Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

AI impact assessment screening funnel from AI inventory to full assessment

AI Impact Assessment Screening: Who Needs One 2026

AI impact assessment screening is the step that decides which of your AI systems need a full impact assessment and which can be recorded briefly. Without it, teams either assess everything to the same depth and burn out, or assess only the systems someone happens to remember. Screening turns the decision into a repeatable, documented rule.

This guide explains how to design AI impact assessment screening, which questions to ask, how to set the threshold and how to record the outcome so you can defend it to an auditor or regulator.

Why AI impact assessment screening matters

Organisations rarely have one AI system. They have a chatbot in customer service, a scoring model in finance, a résumé filter in HR, an image tool in marketing and several vendor products with AI features switched on. Each affects people differently. AI impact assessment screening gives you a fast, consistent way to sort them by potential effect on individuals and society, and to show that the sorting was deliberate.

Screening also supports management system requirements. ISO/IEC 42001 expects an organisation to define a process for assessing AI system impacts; our guide to the ISO 42001 impact assessment explains where that requirement sits. ISO/IEC 42005:2025 offers guidance on how to perform the assessment itself; see the ISO/IEC 42005 listing on iso.org. Neither replaces your own judgment about thresholds.

Building the inventory for AI impact assessment screening

You cannot screen what you have not listed. Start with an inventory that includes systems you build, systems you buy and features inside other tools. For each entry, record the owner, the purpose, the users, the affected people, the data used and whether a supplier is involved. Ask procurement and IT for lists of tools with AI features, and ask business units about tools adopted without formal purchase. The inventory does not need to be perfect on day one, but it should have an owner and a way to add new entries. Our AI risk register guide shows how inventory and risk records can link.

Free AI impact assessment (ISO 42005)

Who could this AI system affect, and how?

Screen the system against sensitive and prohibited uses, describe it, check the safeguards for fairness, transparency and oversight, and rate its impacts on people and society from 26 scenarios with ISO 42001 Annex A measures. Free, with findings.

Start the free AI impact assessment →  or  View premium report sample

Screening questions to include

Keep the screen short enough that an owner can complete it in ten or fifteen minutes. The questions below are a practical starting set; adapt them to your context and any legal rules that apply to you.

Screening questionWhy it matters
Does the system make or influence decisions about individuals?Decisions on jobs, credit, services or safety carry higher impact
Does it use personal or sensitive data?Sensitive data raises the harm from errors or misuse
Is there meaningful human oversight before an outcome takes effect?Automated outcomes without review are riskier
Could it affect children or vulnerable groups?Some groups are harmed more easily and defend themselves less
Is the outcome hard to reverse or appeal?Irreversible effects justify deeper assessment
Does it operate at large scale or in public settings?Scale multiplies the effect of a flaw
Is it built on a third-party model you cannot inspect?Limited visibility is itself a risk to record

Add a legal trigger question

Some systems fall under rules that require a specific assessment. Under the EU AI Act, certain deployers of high-risk systems must carry out a fundamental rights impact assessment; see our guide to the fundamental rights impact assessment. Include a question asking whether any such rule applies, and route those systems straight to a full assessment.

Setting the threshold for AI impact assessment screening

Decide in advance what result leads to a full assessment. A simple rule works well: any “yes” on decisions about individuals, sensitive data, vulnerable groups or hard-to-reverse outcomes triggers a full assessment; systems with all answers “no” get a short recorded rationale. If you prefer scoring, write the scale down and test it on a few known systems to check it separates them sensibly. The threshold should err towards assessment when the answers are uncertain, because a wrongly screened-out system is worse than an unnecessary assessment.

Record the screening decision

Each screening record should show the date, the person who completed it, the answers, the outcome and the reason. Have a second person, such as the AI governance lead, approve any decision to screen a system out. That approval is often the first thing an auditor samples during a review of AI impact assessment screening.

