Skip to content

Impact Assessment

What is Impact Assessment?

An analysis of the potential consequences of a specific event, threat, or vulnerability being realised. Impact assessments consider financial, operational, reputational, legal, and regulatory consequences.

Risk Management

Each of these is named in at least one of the same controls as impact assessment. The number is how many controls name both.

What the standards actually require on impact assessment

Requirements naming impact assessment across 6 standards, quoted from the control text.

ISO 27701:20195 controls

The organization must assess whether a privacy impact assessment is needed and carry one out where appropriate whenever new processing of personal data or a change to existing processing is planned, determining the elements the assessment needs, which can incl...

iso-27701-2019::7.2.5 · Privacy impact assessment

Documented information on the AI system impact assessment shall be maintained and made available to relevant interested parties.

iso-iec-42001-2023::A.5.3 · Documentation of AI system impact assessments

The developer must make available, to the extent feasible, documentation through artifacts such as model cards, dataset cards or impact assessments necessary for the deployer (or its third party) to complete an impact assessment under 6-1-1703(3).

CO-AIA-1702-3 · Impact-Assessment Support Artifacts

Section 25E (added by 2018 GDPR Implementation Act) establishes Data Protection Impact Assessment (DPIA) requirement for processing likely to result in high risk to rights and freedoms of natural persons.

HU-INFOTV-Governance-DPIA-Privacy-by-Design-Risk-Section-25E · HU Infotv Section 25E - Data Protection Impact Assessment + Privacy by Design + Risk + Section 25F Prior Consultation

Algorithmic impact assessment (AIA). Article 22 requires an algorithmic impact assessment for high-risk AI systems, evaluating risks and mitigation measures.

BRAI-A22 · Algorithmic impact assessment
GDPR3 controls

Where a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, carry out an assessment of the i...

GDPR-Art.35 · Data protection impact assessment

Questions people ask about impact assessment

What is Impact Assessment?
An analysis of the potential consequences of a specific event, threat, or vulnerability being realised. Impact assessments consider financial, operational, reputational, legal, and regulatory consequences.
Why is Impact Assessment important for compliance?
Impact Assessment is a key concept in Risk Management. Understanding impact assessment helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Impact Assessment?
Impact Assessment appears in the requirement text of ISO 27701:2019, ISO/IEC 42001:2023, Colorado Artificial Intelligence Act (proposed SB 24-205), Hungary Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act), Brazil AI Framework. Across these standards we have identified 24 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Impact Assessment?
Explore our compliance framework pages to see how impact assessment applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Impact Assessment applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.