GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

AIG-006 AI Impact Assessment

Tier 2+AIProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Before deploying an AI system that may affect individuals or groups, a documented impact assessment is completed. The assessment evaluates potential harms to individuals (including discrimination, privacy, safety, and economic effects) and societal harms (including systemic bias, labour displacement, and environmental impact). Assessments consider vulnerable groups including minors. Results are retained and reviewed when the system's purpose or data inputs change materially.

Rationale

AI systems can cause population-scale harms invisible in individual-system risk assessments; a dedicated impact assessment surface forces proportionate consideration of downstream effects.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore

The impact assessment before use is the deployer's under ISO 42001 A.5. The Art.27 fundamental rights impact assessment is an addition that binds a public body, or a private body providing a public service, deploying a high-risk system. public-body-deployer-eu owns it.

GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredrisk class duty

Art.9(9) gives the vulnerable-groups limb a legal object and a home: the provider considers, in view of the intended purpose, whether the system is likely to have an adverse impact on persons under the age of 18 and, as appropriate, other vulnerable groups. That consideration is part of the risk management system rather than a separate exercise, so it is read inside the Art.11 documentation. The deployer's Art.27 fundamental rights impact assessment stays out of this seat and is recorded not-applicable on the base.

Public Body Deployer (EU)stablerequiredrole duty

Two assessments, not one. The rows are kept apart so a reader does not merge them. AIG-006 is the impact assessment every deployer runs before use. Its anchor is ISO/IEC 42001 A.5 and it binds both seats. AIG-046 is the Art.27 fundamental rights impact assessment and binds only the Art.27 seat, bodies governed by public law and private entities providing public services, which is why Art.27 maps informatively onto this control and fully onto that one. Where the AIG-006 assessment already covers an Art.27 element the fundamental rights assessment cites the section rather than repeating it, the same reuse Art.27(4) allows against a data protection impact assessment.

DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (25)

GRC-10AI Impact Assessmentpartial
EU-AI-Art.26.8Deployer Obligations — GDPR Data Protection Impact Assessment Supportpartial
EU-AI-Art.27Deployer Obligations — Fundamental Rights Impact Assessmentinformative
EU-AI-Art.6.2Classification — Annex III High-Risk Categories and the Derogationinformative
EU-AI-Art.9.6AI Risk Management System — Vulnerable Groups Considerationfull
COP-S-2.2Systemic risk scenariosinformative
A.5.2AI system impact assessment processfull
A.5.3Documentation of AI system impact assessmentsfull
A.5.4Assessing AI system impact on individuals or groups of individualsfull
A.5.5Assessing societal impacts of AI systemsfull
GV-4.2-003Organisational AI Risk Communication | GV-4.2-003partial
MG-2.2-006Deployed AI System Value Maintenance | MG-2.2-006informative
MP-1.1-002AI System Purpose and Deployment Context | MP-1.1-002partial
MP-5.1-002Impact Likelihood and Magnitude Documentation | MP-5.1-002partial
MP-5.2-001External Impact Feedback Practices | MP-5.2-001informative
MS-1.3-002Independent AI Risk Assessment | MS-1.3-002informative
MS-2.11-003AI Fairness and Bias Evaluation | MS-2.11-003partial
MS-2.12-001AI Environmental Impact Assessment | MS-2.12-001full
MS-2.12-002AI Environmental Impact Assessment | MS-2.12-002full
MS-2.12-003AI Environmental Impact Assessment | MS-2.12-003partial
MS-2.6-001AI System Safety Risk Evaluation | MS-2.6-001partial
MS-3.3-001User and Community Feedback Processes | MS-3.3-001full
MAP 3.2AI Error Costs and Risk Tolerancefull
MAP 5.1Impact Likelihood and Magnitude Documentationfull
MEASURE 2.12AI Environmental Impact Assessmentfull

Evidence (2)

recorddocumentmanual

Completed AI impact assessment for each AI system that may affect individuals or groups, covering individual harms (discrimination, privacy, safety, economic), societal harms, and consideration of vulnerable groups.

Example: AI Impact Assessment · Loan Eligibility Model (Confluence), dated 2025-07-20, covering discrimination risk, vulnerable group (minors) analysis, societal bias risk, and retention date

Test: Request impact assessments for all Tier 2+ AI systems affecting individuals. Verify each assessment: (1) covers individual harm categories (discrimination, privacy, safety, economic effects), (2) includes societal harm analysis, (3) explicitly addresses vulnerable group risk, (4) records the outcome and any required mitigations, (5) a re-assessment trigger condition (material change to system purpose or data inputs) is documented.

recorddocumentmanual

Impact assessment register listing each AI system, the assessment covering it, its date, its approver and the trigger that required it.

Example: AI Impact Assessment Register (Confluence, 2026-08-31): 14 production systems, 14 assessments, 3 reassessments triggered by a substantial modification in the period

Test: Request the impact assessment register and the trigger records behind it. Verify: (1) every system in the AI system inventory appears in the register, (2) each entry names the assessment, its date and the person who approved it, (3) each entry records the trigger that required the assessment, (4) a system that had a substantial modification in the period carries a reassessment dated after that modification, (5) an entry with no assessment carries a recorded decision that none was required, with the reason.

Questions (2)

boolean

Does your organisation complete a documented impact assessment before deploying an AI system that may affect individuals or groups?

AI impact assessments must go beyond standard risk assessments to address population-scale harms including discrimination, privacy, economic effects, and societal impacts. The assessment should be retained and revisited when system purpose or data inputs change.

multi

Which of the following harm categories does your AI impact assessment explicitly evaluate?

Discrimination or differential treatment of individualsPrivacy and data subject rights impactsPhysical safety risksEconomic effects on individualsSocietal or systemic harms (e.g. labour displacement, systemic bias)Impacts on vulnerable groups including minorsNone of the above

All six categories should be assessed for systems affecting individuals. Missing vulnerable group analysis or societal harm evaluation are common gaps that create regulatory exposure under the EU AI Act and GDPR.