# AI impact and fundamental-rights impact assessment

- **Record type**: Control
- **Kind**: Process
- **Owner**: AI system owner
- **Frequency**: Once per AI system
- **Duties served**: 11

## What the control achieves

Examines how a planned AI use will affect the people, groups and communities it touches, with particular attention to discrimination and rights, and records the mitigations chosen before the system goes live.

## How it is typically implemented

Before deployment, and again on material change or a set anniversary, the deploying team completes a templated assessment that describes the use, the decisions or outputs it influences, the people affected and the ways they could be harmed. It examines disparate effects across relevant groups, consults affected stakeholders where practical, and documents the transparency, oversight and monitoring measures that will accompany the deployment. The template is designed so that a single exercise can produce the outputs that data-protection, algorithmic-discrimination and rights-based regimes each expect. Completed assessments are retained for the period the strictest applicable rule requires and are available to regulators on request.

## Evidence it produces

- AI impact assessment (impact_assessment): Completed assessment of purpose, affected people, discrimination risk, mitigations and monitoring plan.
- Impact assessment approval (approval_record): Sign-off by the accountable owner and, where required, the privacy or legal function.
- Impact assessment procedure and template (procedure)

## Legal duties this control serves

- Carry out a fundamental rights impact assessment before deployment — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-fundamental-rights-impact-assessment
- Employers must inform workers and their representatives before using high-risk AI at work — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-26-7-worker-information
- Deployers must use the provider's transparency information in their data protection impact assessment — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-26-9-dpia-using-provider-information
- Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits — India DPDP Act, India (supports): https://aipolicytracker.org/obligations/india-dpdp-significant-data-fiduciary-duties
- Operators of high-impact AI should assess its impact on fundamental rights before use — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea (satisfies): https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-35-high-impact-ai-impact-assessment
- Conduct a data protection impact assessment for high-risk processing using new technologies — UAE PDPL, United Arab Emirates (supports): https://aipolicytracker.org/obligations/uae-pdpl-impact-assessment-new-technologies
- Use AI in ways that are fair and do not discriminate unlawfully — UK AI regulation framework, United Kingdom (supports): https://aipolicytracker.org/obligations/uk-principles-fairness
- Carry out a data protection impact assessment for high-risk AI processing — ICO AI guidance, United Kingdom (supports): https://aipolicytracker.org/obligations/uk-ico-dpia-for-ai
- Deployers must complete impact assessments for high-risk AI — Colorado AI Act, Colorado (United States) (satisfies): https://aipolicytracker.org/obligations/us-colorado-deployer-impact-assessment
- Map context, intended use and potential impacts (Map) — NIST AI RMF, United States (satisfies): https://aipolicytracker.org/obligations/us-nist-ai-rmf-map
- Apply minimum risk-management practices to high-impact AI — OMB M-25-21, United States (supports): https://aipolicytracker.org/obligations/us-omb-m-25-21-high-impact-ai-practices

## Standards clauses it corresponds to (clause numbers only)

- ISO/IEC 42001:2023: Clause 6.1.4, 8.4; Annex A.5
- ISO/IEC 42005:2025: ISO/IEC 42005 Clause 5, 6 — Guidance on running and documenting AI system impact assessments.
- NIST AI RMF 1.0: MAP 5.1, 5.2; MEASURE 2.11
- OECD AI Principles: Principle 1.2 Human-centred values and fairness

## MIT AI Risk Repository subdomains addressed

1.1, 1.3, 5.2, 6.2

## Provenance

- **Record page**: https://aipolicytracker.org/controls/ai-impact-assessment
- **Official source**: none recorded — this record is incomplete, see https://aipolicytracker.org/gaps
- **Review status**: pending review
- **Confidence**: high
- **Facts last confirmed**: never confirmed against the official source
- **Retrieved**: 2026-09-24
- **Licence**: https://creativecommons.org/licenses/by/4.0/

> This record is a structured summary with a link to the official text. It is not legal advice. Open the official source before relying on any date or duty. How current each record type must be is published at https://aipolicytracker.org/verification; what a record must carry at all is published at https://aipolicytracker.org/coverage.
