This template helps organisations evaluate risks associated with processing personal data in AI systems and map specific AI-related hazards. It supports GDPR DPIA requirements, EU AI Act mandatory risk management, and ISO 42001 operational risk controls.
The assessment contains the following sections:
| Field | Description | Example |
|---|---|---|
| Data Categories | Types of personal/non-personal data processed. | User queries, log data, metadata |
| Sensitive Data? | Does system process special-category data? | No (default) |
| Source | Where data originates. | Web inputs, emails, chat logs |
| Storage | Where data is stored. | Firestore (EU region), encrypted |
| Retention | How long the data is kept. | 90 days (runtime); 1 year (audit logs) |
| Processors | Third parties involved. | GCP, Zoho, Make.com |
Each risk entry includes:
| Category | Example Risks |
|---|---|
| Bias & Fairness | Skewed results, disproportionate outcomes. |
| Security | Prompt injection, model extraction, data poisoning. |
| Accuracy/Robustness | Drift, hallucinations, misclassifications. |
| Privacy | Unintended personal data use; inference attacks. |
| Safety | AI advice causing physical/psychological risk. |
| Legal/Ethical | Non-compliance with transparency, consent, rights. |
Project_ID,Project_Name,Version,Owner,Lawful_Basis,Data_Categories,Sensitive_Data,Processing_Activities,Storage,Retention,AI_Risks,Impact,Likelihood,Score,Controls,Residual_Risk,Evidence_ID,DPO_Consulted,Decision,Approval_Date
Project_ID: DPIA-2025-004 Project_Name: Zen AI AnswerBot v2.1 Lawful_Basis: Legitimate Interest (Art 6(1)(f)) Data_Categories: Query text, session metadata Sensitive_Data: No AI_Risks: Model hallucination leading to incorrect advice Impact: 4 Likelihood: 3 Score: 12 (High) Controls: Safe responses, fallback rules, escalation to human Residual_Risk: Medium (8) Evidence_ID: EV-DPIA-007 Decision: Approved with mitigation plan
| Framework | Reference | Relevance |
|---|---|---|
| GDPR | Art. 35 | DPIA mandatory for high-risk processing |
| EU AI Act | Art. 9–10 | Mandatory risk management system |
| ISO/IEC 42001 | §6.1 & §8 | Risk controls for AI lifecycle |
| NIST AI RMF | Map + Manage | Context & risk documentation |
© Zen AI Governance UK Ltd • Regulatory Knowledge • v1 20 Nov 2025 • This page is general guidance, not legal advice.