Tier 2: Evidence-grade controls
AI impact assessment (AIIA / risk assessment)
A structured assessment of how an AI system could affect people, operations, and compliance, including mitigations and approvals before deployment.
Board-defensible evidence
- Assessment template capturing intended use, foreseeable misuse, impacted stakeholders, harm scenarios, severity and likelihood ratings, and who performed the assessment with dates.
- Mitigation plan linking each identified risk to a control, owner, due date, and validation method, including how residual risk was determined and approved.
- Stakeholder input records showing consultation with legal, risk, security, privacy, and business owners, including documented disagreements and how they were resolved.
- Approval workflow evidence showing the decision gate to proceed, defer, redesign, or reject the use case, with escalation criteria to governance committees.
- Post-deployment review evidence showing the assessment was revisited after real-world operation, including incident learnings, monitoring results, and updated mitigations.
Why this matters
Impact assessments are a primary artifact regulators look for when evaluating whether harms were foreseeable and whether mitigations were responsibly implemented.
How ready is your board on evidence-grade controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.