OnwynStandards › AI Impact Assessments (DPIA · FRIA · ISO/IEC 42005)

Scheme / framework · 2025

AI Impact Assessments (DPIA · FRIA · ISO/IEC 42005)

Three assessment instruments now converge on companies deploying AI in the EU: the GDPR data protection impact assessment (DPIA) where processing is high-risk for individuals, the AI Act fundamental rights impact assessment (FRIA) for certain deployers of high-risk AI, and the ISO/IEC 42005 AI system impact assessment as the management-system practice tying it together. Done separately they triple the work; done as one layered practice they share a description of the system, one analysis of affected people, and one set of mitigations. This pack makes the assessment layer operational: knowing when each instrument triggers, what each must contain, and how to run them as a single register-driven routine instead of three parallel paper exercises.

17
Requirements
5
Areas
10
Recommended documents
0
Mapped frameworks
Start AI Impact Assessments free Have us do it instead

What this standard asks for

Every requirement in AI Impact Assessments (DPIA · FRIA · ISO/IEC 42005), grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.

When an assessment is required

2 requirements

  • Art. 35(1)/(3)DPIA trigger screening for every new processing
  • Art. 27 (scope)FRIA applicability screening for high-risk AI deployments

DPIA — content & process

4 requirements

  • Art. 35(7)(a)-(b)DPIA foundation — description, necessity and proportionality
  • Art. 35(7)(c)-(d)DPIA core — risks to individuals and the measures against them
  • Art. 35(2)/(9)DPIA process — DPO advice and data subject views
  • Art. 36Prior consultation when residual risk stays high

FRIA — content & process

3 requirements

  • Art. 27(1)(a)-(c)FRIA content I — deployment, duration and affected persons
  • Art. 27(1)(d)-(f)FRIA content II — rights risks, oversight and remediation
  • Art. 27(3)-(4)FRIA process — notify the authority and build on the DPIA

ISO/IEC 42005 — AI impact assessment practice

4 requirements

  • 42005-1Scope the assessment and flag sensitive uses
  • 42005-2Analyze affected stakeholders
  • 42005-3Assess benefits and harms honestly
  • 42005-4Document assessments and wire them into the AIMS

Running the assessment layer

4 requirements

  • OPS-1Assessment register and review cadence
  • OPS-2Combine DPIA and FRIA work — one assessment spine
  • OPS-3Communicate assessment outcomes
  • OPS-4Feed assessment findings into risk treatment

The documents you will end up with

The recommended document set for AI Impact Assessments (DPIA · FRIA · ISO/IEC 42005) — 10 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.

Assessment Trigger Screening Procedure

The short check every new project runs to decide whether it needs a DPIA, a fundamental rights assessment, both or neither — and the record that the check happened.

DPIA Template

The structure a data protection impact assessment follows: what the processing is, why it is necessary and proportionate, what could go wrong for people, and what you are doing about it.

DPIA Consultation Procedure

How the privacy owner's advice is sought and recorded, when you ask the people affected what they think, and what happens if the residual risk stays high.

FRIA Template

The structure a fundamental rights impact assessment follows: the deployment and who it touches, the rights that could be affected, the oversight in place, and what someone can do if it goes wrong for them.

FRIA Notification Procedure

How the completed assessment is notified to the market surveillance authority, and how it reuses the DPIA rather than repeating it.

AI Impact Assessment Method

The organisation's own method for assessing an AI system's effects: how scope and sensitive uses are set, how stakeholders are identified, and how benefits and harms are weighed without flattering the project.

Assessment Record Standard

What a completed assessment must contain, where it is stored, and how its outcomes feed the AI management system and the risk register.

Assessment Register

The one list of every assessment done, its outcome, its owner and when it is next due for review.

Combined Assessment Template

One assessment covering the shared ground — description, stakeholders, risks, mitigations — with regulation-specific sections attached, so the same work is not done three times.

Assessment Outcome Communication Plan

Who hears the result of an assessment — the project team, leadership, affected people, and in some cases the public — and in what form.

Start AI Impact Assessments today

Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.