AIG-006 AI Impact Assessment
Description
Before deploying an AI system that may affect individuals or groups, a documented impact assessment is completed. The assessment evaluates potential harms to individuals (including discrimination, privacy, safety, and economic effects) and societal harms (including systemic bias, labour displacement, and environmental impact). Assessments consider vulnerable groups including minors. Results are retained and reviewed when the system's purpose or data inputs change materially.
Rationale
AI systems can cause population-scale harms invisible in individual-system risk assessments; a dedicated impact assessment surface forces proportionate consideration of downstream effects.
Applicability (9 profiles)
The impact assessment before use is the deployer's under ISO 42001 A.5. The Art.27 fundamental rights impact assessment is an addition that binds a public body, or a private body providing a public service, deploying a high-risk system. public-body-deployer-eu owns it.
Art.9(9) gives the vulnerable-groups limb a legal object and a home: the provider considers, in view of the intended purpose, whether the system is likely to have an adverse impact on persons under the age of 18 and, as appropriate, other vulnerable groups. That consideration is part of the risk management system rather than a separate exercise, so it is read inside the Art.11 documentation. The deployer's Art.27 fundamental rights impact assessment stays out of this seat and is recorded not-applicable on the base.
Two assessments, not one. The rows are kept apart so a reader does not merge them. AIG-006 is the impact assessment every deployer runs before use. Its anchor is ISO/IEC 42001 A.5 and it binds both seats. AIG-046 is the Art.27 fundamental rights impact assessment and binds only the Art.27 seat, bodies governed by public law and private entities providing public services, which is why Art.27 maps informatively onto this control and fully onto that one. Where the AIG-006 assessment already covers an Art.27 element the fundamental rights assessment cites the section rather than repeating it, the same reuse Art.27(4) allows against a data protection impact assessment.
Framework Mappings (25)
| GRC-10 | AI Impact Assessment | partial |
| EU-AI-Art.26.8 | Deployer Obligations — GDPR Data Protection Impact Assessment Support | partial |
| EU-AI-Art.27 | Deployer Obligations — Fundamental Rights Impact Assessment | informative |
| EU-AI-Art.6.2 | Classification — Annex III High-Risk Categories and the Derogation | informative |
| EU-AI-Art.9.6 | AI Risk Management System — Vulnerable Groups Consideration | full |
| COP-S-2.2 | Systemic risk scenarios | informative |
| A.5.2 | AI system impact assessment process | full |
| A.5.3 | Documentation of AI system impact assessments | full |
| A.5.4 | Assessing AI system impact on individuals or groups of individuals | full |
| A.5.5 | Assessing societal impacts of AI systems | full |
| GV-4.2-003 | Organisational AI Risk Communication | GV-4.2-003 | partial |
| MG-2.2-006 | Deployed AI System Value Maintenance | MG-2.2-006 | informative |
| MP-1.1-002 | AI System Purpose and Deployment Context | MP-1.1-002 | partial |
| MP-5.1-002 | Impact Likelihood and Magnitude Documentation | MP-5.1-002 | partial |
| MP-5.2-001 | External Impact Feedback Practices | MP-5.2-001 | informative |
| MS-1.3-002 | Independent AI Risk Assessment | MS-1.3-002 | informative |
| MS-2.11-003 | AI Fairness and Bias Evaluation | MS-2.11-003 | partial |
| MS-2.12-001 | AI Environmental Impact Assessment | MS-2.12-001 | full |
| MS-2.12-002 | AI Environmental Impact Assessment | MS-2.12-002 | full |
| MS-2.12-003 | AI Environmental Impact Assessment | MS-2.12-003 | partial |
| MS-2.6-001 | AI System Safety Risk Evaluation | MS-2.6-001 | partial |
| MS-3.3-001 | User and Community Feedback Processes | MS-3.3-001 | full |
| MAP 3.2 | AI Error Costs and Risk Tolerance | full |
| MAP 5.1 | Impact Likelihood and Magnitude Documentation | full |
| MEASURE 2.12 | AI Environmental Impact Assessment | full |
Evidence (2)
Completed AI impact assessment for each AI system that may affect individuals or groups, covering individual harms (discrimination, privacy, safety, economic), societal harms, and consideration of vulnerable groups.
Example: AI Impact Assessment · Loan Eligibility Model (Confluence), dated 2025-07-20, covering discrimination risk, vulnerable group (minors) analysis, societal bias risk, and retention date
Test: Request impact assessments for all Tier 2+ AI systems affecting individuals. Verify each assessment: (1) covers individual harm categories (discrimination, privacy, safety, economic effects), (2) includes societal harm analysis, (3) explicitly addresses vulnerable group risk, (4) records the outcome and any required mitigations, (5) a re-assessment trigger condition (material change to system purpose or data inputs) is documented.
Impact assessment register listing each AI system, the assessment covering it, its date, its approver and the trigger that required it.
Example: AI Impact Assessment Register (Confluence, 2026-08-31): 14 production systems, 14 assessments, 3 reassessments triggered by a substantial modification in the period
Test: Request the impact assessment register and the trigger records behind it. Verify: (1) every system in the AI system inventory appears in the register, (2) each entry names the assessment, its date and the person who approved it, (3) each entry records the trigger that required the assessment, (4) a system that had a substantial modification in the period carries a reassessment dated after that modification, (5) an entry with no assessment carries a recorded decision that none was required, with the reason.
Questions (2)
Does your organisation complete a documented impact assessment before deploying an AI system that may affect individuals or groups?
AI impact assessments must go beyond standard risk assessments to address population-scale harms including discrimination, privacy, economic effects, and societal impacts. The assessment should be retained and revisited when system purpose or data inputs change.
Which of the following harm categories does your AI impact assessment explicitly evaluate?
All six categories should be assessed for systems affecting individuals. Missing vulnerable group analysis or societal harm evaluation are common gaps that create regulatory exposure under the EU AI Act and GDPR.