AI Impact Assessment Interview

Walking Through an AI Impact Assessment in Any Interview

July 23, 20263 min read

If you’re preparing for an AI governance interview, there is one question you should expect to encounter in some form:

“Walk me through how you’d conduct an AI impact assessment.”

It appears in compliance interviews, risk interviews, policy interviews, and audit interviews. The phrasing varies, but the underlying ask is the same. Can you take a real AI system, break it down, identify who is affected, and recommend what to do about the risks?

Most candidates struggle with this question not because they lack knowledge, but because they lack structure. They know what fairness means. They understand bias in the abstract. But when asked to walk through an assessment from start to finish, they reach for buzzwords instead of a clear process.

This piece offers a four-step structure you can use to answer any impact assessment question with confidence.

Why This Question Keeps Showing Up

There’s regulatory pressure. The EU AI Act, which began phased enforcement in February 2025, requires deployers of high-risk AI systems to conduct fundamental rights impact assessments under Article 27. That obligation means companies need people who can actually do this work, not just describe it.

Even outside the EU, impact assessments are becoming standard practice. The NIST AI Risk Management Framework’s Map function asks organizations to identify context, stakeholders, and potential impacts; which is an impact assessment by another name. ISO 42001 expects documented risk identification for AI systems. The direction is clear: this skill is becoming table stakes for governance roles.

The Four-Step Walkthrough

The structure is straightforward. For any AI system, walk through four steps: Scope the system. Map the stakeholders. Surface the harms. Recommend safeguards.

  1. Scope the system. Before you can assess impact, you need to understand what the system does. What is its intended purpose? What decisions does it make or support? What data does it use? Is a human in the loop? In regulatory terms, this is also where you determine risk classification under frameworks like the EU AI Act’s Annex III.

  2. Map the stakeholders. Think in three rings. The inner ring is the direct users; people who interact with the system. The middle ring is the people the system makes decisions about, who may never see the system themselves. The outer ring is the broader communities who experience downstream effects. Most candidates only think about users. Governance professionals think about all three.

  3. Surface the harms. Organize potential harms into categories: discriminatory outcomes, safety and wellbeing risks, autonomy and transparency risks, and privacy and data risks. For each harm, assess likelihood and severity. That combination helps you prioritize where mitigation effort should go.

  4. Recommend safeguards. For each high-priority harm, recommend mitigations across three types: technical safeguards (bias testing, fairness metrics, output monitoring), procedural safeguards (human review, escalation paths, documentation requirements), and organizational safeguards (clear accountability, review cycles, feedback mechanisms). Always include ongoing monitoring; an impact assessment is not a one-time exercise.

Putting It Into Practice

The best way to build confidence with this framework is to practice it.

  • Pick an AI system you use regularly- a recommendation engine, a chatbot, a content moderation tool and write a half-page assessment using the four steps.

  • Do it for two or three systems, and you’ll have a portfolio of practice assessments you can reference in interviews and share publicly.

Impact assessment questions test applied thinking, not memorization. The interviewer wants to see that you can take a real system, reason through its effects on real people, and propose concrete mitigations. The four-step walkthrough- Scope, Stakeholders, Harms, Safeguards- gives you a repeatable structure for doing exactly that.

Practice it. Write it up. Put it on your resume.

Back to Blog