AI system impact assessment
Understand who may be affected by an AI system and what harms, benefits, rights impacts, or business impacts may occur.
How to implement it
- 01Run impact assessments for new and changed AI systems
- 02Assess affected groups, intended use, foreseeable misuse, and severity of harm
- 03Document controls for fairness, transparency, privacy, security, safety, and human oversight
- 04Approve residual impact before release
Evidence to keep
- - AI impact assessment
- - Affected-party analysis
- - Residual impact approval
- - Control mapping
Metrics to watch
- - Assessment coverage
- - High-impact systems awaiting approval
- - Residual high risks accepted
Put this area into the AI Statement of Applicability with a short rationale: included, excluded, or partially included. Tie that decision to the AI risk assessment, impact assessment, and system inventory.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Change management policyUse for ISO 27001 A.8.32, A.8.9, SOC 2 change management criteria, and PCI DSS requirement 6 change controls.Data breach response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident handling, privacy notification, and PCI DSS requirement 12.10.Data retention and disposal policyUse for ISO 27001 A.5.33, A.5.34, A.8.10, SOC 2 Confidentiality and Privacy, and PCI DSS requirement 3.
Open the control-to-policy map