AI impact assessment: what it asks, and how it differs from a risk assessment
Companies that already do risk assessments often assume they have this covered. They usually do not, because the two documents ask questions that point in opposite directions.
What an AI impact assessment is
The subject is the person on the other side of the system. The applicant who was screened, the customer who was priced, the patient who was triaged, the employee who was scheduled.
Why it is not a risk assessment
A risk assessment is oriented around your organisation. It asks what a failure would cost you: money, reputation, downtime, regulatory attention.
An impact assessment is oriented around the people affected. It asks whether the system treats them fairly, whether they can find out a decision was made about them, whether they can challenge it, and whether it performs differently for different groups of them.
That asymmetry is the whole reason the document exists separately.
When you need one
In a small company the easiest ones to leave off the list are CV screening or ranking, credit or payment-terms decisions, insurance or pricing differentiation, scheduling that affects earnings, content moderation, and customer service routing that determines who gets a human.
What one contains
- What the system does, in plain language, including what it decides or influences and how much weight its output carries.
- Who is affected, including people who never chose to interact with it.
- What could go wrong for them: being wrongly excluded, treated differently, misrepresented, or having no way to know a decision was made.
- Whether it performs evenly across the groups it touches, and what evidence you have either way. If you have none, write that down. An honest gap is a finding, and a confident guess is a liability.
- What a person can do about it: how someone learns a decision was made, how they question it, and who reviews it.
- What you have put in place to reduce each of those, and who owns each measure.
- What would trigger a rethink, and when this gets reviewed.
The honest part most people skip
The question about even performance is where assessments quietly become fiction. Very few small companies have tested whether their AI performs evenly across different groups, and writing that it does without having checked is the worst sentence you can put in a governance file.
"We have not yet tested this and here is when we will" is a defensible position. "No bias identified" with nothing behind it is not, and it is precisely the claim someone will ask you to evidence.
How long it should be
A short assessment that answers the 7 questions above honestly is worth far more to an assessor than twenty pages that avoid them.
Do you need one, and what else is missing?
The check tells you whether an impact assessment is proportionate for your situation, based on what your AI actually touches.
Start the 3-minute check