ISO/IEC 42001

A practical review of purpose, affected people, foreseeable harm, mitigations, and approval for each material AI use.

Which use is being assessed?

Begin with a defined AI system and a specific use, not a model name alone. Record the intended purpose, business owner, provider, data sources, users, affected people, geography, and level of human intervention. One model used for drafting internal notes and for screening applicants needs separate contextual decisions.

ISO/IEC 42001 provides a management system for governing AI across an organization. An impact assessment belongs inside that system: its trigger, reviewer, escalation route, and review cadence should be defined before teams start filling forms.

What could change the decision?

Describe reasonably foreseeable benefits and adverse impacts on people and organizations. Consider inaccurate outputs, unfair treatment, privacy exposure, security misuse, accessibility, over-reliance, and failures in human oversight where relevant to the use. Identify affected groups and the assumptions behind the assessment.

Choose evidence proportionate to those impacts: representative evaluation data, user testing, red-team findings, vendor limitations, or a process walkthrough. NIST's AI Risk Management Framework distinguishes mapping context from measuring risk and managing the response; that sequence helps avoid a purely descriptive assessment.

How are mitigations recorded?

For every material issue, state the control, its owner, test of effectiveness, and residual uncertainty. Controls might include narrower use, human review, input restrictions, monitoring thresholds, incident escalation, or a decision not to deploy. Record what the organization can verify itself and what remains a supplier assertion.

The approval record should explain why the use may proceed, proceed conditionally, or stop. A high score on a generic checklist does not replace a reasoned decision about the real deployment context.

When must the assessment be reopened?

Set triggers for a new model or version, different data, expanded user group, altered autonomy, changed supplier, new geography, or an incident. Assign a date for periodic review even when none of those events occurs. Connect the impact record to the AI inventory, release process, and management review so that changes reach a responsible decision-maker.

Where EU AI Act duties may apply, assess roles and system classification separately with qualified legal input. An ISO/IEC 42001 impact record can support governance, but it does not by itself establish statutory compliance.

Put it into practice

  • Define the use and affected groups before applying a questionnaire.
  • Choose evidence that can reveal the most important failure modes.
  • Record approval conditions, residual uncertainty, and a named owner.
  • Reopen the decision after material changes or incidents.

Primary sources

Normstone resources are general information, not legal advice or an independent assessment.

All resources