AI impact assessment, and its three rivals
Four different assessments get called an AI impact assessment, and they have different triggers, different readers and different legal weight. Doing the wrong one is a common and expensive way to satisfy nobody.
An AI system impact assessment under ISO/IEC 42001 is the documented analysis of what your AI system could do to individuals, to groups and to society, required by clause 6.1.4 and operated under clause 8.4, with four Annex A controls behind it. It is not a privacy impact assessment, it is not the fundamental rights impact assessment the EU AI Act requires of some deployers, and it is not the Algorithmic Impact Assessment the Government of Canada requires of federal institutions. The four overlap in analysis and differ in everything else. Here is which one you owe, to whom, and what goes in it.
Which impact assessment does someone actually want?
| Assessment | Who requires it | What triggers it | Who reads it |
|---|---|---|---|
| AI system impact assessment | ISO/IEC 42001, clause 6.1.4 and clause 8.4 | Voluntary, unless you are certifying. Then it is required for AI systems in your scope | Your certification body at stage 2, and customers who ask how you assess AI harm |
| Data protection impact assessment | GDPR Article 35, and Quebec's Law 25 for certain projects | Processing likely to result in high risk to individuals, including large-scale profiling and automated decisions with legal effect | Your privacy officer, and a supervisory authority if consulted or investigating |
| Fundamental rights impact assessment | EU AI Act, Article 27 | Certain deployers of high-risk systems, including public bodies, private entities providing public services, and deployers of creditworthiness and life and health insurance pricing systems | The national market surveillance authority, which must be notified of the result |
| Algorithmic Impact Assessment | Treasury Board Directive on Automated Decision-Making | A federal institution using an automated decision system for an administrative decision | The public. Completed assessments are published, and the impact level sets the required safeguards |
If a Canadian customer says the words "AI impact assessment", they almost always mean the first row and have read it in a questionnaire. If a European customer says it, ask which one, because a deployer subject to Article 27 needs a specific document with a specific audience and your ISO deliverable will not substitute. The EU picture as it reaches a Canadian supplier is on the EU AI Act page.
You can write one document, if you plan it
These four assessments ask overlapping questions in a different order. It is entirely workable to run one assessment process that produces a core analysis plus the sections a given regime needs, and organizations that do this spend far less than those running a privacy exercise and an AI exercise in separate tools with separate owners. What does not work is writing the privacy one and relabelling it, because a privacy assessment stops at the individual whose data you hold and clause 6.1.4 asks about people who are not in your data at all.
What does ISO 42001 clause 6.1.4 actually require?
The clause requires you to establish a process for assessing the potential consequences for individuals, groups of individuals and societies, of AI systems throughout their life cycle, and to keep documented information on the results. Clause 8.4 makes you actually run that process, and Annex A adds four controls: the process itself, the documentation of assessments, assessment of impact on individuals or groups, and assessment of societal impacts as a separate item.
The separation of individual and societal impact is the part people skip and the part an auditor notices. Impact on an individual is a hiring model rejecting a candidate. Societal impact is what happens if every employer in a sector uses the same model and the same candidates are rejected everywhere. The second question has no counterpart anywhere in an ISO 27001 risk assessment, which asks only what could happen to your organization and its information.
ISO/IEC 42005 is the dedicated guidance standard for AI system impact assessment. It is not required and it is worth buying if this is new to you, because it supplies the structure that clause 6.1.4 leaves open.
What goes in the document?
There is no mandated template. What follows is what a stage 2 auditor asks to see, and it is close to what ISO/IEC 42005 suggests. Work through it per AI system or per coherent group of systems that share a purpose and a population.
0 of 0 sections drafted ·
How do you run one without it taking a quarter?
- Pick the system your customers ask about. Not the easiest one. The first assessment teaches the organization what the exercise is for, and it teaches more if the stakes are real.
- Get the right people in the room. The product owner, the engineer who knows what the model actually does, someone from legal or privacy, and someone who knows the domain it is deployed into. A security team on its own will produce a security document.
- Describe the intended use in one paragraph, then the plausible misuse in another. Off-label use is where most of the harm sits, and writing down the intended use is what makes off-label use detectable.
- Name harms as events, not categories. Not "fairness risk". Rather "a qualified applicant with an employment gap is scored below threshold and never reviewed by a person". You can measure the second one.
