Of everything ISO/IEC 42001 asks for, the AI system impact assessment is the requirement that has no equivalent in the management system standards most organisations already hold. It is not a risk register with a new label, and an ISO 9001 or ISO/IEC 27001 background will not have prepared you for it.
This guide sets out what the standard asks for, where the requirement sits, what an assessment needs to record, and what a certification auditor will want to see. It is written for organisations in the UAE that are preparing for certification to ISO/IEC 42001:2023.
What an AI system impact assessment is
An AI system impact assessment asks a question that risk management alone does not: who is affected by this AI system, and how badly could it affect them?
The subject of the assessment is people. Individuals who are subject to a decision the system makes, groups who may be treated differently by it, and society more broadly where the system is used at scale. ISO's own description of the exercise points in the same direction: the object of study is the effect an AI system and its foreseeable applications have on people, whether individually, as a group, or at the level of society.
That distinction is what separates it from everything else in your management system. A risk register asks what could go wrong for the organisation. An impact assessment asks what could go wrong for everybody else.
Where the AI impact assessment requirement sits in ISO/IEC 42001
ISO/IEC 42001:2023 was published in December 2023 and is the first international management system standard written for artificial intelligence. Its full official title is set out on our ISO/IEC 42001 certification page.
The impact assessment appears in the operation clause, alongside the risk clauses:
| Clause | Title |
|---|---|
| 8.1 | Operational planning and control |
| 8.2 | AI risk assessment |
| 8.3 | AI risk treatment |
| 8.4 | AI system impact assessment |
Clause 6.1, Actions to address risks and opportunities, is where the planning for all of this belongs, and clause 7.5, Documented information, is what makes the output auditable. Annex A of the standard holds the reference control objectives and controls, and Annex B.5, Assessing impacts of AI systems, gives implementation guidance for that group of controls.
The practical reading is straightforward. You plan the approach, you carry the assessment out as an operational activity, and you keep the result as documented information. Leaving any one of those three out is what turns a good assessment into a finding.
AI risk assessment and AI impact assessment are not the same thing
These two get conflated more than anything else in the standard. It treats them as separate clauses because they answer separate questions.
| AI risk assessment (8.2) | AI system impact assessment (8.4) | |
|---|---|---|
| Asks | What could go wrong, and what would it cost us? | Who could be harmed, and how severely? |
| Point of view | The organisation looking outward at threats | The people and groups on the receiving end of the system |
| Typical output | Risks, likelihood, treatment decisions | Affected parties, nature and severity of impact, what you did about it |
| Triggered by | The management system cycle | The AI system and its intended use, plus changes to either |
A useful test: if you could write the whole document without naming a single category of person outside your organisation, you have written a risk assessment and called it an impact assessment.
If you are also looking at information security certification, the two standards overlap in places but ask different questions. We cover that in ISO 42001 vs ISO 27001.
Who an AI impact assessment is about
Work outward in three rings.
- Individuals subject to the system. The job applicant screened by it, the customer whose credit application it scores, the patient whose scan it triages, the employee whose productivity it measures.
- Groups who may be affected unevenly. Where a system performs differently for different groups, that difference is the impact. This is where fairness, accessibility and the quality of your training data stop being abstract and become evidence.
- Society and the wider environment. Relevant where a system operates at scale, shapes what large numbers of people see, or touches safety, employment or public services.
For each ring, the questions worth answering are the same: what is the nature of the impact, how many people does it reach, how severe is it, can it be reversed, and are any of the affected people in a position of dependence or vulnerability that makes the impact worse.
When to carry out an AI impact assessment, and when to repeat it
The assessment is not a one-off document produced for the audit and then filed. Sensible trigger points are:
- Before deployment. An assessment produced after a system is already making decisions has missed its purpose.
- When the intended use changes. A model built for internal document search that gets pointed at customer communications is a new use, and needs a new assessment.
- When the system itself changes materially. A new model version, retraining on different data, or a change of vendor.
- When the operating context changes. A new market, a new user population, or a new category of decision.
- On a defined review cycle. Particularly for systems that continue to learn while in use, since their behaviour changes without anyone deploying anything.
That last case deserves attention. The standard's own introduction singles out continuously learning systems as needing special consideration precisely because their behaviour shifts during use. An assessment that was accurate at go-live can quietly stop being accurate.
Not sure which ISO standard fits your business?
Free quote in 3–4 hours · Certification in 7–10 days · 1,000+ businesses certified
What an AI impact assessment needs to record
The standard sets requirements rather than a template, so there is no single mandated form. What an assessment has to do is stand up as evidence. In practice that means a competent auditor can pick it up and follow the reasoning without you in the room.
A record that achieves that usually covers:
- The system and its boundary. What it is, what it does, what it does not do, and where your responsibility starts and stops if a third party supplies it.
- The intended use, and the foreseeable misuse. The second half is routinely skipped and routinely raised as a finding.
- The people and groups affected, named as categories rather than left as "users".
- The impacts identified, including positive ones, with reasoning rather than a bare score.
