AI impact assessments: ISO 42001 and the EU AI Act
By Sam Rivera, Founder, SentinelPanda · June 2, 2026 · 3 min read · AI Governance
The impact assessment is the one document that survives every audit you face on an AI system. Build it once with both standards in mind.
Why every AI standard wants an impact assessment
A regular risk assessment looks at the organisation's risk — what does this AI system do to us? An impact assessment looks the other way — what does this AI system do to people exposed to it? The answer often involves rights, fairness, and harms that are invisible to the standard cyber-risk taxonomy.
Both ISO 42001 and the EU AI Act ask for this outward-facing view because AI systems can produce concrete harms to identifiable populations: biased decisions in hiring, denied access to services, misidentification by biometric systems, manipulation of behaviour. The assessment is the artefact where you anticipate, document, and mitigate those harms before deployment.
What ISO 42001's impact assessment covers
ISO 42001 Annex A control A.5.5 requires an AI system impact assessment; Annex B (informative) gives the structure. It is process-oriented: define the system and its context, identify the categories of stakeholders affected, analyse the potential positive and negative impacts (on individuals, groups, society, the environment), and document how impacts are mitigated and monitored across the lifecycle.
The 42001 assessment is broad — it is not limited to fundamental rights, and it does not require a specific format. The assessment is reviewed during internal audit and management review, and updates are expected when the system changes or new data shows a different impact pattern.
What the FRIA adds for the AI Act
Article 27 of the EU AI Act introduces the Fundamental Rights Impact Assessment (FRIA), required of certain deployers of high-risk AI systems: public bodies, private bodies providing public services, and deployers of high-risk systems for creditworthiness, life and health insurance pricing. The FRIA is narrower than the 42001 assessment — focused specifically on fundamental rights — but more prescriptive about what must be documented.
The required FRIA elements are listed in Article 27(1): a description of the deployer's processes that use the system; period and frequency of use; categories of natural persons affected; specific risks of harm to those categories; human oversight measures; measures to take if risks materialise. Once completed, the deployer notifies the market surveillance authority of the results.
A practical template you can run once
Build a single impact-assessment template with the union of both standards' requirements. It will be longer than either alone, but it produces a document you can present to either auditor without rewriting. Structure it as: (1) system identification and purpose, (2) intended use and reasonably foreseeable misuse, (3) categories of persons affected and how, (4) fundamental rights at stake and the specific risks to each, (5) data lineage and quality, (6) human oversight design, (7) mitigations and the residual risk, (8) monitoring metrics and review triggers.
Keep it versioned and tied to a specific build or model version. An impact assessment that does not name the model version it covers becomes stale silently — the standards expect you to update it when the system changes materially.
Triggers — when to run a new one
- New AI system being placed on the market or deployed.
- Material change to the model, training data, or intended purpose.
- New category of affected person (e.g. a market expansion).
- Post-deployment incident or complaint pattern suggesting impacts you had not anticipated.
- Regulatory change affecting the rights at stake or the categorisation of the system.