Skip to content
Learn · AI Lessons · Free lesson

Reading an AI Impact Assessment

Your organisation is evaluating a new AI system, perhaps a tool that screens job applications, flags performance issues, or forecasts staffing requirements. Someone sends you a document: the AI Impact Assessment. It runs to forty pages. Where do you even start? This lesson gives you a practical reader's map. An AI Impact Assessment, or AI IA, is a structured document that evaluates the risks, benefits, limitations, and organisational implications of deploying a specific AI system in a specific context. Think of it like a structural survey before buying a building. The surveyor does not decide whether you proceed; that is your call. But a good survey tells you precisely what you are taking on, what has been fixed, and what risk remains. Your signature on an AI IA carries the same weight: you are not endorsing the engineering, you are accepting the residual risk as described. AI IAs are fast becoming mandatory. The EU AI Act requires conformity assessments from providers of high-risk systems, including recruitment and performance-management tools, and fundamental rights impact assessments from certain deployers, chiefly public bodies, private organisations providing public services, and users of credit-scoring and insurance systems; even where no assessment is legally required, many organisations now mandate an AI IA as internal governance. The challenge for leaders is not locating the document. It is knowing what a good one looks like, what a thin one conceals, and what questions to ask before you sign.

Start this lesson freeFree forever. No card required.
Intermediate 10 minutes AI for Leaders Certificate upon completion

Create your free account

Unlock the full lesson, the quiz, and your verifiable completion.

Continue with Google
or
Continue with email

By continuing you agree to the Institute of AI terms of use and privacy policy.

Learners across the UK study with the Institute of AI
Open to everyone From the UK's professional body for AI 100% free, no card required
What you'll learn

By the end of this lesson, you will be able to:

  • Tell a well-formed impact assessment from a merely long one, by looking for specificity.
  • Separate gross risk from residual risk, and know which of the two you are signing off.
  • Spot the three common traps, including treating a vendor assessment as though it covered your context.
  • Set the triggers that force a reassessment, such as a change of scope, data, user population, or regulation.

Recommended before you start

None of these are hard requirements. The lesson is easier if they are already familiar, but everything it uses is explained along the way, so you can start without them.

  • Some experience reading governance or risk documentation, such as a data protection impact assessment.
Join Others Learning AI

Free to start. Free to finish. Free to prove.

Start this lesson free
Inside this lesson

2 sections, about 10 minutes.

Section one is open to everyone. Create a free account to work through the rest and take the quiz.

01

What a Well-Formed AI IA Contains

Free preview

A credible AI IA is not defined by length. Specificity is what matters. Five areas should appear in every document worth reading. Intended purpose and scope: the assessment must state precisely what the system is designed to do and, critically, what it is not designed to do. A candidate-screening tool trained on data from one industry sector is not validated for another, and if the scope section is vague, every subsequent section becomes unverifiable. Known limitations and failure modes: no AI system performs perfectly across all populations and conditions, so a well-formed IA names the specific conditions under which the system degrades, such as low-data scenarios, edge cases, and input types outside the training distribution. Vague language such as "performance may vary" is a warning sign; look for quantified error rates and named test conditions. Data sources and bias considerations: AI systems reflect the data they were trained on, so the IA should identify the origin, age, and composition of training data, and describe how the team assessed it for bias. Fairness sections typically use proxy metrics, indirect measures used as stand-ins for characteristics that cannot be measured directly, and a transparent document acknowledges the limits of those metrics. Equal error rates do not guarantee equitable outcomes in every real-world context, and a sound IA says so. Human oversight mechanisms: who reviews the system's outputs before consequential decisions are made, and how are appeals handled? The IA should name roles, not just principles. "A human will always be in the loop" is not an oversight mechanism; "the line manager receives a confidence score and must document their rationale before proceeding" is. Residual risk is the section that demands your closest attention. Gross risk is what the system could do before any controls are applied. Residual risk is what remains after all stated mitigations. When you sign off on an AI IA, you are accepting the residual risk as it will exist in your environment, with your staff and your processes, rather than the tidier version the vendor imagines. If mitigations rely on training that has not yet happened, or oversight processes that are not yet resourced, the residual risk is higher than the document suggests.

02

Common Traps and How to Avoid Them

Unlock free
How it works

Walk away with proof, not just knowledge.

Step 1

Study the lesson

Work through every section at your own pace, from start to finish.

Step 2

Pass the quiz

A short set of questions on what you have just covered.

Step 3

Get your certification

Every completion has a certificate that you can share publicly for anyone to verify.

Your record of completion

Finish the lesson. Keep the proof.

The Institute of AI
Record of completion
Reading an AI Impact Assessment
Completed by
Your name
Quiz score
90%
theinstituteofai.co.uk/verify/lesson/…

Pass the quiz and the Institute of AI issues you a record of completion with your score. Every completion has its own public verification page, so the link you put on your CV or LinkedIn profile can be checked by anyone, at any time.

  • Verifiable by anyone, with no account needed
  • One link for your CV, email signature, or LinkedIn profile
  • Issued by the UK's professional body for AI
— Common questions —

Frequently asked questions.

Is this lesson really free?+
Yes. Every AI lesson from the Institute of AI is free to take and free to complete, including the quiz and your record of completion. There is no trial, no card, and no catch.
Do I need a technical background?+
This lesson is pitched at intermediate level, so it helps to be comfortable with what is recommended above, though none of it is a hard requirement. Everything is explained in plain English, and if a term matters, the lesson covers it before using it.
How long does this lesson take?+
Around 10 minutes to work through, plus the quiz at the end. You can leave and come back at any point.
What do I get when I finish?+
A record of completion with your score, held on your profile. Each completion has a public verification page, so you can share a link on your CV or LinkedIn profile that anyone can check.
What is the Institute of AI?+
The Institute of AI is the UK’s professional body for artificial intelligence. It sets the standard of AI practice, works to that standard itself, and puts it within reach of everyone else. Its work runs across four areas: Accreditation, Practice, Platforms, and AI for All.

Join learners across the UK and start "Reading an AI Impact Assessment" today.

Free lessons, a quiz to test what you have learned, and a completion you can verify publicly. All from the UK's professional body for artificial intelligence.

The Institute of AI

Free to learn.
Yours to prove.

Every AI lesson is free to start, free to finish, and ends in a completion you can verify publicly.