IT Governance — AI assurance and compliance

Services

ISO/IEC 42005 Assessments

Facilitated ISO/IEC 42005 assessments on the AIIA platform — system context, affected parties, residual impact against thresholds, and approved Annex E documentation that can also support FRIA-style duties.

The service

ISO/IEC 42005:2025 tells organisations how to identify, analyse, and address reasonably foreseeable impacts of an AI system — beneficial and harmful — on individuals, groups, and societies. Accuracy of the model is not enough. We facilitate that assessment on the live AIIA platform at itgovernance.com/pia.

You do not get a blank questionnaire. Specialists walk the system owner, reviewers, and approvers through the ISO pack (239 questions aligned with the standard), complete Annex E registers, and take residual impact through formal validation.

What the facilitated assessment covers

  1. System context — identification, scope, intended and unintended uses, architecture, datasets, models, and deployment environment (Annex E structured records).
  2. Affected parties — individuals, groups, societies, workers, data subjects, and other interested parties, including vulnerable persons.
  3. Impact categories — people, operations, privacy, security, human rights, society, environment, and regulatory compliance, using the standard’s harms and benefits taxonomy.
  4. Severity, likelihood, and measures — residual gauges against organisational thresholds; action plan for remaining harms.
  5. Governance decision — multi-role edit, review, and approval; consultation opinions; acceptance or rejection with a review log (ISO/IEC 42005 §5.9–5.12).

Outputs

Who it is for

Platform detail: ISO/IEC 42005 Impact Assessment Platform. Guidance: AI system impact assessment overview.

← Back to Services