AIPolicyTracker
AssessmentFree · no accountNIST AI RMFISO/IEC 42001Colorado ADMT law (SB 26-189)

AI Impact Assessment

A general impact assessment for any AI system: purpose, affected people, harms by risk domain, mitigations and the decision, with the impact-assessment duties recorded across jurisdictions as the checklist.

Formats: DOCX and XLSX · Version v1 · Built from dataset 914895c3103e · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

What's inside

  • Document: purpose, scope, affected groups, harm analysis by MIT risk domain, mitigations, residual risk, decision and sign-off
  • Duties sheet: every recorded impact-assessment duty, by jurisdiction and instrument
  • Harm areas sheet: the 24 MIT subdomains as prompts

Preview

The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.

Sheet: Harm areas · 6 columns · 24 rows from the records
First rows of the Harm areas sheet
DomainHarm areaDefinition (MIT AI Risk Repository)Relevant to this system ▾AnalysisMitigation
Discrimination & ToxicityUnfair discrimination and misrepresentationUnequal treatment of individuals or groups by AI, often based on race, gender, or other sensitive characteristics, resulting in unfair outcomes and representati
Discrimination & ToxicityExposure to toxic contentAI exposing users to harmful, abusive, unsafe or inappropriate content. May involve AI creating, describing, providing advice, or encouraging action. Examples o
Discrimination & ToxicityUnequal performance across groupsAccuracy and effectiveness of AI decisions and actions is dependent on group membership, where decisions in AI system design and biased training data lead to un
Privacy & SecurityCompromise of privacy by obtaining, leaking or correctly inferring sensitive informationAI systems that memorize and leak sensitive personal data or infer private information about individuals without their consent. Unexpected or unauthorized shari
Privacy & SecurityAI system security vulnerabilities and attacksVulnerabilities in AI systems, software development toolchains, and hardware that can be exploited, resulting in unauthorized access, data and privacy breaches,
MisinformationFalse or misleading informationAI systems that inadvertently generate or spread incorrect or deceptive information, which can lead to inaccurate beliefs in users and undermine their autonomy.
Sheet: Duties by jurisdiction · 14 columns · 7 rows from the records
First rows of the Duties by jurisdiction sheet
DutyCategoryInstrumentJurisdictionWho it bindsNatureSource referenceApplies fromWhat it requiresEvidence a reviewer expectsISO/IEC 42001NIST AI RMFVerificationRecord
Deployers must complete impact assessments for high-risk AIImpact assessmentColorado AI ActColorado (United States)Deployer / user organisationLegal requirementC.R.S. 6-1-1703(3)2026-06-30Deployers must complete an impact assessment before deployment, annually, and within 90 days of any intentional and substantial modification, covering purpose, Algorithmic impact assessmentClause 6.1.4 AI system impact assessmentMAP 5.xSource-linkedhttps://aipolicytracker.org/obligations/us-colorado-deployer-impact-assessment
Carry out a fundamental rights impact assessment before deploymentImpact assessmentEU AI ActEuropean UnionDeployer / user organisation, Public authority / government bodyLegal requirementArticle 272026-08-02Before deploying most Annex III high-risk systems, deployers that are bodies governed by public law or private entities providing public services, and deployersFundamental rights impact assessment reportClause 6.1.4 AI system impact assessment; Annex A control on impact assessmentMAP 5.1, MAP 5.2Source-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-fundamental-rights-impact-assessment
Significant Data Fiduciaries must appoint a DPO and run impact assessments and auditsImpact assessmentIndia DPDP ActIndiaProvider / developer, Deployer / user organisationLegal requirementSection 10Entities notified as Significant Data Fiduciaries, based on factors such as volume and sensitivity of data and risk to individuals, must appoint a Data ProtectiData protection impact assessmentClause 6.1.4 AI system impact assessmentSource-linkedhttps://aipolicytracker.org/obligations/india-dpdp-significant-data-fiduciary-duties
Operators of high-impact AI should assess its impact on fundamental rights before useImpact assessmentFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for TrustSouth KoreaProvider / developer, Deployer / user organisation, Public authority / government bodyVoluntaryArticle 352026-01-22An AI business operator that provides high-impact AI, or a product or service using it, is to make efforts to assess in advance the impact the AI may have on peFundamental-rights impact assessment for high-impact AIClause 6.1.4; Annex A.5.2, A.5.4MAP 5.1, MAP 5.2Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-35-high-impact-ai-impact-assessment
Conduct a data protection impact assessment for high-risk processing using new technologiesImpact assessmentUAE PDPLUnited Arab EmiratesProvider / developer, Deployer / user organisationLegal requirementArticle on data protection impact assessment (reviewer to cite article number)Before processing that uses modern technologies and is likely to pose a high risk to privacy, controllers must assess the impact on personal data protection, coData protection impact assessmentClause 6.1.4 AI system impact assessmentSource-linkedhttps://aipolicytracker.org/obligations/uae-pdpl-impact-assessment-new-technologies
Carry out a data protection impact assessment for high-risk AI processingImpact assessmentICO AI guidanceUnited KingdomProvider / developer, Deployer / user organisation, Public authority / government bodyLegal requirementUK GDPR Article 35; ICO guidance, accountability and governance sectionWhere AI processing of personal data is likely to result in a high risk to individuals, UK GDPR requires a DPIA before processing begins. The ICO treats most AIData protection impact assessmentClause 6.1.4 AI system impact assessmentMAP 5.1Source-linkedhttps://aipolicytracker.org/obligations/uk-ico-dpia-for-ai

Document outline (DOCX)

  1. Scope
  2. Affected people
  3. Harm analysis
  4. Mitigations and residual risk
  5. Decision
  6. Duties this assessment serves
  7. Deployers must complete impact assessments for high-risk AI
  8. Carry out a fundamental rights impact assessment before deployment
  9. Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits
  10. Operators of high-impact AI should assess its impact on fundamental rights before use
  11. Conduct a data protection impact assessment for high-risk processing using new technologies
  12. Carry out a data protection impact assessment for high-risk AI processing
  13. Map context, intended use and potential impacts (Map)

Duties this template covers (11)

Each is cited in the file with its source reference and a link back to the record.

Legal basis

Version history

Versions of AI Impact Assessment
VersionBuiltDatasetWhat changed
v1914895c3103eFirst version, built from dataset 914895c3103e.

Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.

Frequently asked questions

Is the AI Impact Assessment free?
Yes. Download the DOCX and XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
What is it generated from?
Version v1 was built on 26 September 2026 from dataset 914895c3103e: 14 recorded duties are cited in it, drawn from 8 instruments. Every row that cites a duty links to the record, and the record links to the official source.
How will I know when it changes?
The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Is the AI Impact Assessment free?
Yes. Download the DOCX and XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
What is it generated from?
Version v1 was built on 26 September 2026 from dataset 914895c3103e: 14 recorded duties are cited in it, drawn from 8 instruments. Every row that cites a duty links to the record, and the record links to the official source.
How will I know when it changes?
The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.