Policy Register

AI system impact assessment procedure

When and how the effect of an AI system on individuals, groups and society is assessed, documented and acted on before and after deployment.

How the register reads it

Also calledalgorithmic impact assessment, AI risk assessment
FamilyAI and automated decisions
Document typeProcedure. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Folds intoThe regimes accept it folded into the ai governance policy; when neither is listed, the gap is counted once, under the parent.
Expected ownerThe AI governance lead (CTO, CDO or head of data science).
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenISO 42001 is ticked and no line resolves to it or to its parent (GDPR requires it too, inside a parent document, so it does not list it separately).
TemplateNo template yet. The clauses below say what the document is expected to contain.

Which standards require it, and what each expects it to contain

4 requiring clauses, 2 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 42001:2023

ISO 42001 A.5.2 AI system impact assessment process

The organization shall establish a process to assess the potential consequences of the AI system for individuals or groups and societies.

Evidence an auditor accepts: AI impact assessment procedure; assessment template; methodology covering individuals, groups, societies
Common gap: Does the procedure require consultation with affected stakeholders?
Source: ISO/IEC 42001:2023
ISO 42001 A.5.3 Documentation of AI system impact assessments

Documented information on the AI system impact assessment shall be maintained and made available to relevant interested parties.

Evidence an auditor accepts: Completed assessments; distribution records; per-system assessment reports
Common gap: Are assessments made available externally where required (e.g., EU AI Act)?
Source: ISO/IEC 42001:2023
ISO 42001 A.5.4 Assessing AI system impact on individuals or groups

The organization shall assess and document the potential impacts of AI systems to individuals or groups of individuals throughout the system's life cycle.

Evidence an auditor accepts: Per-system impact assessments; fairness analysis; privacy impact (link to PIA where relevant)
Common gap: Are demographic-specific impacts analyzed where relevant?
Source: ISO/IEC 42001:2023

GDPR (Regulation (EU) 2016/679)

GDPR Art. 35 Data protection impact assessment

Where a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data before the processing begins; a single assessment may address a set of similar operations presenting similar risks. An assessment is required in particular for systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions producing legal or similarly significant effects are based, for large scale processing of special category or criminal offence data, and for systematic monitoring of a publicly accessible area on a large scale. Seek the advice of the data protection officer where one is designated, and where appropriate seek the views of data subjects or their representatives. The assessment must contain at least a systematic description of the envisaged operations and purposes including any legitimate interest pursued, an assessment of the necessity and proportionality of the operations in relation to the purposes, an assessment of the risks to the rights and freedoms of data subjects, and the measures envisaged to address those risks including safeguards, security measures and mechanisms to protect personal data and demonstrate compliance. Carry out a review where necessary and at least when the risk represented by the processing operations changes.

Evidence an auditor accepts: The screening or threshold process applied to new and changed processing, with its outcomes recorded including the negative ones; completed assessments checked against the four minimum content elements Article 35(7) requires; the data protection officer's advice sought and given on each assessment, recorded as advice rather than as approval
Common gap: An assessment opened at project start and never revisited, so its residual risk conclusion is never tested against how the processing actually turned out
Source: GDPR (Regulation (EU) 2016/679)

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

AI system development and operation standard · AI use policy (acceptable AI use)