What an auditor, or Sekit's evidence engine, asks for.
AI system impact assessment
The procedure for assessing an AI system's impact before you use it and whenever it changes materially, plus the assessments already done: who it could affect, what risks and wider effects it has, and who approved the decision.
From the Sekit evidence catalog
In practice
Before a company turns on a new AI feature or vendor chatbot, someone has to ask what could go wrong for the people affected, not only for the business. The AI system impact assessment records who reviewed the tool, what risks it carries (bias, wrong outputs, data exposure) and who signed off before go-live. Auditors look for a repeatable trigger, any new AI tool or material change gets an assessment, and check whether the last three tool adoptions have one on file rather than the process existing only for the flagship system.
Common gaps
The impact assessment template exists but no one applied it to the AI vendor tool the sales team adopted last quarter.
A material change to an AI system, a new data source or a model swap, does not trigger a fresh assessment.
The DPIA covers personal data risk but never asks whether the AI output itself could unfairly affect a person.
Questions your auditor will ask
What triggers a new AI impact assessment?
Adopting a new AI system or making a material change to one already in use, as defined in the AI system impact assessment procedure.
Who signs off on the assessment before an AI tool goes live?
A named approver reviews the risks and effects recorded in the assessment and documents the go-live decision.
Does the assessment overlap with your privacy DPIA?
Yes, where the AI system processes personal data the DPIA trigger and process are reused rather than duplicated.
How do you show this is repeatable rather than a one-time exercise?
Each AI tool adoption on file has its own dated assessment, not one single template reused from the initial rollout.
Where regulation demands it
GDPR Article 35.1 requires a DPIA for high-risk processing, which an AI impact assessment can satisfy when personal data is involved.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.