Chapter 13

Annex A Controls: Assessing Impacts of AI Systems (A.5)

Detailed guidance on implementing Annex A controls for AI impact assessment (A.5), covering individual and societal impacts with 4 controls.

20 min read

Chapter Overview

This chapter covers the Assessing Impacts of AI Systems domain (A.5), which ensures organizations evaluate how AI systems affect individuals and society. This domain contains 4 controls and directly supports Clause 8.4 (AI System Impact Assessment).

A.5 Assessing Impacts of AI Systems

This domain requires systematic assessment of AI impacts on individuals and society.

A.5.2 Assessing Impacts on Individuals

AttributeDetails
ControlPotential positive and negative impacts of AI systems on individuals shall be assessed and documented.
PurposeUnderstand and manage how AI affects people
Related Clause8.4 (AI system impact assessment)

Implementation Guidance

  • Identify individuals affected by each AI system
  • Assess both positive and negative impacts
  • Consider direct and indirect impacts
  • Evaluate impacts across different user groups
  • Pay special attention to vulnerable populations
  • Document assessment methodology and results

Individual Impact Categories

CategoryPositive ImpactsNegative Impacts
Rights & FreedomsEnhanced access to servicesPrivacy violations, discrimination
Safety & HealthImproved safety predictionsPhysical harm, mental health impacts
EconomicBetter financial decisionsJob displacement, unfair denial of services
AutonomyAugmented decision-makingReduced agency, manipulation
DignityPersonalized experiencesDehumanization, unfair profiling
AccessImproved service accessDigital exclusion, accessibility barriers

Vulnerable Groups Consideration

Vulnerable Populations

Pay special attention to impacts on:
• Children and elderly
• People with disabilities
• Minority groups
• Economically disadvantaged
• Those with limited digital literacy
• People in dependent relationships (employees, patients, students)

Audit Questions - A.5.2

• How do you assess impacts on individuals?
• Show me an impact assessment for [specific AI system]
• How do you identify affected individuals?
• How do you consider vulnerable groups?
• What positive impacts have you identified?
• What negative impacts have you identified and how are they mitigated?

A.5.3 Assessing Societal Impacts

AttributeDetails
ControlPotential positive and negative societal impacts shall be assessed and documented.
PurposeUnderstand and manage broader societal effects of AI
Related Clause8.4 (AI system impact assessment)

Implementation Guidance

  • Consider impacts beyond direct users
  • Assess effects on communities and society
  • Evaluate economic and labor market impacts
  • Consider environmental implications
  • Assess democratic and cultural impacts
  • Document methodology and findings

Societal Impact Categories

CategoryPositive ImpactsNegative Impacts
Social CohesionImproved connectivityPolarization, filter bubbles
EconomicProductivity gainsWealth concentration, job displacement
DemocraticEnhanced civic participationMisinformation, manipulation
EnvironmentalEfficiency improvementsEnergy consumption, e-waste
CulturalPreservation, accessibilityHomogenization, bias amplification
SecurityThreat detectionSurveillance, weapons
Societal Impact Assessment Questions

Consider these questions:
• What happens if this AI system is widely adopted?
• Could this AI system be misused at scale?
• Does this AI system affect labor markets?
• What are the environmental implications?
• Could this AI system affect democratic processes?
• Does this AI system concentrate power or resources?

Audit Questions - A.5.3

• How do you assess societal impacts?
• What societal impacts have you identified?
• How do you consider environmental impacts?
• How do you evaluate impacts on employment?
• Show me documentation of societal impact assessment

A.5.4 Assessment Documentation

AttributeDetails
ControlResults of AI system impact assessments shall be documented, including the methodology used.
PurposeEnsure assessments are traceable and reviewable
Related Clause7.5 (Documented information)

Implementation Guidance

  • Define standard assessment methodology
  • Create assessment templates
  • Document assessment scope and context
  • Record all identified impacts
  • Document mitigation measures
  • Maintain assessment version history
  • Make assessments accessible for review

Documentation Requirements

ElementContent
MethodologyAssessment approach, criteria, scales used
ScopeAI system, affected parties, boundaries
ContextUse case, deployment environment
FindingsIdentified impacts (positive and negative)
AnalysisLikelihood, severity, affected groups
MitigationsMeasures to address negative impacts
ConclusionsOverall assessment, recommendations
ApprovalsReviewer and approver signatures
Audit Questions - A.5.4

• What is your impact assessment methodology?
• Show me a completed impact assessment document
• How do you ensure consistency across assessments?
• Who reviews and approves assessments?
• How do you maintain assessment records?

A.5.5 AI System Impact Assessment Status

AttributeDetails
ControlThe status of AI system impact assessments shall be tracked.
PurposeEnsure assessments are complete and current
Related Clause9.1 (Monitoring, measurement, analysis and evaluation)

Implementation Guidance

  • Maintain register of all AI systems requiring assessment
  • Track assessment completion status
  • Define reassessment triggers and schedules
  • Monitor for changes requiring reassessment
  • Report status to management
  • Escalate overdue assessments

Assessment Status Tracking

StatusDescription
Not StartedAssessment required but not initiated
In ProgressAssessment underway
Under ReviewAssessment complete, awaiting approval
ApprovedAssessment approved, valid
Reassessment DueScheduled reassessment approaching
ExpiredAssessment no longer valid, reassessment required
Impact Assessment Register

Track for each AI system:
• AI System ID and name
• Assessment requirement (required/not required)
• Current assessment status
• Assessment date
• Assessor name
• Approver name
• Next reassessment date
• Reassessment triggers
• Link to assessment document

Audit Questions - A.5.5

• How do you track impact assessment status?
• Show me your assessment status register
• Are any assessments overdue?
• What triggers reassessment?
• How often are assessments reviewed?

Control Implementation Summary

ControlKey EvidenceCommon Gaps
A.5.2 Individual ImpactsImpact assessments with individual impact analysisOnly negative impacts considered
A.5.3 Societal ImpactsSocietal impact sections in assessmentsSocietal impacts overlooked
A.5.4 DocumentationComplete assessments with methodologyInconsistent documentation
A.5.5 Status TrackingAssessment register, status reportsNo tracking mechanism
Key Takeaways - A.5

1. Impact assessment must cover BOTH individuals AND society
2. Both positive AND negative impacts must be assessed
3. Vulnerable groups require special consideration
4. Documentation must include methodology used
5. Assessment status must be tracked for all AI systems
6. Regular reassessment is required when changes occur

AI Assistant
00:00