Onwyn › Standards › AI Impact Assessments (DPIA · FRIA · ISO/IEC 42005)
Scheme / framework · 2025AI Impact Assessments (DPIA · FRIA · ISO/IEC 42005)
Three assessment instruments now converge on companies deploying AI in the EU: the GDPR data protection impact assessment (DPIA) where processing is high-risk for individuals, the AI Act fundamental rights impact assessment (FRIA) for certain deployers of high-risk AI, and the ISO/IEC 42005 AI system impact assessment as the management-system practice tying it together. Done separately they triple the work; done as one layered practice they share a description of the system, one analysis of affected people, and one set of mitigations. This pack makes the assessment layer operational: knowing when each instrument triggers, what each must contain, and how to run them as a single register-driven routine instead of three parallel paper exercises.
What this standard asks for
Every requirement in AI Impact Assessments (DPIA · FRIA · ISO/IEC 42005), grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.
When an assessment is required
2 requirements
- Art. 35(1)/(3)DPIA trigger screening for every new processing
- Art. 27 (scope)FRIA applicability screening for high-risk AI deployments
DPIA — content & process
4 requirements
- Art. 35(7)(a)-(b)DPIA foundation — description, necessity and proportionality
- Art. 35(7)(c)-(d)DPIA core — risks to individuals and the measures against them
- Art. 35(2)/(9)DPIA process — DPO advice and data subject views
- Art. 36Prior consultation when residual risk stays high
FRIA — content & process
3 requirements
- Art. 27(1)(a)-(c)FRIA content I — deployment, duration and affected persons
- Art. 27(1)(d)-(f)FRIA content II — rights risks, oversight and remediation
- Art. 27(3)-(4)FRIA process — notify the authority and build on the DPIA
ISO/IEC 42005 — AI impact assessment practice
4 requirements
- 42005-1Scope the assessment and flag sensitive uses
- 42005-2Analyze affected stakeholders
- 42005-3Assess benefits and harms honestly
- 42005-4Document assessments and wire them into the AIMS
Running the assessment layer
4 requirements
- OPS-1Assessment register and review cadence
- OPS-2Combine DPIA and FRIA work — one assessment spine
- OPS-3Communicate assessment outcomes
- OPS-4Feed assessment findings into risk treatment
The documents you will end up with
The recommended document set for AI Impact Assessments (DPIA · FRIA · ISO/IEC 42005) — 10 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.
The short check every new project runs to decide whether it needs a DPIA, a fundamental rights assessment, both or neither — and the record that the check happened.
The structure a data protection impact assessment follows: what the processing is, why it is necessary and proportionate, what could go wrong for people, and what you are doing about it.
How the privacy owner's advice is sought and recorded, when you ask the people affected what they think, and what happens if the residual risk stays high.
The structure a fundamental rights impact assessment follows: the deployment and who it touches, the rights that could be affected, the oversight in place, and what someone can do if it goes wrong for them.
How the completed assessment is notified to the market surveillance authority, and how it reuses the DPIA rather than repeating it.
The organisation's own method for assessing an AI system's effects: how scope and sensitive uses are set, how stakeholders are identified, and how benefits and harms are weighed without flattering the project.
What a completed assessment must contain, where it is stored, and how its outcomes feed the AI management system and the risk register.
The one list of every assessment done, its outcome, its owner and when it is next due for review.
One assessment covering the shared ground — description, stakeholders, risks, mitigations — with regulation-specific sections attached, so the same work is not done three times.
Who hears the result of an assessment — the project team, leadership, affected people, and in some cases the public — and in what form.
Start AI Impact Assessments today
Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.