---
title: "AI system impact assessment: DPIA, the AI Act, and ISO/IEC 42001 compared"
url: https://zerofive.ai/en/blog/compliance/ai-impact-assessment-dpia-ai-act-iso-42001
canonical: https://zerofive.ai/en/blog/compliance/ai-impact-assessment-dpia-ai-act-iso-42001
language: en
published: 2026-09-03
updated: 2026-09-18
author: "ZeroFive.AI"
tags: ISO IEC 42001, impact assessment, DPIA, AI Act, AI risk assessment
abstract: "DPIA, AI Act conformity assessment, and ISO 42001 impact assessment: what each actually evaluates, and how to avoid running three separate ones."
---

# AI system impact assessment: DPIA, the AI Act, and ISO/IEC 42001 compared

In a recent assessment we ran into three different documents, produced by three different consultants, all answering the same question: is this AI system risky? None of the three knew the other two existed, and none of them actually covered the full risk perimeter.

## Three assessments, three different purposes

The DPIA comes from the GDPR and looks at personal data: what gets collected, on what legal basis, with what impact on the individual. The AI Act conformity assessment looks at classifying the system by risk tier, and the obligations that follow if it lands in Annex III. The AI system impact assessment required by ISO/IEC 42001 covers an even wider perimeter: not just data, not just regulatory classification, but the overall impact on people, the organization, and society, including impact that never touches privacy and never falls into the AI Act's high-risk categories.

An internal recommendation system that processes no sensitive personal data might not need a DPIA, might sit outside the AI Act's critical categories, and can still need an ISO 42001 impact assessment, because it shapes decisions affecting real people.

## Where they overlap (and where they don't)

- **Data perimeter**: covered by all three, but the DPIA goes deep on it while the other two treat it as just one risk dimension among several
- **Risk classification**: almost exclusively an AI Act concern, ISO 42001 references it as an input without replacing it
- **Impact on groups that can't be individually identified**: bias across categories of people, systemic effects, ground the DPIA doesn't cover and ISO 42001 addresses explicitly
- **Governance and accountability**: who approved it, who answers for it, present in all three but often with different owners, a privacy officer for the DPIA, a risk owner for the AI Act, a process owner for ISO 42001

The overlap itself matters less than the real risk it creates: three different offices producing three parallel assessments that never talk to each other, each one convinced it has covered the whole problem.

## One process, three lenses

Organizations that handle this well don't write three separate documents, they build a single assessment process with modular sections: a shared part that gathers the facts about the system, what data it uses, what decisions it automates, who's involved, then three lenses applied to those same facts. A company with a mature DPIA practice has already done eighty percent of the work, it just needs to add the missing questions.

## Who talks to whom, before the system ships

A unified process on its own isn't enough if privacy, risk, and AI governance keep working in separate rooms: more than shared templates, what matters is who talks to whom before the system goes into production, not after someone has already signed off on the launch. This, not the mechanics of the assessment itself, is usually where organizations lose weeks to avoidable rework.

## Before writing the first assessment

Anyone starting this work does well to begin with one shared document rather than three separate modules, and to bring in whoever already runs the DPIAs instead of starting from zero. The next piece in this series covers the natural next step: the AI system inventory, the foundation without which no impact assessment really knows what it's evaluating.
