Checklist for Clause 8.5 of ISO/IEC 42001 (AIMS): AI System Development

1. Introduction

Below is a certification-grade, auditor-ready tabular checklist for Clause 8.4 of ISO/IEC 42001 - AI System Impact Assessment, built directly from the PECB auditing slides and structured to meet PECB / IAS-accredited audit expectations.

This checklist ensures AI system impact assessments are performed at the right times, triggered by change, aligned with Clause 6.1.4, and fully documented with technical and societal context.

2. ISO/IEC 42001 - Clause 8.4: AI System Impact Assessment

Audit Checklist (Intervals, Change Triggers, Compliance & Records)


#

Clause 8.4 Requirement Area

Audit Objective

Audit Questions (Checklist)

Expected Evidence

Conformance (Y/N/Partial)

Findings / Gaps

Risk Rating

Improvement Actions

8.4-1

Defined Impact-Assessment Intervals

Confirm scheduling

Has the organization defined planned intervals for conducting AI system impact assessments?

Assessment schedule

8.4-2

Interval Adequacy

Validate frequency

Are intervals appropriate to AI system risk, criticality, and lifecycle stage?

Rationale for frequency

8.4-3

Change-Triggered Assessments

Ensure responsiveness

Are impact assessments conducted when significant changes are proposed or occur?

Change logs; assessment triggers

8.4-4

Significant-Change Definition

Prevent ambiguity

Are significant changes clearly defined (model changes, data shifts, context, scale, or purpose)?

Change-classification criteria

8.4-5

Change-Detection Mechanisms

Detect triggers

Does the organization have mechanisms to identify when changes require an impact assessment?

Monitoring alerts; procedures

8.4-6

Adherence to Clause 6.1.4

Confirm compliance

Are impact assessments performed in accordance with Clause 6.1.4 requirements?

Methodology alignment

8.4-7

Technical Context Consideration

Ensure completeness

Do assessments consider the specific technical context of the AI system (architecture, data, environment)?

Technical impact analysis

8.4-8

Societal Context Consideration

Address external effects

Do assessments consider societal impacts (individuals, groups, communities)?

Societal impact sections

8.4-9

Individual & Group Impacts

Protect stakeholders

Are potential impacts on individuals or groups explicitly assessed?

Impact matrices

8.4-10

Lifecycle Coverage

Ensure scope

Are impacts assessed across development, provision, use, and retirement of AI systems?

Lifecycle mapping

8.4-11

Integration with Risk Management

Enable action

Are impact-assessment outcomes integrated into AI risk management and treatment?

Linked risk records

8.4-12

Documentation Retention

Provide evidence

Does the organization retain documented information of all AI system impact assessment results?

Stored assessments

8.4-13

Content Sufficiency

Ensure auditability

Do records include identified consequences, context considered, and conclusions?

Completed templates

8.4-14

Traceability

Support audit

Can impact assessments be traced to specific AI systems, versions, and dates?

Traceability links

8.4-15

Accessibility

Enable use

Are assessment records accessible to authorised personnel when needed?

Access-control evidence

8.4-16

Protection of Records

Safeguard integrity

Are records protected against loss, unauthorised access, or alteration?

Security controls

8.4-17

Review & Update

Maintain currency

Are impact assessments reviewed and updated after incidents, complaints, or new information?

Review logs

8.4-18

Management Oversight

Confirm accountability

Does management review AI system impact assessment outcomes?

Management-review minutes


3. Auditor's Conclusion - Clause 8.4

Assessment Area

Conclusion

Overall Conformance Status

☐ Conform ☐ Minor NC ☐ Major NC

Timeliness of Impact Assessments

☐ Timely ☐ Inconsistent ☐ Reactive

Alignment with Clause 6.1.4

☐ Strong ☐ Partial ☐ Weak

Risk of Unassessed Impacts

☐ Low ☐ Medium ☐ High

4. Common Auditor Findings (Clause 8.4)

Auditors frequently raise findings where:

  • Impact assessments are performed once only and not revisited
  • Significant technical or contextual changes do not trigger reassessment
  • Societal impacts are mentioned superficially
  • Records lack clear linkage to specific AI systems or versions
  • Results are documented but not integrated into risk treatment

This checklist explicitly closes those gaps.

5. ISOLTX Operational Alignment

Clause 8.4 is operationalised through:

  • ERMS → Impact-driven risk updates
  • I²MAS → Incident-triggered reassessments
  • DMS → Controlled impact-assessment records
  • AUDIT → Verification of triggers and methodology
  • PERFORMANCE → Impact trend indicators

It ensures AI system impact assessment is continuous, context-aware, and audit-defensible.

6. Contact Us Today

Are you looking to grow into an Artificial Intelligence (AI) trusted company?

Contact Crest Advisory Africa today for expert guidance on implementing ISO 42001 frameworks tailored to your organization's needs.

Start your journey today. Visit crestadvisoryafrica.com or contact us at +27 (0) 764034307 or nico@crestadvisoryafrica.com.

Let's make 2026 the year of your professional breakthrough!