An impact assessment has to keep observed evidence, inference, mitigation, and authority separate while tracing plausible harm to affected groups and named owners.

Before a system advances, we document what it is intended to do, how it could foreseeably be used or misused, and who may be affected. Each plausible harm is linked to the available evidence, current controls, mitigation owner, and whoever has the authority to decide how much residual risk is acceptable.

An affected-group dossier, mitigation-owner log, and explicit acceptance conditions give your designated authority a clear, traceable residual-risk position.

Illustration of AI Risk & Impact Assessment: a team reviewing AI policy and risk controls in a governance framework

Some of the 500+ brands we've worked with

See all references
  • Halk Yatırım
  • Canbebe
  • Joker
  • Yatsan
  • Teyit.org
  • Jollytur

Evidence, inference, mitigation, and acceptance stay separate throughout the work. That separation keeps uncertainty visible and stops a favorable aggregate rating from hiding a serious open harm path.

  1. Fix the decision and impact boundary

    We agree the system decision under review, its intended and foreseeable uses, affected groups, evidence access, and who has the authority to accept residual risk. The boundary also records which perspectives cannot yet be reached.

    AI assist
    Approved use descriptions, stakeholder groups, and source lists feed a draft boundary. The system owner corrects it.
    Human gate
    Do the uses, affected groups, and evidence access match the boundary confirmed by your system owner? Your system owner decides which uses and affected groups belong in the assessment.
  2. Follow each harm through the system

    Stakeholder evidence is traced through intended use, misuse, and data flows to plausible harms. We mark where the pathway rests on direct evidence, an inference, or a perspective that has not yet been represented.

    AI assist
    Stakeholder input and known scenarios are clustered into candidate harm pathways for specialist review.
    Human gate
    Which affected perspective is still absent or supported too weakly for the assessment to proceed? Your system owner confirms where direct stakeholder evidence is still needed.
  3. Challenge the rating and control evidence

    For every material harm, we examine likelihood, impact, current controls, confidence in the evidence, and the owner of each proposed mitigation. Uncertainty can raise the level of review when the available evidence does not justify a reassuring rating.

    AI assist
    Existing control evidence is laid beside each harm, with confidence notes left visible for the reviewer.
    Human gate
    Does the evidence support the proposed rating, or must the issue remain open at a higher review level? Your designated authority decides whether the rating is supported or needs escalation.
  4. Record the residual risk

    Where the evidence permits, we test material findings again and document the result. Open conditions, mitigation owners, and reassessment triggers are then presented to the authority responsible for the final risk decision.

    AI assist
    Retest findings, open conditions, and mitigation owners feed a first residual-risk record that the designated authority reviews.
    Human gate
    Has the designated authority accepted, conditioned, or rejected the residual risk and named the trigger for another assessment? Your designated authority makes the residual-risk decision and approves the reassessment trigger.

The artifact set makes it possible to distinguish what was observed, what was inferred, which controls exist today, what mitigation is proposed, and which question still needs authority.

  • Report

    Affected-group impact and control-evidence dossier

    The intended uses, affected groups, harm scenarios, control review, evidence confidence, and residual questions in one assessment record.

  • Matrix

    Stakeholder and harm-scenario map

    The people, workflows, uses, misuse paths, data flows, and plausible harms included in the review.

  • Risk register

    Mitigation-owner and reassessment trigger log

    Material risks, existing controls, mitigation actions, owners, evidence, status, and reassessment triggers.

  • Decision record

    Residual-risk conditions and authority sign-off brief

    The decision, accepted conditions, open risks, authority, review date, and stop or reassessment triggers.

Use it when a launch or material change is close and the affected groups, harm paths, or residual-risk authority are still unclear.

A good fit when

  • The system affects people or decisions, but stakeholder perspectives needed to trace plausible harm are still missing from the review.
  • Unknowns are being read as low risk, so weak evidence could let a serious harm path pass without the higher review it needs.
  • Mitigations appear in the plan, but no accountable owner or reassessment trigger says who acts when the system or evidence changes.
  • The intended use is documented, yet foreseeable and misuse scenarios have not been followed through the system to affected groups.
  • Stakeholders are named, but no one has traced how data flows and system decisions could lead to plausible harm.
  • Likelihood and impact ratings exist, although nobody has checked the control evidence or stated how much confidence each rating deserves.
  • Mitigation actions are proposed, but ownership, residual-risk authority, and reassessment triggers are missing from the same record.

Better handled as other work when

  • You want the residual-risk record read as legal, regulatory, audit, or certification authority. Those determinations stay with your qualified specialists.
  • You need a declaration that the system is completely safe or risk-free, while unidentified harm and uncertainty remain possible.
  • You need the mitigations built or operated as part of this review, but the agreed assessment ends with owners and closure conditions.

If one of these is closer to your situation, start here instead: See responsible AI consulting

We've worked with more than 500 brands since Zeo started in 2011. The people helping you decide where AI fits, and where it doesn't yet, are senior engineers and strategists who build and operate production AI systems. The advice stays grounded in work that actually shipped.

  • Anthropic

    drafts the first pass of harm scenarios and evidence summaries an analyst then challenges

  • Datadog

    the production logs that show what a claimed control actually did

  • Hugging Face

    the published model card checked against what the system is claimed to do

  • Giskard

    the automated scan that turns a foreseeable-misuse claim into a test result

  • Guardrails AI

    tests whether a claimed mitigation control actually intercepts the harm it names

  • Jupyter

    runs the likelihood and severity math a second reviewer can rerun and check

Use the system view, stakeholder evidence, current controls, and a named decision-maker. The record separates what is known from what remains open.
Assess the risks

We need intended and foreseeable uses, system and data flows, stakeholder perspectives, current controls, incident history, named mitigation owners, and a decision-maker for the residual risk question. Missing evidence can remain open in the record. We do not replace it with guesses.