# Impact Assessments — AI Strategy, Ethics and Governance

Source: https://www.geekswithgeeks.com/en/ai-strategy-governance/risk-impact-assessment

> Run a structured assessment before launching a high-impact system and record the outcome.

## Think before you ship

An **AI impact assessment** (sometimes combined with a privacy assessment, also called a DPIA where required) walks through: the purpose and benefits, the people affected, the data used and its lawful basis, foreseeable harms and their likelihood, test results including fairness across groups, safeguards and human oversight, how people can contest decisions, and a plan to monitor and review. Do it **before** launch, have it reviewed by someone outside the build team, and update it when the system changes. The document is also your evidence if a regulator or customer asks how you decided.

## Assessment outline

A template makes assessments consistent. Short answers are fine if they are specific and honest.

```text
1 Purpose and expected benefit         2 Who is affected (incl. non-users)
3 Data used, source, lawful basis, retention 4 Foreseeable harms: likelihood x severity
5 Evaluation results, incl. group gaps      6 Safeguards and human oversight
7 How people can contest or get help        8 Monitoring plan, review date, owner
9 Independent reviewer and sign-off         10 Residual risk accepted by (name, date)
```

**Quiz:** When should an AI impact assessment be done?

- [x] Before launch, and updated when the system changes
- [ ] Only after a complaint
- [ ] Never
- [ ] Once, then forgotten

*Answer:* Before launch, and updated when the system changes. Assessing risks up front lets you fix design problems before people are affected.
