In an AI context
Impact assessment is an old instrument — environmental, equality and privacy versions long predate AI — and the AI variant inherits the shape while changing the subject. The question is no longer "is this processing lawful" but "what happens to people when this system works as designed, and what happens when it does not."
Three features distinguish it from the risk assessments sitting next to it in most governance programmes.
It is outward-facing. A risk assessment asks what could harm the organisation. An impact assessment asks what the organisation could do to everyone else — the people a decision is made about, the groups disproportionately affected, and the wider structures the deployment reinforces. Organisations that run one as an inward-facing risk exercise with the labels changed produce a document that satisfies nobody, least of all a regulator.
It covers correct operation, not just failure. The most consequential harms from AI frequently arise when the system does exactly what it was built to do — at a scale, speed or consistency no human process would have applied. An assessment that only enumerates failure modes misses the category entirely.
It has to happen before deployment to mean anything. An impact assessment produced after go-live is a description. The instrument's whole value is that it can still change the design, the scope, or the decision to proceed at all.
The four assessments people mean by this term
Most of the confusion in this area is one word doing four jobs.
AI impact assessment (AIA). The general instrument, and what ISO/IEC 42001 Clause 6.1.4 requires: an assessment of the consequences that development, deployment, intended use or foreseeable misuse of an AI system could have on individuals, groups and society. Not tied to any single regulation, and the broadest of the four.
Data protection impact assessment (DPIA). Required under UK and EU GDPR Article 35 where processing is likely to result in a high risk to the rights and freedoms of natural persons. Its subject is the processing of personal data — lawful basis, necessity, proportionality, security. Many AI deployments trigger one; it does not, on its own, discharge any AI-specific obligation.
Fundamental rights impact assessment (FRIA). The EU AI Act Article 27 instrument. Narrower in who must do it and wider in what it covers: dignity, non-discrimination, freedom of expression, access to an effective remedy — rights a DPIA was never designed to evaluate.
Algorithmic impact assessment. A public-sector convention, most developed in Canada and parts of the UK public sector, typically scoring a system's consequence level and attaching proportionate requirements. Usually a policy instrument rather than a statutory one.
A fifth phrase, system-level impact assessment, is not a separate instrument. It refers to assessing the deployed system as a whole — model, data, interface, human process and downstream decision together — rather than assessing the model in isolation. It is a scoping choice, and the correct one: almost every real-world harm arises from the assembly, not the model.
How they differ, in the way that matters
The distinction that changes what you do is what the assessment is about, not who publishes it.
A DPIA asks whether you may lawfully process this data. A FRIA asks what this decision does to a person's rights. An AIA asks what this system does to people and society generally. They overlap substantially in evidence and barely at all in conclusion — which is why an organisation can hold a complete, competent DPIA and still have no answer to the question a FRIA asks.
Where they overlap, they may be combined; Article 27 anticipates this, and a combined document is usually better than two documents that cite each other. What does not work is treating one as a substitute for another because the evidence-gathering looked similar.
Who has to do one, and when
DPIA — any controller, under UK or EU GDPR Article 35, where processing is likely to result in high risk to individuals. Long-standing law, in force now.
FRIA — under EU AI Act Article 27, deployers of certain high-risk systems: bodies governed by public law, private entities providing public services, and deployers of the Annex III high-risk systems covering creditworthiness evaluation and risk assessment and pricing in life and health insurance. It must be completed before first use and updated when the system or its use changes.
Its application date is currently an open question and worth resolving against primary text rather than commentary. Article 27 sits in Chapter III Section 3 of the Act, and the AI Omnibus deferred Chapter III obligations for Annex III systems from 2 August 2026 to 2 December 2027. On the structural reading, Article 27's application follows that deferral. Some pre-adoption commentary argued the deferral did not reach Article 27; that commentary was written against the proposal rather than the adopted text.
AIA — anyone operating an ISO/IEC 42001 management system, under Clause 6.1.4, and as a matter of defensible practice for anyone deploying a consequential system regardless of whether a specific regulation compels it.
Where it appears in frameworks
ISO/IEC 42001, Clause 6.1.4 is the requirement most directly on point, and the one genuinely unique to AI management systems: an AI system impact assessment covering consequences for individuals, groups and society, whose findings feed back into the risk assessment rather than sitting beside it.
EU AI Act, Article 27 sets the FRIA obligation, its scope and its required content.
UK and EU GDPR, Article 35 sets the DPIA obligation, and Article 36 the consultation duty where residual high risk remains.
NIST AI RMF does not use the term, but its MAP function covers the same ground — establishing context, identifying affected individuals and communities, and characterising impacts before measurement and management begin.
Frequently asked questions
What is an AI impact assessment? A structured evaluation, carried out before deployment, of what an AI system will do to the people and groups it affects — in correct operation as well as in failure. It differs from a risk assessment in direction: a risk assessment protects the organisation, an impact assessment examines what the organisation does to everyone else.
What is the difference between a DPIA and an AI impact assessment? A DPIA examines whether the processing of personal data is lawful, necessary and proportionate. An AI impact assessment examines the consequences of the decision the system produces. An AI system can pass a DPIA comfortably and still cause the harms an impact assessment exists to surface — and a system that processes no personal data at all needs no DPIA while potentially warranting a substantial impact assessment.
What is a FRIA, and does my organisation need one? A fundamental rights impact assessment under EU AI Act Article 27. It is required of deployers that are public bodies, private entities providing public services, or deployers of the high-risk systems covering creditworthiness assessment and life and health insurance pricing. If your organisation is none of those, Article 27 does not bind you — though the underlying question remains worth answering.
What is a system-level impact assessment? Assessing the whole deployed system — model, data, interface, human process and downstream decision — rather than the model alone. It is a scoping decision rather than a distinct instrument, and it is the correct scope: harms almost always arise from the assembly rather than the model in isolation.
Who is responsible for carrying one out? For a FRIA, the deployer, not the provider — the organisation putting the system into use in a specific context, because context is what the assessment is about. For a DPIA, the controller. For an ISO/IEC 42001 impact assessment, the organisation operating the management system. In all three, a named accountable owner rather than a function, since an assessment nobody owns is an assessment nobody updates.
How do I actually run one? Deliberately out of scope for this definition. The step-by-step process, its inputs and the evidence it should produce are covered by the AI impact assessment process control entry.