Chapter 23

AI System Impact Assessment Guide

Complete guide to conducting AI system impact assessments as required by Clause 8.4, including methodology, templates, and examples.

20 min read

Chapter Overview

This chapter provides a comprehensive guide to conducting AI System Impact Assessments as required by Clause 8.4. Impact assessment is unique to ISO 42001 and focuses on how AI affects individuals and society.

Clause 8.4 Requirement

"The organization shall conduct an AI system impact assessment for AI systems, taking into account the potential consequences of the AI system for individuals, groups of individuals, and societies."

Impact Assessment vs Risk Assessment

AspectRisk Assessment (8.2)Impact Assessment (8.4)
FocusRisks to the organizationImpacts on people and society
PerspectiveOrganization-centricHuman-centric
QuestionWhat could go wrong for us?How does this affect people?
ScopeAll risk typesHuman and societal consequences
ControlsAnnex A controlsAnnex A.5 controls specifically

Impact Assessment Process

Process Overview

PhaseActivitiesOutput
1. PreparationDefine scope, gather information, form teamAssessment plan
2. System AnalysisUnderstand AI system functionality and contextSystem description
3. Stakeholder IdentificationIdentify affected partiesStakeholder map
4. Individual Impact AssessmentAssess impacts on individualsIndividual impact analysis
5. Societal Impact AssessmentAssess broader societal impactsSocietal impact analysis
6. Mitigation PlanningIdentify measures to address negative impactsMitigation plan
7. DocumentationDocument assessment and conclusionsImpact assessment report
8. Review and ApprovalReview and approve assessmentApproved assessment

Phase 1: Preparation

Define Scope

  • Which AI system is being assessed
  • Which use cases are included
  • Geographic and demographic scope
  • Assessment boundaries

Gather Information

  • AI system documentation
  • Technical specifications
  • Intended use documentation
  • User information
  • Data processing details
  • Previous assessments (if any)

Form Assessment Team

RoleContribution
Assessment LeadCoordinate assessment, ensure completeness
AI System ExpertTechnical understanding of the system
Business OwnerUse case and context knowledge
Ethics/ComplianceEthical and regulatory perspective
User RepresentativeUser perspective and needs
External StakeholderAffected party perspective (optional)

Phase 2: System Analysis

Document AI System

System Description Template

System Identity:
• System name and ID
• Version assessed
• Business owner
• Technical owner

Functionality:
• Purpose and objectives
• AI type (ML, NLP, computer vision, etc.)
• Key capabilities
• Decision types made

Data:
• Input data types
• Personal data processed
• Data sources
• Output data/decisions

Context:
• Deployment environment
• User groups
• Scale of use
• Integration with other systems

Autonomy Assessment

LevelDescriptionImpact Consideration
AdvisoryAI provides recommendations, humans decideLower direct impact
SupportedAI and human collaborate on decisionsShared impact
AutomatedAI makes decisions, human oversightHigher direct impact
AutonomousAI makes decisions independentlyHighest direct impact

Phase 3: Stakeholder Identification

Identify Affected Parties

CategoryDescriptionExamples
Direct UsersPeople who operate the AI systemEmployees, operators
AI SubjectsPeople about whom AI makes decisionsCustomers, applicants, patients
Indirect AffectedPeople indirectly impactedFamily members, communities
Vulnerable GroupsGroups requiring special considerationChildren, elderly, disabled, minorities

Stakeholder Impact Map

For Each Stakeholder Group Document:

• Group description
• How they interact with/are affected by AI
• Potential positive impacts
• Potential negative impacts
• Vulnerability factors
• Scale (number of people affected)

Phase 4: Individual Impact Assessment

Impact Categories

CategoryPositive ImpactsNegative Impacts
Rights & FreedomsEnhanced access, privacy protectionPrivacy violation, discrimination, surveillance
Safety & HealthImproved safety, health monitoringPhysical harm, mental health impacts
EconomicBetter services, opportunitiesJob loss, unfair denial, financial harm
AutonomyEmpowered decisions, convenienceManipulation, reduced agency, dependence
DignityPersonalization, accessibilityDehumanization, profiling, stigmatization

Assessment Questions

Individual Impact Questions

Rights & Freedoms:
• Does the AI process personal data? How?
• Could the AI discriminate against protected groups?
• Does the AI affect freedom of expression or movement?
• Are individuals informed about AI use?

