Complete one SIA for each AI system before deployment. The SIA must be reviewed and signed by the Executive Accountable Official before any system goes live. Retain as part of the audit documentation for Pillar 02.
1. AI System Details
System name and version
[System name, version, vendor]
Intended use and deployment context
[Describe what the system does and where / how it will be deployed in your operations]
2. Affected Stakeholder Groups
| Stakeholder Group | Nature of Interaction with AI System | Population Size (approx.) | Includes Vulnerable Individuals? |
| Employees / workers | [Describe] | [No.] | [ Yes / No / Unknown ] |
| Contractors / subcontractors | [Describe] | [No.] | [ Yes / No / Unknown ] |
| Clients / principals | [Describe] | [No.] | [ Yes / No / Unknown ] |
| Community / public | [Describe] | [No.] | [ Yes / No / Unknown ] |
3. Harm Category Assessment
| Harm Category | Risk Present? | Likelihood | Severity | Mitigation Measures |
| Algorithmic bias or discrimination | [ Y / N ] | [ H / M / L ] | [ H / M / L ] | [Mitigation] |
| Privacy or data misuse | [ Y / N ] | [ H / M / L ] | [ H / M / L ] | [Mitigation] |
| Safety / physical harm | [ Y / N ] | [ H / M / L ] | [ H / M / L ] | [Mitigation] |
| Employment impact | [ Y / N ] | [ H / M / L ] | [ H / M / L ] | [Mitigation] |
| Financial harm | [ Y / N ] | [ H / M / L ] | [ H / M / L ] | [Mitigation] |
4. Overall Risk Rating & Sign-Off
Residual risk rating after mitigations
[ Unacceptable — do not deploy | High — deploy with enhanced controls | Medium — deploy with standard controls | Low — deploy ]
Assessment completed by
[Name] · [Date]
Approved by — Executive Accountable Official
[Name] · [Date]