An AI Impact Assessment (AIIA) is a structured process for evaluating the potential risks and societal effects of artificial intelligence systems before and during their deployment. ISO 42001 requires these assessments as part of an AI management system, covering aspects such as bias, transparency, human oversight and fundamental rights. The EU AI Act sets out a separate instrument: the fundamental rights impact assessment in Article 27, required only of certain deployers of high-risk AI systems.
The AIIA serves as both a compliance instrument and a risk management tool, helping organisations identify and mitigate harms proactively. It draws parallels with the Data Protection Impact Assessment (DPIA) under GDPR and is increasingly integrated into broader governance, risk and compliance (GRC) frameworks.