Four instruments, one system: risk, impact, DPIA, FRIA
Lesson 5 of 5 in AI Risk Management and Impact Assessment: ISO/IEC 23894 and 42005.
By now your organisation may owe four assessment-shaped documents for the same AI system: a 23894-style risk assessment, a 42005-style impact assessment, a DPIA if personal data processing is likely to create high risk to individuals (GDPR Article 35), and a fundamental rights impact assessment if you are among the deployers the EU AI Act’s Article 27 captures. Teams that treat these as four separate bureaucratic events drown; teams that see them as four lenses over one evidence base run a single machine with four report formats.
The distinctions that matter: whose risk (organisation vs affected people), what scope (all objectives vs personal data vs fundamental rights), and what legal weight (voluntary standard vs statutory obligation with penalties). Everything else — hazard thinking, severity scales, mitigation planning, documentation — is shared machinery you should build once.
| Instrument | Primary lens | Scope of concern | Legal status | Typical trigger |
|---|---|---|---|---|
AI risk assessment (ISO/IEC 23894 / 42001 cl 6.1.2) | Organisational: effect of uncertainty on our objectives | All AI-related objectives — safety, fairness, security, robustness, reputation, compliance | Voluntary standard; contractually or certification-relevant | AIMS planning; planned intervals; significant change |
AI system impact assessment (ISO/IEC 42005 / 42001 cl 6.1.4) | Affected parties: individuals, groups, societies | Benefits and harms across fairness, safety, privacy, environment, employment, autonomy, wellbeing | Voluntary standard; auditable within a 42001 certification | New system; changed use, context, population, model, or data |
DPIA (GDPR Art 35) | Data subjects: risks to rights and freedoms from processing of personal data | Personal data processing only — but within that, deep: necessity, proportionality, subject rights | Legally required when processing is likely high-risk; supervisory authority consultation if risk stays high | New high-risk processing — profiling, large-scale sensitive data, systematic monitoring |
FRIA (EU AI Act Art 27) | Affected persons: impact on fundamental rights — dignity, non-discrimination, social protection, due process | Categories of affected persons, usage frequency and duration, specific harm risks, oversight measures, remediation plans | Legally required for certain deployers of high-risk AI: public bodies, private entities providing public services, and banks/insurers for credit and pricing use cases | Before first use of the high-risk system; updated when elements change |
Can one document satisfy several instruments?
Partially, and the law encourages it: Article 27 lets a FRIA build on an existing DPIA where they overlap, and a 42005 impact assessment is the natural chassis for both — it already documents the system, affected parties, harms, severity, and mitigations. But legal instruments have mandatory content the standards do not require (a DPIA’s necessity-and-proportionality analysis; a FRIA’s categories of affected persons and remediation arrangements). The mature pattern: one evidence base and one workflow, with instrument-specific sections generated from it — never one generic document renamed four times.
Which comes first in practice?
Run the 42005-style impact assessment early — at inception, before architecture hardens — because it determines whether and how to proceed. Its outputs then seed the risk register (harms → risks), the DPIA (personal-data harms → Article 35 analysis), and the FRIA (rights-related harms → Article 27 content). Sequencing the legal documents first tends to produce compliance artifacts that never touch engineering reality.
Who signs what?
Risk acceptance: the named risk owner with authority under your criteria (clause 6.1.3 and 5.3). Impact assessment outcomes: the process owner defined under A.5.2, with escalation for sensitive uses. DPIA: the controller, with DPO advice documented. FRIA: the deployer, with notification to the market surveillance authority as required. Four signatures, four accountabilities — a useful integrity check that your ‘one machine’ has not collapsed the distinct duties it serves.
Key terms: impact assessment, residual risk, data protection impact assessment, fundamental rights impact assessment, risk register
Tool: AI Incident Tabletop — Stress-test your new vocabulary: walk an AI incident tabletop and watch risk sources, registers, and impact assessments earn their keep under pressure.
Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.