What is an AI impact assessment?
An AI impact assessment is a structured review of how an AI system and its foreseeable use may affect people, groups, business processes and wider stakeholders. It documents the system context, affected parties, potential benefits and harms, material risks, existing controls, residual concerns, decision conditions and monitoring or reassessment actions.
When should an organisation conduct an AI impact assessment?
Useful trigger points include design approval, procurement, pre-deployment review, a material change in model or intended use, expansion to a new user group or jurisdiction, a significant incident, evidence of unexpected outcomes, or a governance review that identifies insufficient impact evidence. The right trigger depends on the organisation’s AI lifecycle and risk policy.
Which AI systems can be assessed?
The service can be scoped for predictive models, decision-support systems, automated decision systems, recommendation and ranking systems, computer vision, natural-language systems, generative AI, large language model applications, agentic workflows and third-party AI services. Scope should focus on the deployed use case and operating context, not only the underlying model.
How is an AI impact assessment different from AI risk classification?
Risk classification determines which risk tier, governance route or regulatory category may apply. An impact assessment examines the concrete effects that a specific AI use may have on affected stakeholders and the controls needed to manage those effects. Classification can therefore be an input to, or trigger for, a more detailed impact assessment.
How does this relate to the EU AI Act fundamental rights impact assessment?
Article 27 of the EU AI Act establishes a fundamental-rights impact assessment requirement for certain deployers of specified high-risk AI systems. An AI impact assessment can be structured to support relevant evidence and analysis, but applicability and legal sufficiency depend on the deployer, system category and use context. DataConsultant’s service supports readiness and documentation; it is not legal advice or a legal certification.
Can the assessment align with ISO/IEC 42005:2025?
Yes. ISO/IEC 42005:2025 provides guidance for organisations conducting AI system impact assessments and focuses on impacts on individuals, groups and society across the AI lifecycle. Alignment can be included in the agreed scope, with the exact evidence and mapping depth confirmed during discovery.
Can the assessment map to NIST AI RMF or ISO/IEC 42001?
Yes. Where useful, findings can be mapped to NIST AI RMF risk-management outcomes, ISO/IEC 42001 AI management-system processes, ISO/IEC 23894 risk-management guidance or an organisation’s own AI governance framework. A mapping is not the same as certification or independent conformity assessment.
What deliverables can we expect?
Typical outputs can include a system and use-context record, affected-stakeholder map, impact and harm register, evidence inventory, control and responsibility matrix, residual-risk summary, decision conditions, remediation backlog, monitoring indicators and reassessment triggers. Deliverables are tailored to the decision and governance process the assessment must support.
What evidence should we prepare?
Useful inputs include the business purpose, system description, model or service documentation, data sources, user journeys, affected groups, decision workflows, evaluation results, known limitations, incident history, supplier information, privacy and security assessments, human-oversight design, policies, risk registers and existing controls. Missing evidence should be recorded as a limitation rather than assumed.
Do affected stakeholders need to participate?
Stakeholder input can materially improve an assessment when the AI system affects employees, customers, applicants, patients, citizens, suppliers or other groups. The engagement can identify which perspectives are needed and use interviews, workshops, subject-matter review or existing research depending on proportionality, access and sensitivity.
Can you assess generative AI and LLM applications?
Yes. For generative AI and LLM use cases, the assessment can consider intended use, prompt and data flows, output reliability, harmful or inappropriate content, privacy, security, intellectual-property concerns, human reliance, automation boundaries, vendor dependencies, evaluation evidence and monitoring. Technical testing can be scoped separately when deeper model or application evaluation is required.
How long does an AI impact assessment take?
The timeline is confirmed after scoping because it depends on the number of systems and use cases, assessment depth, stakeholder availability, jurisdictions, evidence readiness, supplier dependencies, workshops, testing requirements and review or approval cycles. A narrowly scoped review and an enterprise-grade assessment for a high-impact deployment require different levels of work.
How is AI impact assessment pricing determined?
Pricing is scope-led and confirmed through a Request a Quote process. Key factors include the number of AI systems and use cases, affected stakeholder groups, jurisdictions, risk and impact profile, data sensitivity, evidence availability, assessment depth, technical validation needs, third-party dependencies, workshop requirements, deliverables and remediation or implementation support.
Can DataConsultant help implement the remediation actions?
Yes. Follow-on support can be scoped for responsible AI controls, human oversight, documentation, monitoring, governance workflows, evaluation, supplier governance, audit readiness or programme mobilisation. Responsibilities, acceptance criteria and any independent assurance requirements should be defined before implementation begins.