AIPolicyTracker
Process Owner: AI system owner Once per AI system

AI impact and fundamental-rights impact assessment

Examines how a planned AI use will affect the people, groups and communities it touches, with particular attention to discrimination and rights, and records the mitigations chosen before the system goes live.

Duties satisfied
4
done properly, does the work
Duties supported
7
contributes; the duty needs more
Jurisdictions
7
Evidence items
3

How is it implemented?

Before deployment, and again on material change or a set anniversary, the deploying team completes a templated assessment that describes the use, the decisions or outputs it influences, the people affected and the ways they could be harmed. It examines disparate effects across relevant groups, consults affected stakeholders where practical, and documents the transparency, oversight and monitoring measures that will accompany the deployment. The template is designed so that a single exercise can produce the outputs that data-protection, algorithmic-discrimination and rights-based regimes each expect. Completed assessments are retained for the period the strictest applicable rule requires and are available to regulators on request.

Which legal duties does it serve?

Satisfies means the control, operated properly, does the work the duty asks for. Supports means it contributes but the duty needs more. The official text decides; open it before relying on either.

Colorado (United States) 1 duty

European Union 3 duties

South Korea 1 duty

United States 2 duties

India 1 duty

United Arab Emirates 1 duty

United Kingdom 2 duties

What evidence shows it is operating?

Evidence this control produces
EvidenceTypeWhat it shows
AI impact assessmentImpact assessmentCompleted assessment of purpose, affected people, discrimination risk, mitigations and monitoring plan.
Impact assessment approvalApproval or sign-off recordSign-off by the accountable owner and, where required, the privacy or legal function.
Impact assessment procedure and templateProcedure or standard operating process

Owner: AI system owner. Frequency: once per ai system.

Which risks does it address?

Subdomains of the MIT AI Risk Repository, with the incidents the AI Incident Database has recorded under each. Counts are live; they say how often a risk has materialised, not how well this control prevents it.

Which standards clauses does it correspond to?

Clause numbers only. A reference means the standard asks for overlapping work, so evidence may be reusable; it never means the standard discharges a legal duty.

Framework references
FrameworkReferenceNoteConfidence
ISO/IEC 42001Clause 6.1.4, 8.4; Annex A.5high
ISO/IEC 42005ISO/IEC 42005 Clause 5, 6Guidance on running and documenting AI system impact assessments.medium
NIST AI RMFMAP 5.1, 5.2; MEASURE 2.11high
OECD AI PrinciplesPrinciple 1.2 Human-centred values and fairnessmedium

Cite this record

AIPolicyTracker (2026). “AI impact and fundamental-rights impact assessment”. https://aipolicytracker.org/controls/ai-impact-assessment (accessed 24 September 2026). Data licensed CC BY 4.0.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Which legal duties does "AI impact and fundamental-rights impact assessment" satisfy?
It is recorded as satisfying 4 and supporting 7 duties across Colorado (United States), European Union, South Korea, United States, India, United Arab Emirates and United Kingdom. A mapping means the control, operated properly, does the work the duty asks for; the official text decides whether it is enough.
What evidence shows this control is operating?
AI impact assessment, Impact assessment approval and Impact assessment procedure and template. Owner: AI system owner. Frequency: once per ai system.