AI Assessments
by Formiti's Global DPO Team
A 13-section regulatory assessment wizard aligned with the EU AI Act and GDPR, providing structured evaluation of AI systems across scope, prohibited practices, high-risk screening, transparency, GPAI, privacy, fairness, and technical robustness.
Who uses this module?
AI Governance Leads, DPOs, Legal Counsel, Technical Owners, Risk Officers.
What governance problem does it solve?
Determining whether an AI system triggers EU AI Act obligations requires structured analysis across multiple regulatory dimensions. AI Assessments replaces subjective judgement with a scored, evidence-based methodology that produces defensible regulatory determinations.
What are the key workflows?
- Select AI system from the Register and initiate assessment
- Complete structured questionnaire across 13 regulatory sections
- Real-time scoring engine determines regulatory outcomes (High-Risk, Prohibited, GPAI, DPIA Required)
- Traffic-light status badges per section highlight areas of concern
- Generate executive reports with scored findings and recommendations
Select AI system from the Register and initiate assessment
Complete structured questionnaire across 13 regulatory sections
Real-time scoring engine determines regulatory outcomes (High-Risk, Prohibited, GPAI, DPIA Required)
Traffic-light status badges per section highlight areas of concern
Generate executive reports with scored findings and recommendations
What evidence and reporting does it produce?
Built-in outputs for accountability and regulatory readiness
Scored assessment records with per-question rationale
Regulatory determination outcomes (High-Risk, Prohibited, etc.)
Section-level scoring with traffic-light indicators
Executive summary reports (PDF, DOCX)
Full response audit trail
How does it connect to other Privacy360 modules?
- Linked to AI System Register as the anchor record
- Flagged findings generate AI Remediation tasks
- Assessment evidence feeds into AI Evidence repository
- High-risk determinations inform review tier assignment
- Privacy section findings can trigger DPIA requirements
What are some example use cases?
A legal counsel completes the EU AI Act assessment for an automated recruitment screening tool; the scoring engine flags it as Potential High-Risk AI, triggering an Escalated review workflow.
A DPO reviews the privacy section of an AI assessment and identifies GDPR DPIA requirements; the finding is linked to the system's DPIA status in the Register.
A governance lead compares assessment scores across five AI systems to prioritise remediation resources.
Related modules
AI System Register
Structured inventory of every AI system with EU AI Act risk tier, named business and technical ownership, and AI Bill of Materials provenance.
AI Remediation
Turn AI assessment findings into assigned, dated remediation tasks with evidence requirements — so gaps close between assessment cycles.
AI Evidence
One indexed repository linking every compliance artefact to the AI system, assessment, task or supplier it evidences.
Privacy Assessments
Run global privacy gap assessments, DPIAs, LIAs, transfer reviews and vendor assessments against 150+ controls — with structured rationale, evidence and AI-assisted review.
AI Assessments guides
Practical articles from Formiti's Global DPO team on running this work well.