Our Solutions
Structured AI system impact assessment based on ISO/IEC 42005—supporting EU AI Act risk management, technical documentation, and responsible market access.
An AI impact assessment identifies and evaluates how an AI system can affect individuals, groups, organisations, and society—across safety, fundamental rights, fairness, privacy, environment, and other relevant impact domains. Under the EU AI Act, providers of high-risk AI systems must implement robust risk management (Article 9) and maintain evidence that risks and impacts have been considered throughout the system life cycle.
Data Protection Schemes delivers AI Impact Assessment tools and expert support grounded in ISO/IEC 42005 (Information technology — Artificial intelligence — AI system impact assessment). The standard provides an internationally recognised framework for planning, conducting, and documenting impact assessments—so your process is systematic, repeatable, and defensible when authorities, partners, or customers ask for evidence.
ISO/IEC 42005 is the dedicated international standard for AI system impact assessment. It guides organisations on:
DPS embeds these principles in a practical workflow: you do not only “fill a template”—you produce living assessment records that connect to risk treatment, quality management, and Authorised Representative documentation where required.
ISO/IEC 42005 is not a substitute for the AI Act, and the Act does not mandate ISO/IEC 42005 by name. Used together, they strengthen compliance practice:
Sets legal duties—classification, risk management (Article 9), data governance, transparency, human oversight, technical documentation, post-market monitoring, and AR obligations for many non-EU providers.
Provides a structured method to identify, analyse, evaluate, and document AI system impacts—supporting the evidence base for risk management, design choices, and ongoing review.
For high-risk systems, impact assessment under ISO/IEC 42005 helps operationalise “what could go wrong for people and society,” while Article 9 requires those risks to be managed continuously. DPS links both into one compliance ecosystem—alongside QMS (Article 17) and our Readiness Assessment.
Following ISO/IEC 42005 practice, the DPS AI Impact Assessment is structured around the system’s intended purpose, context of use, and life-cycle stages. Typical analysis dimensions include:
Clear description of the AI system, use cases, users, affected persons, deployment environment, and system boundaries—the foundation of a valid impact scope.
Identification of individuals and groups who may be affected—directly or indirectly—including vulnerable persons where relevant to the use case.
Analysis of potential impacts on health and safety, fundamental rights, privacy, non-discrimination and fairness, autonomy, economic interests, environment, and organisational objectives—as applicable to the system.
Impacts considered not only at deployment, but across design, data, development, testing, operation, monitoring, update, and decommissioning stages.
Findings feed risk identification, evaluation, and mitigation—so impact assessment is not a parallel paper exercise but part of continuous risk management under the AI Act.
Assessment records, assumptions, residual impacts, and treatment decisions are captured in a form suitable for technical documentation, audits, and authority requests.
Download an overview of the DPS AI Impact Assessment approach for your team or stakeholders.
Impact assessment works best when it is not isolated. DPS connects ISO/IEC 42005-based assessment to:
No. The AI Act sets legal requirements; ISO/IEC 42005 is a voluntary international standard. Using it is a strong way to structure impact assessment and produce evidence that supports AI Act risk management and documentation duties.
A data protection impact assessment focuses on personal data processing risks under GDPR. An ISO/IEC 42005 AI system impact assessment is broader: it addresses AI-specific impacts on people and society (including, but not limited to, privacy). Where personal data is processed, DPIA and AI impact assessment should be coordinated, not confused.
When the intended purpose, model, data, deployment context, or affected population changes materially; after significant incidents or near-misses; and at planned review intervals defined in your QMS and risk process.
Yes. Non-EU providers often need the AR to hold or access compliance documentation. DPS ensures impact assessment outputs are organised for AR cooperation and authority requests.
Talk to DPS about an ISO/IEC 42005-based AI Impact Assessment for your systems—integrated with EU AI Act risk management, QMS, and Authorised Representative readiness.
Get in Touch