AI Governance Gap Check

AI impact assessment: what it asks, and how it differs from a risk assessment

Companies that already do risk assessments often assume they have this covered. They usually do not, because the two documents ask questions that point in opposite directions.

What an AI impact assessment is

An AI impact assessment records how an AI system affects the people it touches, what could go wrong for them, and what you have put in place to prevent it.

The subject is the person on the other side of the system. The applicant who was screened, the customer who was priced, the patient who was triaged, the employee who was scheduled.

Why it is not a risk assessment

A risk assessment is oriented around your organisation. It asks what a failure would cost you: money, reputation, downtime, regulatory attention.

An impact assessment is oriented around the people affected. It asks whether the system treats them fairly, whether they can find out a decision was made about them, whether they can challenge it, and whether it performs differently for different groups of them.

The same AI system can be low risk to the company and high impact on individuals. A tool that quietly filters job applicants costs you almost nothing when it goes wrong, and costs them a great deal.

That asymmetry is the whole reason the document exists separately.

When you need one

The trigger is what the AI touches, not how big your company is. You need one where AI is involved in decisions about people, where it processes personal data, or where its output reaches people who did not choose to interact with it.

Common cases in small companies, all of which people forget to count: CV screening or ranking, credit or payment-terms decisions, insurance or pricing differentiation, scheduling that affects earnings, content moderation, and customer service routing that determines who gets a human.

What one contains

  1. What the system does, in plain language, including what it decides or influences and how much weight its output carries.
  2. Who is affected, including people who never chose to interact with it.
  3. What could go wrong for them: being wrongly excluded, treated differently, misrepresented, or having no way to know a decision was made.
  4. Whether it performs evenly across the groups it touches, and what evidence you have either way. If you have none, write that down. An honest gap is a finding; a confident guess is a liability.
  5. What a person can do about it: how someone learns a decision was made, how they question it, and who reviews it.
  6. What you have put in place to reduce each of those, and who owns each measure.
  7. What would trigger a rethink, and when this gets reviewed.

The honest part most people skip

Section four is where assessments quietly become fiction. Very few small companies have tested whether their AI performs evenly across different groups, and writing that it does without having checked is the single worst sentence you can put in a governance file.

"We have not yet tested this and here is when we will" is a defensible position. "No bias identified" with nothing behind it is not, and it is precisely the claim someone will ask you to evidence.

How long it should be

For one AI use in a small company, two or three pages. Length is not the point. A short assessment that answers the seven questions honestly is worth far more than twenty pages that avoid them.

Do you need one, and what else is missing?

The check tells you whether an impact assessment is proportionate for your situation, based on what your AI actually touches.

Start the check