Assessment

AI Impact Assessments in Practice

An AI impact assessment earns its cost only if it can stop or change a deployment. Everything else in the design follows from that.

Most organisations already run data protection impact assessments. The AI impact assessment is the same instrument pointed at a different object: instead of asking what happens to a person's data, it asks what happens to a person because of a system's output. Run them together where personal data is involved — the overlap is large and the reviewers are the same people.

Screen before you assess

A full assessment on every model is unsustainable and produces box-ticking. A short screening set filters most systems out in minutes:

The sections that carry weight

Make it a gate, not a form

The assessment has to sit at a point in the lifecycle where its findings can still change something — before procurement commits, before the model is embedded, before launch is announced. An assessment completed the week before go-live records a decision that was already made.

Keep it alive

Models drift, use cases expand, and vendors change their underlying models without asking. Re-assess on a trigger — a new use case, a material model update, a performance drop, a complaint — rather than on an annual cycle that will always lag the estate.

← All AI Governance articles

Need help applying this?

Tell me the jurisdiction, the systems in scope and the deadline. I will tell you what is realistic.