NIST AI RMF DATA INFRASTRUCTURE MODEL

Impact assessment

Part of: MP: MAP — Context & Risk Identification

Description

AI system impacts on individuals, groups, communities, organizations, and society are identified and assessed. Impact assessment goes beyond risk identification to consider who bears the burden of AI system errors and how that burden is distributed.

Suggested Actions

1
Assess impacts on individual rights: autonomy (does the system reduce human agency?), privacy (what personal data is collected, inferred, or exposed?), dignity (could system outputs be demeaning or dehumanizing?), and safety (could system errors cause physical harm?)
2
Evaluate differential impacts on protected groups across race, gender, age, disability, and other protected attributes — aggregate performance metrics that look acceptable can mask severe disparities for specific populations
3
Consider broader societal impacts: labor market effects (job displacement, skill degradation), environmental costs (energy consumption, carbon footprint), democratic implications (information manipulation, filter bubbles), and economic concentration (market power, digital divides)
4
Engage affected communities in impact identification and assessment — communities often identify impacts that developers and executives miss because they understand the deployment context from the receiving end
5
Assess cumulative impacts: How does this AI system interact with other AI systems and automated processes the same individuals encounter? A single system may be fair in isolation but contribute to cumulative disadvantage
6
Document impact assessment methodology, findings, and mitigations with enough specificity to enable independent review and reproduce conclusions

Related Controls

AI Risk Self-Assessment