AssessmentFree · no accountNIST AI RMFISO/IEC 42001Colorado ADMT law (SB 26-189)
AI Impact Assessment
A general impact assessment for any AI system: purpose, affected people, harms by risk domain, mitigations and the decision, with the impact-assessment duties recorded across jurisdictions as the checklist.
What's inside
- Document: purpose, scope, affected groups, harm analysis by MIT risk domain, mitigations, residual risk, decision and sign-off
- Duties sheet: every recorded impact-assessment duty, by jurisdiction and instrument
- Harm areas sheet: the 24 MIT subdomains as prompts
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Harm areas
| Domain | Harm area | Definition (MIT AI Risk Repository) | Relevant to this system ▾ | Analysis | Mitigation |
|---|---|---|---|---|---|
| Discrimination & Toxicity | Unfair discrimination and misrepresentation | Unequal treatment of individuals or groups by AI, often based on race, gender, or other sensitive characteristics, resulting in unfair outcomes and representati | |||
| Discrimination & Toxicity | Exposure to toxic content | AI exposing users to harmful, abusive, unsafe or inappropriate content. May involve AI creating, describing, providing advice, or encouraging action. Examples o | |||
| Discrimination & Toxicity | Unequal performance across groups | Accuracy and effectiveness of AI decisions and actions is dependent on group membership, where decisions in AI system design and biased training data lead to un | |||
| Privacy & Security | Compromise of privacy by obtaining, leaking or correctly inferring sensitive information | AI systems that memorize and leak sensitive personal data or infer private information about individuals without their consent. Unexpected or unauthorized shari | |||
| Privacy & Security | AI system security vulnerabilities and attacks | Vulnerabilities in AI systems, software development toolchains, and hardware that can be exploited, resulting in unauthorized access, data and privacy breaches, | |||
| Misinformation | False or misleading information | AI systems that inadvertently generate or spread incorrect or deceptive information, which can lead to inaccurate beliefs in users and undermine their autonomy. |
Sheet: Duties by jurisdiction
| Duty | Category | Instrument | Jurisdiction | Who it binds | Nature | Source reference | Applies from | What it requires | Evidence a reviewer expects | ISO/IEC 42001 | NIST AI RMF | Verification | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Deployers must complete impact assessments for high-risk AI | Impact assessment | Colorado AI Act | Colorado (United States) | Deployer / user organisation | Legal requirement | C.R.S. 6-1-1703(3) | 2026-06-30 | Deployers must complete an impact assessment before deployment, annually, and within 90 days of any intentional and substantial modification, covering purpose, | Algorithmic impact assessment | Clause 6.1.4 AI system impact assessment | MAP 5.x | Source-linked | https://aipolicytracker.org/obligations/us-colorado-deployer-impact-assessment |
| Carry out a fundamental rights impact assessment before deployment | Impact assessment | EU AI Act | European Union | Deployer / user organisation, Public authority / government body | Legal requirement | Article 27 | 2026-08-02 | Before deploying most Annex III high-risk systems, deployers that are bodies governed by public law or private entities providing public services, and deployers | Fundamental rights impact assessment report | Clause 6.1.4 AI system impact assessment; Annex A control on impact assessment | MAP 5.1, MAP 5.2 | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-fundamental-rights-impact-assessment |
| Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits | Impact assessment | India DPDP Act | India | Provider / developer, Deployer / user organisation | Legal requirement | Section 10 | Entities notified as Significant Data Fiduciaries, based on factors such as volume and sensitivity of data and risk to individuals, must appoint a Data Protecti | Data protection impact assessment | Clause 6.1.4 AI system impact assessment | Source-linked | https://aipolicytracker.org/obligations/india-dpdp-significant-data-fiduciary-duties | ||
| Operators of high-impact AI should assess its impact on fundamental rights before use | Impact assessment | Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust | South Korea | Provider / developer, Deployer / user organisation, Public authority / government body | Voluntary | Article 35 | 2026-01-22 | An AI business operator that provides high-impact AI, or a product or service using it, is to make efforts to assess in advance the impact the AI may have on pe | Fundamental-rights impact assessment for high-impact AI | Clause 6.1.4; Annex A.5.2, A.5.4 | MAP 5.1, MAP 5.2 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-35-high-impact-ai-impact-assessment |
| Conduct a data protection impact assessment for high-risk processing using new technologies | Impact assessment | UAE PDPL | United Arab Emirates | Provider / developer, Deployer / user organisation | Legal requirement | Article on data protection impact assessment (reviewer to cite article number) | Before processing that uses modern technologies and is likely to pose a high risk to privacy, controllers must assess the impact on personal data protection, co | Data protection impact assessment | Clause 6.1.4 AI system impact assessment | Source-linked | https://aipolicytracker.org/obligations/uae-pdpl-impact-assessment-new-technologies | ||
| Carry out a data protection impact assessment for high-risk AI processing | Impact assessment | ICO AI guidance | United Kingdom | Provider / developer, Deployer / user organisation, Public authority / government body | Legal requirement | UK GDPR Article 35; ICO guidance, accountability and governance section | Where AI processing of personal data is likely to result in a high risk to individuals, UK GDPR requires a DPIA before processing begins. The ICO treats most AI | Data protection impact assessment | Clause 6.1.4 AI system impact assessment | MAP 5.1 | Source-linked | https://aipolicytracker.org/obligations/uk-ico-dpia-for-ai |
Document outline (DOCX)
- Scope
- Affected people
- Harm analysis
- Mitigations and residual risk
- Decision
- Duties this assessment serves
- Deployers must complete impact assessments for high-risk AI
- Carry out a fundamental rights impact assessment before deployment
- Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits
- Operators of high-impact AI should assess its impact on fundamental rights before use
- Conduct a data protection impact assessment for high-risk processing using new technologies
- Carry out a data protection impact assessment for high-risk AI processing
- Map context, intended use and potential impacts (Map)
Duties this template covers (11)
Each is cited in the file with its source reference and a link back to the record.
- Establish a risk management system for high-risk AI
- Carry out a fundamental rights impact assessment before deployment
- Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits
- Operators of high-impact AI must establish and operate a risk management plan
- Operators of high-impact AI should assess its impact on fundamental rights before use
- Conduct a data protection impact assessment for high-risk processing using new technologies
- Ensure AI systems are safe, secure and robust throughout their lifecycle
- Carry out a data protection impact assessment for high-risk AI processing
- Map context, intended use and potential impacts (Map)
- Prioritise, respond to and monitor AI risks (Manage)
- Apply minimum risk-management practices to high-impact AI
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | 914895c3103e | First version, built from dataset 914895c3103e. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
- Is the AI Impact Assessment free?
- Yes. Download the DOCX and XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 914895c3103e: 14 recorded duties are cited in it, drawn from 8 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Is the AI Impact Assessment free?
- Yes. Download the DOCX and XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 914895c3103e: 14 recorded duties are cited in it, drawn from 8 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.