ISO/IEC 42005:2025
ISO/IEC 42005:2025 guides organizations developing, providing or using AI systems on performing AI system impact assessments for the individuals, groups and societies an AI system and its foreseeable applications can affect, and on documenting them. Clause 5 sets up the process: a structured approach shaped by internal and external factors including prohibited AI uses; documenting the process; integrating it with organizational risk assessment and with privacy, security, safety, human rights and other impact assessments; when to assess and reassess (changes in use, users, data, performance, environment, law) with triaging for high-risk systems; scope and the organization's role in the AI ecosystem; multidisciplinary responsibilities; thresholds for sensitive and restricted uses and impact scales; performing, analysing, recording, approving, monitoring and reviewing. Clause 6 sets the assessment document's contents: scope, AI system description, capabilities, purpose, intended and unintended uses, data information and quality, algorithm and model information, deployment geography and constraints, directly affected and other interested parties, benefits and harms, failures and reasonably foreseeable misuse, and the measures adopted. Annexes align it with ISO/IEC 42001 (whose A.5 controls and B.5 guidance it elaborates), ISO/IEC 23894, a harms and benefits taxonomy, other assessments and a template. Guidance, not certifiable; the EU AI Act's fundamental rights impact assessment and the NIST AI RMF MAP and MEASURE functions are the regimes it is most often used against.
ISO/IEC 42005:2025 is a compliance framework from International with 2 domains and 31 controls. The largest domains are Clause 6: Documenting the AI system impact assessment – ISO/IEC 42005:2025 (19 controls), Clause 5: Developing and implementing an AI system impact assessment process – ISO/IEC 42005:2025 (12 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (2)
Clause 5: Developing and implementing an AI system impact assessment process – ISO/IEC 42005:2025
| Code | Title |
|---|---|
| iso-iec-42005-2025::5.1 | A structured and consistent approach shaped by internal and external factors |
| iso-iec-42005-2025::5.10 | Recording and reporting |
| iso-iec-42005-2025::5.11 | Approval process |
| iso-iec-42005-2025::5.12 | Monitoring and review |
| iso-iec-42005-2025::5.2 | Documenting the process |
| iso-iec-42005-2025::5.3 | Integration with other organizational management processes |
| iso-iec-42005-2025::5.4 | Timing of the assessment, reassessment triggers and triaging |
| iso-iec-42005-2025::5.5 | Scope of the AI system impact assessment |
| iso-iec-42005-2025::5.6 | Allocating responsibilities and the multidisciplinary approach |
| iso-iec-42005-2025::5.7 | Establishing thresholds for sensitive uses, restricted uses and impact scales |
| iso-iec-42005-2025::5.8 | Performing the AI system impact assessment |
| iso-iec-42005-2025::5.9 | Analysing the results of the AI system impact assessment |
Clause 6: Documenting the AI system impact assessment – ISO/IEC 42005:2025
| Code | Title |
|---|---|
| iso-iec-42005-2025::6.2 | Scope of the AI system impact assessment (documented) |
| iso-iec-42005-2025::6.3.1 | AI system description |
| iso-iec-42005-2025::6.3.2 | AI system functionalities and capabilities |
| iso-iec-42005-2025::6.3.3 | AI system purpose |
| iso-iec-42005-2025::6.3.4 | Intended uses |
| iso-iec-42005-2025::6.3.5 | Unintended uses |
| iso-iec-42005-2025::6.4.2 | Data information |
| iso-iec-42005-2025::6.4.3 | Data quality documentation |
| iso-iec-42005-2025::6.5.2 | Information on algorithms used by the organization |
| iso-iec-42005-2025::6.5.3 | Information on algorithm development |
| iso-iec-42005-2025::6.5.4 | Information on models used in an AI system |
| iso-iec-42005-2025::6.5.5 | Information on model development |
| iso-iec-42005-2025::6.6.1 | Geographical area and languages |
| iso-iec-42005-2025::6.6.2 | Deployment environment complexity and constraints |
| iso-iec-42005-2025::6.7.2 | Directly affected interested parties |
| iso-iec-42005-2025::6.7.3 | Other relevant interested parties |
| iso-iec-42005-2025::6.8.2 | Benefits and harms |
| iso-iec-42005-2025::6.8.3 | AI system failures and reasonably foreseeable misuse |
| iso-iec-42005-2025::6.9 | Measures to address harms and benefits |
What is ISO/IEC 42005:2025 and who does it apply to?
ISO/IEC 42005:2025 is a compliance framework from International with 2 domains and 31 controls. ISO/IEC 42005:2025 guides organizations developing, providing or using AI systems on performing AI system impact assessments for the individuals, groups and societies an AI system and its foreseeable applications can affect, and on documenting them. Clause 5 sets up the process: a structured approach shaped by internal and external factors including prohibited AI uses; documenting the process; integrating it with organizational risk assessment and with privacy, security, safety, human rights and other impact assessments; when to assess and reassess (changes in use, users, data, performance, environment, law) with triaging for high-risk systems; scope and the organization's role in the AI ecosystem; multidisciplinary responsibilities; thresholds for sensitive and restricted uses and impact scales; performing, analysing, recording, approving, monitoring and reviewing. Clause 6 sets the assessment document's contents: scope, AI system description, capabilities, purpose, intended and unintended uses, data information and quality, algorithm and model information, deployment geography and constraints, directly affected and other interested parties, benefits and harms, failures and reasonably foreseeable misuse, and the measures adopted. Annexes align it with ISO/IEC 42001 (whose A.5 controls and B.5 guidance it elaborates), ISO/IEC 23894, a harms and benefits taxonomy, other assessments and a template. Guidance, not certifiable; the EU AI Act's fundamental rights impact assessment and the NIST AI RMF MAP and MEASURE functions are the regimes it is most often used against. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO/IEC 42005:2025 actually require?
ISO/IEC 42005:2025 has 31 controls organised across 2 domains. The largest domains are Clause 6: Documenting the AI system impact assessment – ISO/IEC 42005:2025 (19 controls), Clause 5: Developing and implementing an AI system impact assessment process – ISO/IEC 42005:2025 (12 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO/IEC 42005:2025 do I already cover?
ISO/IEC 42005:2025 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement ISO/IEC 42005:2025?
Start your ISO/IEC 42005:2025 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 42005:2025 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 31 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 688 frameworks.
Get Started Free →Free forever — no credit card required