ISO/IEC 42005 Impact Assessment Platform
AI impact assessment · AIIA · ISO/IEC 42005 impact assessment
A platform to create and manage your AIIAs
Overview
This guidance enables organizations to conduct artificial intelligence (AI) system impact assessments for individuals and societies that may be affected by an AI system and its foreseeable applications. It outlines considerations for how and when to perform such assessments, including at relevant stages of the AI system life cycle, and provides guidance on documenting AI system impact assessments.
The ISO/IEC 42005 AI Impact Assessment platform helps organisations assess the impact of AI systems and demonstrate conformity with applicable requirements. In the application it is titled AIIA - AI Impact Assessment and labelled About the ISO/IEC 42005 Tool.
The live application is the Angular PIA front end under /var/www/pia (served at https://itgovernance.com/pia/), with the Rails API pia-back at https://itgovernance.com/pia-api/. The ISO pack (structure template, Help → ISO 42005 Example, and en-iso42005 / fr-iso42005 locales) defines 239 questions aligned with ISO/IEC 42005:2025.
Access the ISO/IEC 42005 platform
What You Work With in the Application
From the home screen and header (labels as in the app):
- My AIIAs / Current AIIAs — portfolio of system impact assessments
- New AIIA / Import AIIA — create or restore assessments
- AIIA templates — structure templates for new assessments
- AIIA Archives — archived assessments
- ISO 42005 Example (Help) — worked training assessment with the same question IDs as the production template
- Tools → Settings — including server URL, users, AIIA exchange, data management, and the organisation AI impact assessment process (Clause 5)
- ISO/IEC 42005 knowledge base — guidance and measures linked from questions
Organisation-level Clause 5 process text and the threshold library live in Settings; each AIIA file holds the system-level Clause 6 / Annex E documentation.
Assessment Structure (Left Menu)
The ISO pack left menu in the PIA application (section titles from en-iso42005.json):
1. Context & AI system information
- 1.1 System identification, scope, uses & responsibilities (E.1, §6.2–6.3, §5.6–5.7)
- 1.2 System narrative: architecture, controls & lifecycle (complements §2)
- 1.3 Annex E structured records (datasets, models, uses, dependencies) — source of truth
2. Data, models, deployment, parties & benefits
- 2.1 Data information and quality (Annex E Tables E.10–E.11)
- 2.2 Algorithms, models and deployment environment (Tables E.12–E.15)
- 2.3 Interested parties & benefits/harms matrix (E.16–E.20)
3. Impacts, measures & residual analysis
- 3.1 Measures to address harms and benefits (§6.9)
- 3.2 Privacy & confidentiality residual impact (ISO 42005 §6.8.2.5)
- 3.3 Integrity of data, models & outputs
- 3.4 Availability of system, data & rights pathways
- 3.5 Impacts overview
- 3.6 Accountability · 3.7 Fairness & non-discrimination · 3.8 Transparency & explainability
- 3.9 Reliability · 3.10 Safety · 3.11 Environmental impact (Annex C dimensions)
- 3.12 Residual prioritisation vs thresholds (after measures)
4. Residual impact, approval, action plan & monitoring (ISO/IEC 42005 §5.9–5.12)
- 4.1 Residual impact mapping & acceptance
- 4.2 Action plan for measures & remediation
- 4.3 Consultation opinions of interested parties (and privacy advisor where applicable)
- 4.4 Formal validation / approval (Annex E Table E.3)
- 4.5 Rejection, suspension, reassessment & review log (§5.4.2, §5.12)
Key Capabilities in the PIA Application
- Structured Annex E registers — system info (E.1), revision history (E.2), approvals (E.3), datasets, models, uses, dependencies, parties, impact matrix, failures/misuse, measure register, review log
- Triage and thresholds — sensitive / restricted / high-risk flags, threshold library, consistency warnings
- Evaluation gate — send for evaluation only when critical registers are complete
- Multi-role workflow — editing, review/evaluation, and validation roles on each AIIA card
- Residual gauges — severity and likelihood for privacy and Annex C impact dimensions
- Action plan — remediation tracking from residual findings and measures
- Import / export — full backup JSON, AIIA exchange (signed partner transfer), Annex E JSON and HTML reports, classic print artefacts
- Help → ISO 42005 Example — full worked assessment for training (same 239 question IDs as new AIIAs)
- Knowledge base — ISO/IEC 42005 knowledge base entries linked from questions
Who Uses It
- Teams creating and editing AIIAs (system owners, product and engineering)
- Reviewers evaluating residual impacts and measures
- Validators approving or rejecting assessments
- Risk, compliance, privacy, and AI governance staff maintaining Clause 5 process and thresholds
- Partners exchanging AIIAs under AIIA exchange rules
Ready to Run an ISO/IEC 42005 Assessment?
Open the platform, sign in, explore Help → ISO 42005 Example, then create a New AIIA for your system. For demos or organisation configuration, contact IT Governance.