Skip to content

ISO/IEC 42005

Gamut supports AI system impact assessment aligned to ISO/IEC 42005:2025. The module provides 119 atomic assessment items covering the assessment process, its documentation and the analysis and treatment of actual and reasonably foreseeable impacts.

The central question is:

For this selected AI system, its intended and foreseeable uses, affected parties and operating context, what benefits and harms may arise, how were they evaluated, and what measures and accountable decisions follow?

If you need to…Read
Understand system scope, the process and 119-item catalogueScope, process and catalogue
Complete an assessment end to endAssessment workflow
Explain maturity, assurance and approved N/AMaturity, assurance and applicability
Gather evidence and engage affected partiesEvidence, engagement and findings
Use per-item and whole-system AI assistanceAI Assist and security
Report and maintain the impact assessmentReporting and reassessment
Look up labels and safe explanatory languageReference and glossary
PropertyGamut assessment
StandardISO/IEC 42005:2025, edition 1
NatureGuidance for AI system impact assessment
ScopeOne selected AI system, version and use context
StructureClauses 5 and 6 represented in five sections
Atomic items119
Maturity1 Not Addressed to 5 Optimised
Assurance depthUnverified, Documented, Implemented, Assured
ApplicabilityIn-scope by default; N/A requires structured human approval
Evidence boundarySelected system, affected parties, context and assessment period
AI supportPer-item and complete-system advisory analysis
AccountabilityHuman assessor owns scope, engagement, impact, treatment and conclusion
SectionItemsPurpose
Process Foundation18Establish and document a repeatable, integrated impact-assessment process
Governance & Triggers25Timing, scope, responsibilities and thresholds for sensitive or restricted uses
Execution & Review25Perform, analyse, record, approve, monitor and review assessments
Documentation Content29System, use, data, model, deployment and interested-party information
Impacts & Measures22Identify impacts and record measures addressing harms and benefits
Selected AI system and approved boundary
→ intended use, foreseeable misuse and affected parties
→ impact-assessment trigger, responsibility and thresholds
→ 119 atomic maturity and assurance decisions
→ evidence, stakeholder input, tests and findings
→ harms, benefits, measures and residual uncertainty
→ accountable system-level conclusion
→ monitoring and event-driven reassessment
  • Selected system, version, purpose and deployment environment.
  • Organisational role, lifecycle stage and dependencies.
  • Intended uses and reasonably foreseeable misuse.
  • Directly and indirectly affected people, groups and society.
  • Data, model, algorithm and deployment information.
  • Stakeholder and affected-party engagement.
  • Actual and foreseeable beneficial and adverse impacts.
  • Severity, likelihood, distribution, reversibility and uncertainty.
  • Measures, owners, residual impacts and decision thresholds.
  • Objective evidence, testing, findings and limitations.
  • Approval, publication decision, monitoring and reassessment triggers.

It does not by itself prove:

  • That every affected party was identified.
  • That stakeholder engagement occurred because a policy requires it.
  • That legal impact assessments are complete.
  • That a high maturity score means impacts are acceptable.
  • That an item is irrelevant without an approved basis.
  • That crosswalked evidence automatically satisfies the guidance.
  • That AI-generated analysis is an approved impact conclusion.
  1. Scope, process and catalogue
  2. Assessment workflow
  3. Maturity, assurance and applicability
  4. Evidence, engagement and findings
  5. AI Assist and security
  6. Reporting and reassessment
  7. Reference and glossary