# AI Management System – Policy & Impact Assessment

> ISO/IEC 42001:2023 (AIMS) – the AI management standard. Two
> artifacts here: the AI policy + the AI system impact assessment
> (the AIMS analog of a DPIA, per Annex A controls).

| Field | Value |
|-------|-------|
| Document ID | DOC-AIMS-NNN |
| AI system | name/version |
| Owner | AI governance lead |
| Date | YYYY-MM-DD |

## Part A – AI policy commitments

1. AI systems are developed/used responsibly: fairness, transparency,
   accountability, safety, privacy.
2. AI risk is assessed before deployment and monitored continuously.
3. Human oversight level is defined per system and enforced.
4. Roles and responsibilities for AI governance are assigned.
5. Legal obligations (AI Act, sector rules) are tracked and met.

## Part B – AI system impact assessment

### B.1 System description

- Purpose, users, affected stakeholders
- Model type, data sources, decision autonomy level
- Deployment context (internal / customer-facing / regulated domain)

### B.2 Risk classification

| Dimension | Assessment | Rating |
|-----------|------------|--------|
| Impact on individuals' rights | decisions about people? | H/M/L |
| Safety impact | physical harm possible? | |
| Scale | number of people affected | |
| Autonomy | human-in/on/out-of-loop | |
| Data sensitivity | personal/special category data | |

### B.3 Impact analysis

| Impact area | Description | Likelihood | Severity | Mitigation |
|-------------|-------------|------------|----------|------------|
| Fairness/bias | group disadvantage | | | bias testing |
| Transparency | explainability to subjects | | | model cards |
| Privacy | data exposure | | | DPIA link |
| Safety | harmful outputs | | | guardrails, HITL |
| Security | adversarial attack | | | red teaming |

### B.4 Controls & monitoring

| Control | Implementation | Monitoring metric | Review |
|---------|----------------|-------------------|--------|
| Human oversight | review step in workflow | override rate | monthly |
| Performance drift | eval harness | accuracy delta | continuous |
| Bias monitoring | subgroup metrics | fairness delta | quarterly |

### B.5 Decision

- [ ] Deploy as assessed
- [ ] Deploy with conditions
- [ ] Not acceptable – redesign

Approved: ____________ Date: ________
