GRC Careers: AI Governance, Risk and Compliance JobsConnecting Talent and Trust. Post a Job Log in

HomeCybersecurity & GRC Career GuidesAI Impact Assessment Skills

AI Impact Assessment Skills

Get new GRC career guides by email. We publish most weeks. No spam, and we never sell or share your address with anyone.

AI Impact Assessment Skills illustration

An AI impact assessment asks a question a security review does not: not whether the system is safe from attackers, but what it might do to the people it is used on. Those are different questions, and confusing them is why so many assessments miss the thing that later becomes the problem.

This is pre-deployment work. Testing whether a live system behaves as claimed is auditing, and responding when it does not is incident response.

Start with who is affected, not what it does

The technical description is the wrong opening. "A model that ranks applicants" tells you nothing about exposure. "A model that decides which of 40,000 applicants a recruiter ever sees, where being filtered out is invisible to the applicant and unappealable" tells you everything.

Three questions do most of the work. Who is subject to this, including people who never chose to interact with it. What decision does it influence, and how reversible is that decision. Would the affected person know it happened, and could they contest it?

A system where the answer to the third is no deserves far more scrutiny, because nothing external will surface its errors.

The harms people forget

Allocative harm, where someone loses access to a job, a loan or a service, is the one everybody assesses. The ones that get missed are quieter.

Performance that differs across groups, which is invisible unless you deliberately measure it by subgroup rather than in aggregate. Feedback loops, where the model's output becomes tomorrow's training data and an initial skew compounds. Automation bias, where a human reviewer is nominally in the loop but approves ninety-eight percent of recommendations, which is not oversight. And the effect of being wrong in the rare case, which aggregate accuracy hides completely.

What the regulation asks for

Under the EU AI Act, deployers of certain high-risk systems, notably public bodies and private entities providing public services, must carry out a fundamental rights impact assessment before use, under Article 27. It covers the deployment context, the categories of people affected, the specific risks of harm to them, the human oversight arrangements, and what happens if the risks materialize.

The NIST AI Risk Management Framework organizes the same territory around Govern, Map, Measure and Manage, and its Map function is essentially impact assessment. ISO/IEC 42001 requires an AI system impact assessment as part of the management system.

Knowing which of these the organization is subject to, and being able to say why, is a straightforward differentiator in interviews.

Assessment that changes something

The failure mode is a thorough document that lands after the deployment date. An assessment that cannot change a decision is paperwork.

So the practical requirements are unglamorous: run it early enough that "do not deploy this" is still available, write mitigations that name an owner and a date, and record residual concerns with a person who accepted them. An assessment ending in "risks were identified" has not finished.

Getting into this work

The people who do it well come from unexpected places. Privacy professionals already know how to run a structured assessment and consult affected groups. Social researchers know how to ask who is harmed. Domain experts know which errors matter, which is knowledge no model card contains. Technical depth helps, and it is not the scarce ingredient.

Where to go next

Frequently Asked Questions

What is an AI impact assessment?

A structured evaluation, carried out before deployment, of how an AI system could affect the people subject to it. It differs from a security review, which asks whether the system is safe from attackers rather than what it might do to people.

What is a fundamental rights impact assessment?

The assessment required by Article 27 of the EU AI Act for certain deployers of high-risk systems, particularly public bodies and private entities providing public services. It covers deployment context, affected groups, specific risks of harm, human oversight arrangements, and the response if risks materialize.

How does an impact assessment differ from AI auditing?

Impact assessment is pre-deployment and predictive, asking what could happen. Auditing is post-deployment and evidential, testing whether the system behaves as claimed. Both are needed and they are separate disciplines.

What harms do assessments most often miss?

Performance differences across subgroups, which stay invisible unless measured by subgroup rather than in aggregate. Feedback loops where model output becomes future training data. Automation bias, where nominal human oversight approves nearly everything. And the severity of rare errors, which aggregate accuracy conceals.

Which frameworks require an AI impact assessment?

The EU AI Act under Article 27 for certain high-risk deployers. ISO/IEC 42001 requires an AI system impact assessment as part of the management system. The NIST AI Risk Management Framework covers the same ground through its Map function.

When should an impact assessment be performed?

Early enough that the outcome can still change the decision, including a decision not to deploy. An assessment delivered after the deployment date is documentation rather than governance.

What makes an impact assessment useful rather than performative?

Mitigations with a named owner and a date, and residual concerns recorded against a person who accepted them. An assessment that concludes "risks were identified" has not reached a decision.

Do I need a machine learning background?

It helps and it is not the scarce ingredient. Privacy professionals bring structured assessment and consultation experience, social researchers bring the discipline of asking who is harmed, and domain experts know which errors actually matter in context.

What jobs require AI impact assessment skills?

AI governance analyst and manager, responsible AI lead, privacy roles extending into AI, model risk, and public sector technology governance where Article 27 obligations apply directly.

More in this series

Written and reviewed by
Founder and Publisher, GRC Careers and AI Governance Jobs
  • Founder of ExecSearches and GRC Careers
  • Executive search across corporate, higher education, financial services, and nonprofit sectors
  • Focus on AI governance and GRC hiring
VP of Operations and GRC Practitioner
  • More than a decade in risk advisory and internal audit in financial services
  • Led SOX and regulatory audits for Citi, Goldman Sachs, Morgan Stanley, and McKesson
  • Public Accounting Certification, Cornell University