- For each harm, record what you did and what is left. The residual position is the part auditors read, because a document where every harm is fully mitigated is a document nobody believed.
- Set the review trigger before you close it. A model retrain, a new deployment context, a threshold change, or a fixed interval. Then put it in the change process so the trigger actually fires.
Where the Canadian obligation bites
Quebec's Law 25 requires an organization to inform an individual when a decision about them is based exclusively on automated processing, and on request to tell them the personal information used, the reasons and principal factors behind the decision, and to allow them to submit observations to a person who can review it. That is a product requirement, not a policy requirement, and it is in force today. If your impact assessment does not reach the question of whether a person can review a decision and on what information, it has missed the one AI-specific obligation currently binding in Canada. Privacy obligations around the underlying data are covered by PIPEDA or the provincial statute that displaces it.
What does an impact assessment cost in Canada?
$5,000 to $20,000 CAD, impact assessments scoped as a separate consulting deliverable
20 to 60 Internal hours for a first assessment on one system
The consulting range assumes a small number of systems and a facilitator rather than a document factory. The internal hours are the real cost and they fall on people who are not compliance staff, which is why the first one takes three times as long as the fourth. Doing them yourself is entirely reasonable once you have seen one done properly, and the templates that come with a readiness engagement are usually worth more than the assessments themselves. The wider cost picture is on the ISO 42001 certification page.
When is this not worth doing?
If your only AI is a commercial assistant your staff use internally, a formal impact assessment on it is paperwork with no reader. The system affects your own employees, the vendor has already published more about the model than you could assess, and the useful controls are an acceptable use policy and vendor terms. Write half a page recording that you considered it and why the impact is limited, and spend the time on the inventory instead. That judgement, and where it stops holding, is the subject of who needs ISO 42001.
The counter-case is worth stating plainly too. Companies that skip the assessment because their system feels low stakes are usually the ones who have not asked who is affected beyond the paying customer. A support triage model that quietly deprioritises certain accounts is affecting people. If you cannot say who is affected without looking it up, the assessment is exactly the exercise you need.
Get help with a first impact assessment
Tell us what the system does and who it affects, and we will match you with Canadian firms that facilitate these rather than sell you a template.
Get matchedCommon questions
Is an AI impact assessment the same as a privacy impact assessment?
No. A privacy impact assessment asks what happens to personal information you hold and whether the processing is lawful and proportionate. An AI system impact assessment under ISO 42001 clause 6.1.4 asks what the system could do to individuals, groups and society, whether or not personal information is involved. A system trained entirely on synthetic data can still cause harm, and a privacy assessment would not find it.
Does ISO 42001 require an impact assessment for every AI system?
For every AI system inside your certification scope, yes, though the depth should be proportionate to the risk. A short assessment concluding that impact is limited, with the reasoning recorded, satisfies the clause for a low-stakes system. What does not satisfy it is having no process, or having a process that has never been run.
What is ISO 42005 and do we need to buy it?
ISO/IEC 42005 is the guidance standard for AI system impact assessment. It is not required for certification and it is the most useful of the companion documents if impact assessment is new to your organization, because clause 6.1.4 tells you to have a process without telling you what the process should contain. Budget a few hundred Canadian dollars for it alongside the standard itself.
Who should own the impact assessment internally?
The product owner for the AI system, with input from engineering, legal or privacy, and someone who knows the domain the system is deployed into. Handing it to the security team produces a document about confidentiality and availability, which is a different question. The management system owner should own the process, not each assessment.
How often do we have to redo it?
Whenever a defined trigger fires, plus a fixed interval as a backstop. Reasonable triggers are a retrain or model version change, deployment into a new context or jurisdiction, a change to the decision threshold or the degree of automation, and any incident involving the system. An annual review of assessments that have had no trigger is the usual backstop and is what auditors expect to see evidence of.
Will our certification body accept a fundamental rights impact assessment instead?
Not on its own. An Article 27 fundamental rights impact assessment under the EU AI Act covers a narrower set of systems and is written for a market surveillance authority. It will supply much of the analysis, and a certification body will still expect to see your clause 6.1.4 process, including the societal impact element and coverage of the AI systems in your scope that the Article 27 duty does not reach.