Safety & Health:
• Could AI errors cause physical harm?
• Could the AI cause psychological distress?
• Are there safety-critical decisions?

Economic:
• Does the AI affect access to services or opportunities?
• Could the AI cause financial harm?
• Does the AI affect employment?

Autonomy:
• Can individuals understand AI decisions affecting them?
• Can individuals contest or appeal AI decisions?
• Does the AI manipulate or nudge behavior?

Dignity:
• Does the AI treat people as individuals?
• Could the AI be perceived as dehumanizing?
• Are vulnerable groups specially protected?

Phase 5: Societal Impact Assessment

Societal Impact Categories

CategoryPositive ImpactsNegative Impacts
SocialConnectivity, accessibilityPolarization, inequality, isolation
EconomicProductivity, new opportunitiesJob displacement, wealth concentration
DemocraticParticipation, transparencyManipulation, misinformation
EnvironmentalEfficiency, optimizationEnergy consumption, e-waste
CulturalPreservation, accessHomogenization, bias amplification

Scale Assessment

Scale FactorQuestions
ReachHow many people could be affected?
FrequencyHow often are decisions made?
CumulativeWhat is the cumulative effect over time?
SystemicCould this affect entire systems or markets?

Phase 6: Mitigation Planning

Mitigation Strategies

StrategyDescriptionExamples
EliminateRemove the source of negative impactDon't use AI for this decision
SubstituteReplace with less impactful approachUse advisory instead of automated
ControlImplement safeguardsHuman oversight, bias testing
InformEnsure transparencyClear disclosure, explanations
EmpowerGive affected parties recourseAppeals process, opt-out

Phase 7: Documentation

Impact Assessment Report Template

Complete Impact Assessment Template

1. EXECUTIVE SUMMARY
• AI system name and purpose
• Assessment date and team
• Key findings summary
• Overall impact rating
• Key recommendations

2. AI SYSTEM DESCRIPTION
• System overview and functionality
• Autonomy level
• Data processed
• Scale and context

3. AFFECTED PARTIES
• Stakeholder map
• Vulnerable groups identified
• Scale of affected population

4. INDIVIDUAL IMPACT ASSESSMENT
For each impact category:
• Potential positive impacts
• Potential negative impacts
• Affected groups
• Likelihood (1-5)
• Severity (1-5)
• Impact score
• Existing mitigations

5. SOCIETAL IMPACT ASSESSMENT
For each societal category:
• Potential positive impacts
• Potential negative impacts
• Scale of impact
• Severity assessment

6. MITIGATION MEASURES
• Recommended mitigations
• Responsible parties
• Implementation timeline

7. CONCLUSIONS
• Overall impact assessment
• Recommendation (proceed/proceed with conditions/do not proceed)
• Conditions for proceeding
• Monitoring requirements

8. APPROVAL
• Assessed by: [Name, Date]
• Reviewed by: [Name, Date]
• Approved by: [Name, Date]

Impact Rating Scale

RatingDescriptionAction
MinimalNegligible negative impacts, clear benefitsProceed with standard monitoring
LowMinor negative impacts, manageableProceed with identified mitigations
ModerateNotable impacts requiring attentionProceed with enhanced controls
HighSignificant negative impactsProceed only with robust mitigations
SevereSerious harm potentialDo not proceed without fundamental changes
Key Takeaways - Impact Assessment

1. Impact assessment is mandatory (Clause 8.4)
2. Focus is on people and society, not organizational risk
3. Assess both positive AND negative impacts
4. Consider individuals AND society
5. Pay special attention to vulnerable groups
6. Document methodology, findings, and mitigations
7. Obtain appropriate approval before deployment

AI Assistant
00:00