AI system impact assessment under ISO 42001
By Sam Rivera, Founder, SentinelPanda · June 20, 2026 · 1 min read · ISO 42001
The impact assessment is where AI governance gets serious about people — documenting who a system affects and how, before it affects them.
Assessing impact on people
A distinctive ISO 42001 requirement is the AI system impact assessment: evaluating how an AI system affects individuals and groups. It asks who is affected, how, and what could go wrong for them — extending governance beyond "does it work" to "what does it do to people."
What it examines
An impact assessment considers effects on rights and freedoms, fairness across groups, safety, and wellbeing, plus the consequences of errors and the availability of recourse. For a hiring, lending, or healthcare model, these are the stakes that matter most — and exactly what regulators and the public scrutinise.
Link to the EU AI Act
This overlaps with the EU AI Act, which requires a fundamental-rights impact assessment for certain high-risk systems. Doing a thorough ISO 42001 impact assessment positions you well for that obligation — the analysis is largely the same, documented once.
Document and act on it
The value is not the document but the decisions: mitigations, oversight, or not deploying a system whose impact is unacceptable. Keep the assessment as evidence and revisit it as the system changes. SentinelPanda tracks impact assessments per AI system.