Checklist for Clause 8.4 of ISO/IEC 42001 (AIMS): AI System Impact Assessment

1. Introduction

Below is a certification-grade, auditor-ready tabular checklist for Clause 8.4 of ISO/IEC 42001 - AI System Impact Assessment, built directly from the PECB auditing slides and structured to meet PECB / IAS-accredited audit expectations.

This checklist ensures AI system impact assessments are performed at the right times, triggered by change, aligned with Clause 6.1.4, and fully documented with technical and societal context.

2. ISO/IEC 42001 - Clause 8.4: AI System Impact Assessment

Audit Checklist (Intervals, Change Triggers, Compliance & Records)


# Clause 8.4 Requirement Area Audit Objective Audit Questions (Checklist) Expected Evidence Conformance (Y/N/Partial) Findings / Gaps Risk Rating Improvement Actions
8.4-1 Defined Impact-Assessment Intervals Confirm scheduling Has the organization defined planned intervals for conducting AI system impact assessments? Assessment schedule     
8.4-2 Interval Adequacy Validate frequency Are intervals appropriate to AI system risk, criticality, and lifecycle stage? Rationale for frequency     
8.4-3 Change-Triggered Assessments Ensure responsiveness Are impact assessments conducted when significant changes are proposed or occur? Change logs; assessment triggers     
8.4-4 Significant-Change Definition Prevent ambiguity Are significant changes clearly defined (model changes, data shifts, context, scale, or purpose)? Change-classification criteria     
8.4-5 Change-Detection Mechanisms Detect triggers Does the organization have mechanisms to identify when changes require an impact assessment? Monitoring alerts; procedures     
8.4-6 Adherence to Clause 6.1.4 Confirm compliance Are impact assessments performed in accordance with Clause 6.1.4 requirements? Methodology alignment     
8.4-7 Technical Context Consideration Ensure completeness Do assessments consider the specific technical context of the AI system (architecture, data, environment)? Technical impact analysis     
8.4-8 Societal Context Consideration Address external effects Do assessments consider societal impacts (individuals, groups, communities)? Societal impact sections     
8.4-9 Individual & Group Impacts Protect stakeholders Are potential impacts on individuals or groups explicitly assessed? Impact matrices     
8.4-10 Lifecycle Coverage Ensure scope Are impacts assessed across development, provision, use, and retirement of AI systems? Lifecycle mapping     
8.4-11 Integration with Risk Management Enable action Are impact-assessment outcomes integrated into AI risk management and treatment? Linked risk records     
8.4-12 Documentation Retention Provide evidence Does the organization retain documented information of all AI system impact assessment results? Stored assessments     
8.4-13 Content Sufficiency Ensure auditability Do records include identified consequences, context considered, and conclusions? Completed templates     
8.4-14 Traceability Support audit Can impact assessments be traced to specific AI systems, versions, and dates? Traceability links     
8.4-15 Accessibility Enable use Are assessment records accessible to authorised personnel when needed? Access-control evidence     
8.4-16 Protection of Records Safeguard integrity Are records protected against loss, unauthorised access, or alteration? Security controls     
8.4-17 Review & Update Maintain currency Are impact assessments reviewed and updated after incidents, complaints, or new information? Review logs     
8.4-18 Management Oversight Confirm accountability Does management review AI system impact assessment outcomes? Management-review minutes     


3. Auditor's Conclusion - Clause 8.4

Assessment Area Conclusion
Overall Conformance Status ☐ Conform ☐ Minor NC ☐ Major NC
Timeliness of Impact Assessments ☐ Timely ☐ Inconsistent ☐ Reactive
Alignment with Clause 6.1.4 ☐ Strong ☐ Partial ☐ Weak
Risk of Unassessed Impacts ☐ Low ☐ Medium ☐ High

4. Common Auditor Findings (Clause 8.4)

Auditors frequently raise findings where:

  • Impact assessments are performed once only and not revisited
  • Significant technical or contextual changes do not trigger reassessment
  • Societal impacts are mentioned superficially
  • Records lack clear linkage to specific AI systems or versions
  • Results are documented but not integrated into risk treatment

This checklist explicitly closes those gaps.

5. ISOLTX Operational Alignment

Clause 8.4 is operationalised through:

  • ERMS → Impact-driven risk updates
  • I²MAS → Incident-triggered reassessments
  • DMS → Controlled impact-assessment records
  • AUDIT → Verification of triggers and methodology
  • PERFORMANCE → Impact trend indicators

It ensures AI system impact assessment is continuous, context-aware, and audit-defensible.

6. Contact Us Today

Are you looking to grow into an Artificial Intelligence (AI) trusted company?

Contact Crest Advisory Africa today for expert guidance on implementing ISO 42001 frameworks tailored to your organization's needs.

Start your journey today. Visit crestadvisoryafrica.com or contact us at +27 (0) 764034307 or nico@crestadvisoryafrica.com.

Let's make 2026 the year of your professional breakthrough!