AI Governance Consulting
of organizations say they'll institute an AI ethics program
Without clear guardrails, AI systems can introduce bias, security vulnerabilities, legal exposure, and reputational risk. A lack of oversight is one of the leading reasons AI initiatives stall or fail to scale.
Adopt a responsible AI governance program that establishes accountability, escalation paths, decision rights, and oversight structures across your AI lifecycle.
Evaluate risks across your AI use cases using qualitative and quantitative assessments to identify, assess, and mitigate threats while ensuring compliance.
Comprehensive AI ethics and literacy training for employees and stakeholders, enabling them to understand AI's opportunities, risks, and obligations.
Independent audits to evaluate AI systems for fairness, accuracy, security, and compliance—ensuring accountability and informed governance.
🛡️
Navigate EU AI Act, NIST AI RMF, and internal policies to avoid reputational damage.
📈
Advance accountability, decision rights, and oversight structures across your AI lifecycle.
👥
Create an AI-capable workforce that recognizes opportunities and risks while advancing goals.

If you’re preparing for an AI governance interview, there is one question you should expect to encounter in some form:
“Walk me through how you’d conduct an AI impact assessment.”
It appears in compliance interviews, risk interviews, policy interviews, and audit interviews. The phrasing varies, but the underlying ask is the same. Can you take a real AI system, break it down, identify who is affected, and recommend what to do about the risks?
Most candidates struggle with this question not because they lack knowledge, but because they lack structure. They know what fairness means. They understand bias in the abstract. But when asked to walk through an assessment from start to finish, they reach for buzzwords instead of a clear process.
This piece offers a four-step structure you can use to answer any impact assessment question with confidence.
There’s regulatory pressure. The EU AI Act, which began phased enforcement in February 2025, requires deployers of high-risk AI systems to conduct fundamental rights impact assessments under Article 27. That obligation means companies need people who can actually do this work, not just describe it.
Even outside the EU, impact assessments are becoming standard practice. The NIST AI Risk Management Framework’s Map function asks organizations to identify context, stakeholders, and potential impacts; which is an impact assessment by another name. ISO 42001 expects documented risk identification for AI systems. The direction is clear: this skill is becoming table stakes for governance roles.
The structure is straightforward. For any AI system, walk through four steps: Scope the system. Map the stakeholders. Surface the harms. Recommend safeguards.
Scope the system. Before you can assess impact, you need to understand what the system does. What is its intended purpose? What decisions does it make or support? What data does it use? Is a human in the loop? In regulatory terms, this is also where you determine risk classification under frameworks like the EU AI Act’s Annex III.
Map the stakeholders. Think in three rings. The inner ring is the direct users; people who interact with the system. The middle ring is the people the system makes decisions about, who may never see the system themselves. The outer ring is the broader communities who experience downstream effects. Most candidates only think about users. Governance professionals think about all three.
Surface the harms. Organize potential harms into categories: discriminatory outcomes, safety and wellbeing risks, autonomy and transparency risks, and privacy and data risks. For each harm, assess likelihood and severity. That combination helps you prioritize where mitigation effort should go.
Recommend safeguards. For each high-priority harm, recommend mitigations across three types: technical safeguards (bias testing, fairness metrics, output monitoring), procedural safeguards (human review, escalation paths, documentation requirements), and organizational safeguards (clear accountability, review cycles, feedback mechanisms). Always include ongoing monitoring; an impact assessment is not a one-time exercise.
The best way to build confidence with this framework is to practice it.
Pick an AI system you use regularly- a recommendation engine, a chatbot, a content moderation tool and write a half-page assessment using the four steps.
Do it for two or three systems, and you’ll have a portfolio of practice assessments you can reference in interviews and share publicly.
Impact assessment questions test applied thinking, not memorization. The interviewer wants to see that you can take a real system, reason through its effects on real people, and propose concrete mitigations. The four-step walkthrough- Scope, Stakeholders, Harms, Safeguards- gives you a repeatable structure for doing exactly that.
Practice it. Write it up. Put it on your resume.
Helping professionals build meaningful careers in AI, AI Governance, and organizations build AI systems people can trust.
Resources
Services
Connect
© 2026 Obi Ogbanufe. All rights reserved.