TwinEthosRequest access

Control

AI system deployed without an AI system impact assessment

Organizations should conduct an AI system impact assessment covering effects on individuals, groups, and society.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: AI is deployed without a documented risk-management process or impact assessment · control id cond.ai-system-no-impact-assessment

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
1standards and frameworks on the same control

The guard to add

Document an impact assessment for each AI system covering its consequences for individuals, groups, and society, and revisit it when the system changes.

A per-system impact assessment, distinct from the organizational risk register, that looks outward: intended use and context, who is affected (individuals, groups including vulnerable ones, society), foreseeable benefits and harms (rights, safety, fairness, access, wider societal effects), reasonably foreseeable misuse, mitigations, residual impact, and sign-off. The AI system owner maintains it within the AI management system and revisits it before release and on any material change of model, data, or use. Keep it next to the model card and have a release check confirm a current assessment exists for each deployed system.

Where it goes: 12 repository artifacts, 11 CI/CD pipeline.

What reviewers look for: an assessment per deployed AI system that names affected individuals and groups and societal effects (not only business or security risk), with mitigations, a sign-off, and a date later than the last material change to the model or its use.

Organizational control: the evidence is a kept record, its owner and its upkeep, not code.

Example (Impact assessment record (docs/impact/)), before:

# Resume screener
Risk: low. Approved.

After:

# AI system impact assessment: resume screener (v3, 2026-09-01)
- Intended use: rank applications for recruiter review; no automatic rejection
- Affected: applicants; groups at risk: career-gap, non-native-language applicants
- Harms: unfair exclusion, opaque ranking; societal: narrowing of hiring pools
- Mitigations: subgroup ranking audit each release; recruiter sees all applicants
- Residual impact: medium, accepted by Head of Talent (signed 2026-09-03)
- Revisit: on model, feature, or use change

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Standard / soft law (1)