Four instruments, one system: risk, impact, DPIA, FRIA

Lesson 5 of 5 in AI Risk Management and Impact Assessment: ISO/IEC 23894 and 42005.

By now your organisation may owe four assessment-shaped documents for the same AI system: a 23894-style risk assessment, a 42005-style impact assessment, a DPIA if personal data processing is likely to create high risk to individuals (GDPR Article 35), and a fundamental rights impact assessment if you are among the deployers the EU AI Act’s Article 27 captures. Teams that treat these as four separate bureaucratic events drown; teams that see them as four lenses over one evidence base run a single machine with four report formats.

The distinctions that matter: whose risk (organisation vs affected people), what scope (all objectives vs personal data vs fundamental rights), and what legal weight (voluntary standard vs statutory obligation with penalties). Everything else — hazard thinking, severity scales, mitigation planning, documentation — is shared machinery you should build once.

The four assessment instruments compared
InstrumentPrimary lensScope of concernLegal statusTypical trigger

AI risk assessment (ISO/IEC 23894 / 42001 cl 6.1.2)

Organisational: effect of uncertainty on our objectives

All AI-related objectives — safety, fairness, security, robustness, reputation, compliance

Voluntary standard; contractually or certification-relevant

AIMS planning; planned intervals; significant change

AI system impact assessment (ISO/IEC 42005 / 42001 cl 6.1.4)

Affected parties: individuals, groups, societies

Benefits and harms across fairness, safety, privacy, environment, employment, autonomy, wellbeing

Voluntary standard; auditable within a 42001 certification

New system; changed use, context, population, model, or data

DPIA (GDPR Art 35)

Data subjects: risks to rights and freedoms from processing of personal data

Personal data processing only — but within that, deep: necessity, proportionality, subject rights

Legally required when processing is likely high-risk; supervisory authority consultation if risk stays high

New high-risk processing — profiling, large-scale sensitive data, systematic monitoring

FRIA (EU AI Act Art 27)

Affected persons: impact on fundamental rights — dignity, non-discrimination, social protection, due process

Categories of affected persons, usage frequency and duration, specific harm risks, oversight measures, remediation plans

Legally required for certain deployers of high-risk AI: public bodies, private entities providing public services, and banks/insurers for credit and pricing use cases

Before first use of the high-risk system; updated when elements change

Can one document satisfy several instruments?

Partially, and the law encourages it: Article 27 lets a FRIA build on an existing DPIA where they overlap, and a 42005 impact assessment is the natural chassis for both — it already documents the system, affected parties, harms, severity, and mitigations. But legal instruments have mandatory content the standards do not require (a DPIA’s necessity-and-proportionality analysis; a FRIA’s categories of affected persons and remediation arrangements). The mature pattern: one evidence base and one workflow, with instrument-specific sections generated from it — never one generic document renamed four times.

Which comes first in practice?

Run the 42005-style impact assessment early — at inception, before architecture hardens — because it determines whether and how to proceed. Its outputs then seed the risk register (harms → risks), the DPIA (personal-data harms → Article 35 analysis), and the FRIA (rights-related harms → Article 27 content). Sequencing the legal documents first tends to produce compliance artifacts that never touch engineering reality.

Who signs what?

Risk acceptance: the named risk owner with authority under your criteria (clause 6.1.3 and 5.3). Impact assessment outcomes: the process owner defined under A.5.2, with escalation for sensitive uses. DPIA: the controller, with DPO advice documented. FRIA: the deployer, with notification to the market surveillance authority as required. Four signatures, four accountabilities — a useful integrity check that your ‘one machine’ has not collapsed the distinct duties it serves.

Key terms: impact assessment, residual risk, data protection impact assessment, fundamental rights impact assessment, risk register

Tool: AI Incident Tabletop — Stress-test your new vocabulary: walk an AI incident tabletop and watch risk sources, registers, and impact assessments earn their keep under pressure.

Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.