Skip to main content

AI Governance & Assurance

AI Impact Assessment

Assess a specific AI use case, its potential impacts and the safeguards and evidence needed for an accountable decision.

A structured assessment of one AI use case — distinct from an organisation-wide governance review.

View relevant evidence — View Relevant Evidence

When this service fits

For a planned or live AI use case that affects people, decisions or regulated outcomes and needs a defensible go, condition or stop decision.

  • A new AI use case affects customers, patients or staff

  • A supplier is introducing AI into a service you rely on

  • Leadership needs a defensible basis to approve or decline

  • A DPIA or clinical safety review raised AI-specific questions

  • An existing AI use has changed in purpose or scale

  • Procurement or a regulator is asking how the use case was assessed

The service

One use case, examined properly

The assessment looks at the intended purpose, the people affected, the data involved, supplier dependencies, human oversight and the relevant legal, privacy, safety, security and operational risks — then sets out the safeguards and evidence needed before a decision.

It connects with, but does not replace, a DPIA, clinical safety assessment (DCB0129/DCB0160), cyber review or any applicable regulatory assessment. Where one of those is required, it is identified and scoped on its own terms.

Management remains responsible for the deployment decision and for accepting residual risk.

What changes for your organisation

Outcomes the service is built to deliver

  • Use case and purpose

    What the AI does, for whom and why, within agreed boundaries.

  • Affected people

    Who could be affected, how, and how they could raise concerns.

  • Supplier dependencies

    What the supplier provides, claims and evidences.

  • Oversight

    How humans monitor, intervene in and override outputs.

  • Relevant risks

    Legal, privacy, safety, security, fairness and operational risks proportionate to the use.

  • Safeguards and evidence

    Controls needed, evidence required and conditions for a decision.

How we deliver

Assess → Build → Manage → Assure → Improve

  1. Assess

    Confirm the use case, scope and evidence available.

  2. Build

    Assess impacts and define safeguards and conditions.

  3. Manage

    Optional — ongoing review is scoped separately if wanted.

  4. Assure

    Present a decision record to management.

  5. Improve

    Reassess when purpose, supplier or scale changes.

Improve feeds the next Assess cycle, so evidence stays current.

What you receive

The working records this service produces

Illustrative examples of the registers, records and executive reporting that may support the engagement.

AI Governance Dashboard · Q3 periodIllustrative data — not client data
Overall positionAmber — improving
AI systems registered
16
▲ 3 this period
Impact assessments open / closed
3 / 9
▲ 2 closed
Systems awaiting approval
2
No change
AI issues under review
1
No change

AI risk by level

  • High2
  • Medium3
  • Low2

Controls evidenced

76%

Model reviews due
3
Overdue actions
2
Matters for escalation
1

Illustrative output

AI Governance Dashboard

Ongoing oversight

A recurring view of AI systems, assessments and controls, so AI risk is seen and escalated before it becomes exposure.

What it helps you see

  • AI system inventory and movement
  • Impact assessments and approvals
  • AI risk by level
  • Reviews, actions and escalations

Likely format

Dashboard / reporting view · Supporting registers and evidence records · Executive PDF summary where agreed

AI Impact Assessment RecordIllustrative data — not client data
Illustrative AI Impact Assessment Record
ImpactWhoLikelihoodSafeguard
Incorrect outputService usersPossibleHuman review
Data reuseCustomersUnlikelyContract term

Illustrative output

AI Impact Assessment Record

Assessment

The structured assessment of the use case.

What it helps you see

  • Purpose and context
  • Affected people
  • Impacts and risks
  • Safeguards

Likely format

Decision & Conditions RecordIllustrative data — not client data
Illustrative Decision & Conditions Record
DecisionConditionOwnerReview
Proceed with conditionsSupplier evidenceOwner AOn change

Illustrative output

Decision & Conditions Record

Decision

What management is asked to decide, and on what conditions.

What it helps you see

  • Recommendation
  • Conditions
  • Residual risk
  • Decision owner

Likely format

Illustrative structure — not a client document. Exact outputs and formats depend on the agreed scope.

Scope boundaries

What is included, and what is scoped separately

Included in the core service

  • Use-case scoping
  • Impact and risk assessment
  • Review of supplier evidence within scope
  • Safeguards and conditions
  • Decision record for management
  • Identification of related assessments required

Separately scoped where required

  • DPIAs, clinical safety cases or regulatory submissions themselves
  • Technical model testing or red teaming
  • Formal legal opinions
  • Organisation-wide governance assessment
  • Implementing safeguards

Scope, deliverables and assumptions are agreed in writing before work begins.

Relevant evidence

Relevant governance & assurance capability

This evidence shows related HealthTech, governance and assurance capability. It is not presented as a completed AI impact assessment unless the case says so.

  • Named client · Technology / SaaS / RegTech

    Clini-Hub

    Embedded governance and clinical-safety support since start-up

    NHS AI Toolkit, DSPT, DTAC and clinical-safety governance from start-up

    View the evidence: Clini-Hub
  • Anonymised engagement · Technology / SaaS / RegTech

    A FTSE 100 organisation

    Three-stage governance and audit-readiness plan

    Audit-ready UK policies ahead of a third-party maturity assessment

    View the evidence: A FTSE 100 organisation
  • Named client · Financial Services

    AIG

    Supplier data-governance audit

    Nationwide supplier audit

    View the evidence: AIG

Your IG-Smart team

Specialist expertise, coordinated around your requirement

Subject-matter expertise is paired with a clear client and programme contact from initial scoping through delivery.

  • Subject-matter expert

    Michael Abtar

    LLB (Hons), PG.Dip.Law, Cert. DPO

    View profile
  • Client & programme contact

    Julia Andrade

    Coordinates scope, practitioners, delivery and stakeholder communication.

    View profile

Buyer decisions

Questions before you engage

How is this different from an AI governance assessment?

A governance assessment reviews how AI is governed across the organisation. An impact assessment examines one specific use case and supports a decision about it.
AI Governance Assessment

Does it replace a DPIA?

No. It identifies where a DPIA, clinical safety assessment, cyber review or regulatory assessment is needed and connects with them, but does not satisfy each requirement automatically.

Who decides whether the AI is deployed?

Your management. The assessment frames the impacts, safeguards and residual risk; the decision and risk acceptance remain yours.

Can you assess a supplier's AI?

Yes, within scope — based on the supplier's documentation and evidence. Technical model testing is separately scoped.

Investment

Scoped to requirement

Scope, deliverables, assumptions and fees are agreed in writing before work begins.

The fee depends on

  • Complexity and impact of the use case
  • Affected people and data
  • Supplier evidence available
  • Related assessments to coordinate
  • Timescale for the decision

Procurement or supplier-assurance review?

Visit our Trust Centre

Ready to move forward?

Need a defensible decision on a specific AI use case?

Not sure which service applies? Find the Right Service

  • Still defining your requirement?

    Discuss an AI Use-Case Assessment

    Discuss the requirement, risk, scope and the right engagement model with an experienced practitioner.

    Discuss an AI Use-Case Assessment
  • Have a defined scope, tender or RFP?

    Submit an AI Impact Assessment Requirement

    Share a defined requirement, RFP, tender, statement of work or existing scope for senior review.

    Submit an AI Impact Assessment Requirement
  • Procurement or supplier assurance

    Prepare for Procurement Review

    Access company, security and assurance information for supplier review, with controlled evidence available on request.

    Open Trust Centre