AI impact and fundamental-rights impact assessment
Examines how a planned AI use will affect the people, groups and communities it touches, with particular attention to discrimination and rights, and records the mitigations chosen before the system goes live.
- Duties satisfied
- 4
- done properly, does the work
- Duties supported
- 7
- contributes; the duty needs more
- Jurisdictions
- 7
- Evidence items
- 3
How is it implemented?
Before deployment, and again on material change or a set anniversary, the deploying team completes a templated assessment that describes the use, the decisions or outputs it influences, the people affected and the ways they could be harmed. It examines disparate effects across relevant groups, consults affected stakeholders where practical, and documents the transparency, oversight and monitoring measures that will accompany the deployment. The template is designed so that a single exercise can produce the outputs that data-protection, algorithmic-discrimination and rights-based regimes each expect. Completed assessments are retained for the period the strictest applicable rule requires and are available to regulators on request.
Which legal duties does it serve?
Satisfies means the control, operated properly, does the work the duty asks for. Supports means it contributes but the duty needs more. The official text decides; open it before relying on either.
Colorado (United States) 1 duty
-
satisfies Legal requirement confidence highDeployers must complete impact assessments for high-risk AI
Colorado AI Act · C.R.S. 6-1-1703(3) · applies from 30 Jun 2026
Templated assessment aligned to the statutory elements, refreshed annually and on material change.
European Union 3 duties
-
satisfies Legal requirement confidence highCarry out a fundamental rights impact assessment before deployment
EU AI Act · Article 27 · applies from 2 Aug 2026
A rights-focused assessment template covering the required elements.
-
supports Legal requirementEmployers must inform workers and their representatives before using high-risk AI at work
EU AI Act · Article 26(7) · applies from 2 Aug 2026
Identifies the affected worker groups to notify.
-
supports Legal requirementDeployers must use the provider's transparency information in their data protection impact assessment
EU AI Act · Article 26(9) · applies from 2 Aug 2026
Shared inputs with the fundamental rights impact assessment.
South Korea 1 duty
-
satisfies Voluntary confidence highOperators of high-impact AI should assess its impact on fundamental rights before use
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 35 · applies from 22 Jan 2026
Fundamental-rights assessment before deployment.
United States 2 duties
-
satisfies VoluntaryMap context, intended use and potential impacts (Map)
NIST AI RMF · MAP function
Context, affected people and impact analysis produced before development.
-
supports Legal requirementApply minimum risk-management practices to high-impact AI
OMB M-25-21 · Section 4
AI impact assessment content.
India 1 duty
-
supports Legal requirementSignificant Data Fiduciaries must appoint a DPO and run impact assessments and audits
India DPDP Act · Section 10
Assessment content can be shared with the DPIA.
United Arab Emirates 1 duty
-
supports Legal requirementConduct a data protection impact assessment for high-risk processing using new technologies
UAE PDPL · Article on data protection impact assessment (reviewer to cite article number)
Broader impact analysis feeds the DPIA.
United Kingdom 2 duties
-
supports VoluntaryUse AI in ways that are fair and do not discriminate unlawfully
UK AI regulation framework · Principle 3, Part 3
Identifies groups at risk of unfair treatment.
-
supports Legal requirementCarry out a data protection impact assessment for high-risk AI processing
ICO AI guidance · UK GDPR Article 35; ICO guidance, accountability and governance section
Bias, explainability and oversight analysis reused in the DPIA.
What evidence shows it is operating?
| Evidence | Type | What it shows |
|---|---|---|
| AI impact assessment | Impact assessment | Completed assessment of purpose, affected people, discrimination risk, mitigations and monitoring plan. |
| Impact assessment approval | Approval or sign-off record | Sign-off by the accountable owner and, where required, the privacy or legal function. |
| Impact assessment procedure and template | Procedure or standard operating process |
Owner: AI system owner. Frequency: once per ai system.
Which risks does it address?
Subdomains of the MIT AI Risk Repository, with the incidents the AI Incident Database has recorded under each. Counts are live; they say how often a risk has materialised, not how well this control prevents it.
- 1.1 Unfair discrimination and misrepresentation Discrimination & Toxicity118 incidents · 83 risk entries
- 1.3 Unequal performance across groups Discrimination & Toxicity34 incidents · 17 risk entries
- 5.2 Loss of human agency and autonomy Human-Computer Interaction4 incidents · 47 risk entries
- 6.2 Increased inequality and decline in employment quality Socioeconomic & Environmental6 incidents · 55 risk entries
Which standards clauses does it correspond to?
Clause numbers only. A reference means the standard asks for overlapping work, so evidence may be reusable; it never means the standard discharges a legal duty.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001 | Clause 6.1.4, 8.4; Annex A.5 | high | |
| ISO/IEC 42005 | ISO/IEC 42005 Clause 5, 6 | Guidance on running and documenting AI system impact assessments. | medium |
| NIST AI RMF | MAP 5.1, 5.2; MEASURE 2.11 | high | |
| OECD AI Principles | Principle 1.2 Human-centred values and fairness | medium |
Cite this record
AIPolicyTracker (2026). “AI impact and fundamental-rights impact assessment”. https://aipolicytracker.org/controls/ai-impact-assessment (accessed 24 September 2026). Data licensed CC BY 4.0.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Which legal duties does "AI impact and fundamental-rights impact assessment" satisfy?
- It is recorded as satisfying 4 and supporting 7 duties across Colorado (United States), European Union, South Korea, United States, India, United Arab Emirates and United Kingdom. A mapping means the control, operated properly, does the work the duty asks for; the official text decides whether it is enough.
- What evidence shows this control is operating?
- AI impact assessment, Impact assessment approval and Impact assessment procedure and template. Owner: AI system owner. Frequency: once per ai system.