ISO 42005
ISO/IEC 42005 is international guidance on how to conduct an AI system impact assessment — a structured way to document what an AI system is for, who and what it could affect, and the potential benefits and harms it may cause. If you're standing up AI governance and need a repeatable method for assessing impact (for your own management system, or to support the EU AI Act), here's the plain-language version: what it is, how it fits with ISO 42001, what an impact assessment actually covers, who should run it, and how to get ready.
ISO 42005 checklist
A step-by-step AI impact assessment checklist.
Free readiness assessment
See your ISO 42005 gaps in minutes.
Map to other frameworks
How ISO 42005 lines up with ISO 42001, the EU AI Act & NIST AI RMF.
Illustrative statuses. Your real assessment is generated from your answers in the app. Standpoint is a self-assessment aid, not legal advice.
What is ISO 42005?
ISO/IEC 42005 is a guidance document, not a certification. It sets out how an organization can carry out an AI system impact assessment: a structured process for understanding the effects an AI system may have on individuals, groups, and wider society, and for recording that analysis in a way you can act on and defend. Rather than certifying an outcome, it describes a method — what to consider, when to consider it, and what to write down — so impact assessments are consistent and repeatable instead of ad hoc. It was published in 2025 by ISO and IEC as companion guidance to the AI management system standard.
How ISO 42005 fits with ISO 42001, the EU AI Act & NIST AI RMF
ISO 42005 doesn't stand alone — it plugs into the AI-governance work you're already doing. ISO 42001 (the AI management system standard) expects you to assess the impact of your AI systems as part of planning and operation; ISO 42005 operationalizes that expectation, giving you a concrete method to satisfy it. It also supports the EU AI Act, whose obligations for higher-risk AI include risk management and, in some cases, a fundamental-rights impact assessment — a well-run 42005 assessment produces much of the analysis those obligations expect. And it complements the NIST AI RMF (AI Risk Management Framework), where the MAP and MEASURE functions call for exactly this kind of context-setting and impact analysis. Because the underlying analysis overlaps, one solid impact assessment feeds all three.
What an AI system impact assessment covers
In our own words, ISO 42005 describes an assessment that works through the following, and records the reasoning at each step: We describe the elements in our own words and reference clause structure only. For the authoritative guidance text, consult your licensed copy of ISO/IEC 42005:2025.
Who should use ISO 42005?
It's designed for any organization that builds, supplies, or uses AI and needs a defensible way to assess impact — whether you train your own models, embed third-party models in your product, or deploy AI internally. Teams typically reach for it when: - they're implementing ISO 42001 and need a concrete method for the impact assessments it expects; - they face EU AI Act obligations and want structured analysis to support risk management and fundamental-rights impact work; - customers, boards, or regulators are asking how the organization evaluates the effects of its AI on people; - they want i…
A practical path to readiness
- Set your thresholds. Decide which AI systems and changes trigger an impact assessment, and how deep it should go. - Scope the system. Document intended use, context, data, dependencies, and reasonably foreseeable misuse. - Analyze affected parties, harms & benefits. Work through fairness, safety, privacy, transparency, and human oversight. - Record roles & findings. Capture who assessed what, the conclusions, and who reviewed and approved them. - Feed mitigations & monitoring, then reassess when the system or its context materially changes. The fastest start is a gap assessment. Our free ISO 42005 readiness assessment shows where you stand, and the impact assessment checklist turns it into a working plan.
Frequently asked questions
Q: Is ISO 42005 certifiable? A: No. ISO 42005 is guidance on how to conduct an AI system impact assessment — it isn't a certifiable management-system standard. You get certified against ISO 42001; ISO 42005 shows you how to perform one of its key activities well. Q: How is ISO 42005 different from ISO 42001? A: ISO 42001 is the AI management system standard — the overall framework for governing AI responsibly, and it's certifiable. ISO 42005 is focused guidance on a single activity within that system: conducting and documenting AI system impact assessments. In short, 42001 is the system; 4200…
ISO 42005 work counts elsewhere too
The crosswalk maps your ISO 42005 evidence onto the frameworks it overlaps — so you move forward on several at once.