Back to Insights
AI Governance1 July 2026

What Is an AI Impact Assessment and Why Every Care Provider Needs One Now

The Care Quality Commission has already incorporated ungoverned AI use into at least one Inadequate rating. The Information Commissioner's Office is actively enforcing its Better Records Together standards, with reprimands and financial penalties already issued for records failures in social care settings. The Medical Protection Society has published a formal report warning that clinicians bear default legal liability for AI-assisted decisions under the current UK framework. These three developments have a common thread: the consequences of deploying AI in care and health settings without a documented governance process are no longer theoretical. They are regulatory, legal, and operational realities that care providers are already facing.

An AI Impact Assessment is the foundational document that addresses all three simultaneously. It is not a complex or onerous exercise. It is a structured process for asking, and answering on paper, the questions about an AI tool that any responsible organisation should be able to answer before that tool touches anything related to care delivery, care records, or professional practice.

What an AI Impact Assessment Is

An AI Impact Assessment is a documented evaluation of an AI tool or system before it is deployed, covering the risks it introduces, the data it processes, the decisions it influences, and the governance controls in place to manage its use appropriately. It is distinct from a Data Protection Impact Assessment, though the two overlap — a DPIA focuses specifically on data protection risks under UK GDPR, while an AI Impact Assessment covers a broader range of operational, clinical, and governance risks that may not have a data protection dimension.

The term is used in different ways across different regulatory frameworks. Under the EU AI Act, a conformity assessment is required for high-risk AI systems before they can be placed on the market. Under the NHS Digital Technology Assessment Criteria, a risk management framework is required for any digital health technology seeking NHS deployment. Under the CQC's Well-led key question, providers are expected to have systems for identifying and managing risk — which now explicitly includes the risk introduced by AI tools being used within the service.

For most care providers, the AI Impact Assessment sits at the intersection of all three frameworks: it addresses the governance question the CQC is beginning to ask, supports the data protection obligations the ICO is enforcing, and provides the documentary evidence that would be required to demonstrate responsible AI deployment to any regulatory body that asks.

Why Care Providers Need One Now

The documented CQC case that emerged from the South East Social Care Alliance conference in June 2026 is the clearest signal yet of where the regulatory direction of travel is heading. A home care provider received an Inadequate rating partly because confidential care records were processed through AI tools with no risk assessment, no governance framework, and no evidence that the organisation had evaluated whether the use was appropriate.

The critical word in that finding is not AI. It is ungoverned. The CQC did not find against the provider for using AI. It found against the provider for using AI without having asked, and answered on paper, the basic questions about appropriateness, risk, and oversight that any governance-conscious organisation should be able to answer about any significant operational decision.

An AI Impact Assessment is the document that answers those questions before they become the subject of an inspection finding.

The timing matters because AI adoption in care settings is accelerating faster than governance awareness. Care workers and managers are using AI tools — chatbots, writing assistants, summarisation tools, documentation aids — in their daily work, often without any organisational assessment of whether those tools are appropriate, what data they process, or how their outputs are reviewed before entering care records. In many cases, this is happening without the knowledge of the registered manager or the information governance lead.

An AI Impact Assessment conducted at the organisational level creates visibility. It answers the question: what AI tools are we actually using, across the whole service, and have we thought carefully enough about each of them?

What an AI Impact Assessment Should Cover

A comprehensive AI Impact Assessment for a CQC-regulated care provider should address seven areas.

1. Identification

A complete inventory of AI tools in use across the service, including tools used by individual staff members that have not been formally approved by the organisation. This is frequently the most revealing part of the exercise, because shadow AI use — tools adopted informally without organisational knowledge — is more common than most managers realise.

2. Purpose and Scope

For each identified tool, a clear statement of what it is being used for, what decisions or outputs it influences, and whether that use is within the scope for which the tool was designed and approved. This addresses the specific risk identified by Ryan Samuels at Eolas Medical: endorsement for one use case is not endorsement for another, and a tool approved for drafting emails is not approved for producing care records, even if it is technically capable of doing so.

3. Data Assessment

What personal data, if any, the tool processes, whether that data includes information about service users or clinical details, and whether processing that data through the tool is consistent with the organisation's UK GDPR obligations and the ICO's care records standards. This section effectively produces the AI-specific input to the organisation's DPIA.

4. Accuracy and Reliability

How the organisation evaluates whether AI outputs are accurate before they are used in care records or operational decisions, who is responsible for that review, and what process exists for identifying and correcting errors. This is the section the CQC is most likely to ask about, because it directly addresses whether the human remains accountable for what the AI produces.

