AI Governance Gap Check

AI impact assessment: what it asks, and how it differs from a risk assessment

Companies that already do risk assessments often assume they have this covered. They usually do not, because the two documents ask questions that point in opposite directions.

What an AI impact assessment is

An AI impact assessment records how an AI system affects the people it touches, what could go wrong for them, and what you have put in place to prevent it.

The subject is the person on the other side of the system. The applicant who was screened, the customer who was priced, the patient who was triaged, the employee who was scheduled.

Why it is not a risk assessment

A risk assessment is oriented around your organisation. It asks what a failure would cost you: money, reputation, downtime, regulatory attention.

An impact assessment is oriented around the people affected. It asks whether the system treats them fairly, whether they can find out a decision was made about them, whether they can challenge it, and whether it performs differently for different groups of them.

The same AI system can be low risk to the company and high impact on individuals. A tool that quietly filters job applicants costs you almost nothing when it goes wrong, and costs them a great deal.

That asymmetry is the whole reason the document exists separately.

When you need one

You need an AI impact assessment where AI takes part in decisions about people, processes personal data, or reaches people who never chose to interact with it. Company size does not decide it.

In a small company the easiest ones to leave off the list are CV screening or ranking, credit or payment-terms decisions, insurance or pricing differentiation, scheduling that affects earnings, content moderation, and customer service routing that determines who gets a human.

What one contains

An AI impact assessment records what the system does, who it affects, what could go wrong for them, whether it performs evenly across groups, what a person can do about it, what you have put in place, and what would trigger a rethink.
  1. What the system does, in plain language, including what it decides or influences and how much weight its output carries.
  2. Who is affected, including people who never chose to interact with it.
  3. What could go wrong for them: being wrongly excluded, treated differently, misrepresented, or having no way to know a decision was made.
  4. Whether it performs evenly across the groups it touches, and what evidence you have either way. If you have none, write that down. An honest gap is a finding, and a confident guess is a liability.
  5. What a person can do about it: how someone learns a decision was made, how they question it, and who reviews it.
  6. What you have put in place to reduce each of those, and who owns each measure.
  7. What would trigger a rethink, and when this gets reviewed.

The honest part most people skip

The question about even performance is where assessments quietly become fiction. Very few small companies have tested whether their AI performs evenly across different groups, and writing that it does without having checked is the worst sentence you can put in a governance file.

"We have not yet tested this and here is when we will" is a defensible position. "No bias identified" with nothing behind it is not, and it is precisely the claim someone will ask you to evidence.

How long it should be

For one AI use in a small company, an impact assessment of two or three pages is enough.

A short assessment that answers the 7 questions above honestly is worth far more to an assessor than twenty pages that avoid them.

Do you need one, and what else is missing?

The check tells you whether an impact assessment is proportionate for your situation, based on what your AI actually touches.

Start the 3-minute check