This free AI impact assessment template works the way ISO/IEC 42005 describes an AI system impact assessment: one AI system, its reasonably foreseeable impacts on the individuals, groups and society it affects, weighed against its benefits, before it is deployed and again when it changes. Instead of a blank document, it asks the questions in turn, checks your answers as you go and tells you what an auditor or regulator would still ask for.
Start by screening the system against prohibited and sensitive uses, then describe it, check the safeguards for each dimension of impact, rate its impacts from a library of 26 scenarios, choose measures from the ISO/IEC 42001 Annex A controls and record the review and the decision. It supports clause 6.1.4 of ISO/IEC 42001 and follows the guidance in ISO/IEC 42005:2025. It is free, and your answers save as you go.
Premium report
See what the premium AI impact assessment report looks like
A worked AI system impact assessment for a fictional organization: the screening, the description of the system, the safeguards for each dimension of impact, every impact on people and society with its measures and ISO 42001 Annex A references, the review and decision, every finding with what closes it, an AI-assisted analysis with a 30/60/90-day roadmap, plus the live Excel workbook.
Other free risk assessments: Information Security Risk Assessment (ISO 27001) Privacy Risk Assessment (ISO 27701) Business Continuity Risk Assessment (ISO 22301) Enterprise Risk Assessment (ISO 31000) AI Risk Assessment (ISO 42001) Data Protection Impact Assessment (GDPR) Transfer Impact Assessment (GDPR) Legitimate Interests Assessment (GDPR) Third-Party Risk Assessment (ISO 27001)
What this AI impact assessment template covers

- Screening. Whether the system could fall within a prohibited practice, whether it has a sensitive use such as recruitment, credit or biometrics, and the context factors that call for a full assessment, with the verdict and your reasoning.
- Scope and criteria. The AI system you are assessing, and likelihood and severity scales that describe the harm to people and society, not to the organization.
- What the system involves. The AI system and its features, the uses and decisions it supports, the people and groups it affects, its data, its model and its providers.
- The system and its safeguards. Purpose, intended uses, foreseeable misuse, data, model, deployment environment, the people affected and the expected benefits, then ten questions on the safeguards for fairness, transparency, explanation, oversight, contestability, privacy, safety, monitoring, society and accountability.
- Impacts. Scenarios from unfair outcomes and missing explanations to automation bias, misuse, drift, effects on jobs and misinformation, each rated for the people affected.
- Measures. The measures that address each impact, each referenced to an ISO/IEC 42001 Annex A control, with an owner, a date and the level expected afterwards.
- Review and decision. The governance review, the views of the people affected, the decision (proceed, proceed with measures, proceed within limits, or do not deploy) and the next review date.
What you get from the AI impact assessment template, free
The screening verdict, a heat map of the impacts, the check that tells you whether High or Critical impact remains once your measures are in place, a process score out of 100, and the findings an auditor would raise, such as a missing route for people to contest a result or no monitoring after launch. Sign in and it stays in your account, ready for the next review.
The full AI impact assessment report turns the AI impact assessment template into a finished record, with the measures by owner and due date and their Annex A references, the decision, an AI-assisted analysis with a 30/60/90-day roadmap, and the whole assessment as a live Excel workbook.
Where this fits
An AI impact assessment template like this one looks outward, at the people and society an AI system affects. The AI risk assessment looks at the risks to your organization and its objectives; ISO/IEC 42001 asks for both, and the impacts you find here feed the risk treatment there. Our guide to the AI system impact assessment and ISO 42005 explains the method in full. If the system processes personal data, it may also need a DPIA, and deployers of some high-risk systems owe a fundamental rights impact assessment under the EU AI Act. For the documents around it, see the ISO 42001 Toolkit.
Frequently asked questions
When should I use the AI impact assessment template?
Before an AI system is deployed, and again after any significant change: a new use, new data, a new model, new users or a new country. ISO/IEC 42001 clause 6.1.4 asks for an AI system impact assessment as part of planning, and clause 8.4 asks for it to be carried out at planned intervals or when significant changes are proposed.
Is this the same as a fundamental rights impact assessment?
No, but it covers much of the same ground. The EU AI Act’s Article 27 assessment is owed by certain deployers of high-risk systems and has its own required content and a notification to the authority. An ISO/IEC 42005 impact assessment is broader and voluntary, and a good starting point for it.
Does the AI impact assessment template work for bought-in AI?
Yes. Many of the scenarios deal with third-party models and providers, and the description step asks what you know, and do not know, about the model you rely on.
Is this a substitute for legal advice?
No. It is a structured self-assessment built from the information you enter, and Governance Docs does not review or verify it. Whether a use is prohibited or high-risk under the EU AI Act is a legal question.
What happens to the information I enter?
It is stored with your assessment so you can come back to it, and it is never shared. Describe the system and the people it affects in general terms rather than entering any real personal data. You can delete an assessment permanently from your account at any time.