5. Access and Oversight

Who within the organisation has access to each AI tool, whether that access is controlled and appropriate, and what audit trail exists of AI use within the service.

6. Risk Rating

A structured assessment of the risk each tool introduces, taking into account its purpose, the data it processes, the decisions it influences, and the controls in place. This rating determines which tools require the most rigorous governance controls and which can be managed with lighter oversight.

7. Mitigation and Controls

The specific governance measures in place for each tool: acceptable use standards, output review processes, staff training, supplier due diligence, and the process for reviewing and updating the assessment when tools change or when new AI capabilities are introduced.

Who Should Conduct It

The AI Impact Assessment should be conducted by someone with sufficient authority to gather accurate information from across the service, sufficient understanding of the organisation's operational practices to identify informal AI use, and sufficient governance awareness to evaluate the risks identified. In most care settings, this is the registered manager, the information governance lead, or a senior staff member with oversight of operational processes.

The assessment does not require technical AI expertise. It requires the same structured governance thinking that effective care managers apply to any other operational risk assessment. The questions are the same: what are we doing, what could go wrong, who is responsible, and what have we put in place to manage the risk.

Ready to Build Your AI Governance Foundation

AI Impact Assessment Template + Complete Governance Pack

10 editable Microsoft Word templates including AI Impact Assessment, AI Systems Register, Risk Assessment, Acceptable Use Standard, Output Review Record, and six more governance documents. Start with the assessment. Build from there.

The Relationship to Other Governance Documents

An AI Impact Assessment does not replace a DPIA — it complements it. The DPIA remains the specific, legally required document for processing activities that are likely to result in high risk to individuals. The AI Impact Assessment is broader, covering operational and clinical governance risks that may not have a data protection dimension.

Similarly, an AI Impact Assessment does not replace a clinical risk assessment under DCB0129 for health IT systems. For digital health technologies seeking NHS deployment, DCB0129 remains the applicable standard. The AI Impact Assessment addresses the organisation's use of AI tools from the deploying organisation's perspective — it is the tool that the care provider completes, while DCB0129 documentation is produced by the technology manufacturer.

For care providers, the relevant analogy is the risk register — a document that is already a core governance expectation under the CQC's Well-led framework. The AI Impact Assessment is a section of the risk register brought to life: a systematic process for identifying, evaluating, and mitigating the specific category of risk that AI tools introduce to the organisation.

When to Conduct One

An AI Impact Assessment should be conducted before a new AI tool is introduced to the service — not after it has been in use for several months and has already influenced care records or operational decisions. Retrospective assessments are possible and better than no assessment at all, but they cannot undo the period of ungoverned use that preceded them.

The assessment should be reviewed and updated whenever a new AI tool is introduced, whenever an existing tool is significantly changed or upgraded, whenever the organisation's use of an existing tool changes substantially, and annually as part of the organisation's regular governance review cycle.

For organisations that are only now becoming aware of AI Impact Assessments as a governance requirement, the right starting point is a rapid audit: identify every AI tool currently in use across the service, prioritise them by the sensitivity of the data they process and the significance of the decisions they influence, and conduct the full assessment for the highest-priority tools first.

What the Assessment Produces

A completed AI Impact Assessment produces three outcomes. The first is a documented record that the organisation has asked and answered the right questions about its AI use — the record that demonstrates responsible governance to a CQC inspector, an ICO investigator, or any other regulatory body that asks.

The second is a structured view of the organisation's actual AI risk profile — which tools introduce material risk, which are being used appropriately within their designed scope, and which require additional controls or should be discontinued.

The third is a governance baseline from which future AI adoption decisions can be made. An organisation with a completed AI Impact Assessment for its current tools is in a position to evaluate new AI tools systematically rather than reactively, comparing each proposed new tool against the governance standards the assessment has established.

This last outcome is perhaps the most valuable in the long run. AI tools for care settings are proliferating rapidly, and the organisations that will navigate this environment most effectively are not those that avoid AI — the efficiency and quality benefits are real and the direction of travel is clear — but those that have built the governance infrastructure to adopt AI responsibly, at pace, with documented evidence of responsible decision-making at each step.

An AI Impact Assessment is where that infrastructure begins.


This article aligns with PAIDS™ (Professional AI Documentation Standards) — well-sourced, thoroughly researched, and defensible with verifiable data. reporticaai.co.uk/governance

Cross-referenced with: AI Governance in Care Settings, ICO Better Records Together Campaign, CQC AI Guidance and Documentation