AI Impact Assessment (AIIA)

Systematic evaluation of risks and effects of AI systems on individuals, groups and society, required under the EU AI Act.

A

An AI Impact Assessment (AIIA) is a structured process for evaluating the potential risks and societal effects of artificial intelligence systems before and during their deployment. Under the EU AI Act, organisations deploying high-risk AI systems are required to conduct these assessments, covering aspects such as bias, transparency, human oversight and fundamental rights.

The AIIA serves as both a compliance instrument and a risk management tool, helping organisations identify and mitigate harms proactively. It draws parallels with the Data Protection Impact Assessment (DPIA) under GDPR and is increasingly integrated into broader governance, risk and compliance (GRC) frameworks.

B

C

D

E

F

G

H

I

J

K

L

M

N

O

P

Q

R

S

T

U

V

W

Z

Frequently asked questions

What is an AI Impact Assessment (AIIA)?
An AI Impact Assessment is a structured review of an AI system before and during deployment: what it decides, on whom, using which data, what could go wrong, and which safeguards and human oversight are in place.
Is an AIIA the same as the AI Act’s fundamental rights impact assessment?
No. The EU AI Act sets out a specific Fundamental Rights Impact Assessment (FRIA) in Article 27, required of certain deployers of high-risk AI systems. An AIIA is a broader instrument — voluntary for businesses, though Dutch central government mandates it for its own AI systems — that can help prepare for a FRIA but does not by itself satisfy it.
When should you run an AI Impact Assessment?
Before an AI system goes live, and again when its purpose, data or model changes materially. Assessing a system already in production means you are documenting decisions rather than influencing them.