The organization is required to institute and maintain a formal methodology for evaluating the potential effects of its artificial intelligence systems. This evaluation must scrutinize the consequences arising from the entire AI system lifecycle—including its planned applications and foreseeable abuses—on individuals, communities, and society as a whole. Such an analysis must be grounded in the specific technical, societal, and legal environment where the system operates. The conclusions of this impact analysis must be officially documented, serving as a foundational element for the AI risk assessment framework. Where suitable, these findings may be disclosed to pertinent stakeholders in accordance with the controls specified in Annex A.






The organization must formally conduct AI system impact assessments according to the process established during its initial planning (as per ISO 42001 section 6.1.4).
These impact assessments, which evaluate the system's effect on individuals and society, must be performed at two key intervals:
Following every assessment, the organization must create and maintain documented information recording the findings, analysis, and conclusions of the impact assessment process.






The organization should establish a process for assessing the potential impacts of AI systems on individuals, groups, and society throughout their entire lifecycle. This process should define how impacts are identified, analyzed, evaluated, and mitigated, and how these assessments are reviewed and updated regularly.






The organization has defined procedures for assessing and treating risks to fundamental rights. The definition includes at least:






The organization should ensure that its AI system impact assessments are thoroughly grounded in the specific technical, societal, and legal environment in which the AI system operates. This involves analyzing relevant technical constraints, prevailing societal norms and values, and applicable legal and regulatory frameworks to accurately evaluate potential impacts.






The organization should systematically identify and evaluate potential foreseeable abuses of its artificial intelligence systems throughout their lifecycle. This assessment should consider how the system could be intentionally or unintentionally misused, exploited, or lead to unintended harmful outcomes, and integrate these findings into the overall impact assessment.
Digiturvamallissa kaikki vaatimuskehikkojen vaatimukset kohdistetaan universaaleihin tietoturvatehtäviin, jotta voitte muodostaa yksittäisen suunnitelman, joka täyttää ison kasan vaatimuksia.
.png)