For Heads-of · Practitioner
AI impact assessment process
A mandatory, structured assessment of an AI system's impact on individuals, groups, and society, completed before deployment.
- directive
- governance
- impact-assessment
- policy
What it does
Requires a documented impact assessment covering affected individuals, foreseeable harms, and mitigations, signed off before an AI system is allowed to go live.
Where it fits
The upstream gate that is meant to catch fairness, transparency, and oversight gaps before they reach production, not after.
How this differs from a DPIA or a FRIA
This entry covers how to run the assessment. For what an AI impact assessment actually is, and how it differs from a data protection impact assessment and a fundamental rights impact assessment, see AI impact assessment in the glossary.
Risks this mitigates
The risks this control addresses, ranked by effectiveness.
AI system lifecycle controls gap
AI systems lack defined lifecycle controls, so changes ship without a consistent governance checkpoint from requirements through decommissioning.
Missing AI impact assessment process
AI systems are deployed without a structured process to assess their impact on individuals, groups, and society before go-live.
Inadequate fairness testing before deployment
An AI system used in a high-risk domain is deployed without pre-deployment testing for disparate performance or outcomes across demographic groups.
Missing DPIA for high-risk AI processing
AI processing likely to result in high risk to individuals proceeds without a documented Data Protection Impact Assessment.
Framework and clause references
| Framework | Clause | Title |
|---|---|---|
| ISO/IEC 42001:2023 | Annex A.5 | Assessing impacts of AI systems |
| EU AI Act | Article 9 | Risk management system |