Standard / soft law
AI systems should undergo a documented AI system impact assessment (ISO/IEC 42001)
In our own words: ISO/IEC 42001:2023 distinctively requires an AI system impact assessment — assessing potential consequences of an AI system for individuals, groups of individuals, and society — carried out and maintained within the AI management system (Clause 6 planning + the Annex A impact-assessment control area), rather than only an organizational risk assessment. Detect an AI deployment with no documented impact assessment covering individual, group, and societal effects. [TIER C: own-words summary of PUBLIC scope; licensed normative text not stored.]
Who it applies to
- Duty falls on: developer, deployer
- Systems covered: automated decision, high risk
- Organizations operating an AIMS under ISO/IEC 42001. The AI system impact assessment is a distinguishing requirement vs. generic management-system standards. Voluntary but certifiable.
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Organizational artifact to keep (not verifiable from code); the guard is the record, its owner and its upkeep.
Document an impact assessment for each AI system covering its consequences for individuals, groups, and society, and revisit it when the system changes.
A per-system impact assessment, distinct from the organizational risk register, that looks outward: intended use and context, who is affected (individuals, groups including vulnerable ones, society), foreseeable benefits and harms (rights, safety, fairness, access, wider societal effects), reasonably foreseeable misuse, mitigations, residual impact, and sign-off. The AI system owner maintains it within the AI management system and revisits it before release and on any material change of model, data, or use. Keep it next to the model card and have a release check confirm a current assessment exists for each deployed system.
Where it goes: 12 repository artifacts, 11 CI/CD pipeline.
Example (Impact assessment record (docs/impact/)), before:
# Resume screener
Risk: low. Approved.After:
# AI system impact assessment: resume screener (v3, 2026-09-01)
- Intended use: rank applications for recruiter review; no automatic rejection
- Affected: applicants; groups at risk: career-gap, non-native-language applicants
- Harms: unfair exclusion, opaque ranking; societal: narrowing of hiring pools
- Mitigations: subgroup ranking audit each release; recruiter sees all applicants
- Residual impact: medium, accepted by Head of Talent (signed 2026-09-03)
- Revisit: on model, feature, or use changeControl: AI system deployed without an AI system impact assessment. The same guard addresses 1 item. Engineering guidance, not legal advice.
Rule id iso-42001.ai-system-impact-assessment · review status: tier c citation only