Free governance tool · 2026 edition

Understand who an AI system could affect before you deploy it

Map plausible impacts, test 29 lifecycle controls, expose blocking gaps, and generate an accountable mitigation and monitoring brief.

Step 1 of 7 · System context

Define the system and decision

Assess one specific system, purpose, deployment, user group, and level of authority. A broad label such as “customer-service AI” is not a sufficient boundary.

Use a recognizable internal name; do not enter personal data.
People or groups that may be affected *

Include people affected by decisions or errors, not only direct users.

Boundary rule: reassess when purpose, model, data, integrations, affected groups, reach, or authority changes materially.

Transparent methodology

Impact first, then controls and evidence

The tool separates plausible inherent impact from control maturity and reviewed evidence. A serious rights, safety, privacy, or human-oversight gap can pause the decision even when the average score looks acceptable.

20%

People & rights

Stakeholders, participation, notice, explanation, accessibility, challenge, and remedy.

20%

Data & privacy

Necessity, purpose, minimization, provenance, quality, retention, rights, and assessment.

20%

Quality & fairness

Fitness, representative tests, subgroup outcomes, failure analysis, reproducibility, and drift.

20%

Safety & security

Threats, injection, access, output handling, incidents, resilience, fallback, and recovery.

20%

Oversight & lifecycle

Ownership, human authority, training, monitoring, change, documentation, and decommissioning.

How the calculation works

  • Impact rating: severity (0–4) × likelihood (1–4) for each of eight domains.
  • Inherent impact: the strongest plausible impact domains plus contextual uplift for reach, authority, reversibility, data, stage, and affected groups.
  • Control maturity: Verified = 100, Partial = 60, Planned = 30, Unknown = 10, Missing = 0, weighted by importance.
  • Residual planning risk: inherent impact reduced by control maturity, then adjusted for evidence coverage and critical gates.
  • Scope: scores support prioritization and accountable discussion; they are not probabilities, certifications, or legal conclusions.

Need the complete step-by-step process?

Use the practical guide to define scope, involve affected stakeholders, map benefits and harms, rate severity and likelihood, verify controls, document mitigations, and set monitoring and reassessment triggers.

Read the AI Impact Assessment Guide
Continue the governance chain

Turn system impact into owned risk action

An impact assessment should feed a living risk register, procurement conditions, acceptable-use rules, controls, testing, monitoring, and reassessment.

Owned risk action

AI Risk Register Generator

Assign owners, treatments, deadlines, evidence, and residual ratings to the risks identified in this assessment.

Build the Register
Vendor evidence

AI Vendor Risk Assessment

Check whether the selected vendor and contract can support the controls this impact review requires.

Assess the Vendor
Governance rules

AI Policy Generator

Turn risk boundaries into workplace rules for tools, data, oversight, security, incidents, and training.

Generate a Policy
Observed evidence

AI Automation Pilot Scorecard

Test value, quality, reliability, controls, and evidence before making a scale decision.

Score a Pilot
FAQ

AI impact assessment questions