaps and responses to support deployment and change decisions.
For Your Business
Who this service is for and when to start
For businesses whose AI affects staff, customers or external groups, or that need documented impact assessments. Before introducing a new use, extending the user base or making major functional changes, identify who could be affected and set an appropriate assessment depth.
The Challenge
Common challenges faced by businesses
Focusing only on enterprise efficiency and costs may overlook how usage results affect others. People who do not directly operate AI may also be affected by decisions or content.
Abstract statements about fairness and transparency are not enough. An assessment needs specific scenarios, evidence and responsibility for responses to support decisions about deployment and restrictions.
Our Approach
Methods and applicable requirements
ISO/IEC 42005:2025 provides guidance for AI system impact assessments, covering the effects of systems and foreseeable applications on individuals, groups, and society. Assessments can support governance and risk management but do not automatically replace specific legal or personal data impact assessments.
The priorities below depend on the organisation’s context. Confirm the scope and level of supporting evidence at the start.
Scope of Assessment
Confirm system uses, lifecycle, and foreseeable applications, identify directly and indirectly affected parties, and avoid setting the scope solely from the development team’s perspective.
Impact Identification
Document positive and negative impacts and the conditions in which they may occur. Separate evidence from assumptions that still need checking, and seek appropriate feedback where needed.
Response and Decision Making
Link significant impacts to measures, restrictions, and responsible parties, so that approvers know which issues have been addressed and which remain unresolved.
Reassessment and Record Keeping
Record the assessment scope, judgements and reasons for decisions. Arrange reviews when uses, affected groups or functions change so the report remains useful after deployment.
Process
Consulting scope and process
Define uses and affected groups
Confirm purposes, usage processes, and affected parties with business and technical personnel.
Organize Impact Evidence
Through scenario discussions and existing data, identify potential impacts, information gaps, and matters requiring further confirmation.
Formulate Response Plans
Help departments propose measures, restrictions and information for decisions, then arrange review by the appropriate people.
Set up reassessment
Confirm tracking data and change triggers so that the assessment continues to update as the application develops.
Preparation
What documents do companies need to prepare?
- Systems and Uses: Functions, usage processes, and expected applications.
- Affected Parties: Users and other potentially impacted groups.
- Assessment Basis: Test, feedback, known limitations, and impact data.
- Decisions and measures: Control, approval, changes, and tracking records.
An index or summary is enough for an initial discussion. Before sharing personal data, confidential contract information or system records, agree on access authorisation, redaction and retention.
Project Planning
Estimating time and cost
Evaluate based on AI usage, affected scope, evidence availability, and participation method. Professional testing, external interviews, or specific legal assessments should be arranged separately when needed, and general reports should not be considered as covering all usage scenarios.
FAQ
Frequently asked questions
Should the assessment cover only users?
No. It should also consider people or groups who could be indirectly affected by system outputs, with the scope defined for the actual use.
Is it the same as general AI risk assessment?
The two are related, but this assessment focuses on impacts on people and society. Business losses and technical failures alone do not capture these impacts.
Can it replace personal data impact assessment?
It cannot directly replace it. Data and legal purposes are different; related data can be shared, but applicable requirements need separate confirmation.
Do interviews need to be conducted with everyone?
Not necessarily. Choose participation methods according to the impacts and information needed, and explain any gaps in coverage.
Can it guarantee no negative impacts after implementation?
No. Assessment helps identify and address impacts, but uncertainty about data and future uses still requires monitoring.
Is re-evaluation needed even if the model has not changed?
Possibly. Changes in usage, target users, or processes, even if the model is the same, may result in different impacts.
Related
Related services and enquiries
Tell us your industry, the activities you want to improve, your existing system and your target completion date so we can define the scope together.
Content checked: . Applicable versions and requirements depend on the company’s circumstances.
Let's Talk
Start a conversation about your needs.
Tell us how the work is done today and when you hope to finish,
so we can agree the scope and way of working together.
Blog
Sustainability and AI insights
Start with understanding,
and see where change can lead.

