Compliance

Impact Assessment

A systematic, documented review (ex‑ante or ongoing) of how an AI system may affect individuals, groups, organisations or society and measures to mitigate harms.

Definitions (11)

A focused assessment that analyzes the potential downstream effects of an AI system on rights, equity, privacy and public values, producing documented findings and mitigation measures to inform design, procurement and deployment decisions. The instrument frames impact assessments as a prerequisite for high-risk or sensitive public-sector applications and for informing monitoring plans.

A structured pre-deployment evaluation that examines risks including bias, discrimination, privacy, security and safety issues associated with an AI system; required to be submitted to the authority for systems above predefined risk thresholds and used to inform authorization, mitigation, and monitoring decisions.

A documented quantitative and qualitative analysis performed prior to deployment that identifies risks posed by an AI system, evaluates mitigation measures, and records residual risk and plans for monitoring and redress. The Plan requires Impact Assessments (e.g., AI Impact Assessment) for priority public sector deployments and high‑risk systems.

An ongoing study and documentation process that evaluates an automated decision system across development, validation, deployment, monitoring, and remediation stages, including baseline comparisons, data provenance, testing/validation metrics, stakeholder consultation, mitigation plans, and records of infeasible assessment elements.

An ongoing study and documentation that describes a system's decision purpose, datasets and provenance, training/labeling practices, technical and business performance metrics, benchmarking and test procedures, evaluations of differential performance across demographic and protected categories, stakeholder consultation, security and privacy protections, remediation plans, and consumer rights pathways. Covered entities must create, retain, and make machine-readable summary reports derived from these assessments available to the FTC and, in limited form, to the public repository.

A documented assessment required for higher-risk AI systems that identifies and analyzes risks to privacy, safety, non-discrimination and socio-economic outcomes, outlines mitigation measures, and supports conformity assessment, registration, monitoring and regulatory oversight.

A systematic evaluation tool (including templates) for public-sector AI deployments to identify privacy, bias, fairness and administrative impacts, along with mitigation measures, transparency requirements and appeals mechanisms for affected citizens.

A structured ex-ante evaluation process to identify, analyze and propose mitigation for potential negative impacts and risks (including rights-related harms) associated with AI systems, especially for higher-risk public deployments.

A mandatory evaluation conducted by state agencies prior to implementing an AI system, and on an ongoing basis, to ensure the system will not result in any unlawful discrimination or disparate impact against individuals or groups based on actual or perceived differentiating characteristics.

An impact assessment, in the context of algorithmic systems, is a structured evaluation conducted to identify and analyze the potential positive and negative effects, particularly discriminatory impacts, that an algorithm or AI system might have on individuals or groups. It typically involves evaluating data sources, model design, deployment context, and mitigation strategies to ensure fairness and prevent harm.

A continuous process of reviewing and understanding the consequences of deploying generative AI systems, focusing on administrative efficiency, service delivery, ethical considerations, and the prevention of unintended biases or discriminatory outcomes.