Comply · International standards
ISO/IEC 42005:2025 — AI system impact assessment
Guidance for AI system impact assessment.
ISO/IEC 42005:2025 provides guidance on conducting AI system impact assessments — how and when to assess potential impacts of an AI system on individuals and society, what to document, and how to integrate the assessment into the AI lifecycle and an AI management system.
Who it applies to
Organizations performing structured AI impact assessments, often alongside ISO/IEC 42001.
Key obligations
- Define when and how to perform AI impact assessments
- Document scope, impacts, and mitigations
- Integrate assessments into the AI lifecycle
- Review and update assessments over time
How Maetra maps agents to ISO/IEC 42005
Maetra generates and versions impact-assessment evidence per agent, aligned to the standard's structure. (Licensed standard — activated on demand.)
In practice, Maetra:
- Scans and fingerprints each agent. Discover reads the agent’s code — its tools, data access and sensitivity, actions, model, and environment — into an evidence-backed profile tied to the exact file and commit.
- Decides what applies. That profile determines whether ISO/IEC 42005 is in scope for the agent and which of its requirements apply.
- Auto-detects controls and surfaces gaps. Controls your code already satisfies are detected automatically from the scan; the rest become a clear list of gaps, each tied to the requirement and the evidence it still needs.
- Proves it and keeps it current. Close gaps with linked evidence or generated documents — reused across every framework the same control supports — and Maetra re-checks on each rescan and flags evidence that has gone stale.
Related frameworks
Prove ISO/IEC 42005 compliance with Maetra
Classify your AI agents once and Maetra maps them to ISO/IEC 42005 and every other framework it supports — generating the evidence and documentation, tracking gaps and deadlines, and sealing every decision in an immutable audit trail.