ISO/IEC 42005 AI Impact Assessment

Jurisdiction:
OECD
voluntary
Effective:
May 28, 2025
Authority:
International Organization for Standardization
Official text

Obligations Covered

Risk Assessment

Timeline

MilestoneDateNotes
PublishedMay 28, 2025First edition; 39 pages
Integrates with ISO 420012025–Designed to complement ISO/IEC 42001 and ISO/IEC 23894

Regulatory Crosswalk

Binding regulations that require the same obligations this standard addresses. Implementing this standard can help satisfy these regulatory requirements.

RegulationJurisdictionShared Obligations
Work Health and Safety Amendment (Digital Work Systems) Act 2026 New South Wales 1
Privacy Act 1988 — Automated Decision-Making Reforms Australia 1
Brazil AI Bill (PL 2338/2023) Brazil 1
California CCPA ADMT Regulations California 1
California Companion Chatbot Safeguards (SB 243) California 1
Provisions on the Management of Algorithmic Recommendations China 1
Interim Measures for Generative AI Services China 1
Framework Convention on AI, Human Rights, Democracy and Rule of Law (CETS 225) Council of Europe 1
Colorado Privacy Act Rules (4 CCR 904-3) Colorado 1
Colorado Conversational AI Service Operator Requirements (HB 26-1263) Colorado 1
Colorado Protecting Consumers from Unfair Discrimination in Insurance Practices Colorado 1
Connecticut AI Responsibility Act (PA 26-15) Connecticut 1
Connecticut CTDPA Amendments (SB 1295 / Public Act 25-113) Connecticut 1
EU AI Act European Union 1
Digital Operational Resilience Act (DORA) European Union 1
Georgia AI Companion Chatbot Safeguards (SB 540) Georgia 1
Hawaii Artificial Intelligence Disclosure and Safety Act (SB 3001) Hawaii 1
Idaho Conversational AI Safety Act (S 1297) Idaho 1
Iowa Conversational AI Services Act (SF 2417) Iowa 1
AI Promotion Act Japan 1
AI Basic Act South Korea 1
Law on Artificial Intelligence Kazakhstan 1
Artificial Intelligence Regulations 2025 Malta 1
Nebraska Conversational Artificial Intelligence Safety Act (LB 525) Nebraska 1
New York AI Companion Models Law (GBL Article 47) New York 1
New York RAISE Act New York 1
Oregon Artificial Intelligence Companion Act (SB 1546) Oregon 1
Law Promoting the Use of Artificial Intelligence (Ley 31814) and Implementing Regulation Peru 1
QCB Artificial Intelligence Guideline Qatar 1
Rhode Island Artificial Intelligence Companion Models Act (S 2195) Rhode Island 1
Law for the Promotion of Artificial Intelligence and Technologies El Salvador 1
Artificial Intelligence Basic Act Taiwan 1
UK Online Safety Act 2023 United Kingdom 1
EO 14319 — Preventing Woke AI in the Federal Government United States 1
EO 14409 — Promoting Advanced Artificial Intelligence Innovation and Security United States 1
Executive Order on AI State Law Preemption United States 1
Utah AI Policy Act (stack — SB 149 + 2025 + 2026 amendments) Utah 1
Law on Artificial Intelligence Vietnam 1
Washington AI Companion Chatbots Act (ESHB 2225) Washington 1

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

Provisions (1)

AI System Impact Assessment #

Obligation:
Risk Assessment
enforcing
Effective:
May 1, 2025
Risk tier:
all
Scope:
providers, deployers
cross-domain
ISO/IEC 42005 fills the gap between generic risk management (ISO 23894) and impact on individuals and society — it is the AI equivalent of a Data Protection Impact Assessment (DPIA). As AI impact assessment requirements appear in the EU AI Act, CETS 225, and national strategies, this standard provides the reference methodology for conducting them.

Requirements

RequirementDetails
Impact identificationIdentify potential impacts of AI systems and their foreseeable applications on individuals, groups, and society
Intended and unintended use assessmentAssess intended, unintended, sensitive, restricted uses, and foreseeable misuse scenarios
Benefit and harm evaluationEvaluate both positive and negative impacts throughout the AI lifecycle
Stakeholder perspectiveIntegrate perspectives of affected individuals and groups in the assessment process
DocumentationProduce assessment documentation supporting transparency, accountability, and fairness
Lifecycle integrationApply impact assessment from design and development through deployment and post-market monitoring
Integration with risk managementCoordinate impact assessment with ISO/IEC 23894 (risk management) and ISO/IEC 42001 (management system)

Penalties

ViolationFine
Non-complianceVoluntary — no binding enforcement mechanism
Cite this regulation

Permalink: https://everyailaw.com/regulation/iso-42005/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “ISO/IEC 42005 AI Impact Assessment”, EveryAILaw.com, Mar 26, 2026. https://everyailaw.com/regulation/iso-42005/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.