Governance & Compliance · Data artifact
AI Impact Assessment Record
Data artifactGovernance & ComplianceSafety, Security & Governancearc:AIImpactAssessmentRecord
A structured assessment recording, at problem formulation, which stakeholders and communities a proposed AI system may harm, fairness and privacy considerations, alternatives, and the resulting design decisions.
Responsibility. Documents potential harms to stakeholders and the fairness/privacy trade-off decisions taken.
Also known as: Fairness impact assessment, Privacy impact assessment (with fairness considerations), Stakeholder analysis, AIA, AI Impact Assessment, Fundamental Rights Impact Assessment, FRIA, Data protection impact assessment
Relationships
configures structural
receives data from dynamic
sends data to dynamic
is audited by assurance
is evaluated by assurance
Design guidance
- SHOULD be conducted during problem formulation, before data collection and model development.
- SHOULD identify direct users, data subjects, indirect stakeholders and vulnerable populations.
- MUST be reassessed at least annually, on significant system change, and when stakeholders raise new concerns.
- SHOULD consider not deploying AI at all as a legitimate mitigation outcome.
- MUST NOT replace human judgment: humans decide whether identified impacts are acceptable.
- SHOULD communicate findings in formats suited to technical teams, executives, regulators and affected communities.
Quantitative guidance
As stated by the sources; verify before use.
- Reassessment at least annually (Ch9.8).
Classification
- Patterns
- Seven-stage impact assessment (scoping, information gathering, identification, analysis, evaluation & mitigation, documentation & communication, monitoring & iteration)
- Quality attributes
- Transparency and accountability (NIST AI RMF: accountable and transparent)Fairness (NIST AI RMF: fair, harmful bias managed)Privacy (NIST AI RMF: privacy-enhanced)
- Risks mitigated
- Unanticipated societal or rights harmsHarms concentrated on specific demographic groupsStale assessments after system or context change
- Frameworks & regulations
- NIST AI RMF: MAPISO/IEC 42001 §6 Planning (AI impact assessment)EU AI Act: Fundamental Rights Impact AssessmentGDPR: data protection impact assessment
Sources
- Ch9.4: T. Nguyen, "Fairness and Bias Mitigation," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.4. ISBN: 9798244538229.
- Ch9.8: T. Nguyen, "Standards and Frameworks for AI Governance," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.8. ISBN: 9798244538229.
- Ref9.02: "Responsible AI and Ethical Principles," unpublished reference note (02-Responsible-AI-Ethical-Principles.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note
- Ref9.06: "Auditing and Compliance Monitoring for AI Systems," unpublished reference note (references/Chapter 9 - Safety, Ethics, and Compliance/06-Auditing-Compliance-Monitoring.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note