Who owns the screening process

Give the process a single owner, usually the AI governance lead or the head of risk, who maintains the questions, the threshold and the register of decisions. System owners answer the questions; the process owner checks consistency across the portfolio. Without that central view, different departments will read the same question differently and the results will not compare.

Agree how often the questions themselves are reviewed. New laws, new incident types and lessons from earlier assessments should all feed back into the screen. A yearly review is a reasonable minimum, with an earlier update when a significant regulation or standard changes.

Training the people who answer

Most poor answers come from misunderstanding, not bad faith. A one-page guide with a worked example for each question helps owners see what counts as a “decision about an individual” or “meaningful human oversight”. For instance, a person who clicks approve on every recommendation without reading it is not meaningful oversight, and the guide should say so. Short training at onboarding and when the questions change keeps answers consistent and gives auditors evidence that the process is understood.

Handling shadow AI

Staff will adopt tools without telling anyone. Make it easy to report a new tool, keep the form short and do not punish people who come forward. Pair the reporting route with procurement controls and network or licence reviews so new tools surface early. Every newly discovered system should go through the screen within a defined number of days, and the discovery itself should be logged as a source of inventory gaps.

What happens after AI impact assessment screening

Systems that pass the threshold get a full assessment covering affected parties, benefits, harms, severity, likelihood, mitigations and residual impact. Those findings should feed your risk register and your treatment plans. For how the assessment differs from a risk assessment, see our comparison of AI impact assessment vs risk assessment. A finished record is shown in our AI impact assessment example.

Systems screened out still need a review trigger. A model update, a new data source, a new user group or an incident should send the system back through the screen. Without triggers, AI impact assessment screening becomes a one-off gate that quickly goes out of date.

A hypothetical example of AI impact assessment screening

The following is a hypothetical example invented for illustration. A logistics company screens three systems. The first is a code assistant used by its own engineers: no decisions about individuals, no sensitive data, humans review all output. It is screened out with a written reason. The second is a route optimiser for drivers: it affects working schedules but is reviewed by dispatchers and can be overridden; the owner answers “yes” on decisions about individuals and it moves to a full assessment focused on fairness of workload.

The third is a vendor tool that scores job applicants. It answers “yes” on decisions, sensitive data, oversight gaps and hard-to-reverse outcomes, and the supplier shares little documentation. It goes to a full assessment immediately, and the missing supplier information becomes a recorded finding. The screening took under an hour for all three and produced clear priorities.

Common mistakes in AI impact assessment screening

Typical weaknesses include screening only in-house models and ignoring vendor features, using a screen so long that owners skip it, letting the system owner alone decide to screen out, having no written threshold, failing to re-screen after changes and treating the screen as the assessment. Another is asking the wrong people: owners often understate impact, so involve legal, privacy or the affected teams where the answers are borderline.

Using a structured report after AI impact assessment screening

Once screening identifies which systems need a full record, a consistent format keeps results comparable. The AI Impact Assessment Report and Workbook provides a report with screening, safeguards, impacts and measures alongside a workbook. Whether you use it or your own form, apply the same structure to every system so leaders can compare the portfolio.

AI impact assessment screening FAQ

Is AI impact assessment screening required by ISO 42001?

The standard requires a process for assessing AI system impacts. It does not prescribe screening, but a screen is a practical way to decide which systems get a full assessment and to document that decision.

Who should complete the screening questions?

The accountable owner of the system should complete them, with review by an AI governance lead or privacy team for borderline cases.

Can a screened-out system be revisited later?

Yes, and it should be. Define triggers such as model updates, new data, new users and incidents that send a system back through the screen.

Do vendor AI features need screening?

Yes. If a supplier’s AI influences a decision you are accountable for, include it in the inventory and screen it, recording what documentation the supplier provided.

How detailed should the screening record be?

Short but complete: the date, the person, the answers, the outcome and the reason. The aim is to show that the decision was deliberate and consistent.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.