An impact assessment has to keep observed evidence, inference, mitigation, and authority separate while tracing plausible harm to affected groups and named owners.

Before a system advances, we document what it is intended to do, how it could foreseeably be used or misused, and who may be affected. Each plausible harm is linked to the available evidence, current controls, mitigation owner, and whoever has the authority to decide how much residual risk is acceptable. An affected-group dossier, mitigation-owner log, and explicit acceptance conditions give your designated authority a clear, traceable residual-risk position.

Illustration of AI Risk & Impact Assessment: a team reviewing AI policy and risk controls in a governance framework

Some of the 500+ brands we've worked with

See all references
  • Halk Yatırım
  • Canbebe
  • Joker
  • Yatsan
  • Teyit.org
  • Jollytur
  • Amazon
  • BMW
  • Shell
  • Hyundai
  • PepsiCo
  • Red Bull
  • Decathlon
  • MediaMarkt
  • Bayer
  • Sanofi
  • EY
  • KPMG
  • GE
  • 3M
  • Domino’s
  • Lexus
  • Trendyol
  • Hepsiburada

Evidence, inference, mitigation, and acceptance stay separate throughout the work. That separation keeps uncertainty visible and stops a favorable aggregate rating from hiding a serious open harm path.

  1. Fix the decision and impact boundary

    We agree the system decision under review, its intended and foreseeable uses, affected groups, evidence access, and who has the authority to accept residual risk. The boundary also records which perspectives cannot yet be reached. Your system owner decides which uses and affected groups belong in the assessment.

  2. Follow each harm through the system

    Stakeholder evidence is traced through intended use, misuse, and data flows to plausible harms. We mark where the pathway rests on direct evidence, an inference, or a perspective that has not yet been represented. Your system owner confirms where direct stakeholder evidence is still needed.

  3. Challenge the rating and control evidence

    For every material harm, we examine likelihood, impact, current controls, confidence in the evidence, and the owner of each proposed mitigation. Uncertainty can raise the level of review when the available evidence does not justify a reassuring rating. Your designated authority decides whether the rating is supported or needs escalation.

  4. Record the residual risk

    Where the evidence permits, we test material findings again and document the result. Open conditions, mitigation owners, and reassessment triggers are then presented to the authority responsible for the final risk decision. Your designated authority makes the residual-risk decision and approves the reassessment trigger.

The artifact set makes it possible to distinguish what was observed, what was inferred, which controls exist today, what mitigation is proposed, and which question still needs authority.

  • Report

    Affected-group impact and control-evidence dossier

    The intended uses, affected groups, harm scenarios, control review, evidence confidence, and residual questions in one assessment record.

  • Matrix

    Stakeholder and harm-scenario map

    The people, workflows, uses, misuse paths, data flows, and plausible harms included in the review.

  • Risk register

    Mitigation-owner and reassessment trigger log

    Material risks, existing controls, mitigation actions, owners, evidence, status, and reassessment triggers.

  • Decision record

    Residual-risk conditions and authority sign-off brief

    The decision, accepted conditions, open risks, authority, review date, and stop or reassessment triggers.

Use it when a launch or material change is close and the affected groups, harm paths, or residual-risk authority are still unclear.

A good fit when

  • The system affects people or decisions, but stakeholder perspectives needed to trace plausible harm are still missing from the review.
  • Unknowns are being read as low risk, so weak evidence could let a serious harm path pass without the higher review it needs.
  • Mitigations appear in the plan, but no accountable owner or reassessment trigger says who acts when the system or evidence changes.
  • The intended use is documented, yet foreseeable and misuse scenarios have not been followed through the system to affected groups.
  • Stakeholders are named, but no one has traced how data flows and system decisions could lead to plausible harm.
  • Likelihood and impact ratings exist, although nobody has checked the control evidence or stated how much confidence each rating deserves.
  • Mitigation actions are proposed, but ownership, residual-risk authority, and reassessment triggers are missing from the same record.

Better handled as other work when

  • You want the residual-risk record read as legal, regulatory, audit, or certification authority. Those determinations stay with your qualified specialists.
  • You need a declaration that the system is completely safe or risk-free, while unidentified harm and uncertainty remain possible.
  • You need the mitigations built or operated as part of this review, but the agreed assessment ends with owners and closure conditions.

If one of these is closer to your situation, start here instead: See responsible AI consulting

We've worked with more than 500 brands since Zeo started in 2011. The people helping you decide where AI fits, and where it doesn't yet, are senior engineers and strategists who build and operate production AI systems. The advice stays grounded in work that actually shipped.

  • Anthropic

    drafts the first pass of harm scenarios and evidence summaries an analyst then challenges

  • Datadog

    the production logs that show what a claimed control actually did

  • Hugging Face

    the published model card checked against what the system is claimed to do

  • Giskard

    the automated scan that turns a foreseeable-misuse claim into a test result

  • Guardrails AI

    tests whether a claimed mitigation control actually intercepts the harm it names

  • Jupyter

    runs the likelihood and severity math a second reviewer can rerun and check

Use the system view, stakeholder evidence, current controls, and a named decision-maker. The record separates what is known from what remains open.
Assess the risks

What evidence do you need for an impact assessment?

We need intended and foreseeable uses, system and data flows, stakeholder perspectives, current controls, incident history, named mitigation owners, and a decision-maker for the residual risk question. Missing evidence can remain open in the record. We do not replace it with guesses.

What can AI contribute to the assessment?

AI may organize approved evidence, compare scenario coverage, and prepare draft cases for specialist review. It cannot decide who is affected, assign risk, interpret law, or mark a mitigation complete.

What has to be true before the assessment reaches a decision?

Affected groups and material scenarios must be represented well enough for review. Each risk rating needs a stated evidence confidence. High-priority mitigations need owners and checkable closure conditions. A severe unresolved harm path remains material even if the average result looks favorable.

Does this prove the system is safe?

The record informs an authority decision for the agreed scope while residual risk, uncertainty, and possible unidentified harm remain visible.