SekitCrosswalk
ISO/IEC 42001:2023 — Annex A · derived mapping target

A.5.2AI system impact assessment process

Operate a repeatable impact assessment process before deployment and when material changes alter an AI system’s effects.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

ISO/IEC 27001:2022 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

NIST CSF 2.0 counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

AI system impact assessment
The procedure for assessing an AI system's impact before you use it and whenever it changes materially, plus the assessments already done: who it could affect, what risks and wider effects it has, and who approved the decision.
From the Sekit evidence catalog

In practice

Before a company turns on a new AI feature or vendor chatbot, someone has to ask what could go wrong for the people affected, not only for the business. The AI system impact assessment records who reviewed the tool, what risks it carries (bias, wrong outputs, data exposure) and who signed off before go-live. Auditors look for a repeatable trigger, any new AI tool or material change gets an assessment, and check whether the last three tool adoptions have one on file rather than the process existing only for the flagship system.

Common gaps

The impact assessment template exists but no one applied it to the AI vendor tool the sales team adopted last quarter.
A material change to an AI system, a new data source or a model swap, does not trigger a fresh assessment.
The DPIA covers personal data risk but never asks whether the AI output itself could unfairly affect a person.

Questions your auditor will ask

What triggers a new AI impact assessment?
Adopting a new AI system or making a material change to one already in use, as defined in the AI system impact assessment procedure.
Who signs off on the assessment before an AI tool goes live?
A named approver reviews the risks and effects recorded in the assessment and documents the go-live decision.
Does the assessment overlap with your privacy DPIA?
Yes, where the AI system processes personal data the DPIA trigger and process are reused rather than duplicated.
How do you show this is repeatable rather than a one-time exercise?
Each AI tool adoption on file has its own dated assessment, not one single template reused from the initial rollout.

Where regulation demands it

GDPR Article 35.1 requires a DPIA for high-risk processing, which an AI impact assessment can satisfy when personal data is involved.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.5.2?”
Also via MCP, free with account