AI System Impact Assessments
The Impact Assessment register implements ISO 42001 Annex A.5.5: societal, environmental, economic, and human-rights impacts of each AI system. It is broader than the org-risk Risk Assessment (which focuses on impact to the organization) — A.5.5 asks you to consider impacts on people, communities, and the environment.
Who can do what
- Org Admins can create, edit, approve, mark reviewed, and delete.
- Workflow Admins can create, edit, submit for review, and mark reviewed.
- All members can view assessments and export DOCX reports.
Workflow
- Draft — Add title, scope, and per-impact lines (severity 1-5, likelihood 1-5, reversibility, mitigations, residual severity).
- Submit for Review — Requires title, scope, and at least one described impact line.
- Approved — An OrgAdmin approves; the version locks. Re-assessment cadence kicks in.
- Mark Reviewed — Use during the cadence interval to keep the schedule fresh.
- Superseded — Older approved assessments can be marked superseded when a new one supersedes them.
Risk math
Each line scores Severity × Likelihood (inherent) andResidual Severity × Likelihood (residual). Bands match the platform's 5×5 convention: Low (<6), Medium (6-11), High (12-19), Critical (≥20). The register's "Highest Residual" column shows the worst residual band across all lines.
Exports
- Per-assessment DOCX:
RhindonCyber_AISystemImpactAssessment_{system}_{MMDDYYYY-HHMM}.docx - Register DOCX (rollup of all approved assessments):
RhindonCyber_ImpactAssessmentRegister_{org-slug}_{MMDDYYYY-HHMM}.docx
Audit trail
Every action writes an audit row visible in your activity log and the platform audit log:
IMPACT_ASSESSMENT_CREATEDIMPACT_ASSESSMENT_UPDATEDIMPACT_ASSESSMENT_SUBMITTED_FOR_REVIEWIMPACT_ASSESSMENT_APPROVEDIMPACT_ASSESSMENT_REVIEWEDIMPACT_ASSESSMENT_SUPERSEDEDIMPACT_ASSESSMENT_EXPORTED
