Study the lesson
Work through every section at your own pace, from start to finish.
Your organisation is evaluating a new AI system, perhaps a tool that screens job applications, flags performance issues, or forecasts staffing requirements. Someone sends you a document: the AI Impact Assessment. It runs to forty pages. Where do you even start? This lesson gives you a practical reader's map. An AI Impact Assessment, or AI IA, is a structured document that evaluates the risks, benefits, limitations, and organisational implications of deploying a specific AI system in a specific context. Think of it like a structural survey before buying a building. The surveyor does not decide whether you proceed; that is your call. But a good survey tells you precisely what you are taking on, what has been fixed, and what risk remains. Your signature on an AI IA carries the same weight: you are not endorsing the engineering, you are accepting the residual risk as described. AI IAs are fast becoming mandatory. The EU AI Act requires conformity assessments from providers of high-risk systems, including recruitment and performance-management tools, and fundamental rights impact assessments from certain deployers, chiefly public bodies, private organisations providing public services, and users of credit-scoring and insurance systems; even where no assessment is legally required, many organisations now mandate an AI IA as internal governance. The challenge for leaders is not locating the document. It is knowing what a good one looks like, what a thin one conceals, and what questions to ask before you sign.
Unlock the full lesson, the quiz, and your verifiable completion.
Continue with GoogleBy continuing you agree to the Institute of AI terms of use and privacy policy.
None of these are hard requirements. The lesson is easier if they are already familiar, but everything it uses is explained along the way, so you can start without them.
Section one is open to everyone. Create a free account to work through the rest and take the quiz.
A credible AI IA is not defined by length. Specificity is what matters. Five areas should appear in every document worth reading. Intended purpose and scope: the assessment must state precisely what the system is designed to do and, critically, what it is not designed to do. A candidate-screening tool trained on data from one industry sector is not validated for another, and if the scope section is vague, every subsequent section becomes unverifiable. Known limitations and failure modes: no AI system performs perfectly across all populations and conditions, so a well-formed IA names the specific conditions under which the system degrades, such as low-data scenarios, edge cases, and input types outside the training distribution. Vague language such as "performance may vary" is a warning sign; look for quantified error rates and named test conditions. Data sources and bias considerations: AI systems reflect the data they were trained on, so the IA should identify the origin, age, and composition of training data, and describe how the team assessed it for bias. Fairness sections typically use proxy metrics, indirect measures used as stand-ins for characteristics that cannot be measured directly, and a transparent document acknowledges the limits of those metrics. Equal error rates do not guarantee equitable outcomes in every real-world context, and a sound IA says so. Human oversight mechanisms: who reviews the system's outputs before consequential decisions are made, and how are appeals handled? The IA should name roles, not just principles. "A human will always be in the loop" is not an oversight mechanism; "the line manager receives a confidence score and must document their rationale before proceeding" is. Residual risk is the section that demands your closest attention. Gross risk is what the system could do before any controls are applied. Residual risk is what remains after all stated mitigations. When you sign off on an AI IA, you are accepting the residual risk as it will exist in your environment, with your staff and your processes, rather than the tidier version the vendor imagines. If mitigations rely on training that has not yet happened, or oversight processes that are not yet resourced, the residual risk is higher than the document suggests.
Work through every section at your own pace, from start to finish.
A short set of questions on what you have just covered.
Every completion has a certificate that you can share publicly for anyone to verify.
Pass the quiz and the Institute of AI issues you a record of completion with your score. Every completion has its own public verification page, so the link you put on your CV or LinkedIn profile can be checked by anyone, at any time.
Free lessons, a quiz to test what you have learned, and a completion you can verify publicly. All from the UK's professional body for artificial intelligence.
Every AI lesson is free to start, free to finish, and ends in a completion you can verify publicly.