AI system impact assessment procedure
When and how the effect of an AI system on individuals, groups and society is assessed, documented and acted on before and after deployment.
How the register reads it
| Also called | algorithmic impact assessment, AI risk assessment |
|---|---|
| Family | AI and automated decisions |
| Document type | Procedure. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Folds into | The regimes accept it folded into the ai governance policy; when neither is listed, the gap is counted once, under the parent. |
| Expected owner | The AI governance lead (CTO, CDO or head of data science). |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | ISO 42001 is ticked and no line resolves to it or to its parent (GDPR requires it too, inside a parent document, so it does not list it separately). |
| Template | No template yet. The clauses below say what the document is expected to contain. |
Which standards require it, and what each expects it to contain
4 requiring clauses, 2 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 42001:2023
ISO 42001 A.5.2 AI system impact assessment processThe organization shall establish a process to assess the potential consequences of the AI system for individuals or groups and societies.
Common gap: Does the procedure require consultation with affected stakeholders?
Source: ISO/IEC 42001:2023
ISO 42001 A.5.3 Documentation of AI system impact assessmentsDocumented information on the AI system impact assessment shall be maintained and made available to relevant interested parties.
Common gap: Are assessments made available externally where required (e.g., EU AI Act)?
Source: ISO/IEC 42001:2023
ISO 42001 A.5.4 Assessing AI system impact on individuals or groupsThe organization shall assess and document the potential impacts of AI systems to individuals or groups of individuals throughout the system's life cycle.
Common gap: Are demographic-specific impacts analyzed where relevant?
Source: ISO/IEC 42001:2023
GDPR (Regulation (EU) 2016/679)
GDPR Art. 35 Data protection impact assessmentWhere a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data before the processing begins; a single assessment may address a set of similar operations presenting similar risks. An assessment is required in particular for systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions producing legal or similarly significant effects are based, for large scale processing of special category or criminal offence data, and for systematic monitoring of a publicly accessible area on a large scale. Seek the advice of the data protection officer where one is designated, and where appropriate seek the views of data subjects or their representatives. The assessment must contain at least a systematic description of the envisaged operations and purposes including any legitimate interest pursued, an assessment of the necessity and proportionality of the operations in relation to the purposes, an assessment of the risks to the rights and freedoms of data subjects, and the measures envisaged to address those risks including safeguards, security measures and mechanisms to protect personal data and demonstrate compliance. Carry out a review where necessary and at least when the risk represented by the processing operations changes.
Common gap: An assessment opened at project start and never revisited, so its residual risk conclusion is never tested against how the processing actually turned out
Source: GDPR (Regulation (EU) 2016/679)
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a registerAI system development and operation standard · AI use policy (acceptable AI use)