The impact assessment must stay open
An AI impact assessment completed before launch becomes historical evidence unless the institution has rules for reopening it when the system, use, or world changes.
The easiest impact assessment to administer is the one that ends. A team describes the system, lists affected groups, scores foreseeable harms, approves mitigations, and attaches the document to a launch decision. The artifact is complete. The product moves. Six months later the model, user population, workflow, and surrounding institutions have changed, but the assessment still speaks in the present tense.
ISO/IEC 42005:2025 rejects the idea that impact assessment belongs only to design review. The public description of the standard places assessment across the AI system lifecycle, from design and development through deployment and post-market monitoring, with updates as needed. That lifecycle language changes the artifact from a launch form into an operating process.
The change is necessary because impact is relational. It does not reside entirely inside a model. It arises from a system used by particular people, for a particular purpose, under particular rules, with particular alternatives and remedies. Even a model that does not change can produce different effects when the institution around it does.
The object of assessment moves
A deployer may broaden the eligible population. A recommendation may become a default. A human reviewer may lose time as volume grows. An optional feature may become required to receive service. A vendor may replace the underlying model without changing the product name. Each change can alter impact while leaving the original system inventory apparently intact.
External conditions move as well. New evidence may reveal uneven error rates. A downstream market may begin relying on the output. A group excluded from early testing may become a major user population. A remedy that was practical at low volume may become inaccessible at scale. The assessment must be capable of learning facts that did not exist at approval.
An impact assessment that cannot be reopened is not a control. It is a dated description of hope.
Reopening should not depend on a conscientious employee remembering the document. The institution needs triggers. Material model changes, new data sources, changed purpose, expanded autonomy, altered thresholds, new affected groups, serious incidents, recurring complaints, and control failures should each force a review. The trigger list should be versioned and owned.
The trigger need not always produce a full reassessment. A triage can determine whether the change is material and document the basis. But a decision not to reopen is itself a lifecycle decision. It should leave evidence of what changed, who evaluated it, which prior assumptions remain valid, and when the question will next be reviewed.
Assessment must connect to operations
ISO/IEC 42005 complements the management-system approach of ISO/IEC 42001, which emphasizes establishing, implementing, maintaining, and continually improving organizational processes for AI. The connection matters. An impact assessment identifies obligations; a management system assigns the owners, controls, monitoring, and review cadence that keep those obligations alive.
Monitoring should follow the impact hypotheses, not only technical health. If the assessment identifies a risk that a subgroup will face more false rejections, operations must collect evidence capable of detecting that outcome. Uptime, latency, and aggregate accuracy cannot answer it. A risk with no observable indicator is a paragraph, not a managed condition.
Complaint and appeal channels are sensors in this system. They reveal effects that laboratory evaluation missed and classifications that aggregate metrics concealed. Treating complaints only as customer-service work strips them of governance value. The assessment process should specify how patterns in objections, reversals, and abandonment feed back into impact review.
The institution should also preserve superseded assessments. Later reviewers need to know what was believed when an action was authorized, what evidence existed, and which assumptions changed. Replacing the old document with the new one creates a current view while destroying the history needed to assess whether the organization responded reasonably as knowledge evolved.
Ownership cannot remain collective in the abstract. Each impact, mitigation, monitoring signal, and reassessment trigger needs an office capable of changing the system. A committee may review the whole account, but named operators must be able to gather evidence, suspend a use, contact affected groups, and bring unresolved tradeoffs to someone with authority.
Closure needs a condition
An assessment should state not only mitigations but closure conditions. What evidence would show that a risk has been reduced enough? Which residual impacts have been accepted, by whom, and for how long? What finding would require suspension rather than another mitigation plan? Without those conditions, the process can remain perpetually ‘in progress’ while the system continues unchanged.
Decommissioning needs assessment too. Removing a model does not remove decisions made with it, data derived from it, or dependencies built around its outputs. People may still be affected by scores in an archive. Appeals may still be pending. Replacement systems may inherit labels the old system produced. The lifecycle ends only when those obligations have an owner.
The Council of Europe’s Framework Convention on AI likewise frames consistency with human rights, democracy, and rule of law across AI system lifecycles. That breadth is a reminder that impact review is not a vendor exercise. Public and private institutions remain responsible for the contexts in which they choose to use the system.
A good impact assessment is therefore designed to be disturbed. New incidents should challenge it. New users should enlarge it. Model and policy changes should reopen it. Monitoring should test its predictions. Appeals should expose its blind spots. The document earns authority not by remaining stable, but by showing how the institution changes its judgment when the object of judgment moves.
— Dispatches · Summit Cognitive
Continue from here
Turn the argument into a practice.
Get new dispatches, assess how your organization handles consequential decisions, or explore Summit Cognitive.