AI Impact Assessment: ISO 42001, EU AI Act, and Colorado AI Act
A single well-designed AI impact assessment satisfies ISO/IEC 42001:2023 Clause 6.1.4 and Annex A.5, the EU AI Act Article 27 Fundamental Rights Impact Assessment (FRIA) for high-risk AI deployers, and the Colorado AI Act impact-assessment requirement.
What an AI impact assessment is
An AI impact assessment (AIIA) is a documented evaluation of how a specific AI system affects individuals, groups, and society, before and during deployment. It's distinct from the broader risk assessment, which is organisation-centric. The impact assessment is stakeholder-centric: who is affected, how, and what we do about it.
What ISO 42001 requires (6.1.4 and A.5)
Clause 6.1.4 requires the organisation to conduct AI system impact assessments at planned intervals and whenever changes warrant. Annex A.5 expands with four specific controls:
- A.5.2, AI system impact assessment process
- A.5.3, Documentation of AI system impact assessments
- A.5.4, Assessing impacts on individuals or groups
- A.5.5, Assessing societal impacts
In the Starter tier, AIMS-08 is the Procedure and AIMS-09 is the Record template. In the Professional tier, three industry-tuned variants (SaaS, FinTech, HealthTech) add regulator-specific overlays.
What the EU AI Act requires (Article 27 FRIA)
The EU AI Act requires deployers of certain high-risk AI systems (especially in public services, private essential services, and large-scale employment decisions) to conduct a Fundamental Rights Impact Assessment before putting the system into use. The FRIA must cover:
- Purpose of the deployment and context
- Period and frequency of use, and categories of persons affected
- Specific risks of harm to affected groups
- Human oversight measures
- Measures to mitigate risks and complaint-handling procedures
A well-designed AIMS impact assessment (ISO 42001 6.1.4) can incorporate the FRIA requirements, producing one assessment that satisfies both.
What the Colorado AI Act requires
Colorado's original AI Act (SB 24-205) required deployers of high-risk AI systems to conduct impact assessments; that mandate was repealed by SB 189 (May 2026, effective 1 January 2027). Impact assessments nonetheless remain best practice and are required under other regimes such as the EU AI Act. A robust assessment covers:
- Purpose, intended uses, deployment context, benefits
- Analysis of whether deployment poses risks of algorithmic discrimination and mitigation steps
- Description of input and output data categories
- Metrics used to evaluate performance and limitations
- Transparency measures
- Post-deployment monitoring and oversight processes
ISO 42001 impact-assessment alignment supports the documentation expectations under Colorado's SB 189 and the EU AI Act.
Structure of a unified AIIA
A single assessment template can satisfy all three frameworks if it covers these sections:
- System identification, name, version, owner, vendor (if applicable), scope
- Purpose and context, intended use, foreseeable misuse, deployment environment
- Affected parties, individuals, groups, society; whose fundamental rights are at stake
- Data, inputs, outputs, training data, personal data categories
- Algorithmic discrimination analysis, protected-characteristic considerations, bias testing
- Performance metrics, accuracy, robustness, explainability where measurable
- Human oversight, who reviews what, when, with what authority
- Mitigation measures, what controls reduce identified risks
- Transparency measures, disclosure to users, documentation for interested parties
- Monitoring and review, post-deployment monitoring, review cadence, triggers for re-assessment
- Complaint handling, how affected individuals raise concerns
- Sign-off, risk owner, system owner, reviewer, approver
AIMS-09 in the Starter tier implements this structure. The industry variants in the Professional tier extend with sector-specific prompts.
When to conduct assessments
- Before a new AI system enters the AIMS scope
- Before a significant change to an existing in-scope system (new training data source, new use case, architecture change)
- At least annually for systems in production
- After any serious incident involving the system
- When external context changes materially (new regulation, new risk evidence)
Who performs the assessment
A good AIIA is multidisciplinary. The system owner brings technical knowledge; a risk/compliance lead brings governance framing; a domain expert (legal, HR, clinical depending on the use case) brings impact-domain understanding; where possible, someone representing affected stakeholders (or at least empathetic to them) participates. A single technical author typically produces an assessment that misses the non-technical dimensions.