- Severity, judged on scale, reversibility and the vulnerability of those affected.
- What was decided as a result, and by whom.
- Who carried out the assessment, who reviewed it, who approved it, and on what date.
- The link to your AI risk treatment, so an identified impact visibly leads somewhere.
The last two are what usually separate a document that satisfies clause 8.4 from one that does not. An assessment with no named approver and no consequence reads as an exercise, and auditors read it that way.
How ISO/IEC 42005:2025 fits in
ISO/IEC 42001 states the requirement. It does not tell you how to run the assessment in detail.
That guidance was published separately in May 2025 as ISO/IEC 42005:2025, a standard devoted entirely to AI system impact assessment. It covers how and when to perform an assessment, which stages of the AI system life cycle to consider, and how to document the result.
ISO/IEC 42005 is guidance, so you are not certified against it and you are not obliged to follow it. It is, however, the most direct answer to "what should this document actually look like", and an assessment built along its lines is straightforward to audit.
What an auditor asks to see
At UCS the certification route runs Application, Certification Agreement, Stage 1 Audit, Stage 1 Audit Report, Stage 2 Audit, then Final Report and Certification, followed by annual surveillance audits. You can read the full sequence on our ISO certification process page.
Stage 1 is described on that page as a thorough review of your documentation, processes and overall readiness against the applicable standard. For clause 8.4 that means the assessment records exist, they cover the AI systems inside your declared scope, and they are current.
Stage 2 is where the standard asks you to document how the system complies by using objective evidence. For an impact assessment, objective evidence tends to look like this:
- An assessment dated before the system went live, not after.
- A named approver with the authority to approve it.
- At least one instance where an assessment changed a decision, and the trail showing it.
- Evidence of reassessment after a change, if a change has occurred.
- People who took part being able to describe what they did.
Any nonconformity identified at Stage 2 has to be addressed before certification is granted.
AI impact assessment for organisations in the UAE
Two points matter more in the UAE than the general guides tend to admit.
The first is that ISO/IEC 42001 is a voluntary international standard, not UAE law. Certifying to it does not replace any legal duty that already applies to you, and it does not exempt you from one. If a regulator, a client contract or a tender in the UAE places its own obligations on how you use AI, those obligations continue to apply in full. Treat the impact assessment as a management system requirement that sits alongside your legal advice, not as a substitute for it.
The second is that you do not have to build AI to be caught by this clause. ISO/IEC 42001 applies to organisations that develop, provide or use AI-based products and services. A UAE company that has bought an AI recruitment screening tool, an AI chatbot for customer service or an AI-powered analytics product from an overseas vendor still has to assess the impact of its own use of that system on the people affected by it. The vendor's assessment, if one exists, covers the vendor's context and not yours.
That second point is where most first attempts fall down. A company scopes its AI management system around the systems it wrote itself and quietly leaves out the tools it licenses, which are usually the ones making decisions about real people.
Frequently asked questions
Is an AI impact assessment mandatory under ISO/IEC 42001?
Clause 8.4, AI system impact assessment, is part of the requirements of ISO/IEC 42001:2023. An organisation seeking certification has to satisfy it for the AI systems within its declared scope.
Can we use our existing data protection impact assessment instead?
Not on its own. A privacy impact assessment looks at personal data. An AI system impact assessment looks at the effects of the system on people, which includes matters such as fairness, accuracy, transparency and the consequences of an automated decision, whether or not personal data is involved. The two overlap and can share evidence, but one does not replace the other.
Do we need an impact assessment for AI tools we bought rather than built?
Yes, for your use of them. ISO/IEC 42001 applies to organisations that develop, provide or use AI systems. Your assessment covers your context, your users and your decisions, which the supplier's assessment cannot.
How often should the assessment be repeated?
The standard does not fix an interval. Set your own trigger points and review cycle, write them down, and follow them. An auditor is checking that your rule exists and that you kept to it.
Does ISO/IEC 42001 certification make us compliant with AI law in the UAE?
No. ISO/IEC 42001 is a voluntary international standard. Certification demonstrates that you operate an AI management system that meets the standard's requirements. It is not a legal determination and does not replace legal advice about obligations that apply to you in the UAE.
Who is allowed to write our impact assessment?
Your organisation, or an adviser you appoint. It cannot be UCS. As an accredited certification body operating to ISO/IEC 17021-1:2015 we are not permitted to design, build or write the systems and documents we then assess. That separation is what makes the certificate worth holding.
Reading an assessment you have written and reporting what is missing is a different activity, and it is permitted. That is what a Stage 1 audit does, and it is what our pre-certification audit does before that. The line is between assessing your work and doing your work.
Next steps
If you are working towards ISO/IEC 42001 certification in the UAE, our ISO/IEC 42001 certification page sets out the standard, the scope and how certification works. To discuss your scope with an auditor, request a free assessment or contact the UCS team on +971 6 531 4406.
Ready to Get ISO Certified?
Most businesses achieve certification in just 7–10 days. Get a free assessment and tailored quote from our accredited team — clear pricing, no jargon.