Contact us
Illustration for ISO management-system services

ISO/IEC 42005

ISO/IEC 42005 AI system impact assessment support

ISO/IEC 42005 consulting helps businesses assess how AI affects individuals, groups and society. Vosurein starts with the intended use and the people affected, then documents possible consequences, information gaps and responses to support deployment and change decisions.

Discuss ISO/IEC 42005 AI impact assessment consulting

For Your Business

Who this service is for and when to start

For businesses whose AI affects staff, customers or external groups, or that need documented impact assessments. Before introducing a new use, extending the user base or making major functional changes, identify who could be affected and set an appropriate assessment depth.

The Challenge

Common challenges faced by businesses

Focusing only on enterprise efficiency and costs may overlook how usage results affect others. People who do not directly operate AI may also be affected by decisions or content.

Abstract statements about fairness and transparency are not enough. An assessment needs specific scenarios, evidence and responsibility for responses to support decisions about deployment and restrictions.

Our Approach

Methods and applicable requirements

ISO/IEC 42005:2025 provides guidance for AI system impact assessments, covering the effects of systems and foreseeable applications on individuals, groups, and society. Assessments can support governance and risk management but do not automatically replace specific legal or personal data impact assessments.

The priorities below depend on the organisation’s context. Confirm the scope and level of supporting evidence at the start.

Scope of Assessment

Confirm system uses, lifecycle, and foreseeable applications, identify directly and indirectly affected parties, and avoid setting the scope solely from the development team’s perspective.

Impact Identification

Document positive and negative impacts and the conditions in which they may occur. Separate evidence from assumptions that still need checking, and seek appropriate feedback where needed.

Response and Decision Making

Link significant impacts to measures, restrictions, and responsible parties, so that approvers know which issues have been addressed and which remain unresolved.

Reassessment and Record Keeping

Record the assessment scope, judgements and reasons for decisions. Arrange reviews when uses, affected groups or functions change so the report remains useful after deployment.

Process

Consulting scope and process

  1. Define uses and affected groups

    Confirm purposes, usage processes, and affected parties with business and technical personnel.

  2. Organize Impact Evidence

    Through scenario discussions and existing data, identify potential impacts, information gaps, and matters requiring further confirmation.

  3. Formulate Response Plans

    Help departments propose measures, restrictions and information for decisions, then arrange review by the appropriate people.

  4. Set up reassessment

    Confirm tracking data and change triggers so that the assessment continues to update as the application develops.

Preparation

What documents do companies need to prepare?

  • Systems and Uses: Functions, usage processes, and expected applications.
  • Affected Parties: Users and other potentially impacted groups.
  • Assessment Basis: Test, feedback, known limitations, and impact data.
  • Decisions and measures: Control, approval, changes, and tracking records.

An index or summary is enough for an initial discussion. Before sharing personal data, confidential contract information or system records, agree on access authorisation, redaction and retention.

Project Planning

Estimating time and cost

Evaluate based on AI usage, affected scope, evidence availability, and participation method. Professional testing, external interviews, or specific legal assessments should be arranged separately when needed, and general reports should not be considered as covering all usage scenarios.

FAQ

Frequently asked questions

Should the assessment cover only users?

No. It should also consider people or groups who could be indirectly affected by system outputs, with the scope defined for the actual use.

Is it the same as general AI risk assessment?

The two are related, but this assessment focuses on impacts on people and society. Business losses and technical failures alone do not capture these impacts.

Can it replace personal data impact assessment?

It cannot directly replace it. Data and legal purposes are different; related data can be shared, but applicable requirements need separate confirmation.

Do interviews need to be conducted with everyone?

Not necessarily. Choose participation methods according to the impacts and information needed, and explain any gaps in coverage.

Can it guarantee no negative impacts after implementation?

No. Assessment helps identify and address impacts, but uncertainty about data and future uses still requires monitoring.

Is re-evaluation needed even if the model has not changed?

Possibly. Changes in usage, target users, or processes, even if the model is the same, may result in different impacts.

Related

Related services and enquiries

Tell us your industry, the activities you want to improve, your existing system and your target completion date so we can define the scope together.

Content checked: . Applicable versions and requirements depend on the company’s circumstances.

Let's Talk

Start a conversation about your needs.

Tell us how the work is done today and when you hope to finish,
so we can agree the scope and way of working together.

Discuss your service needsBack to ISO management-system contents