Scope, process & catalogue
System-specific scope
Section titled “System-specific scope”Select the registered AI system before assessing. Confirm:
- System and version.
- Purpose and intended uses.
- Foreseeable unintended use and misuse.
- Lifecycle stage.
- Organisational role.
- System and assessment boundaries.
- Models, data, interfaces, suppliers and dependencies.
- Deployment environment and jurisdictions.
- Users, operators and decision subjects.
- Directly and indirectly affected people, groups and society.
The same model in two use contexts may have different impacts and needs separate system-scoped reasoning.
When an impact assessment is needed
Section titled “When an impact assessment is needed”Use impact screening throughout the lifecycle. Relevant triggers include:
- A new AI system or materially different use.
- Consequential or legally significant decisions.
- Vulnerable or marginalised populations.
- Biometrics, emotion recognition or synthetic content.
- Critical services or public-sector functions.
- Training or deployment in a new population or geography.
- Significant model, data, supplier or autonomy change.
- Incident, complaint, monitoring trend or newly identified impact.
Incomplete material facts lead to screening; they do not support exclusion.
Clause 5 — the process
Section titled “Clause 5 — the process”The process portion addresses:
- Establishing and documenting a consistent method.
- Integrating it with risk, privacy, security, human-rights and management processes.
- Defining timing, scope and responsibility.
- Establishing sensitive-use and impact thresholds.
- Performing and analysing the assessment.
- Recording, reporting and approval.
- Monitoring, review and improvement.
Clause 6 — assessment content
Section titled “Clause 6 — assessment content”The content portion addresses:
- Scope and system information.
- Functionality, capability, purpose and use.
- Data and quality.
- Algorithms, models and evaluation.
- Deployment environment.
- Relevant interested parties.
- Actual and reasonably foreseeable impacts.
- Measures addressing harms and benefits.
Atomic catalogue
Section titled “Atomic catalogue”Gamut represents the guidance as 119 unique atomic items:
| Section | Items |
|---|---|
| Process Foundation | 18 |
| Governance & Triggers | 25 |
| Execution & Review | 25 |
| Documentation Content | 29 |
| Impacts & Measures | 22 |
Atomic separation prevents a broad answer from obscuring missing scope, evidence, consultation, approval, monitoring or treatment work.
Impact dimensions to consider
Section titled “Impact dimensions to consider”For each plausible impact, examine:
- Affected people or groups.
- Benefit or harm.
- Direct, indirect and cumulative effects.
- Likelihood and magnitude.
- Duration and reversibility.
- Distribution and differential impact.
- Scale and geographic reach.
- Vulnerability and ability to contest.
- Uncertainty and evidence limitations.
- Interaction with other systems and social conditions.
Avoid relying only on aggregate model metrics. A technically accurate system can still cause unfair, unsafe, inaccessible or socially harmful outcomes.
Relationship with routing
Section titled “Relationship with routing”Authoritative routing decides whether the system should enter impact screening. The ISO/IEC 42005 assessment then establishes detailed scope and item-level applicability. Routing does not decide maturity, approve N/A or accept an impact.
Relationship with other work
Section titled “Relationship with other work”- ISO/IEC 42001 integrates impact assessment into the AIMS.
- EU AI Act may require legal risk or fundamental-rights work.
- NIST AI RMF provides broader risk-management outcomes.
- NAGF applies Nigerian legal and policy routes.
- GTSAF provides wider assurance controls.
Evidence can be reused only after scope and criteria are checked.