AI Assurance Logo
AI Assurance aiassurance.co.za
Get In Touch

AI Impact Assessment Platform

Pre-market evidence for high-risk AI systems under the EU AI Act.

AIIA is a software platform for organisations that must show conformity with the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) for high-risk AI systems. It is built for pre-market readiness: the file a notified body or authority can sample, not a checklist of clauses.

For a South African organisation this page applies only where you are a provider placing a high-risk system on the Union market, putting one into service there, or producing output that is used in the Union. POPIA still governs any personal information in the same system. A PIIA under Regulation 4(1)(b) is a different file. AIIA does not replace it. A Fundamental Rights Impact Assessment under Article 27, where that article applies, does not discharge POPIA either.

The platform integrates obligations from the AI Act, and from GDPR where Union people are in the file, with harmonised-standard practice including prEN 18286 for an AI quality management system.

Three pillars

  • Proportionality, necessity and foundational controls - purpose-bound processing and baseline safeguards.
  • Operational rights, transparency and oversight - information, the exercise of rights, and meaningful human oversight.
  • Governance, risk, security and sustainability - lifecycle risk management, cybersecurity and resource tracking across the estate.

Multi-role collaboration (preparer, reviewer, approver) lets technical, legal and compliance teams, and external parties such as providers and suppliers, contribute to the system description, technical documentation, risk assessment, controls and acceptance.

What it produces

From the work as it is done, AIIA generates the documents required for conformity assessment: technical documentation aligned with Annex IV, an EU declaration of conformity aligned with Annex V, a Fundamental Rights Impact Assessment where Article 27 applies, a post-market monitoring plan under Article 72, and a residual-risk acceptance statement.

What the platform does

  • A regulatory roadmap from classification and technical documentation through post-market monitoring and serious-incident reporting.
  • Each question linked to a named AI Act article, GDPR provision where it applies, or harmonised-standard clause (including prEN 18286, prEN 18284 and prEN 18283), with the evidence that question needs.
  • Traceability and gap analysis against those requirements as answers are recorded.
  • Integrated FRIA and Article 9 risk management, with post-market monitoring feeding back into design and controls.
  • Tracking of energy use and environmental impact where that is in scope.
  • Role-based access, version control and a controlled exchange with external parties.

Who it is for

  • South African providers and manufacturers placing high-risk systems on the Union market
  • Deployers of high-risk systems in the Union, including SA groups with an EU affiliate
  • Quality, compliance, risk and data-protection officers who have to produce the Act file
  • Legal and regulatory teams, internal auditors and conformity coordinators

AIIA is delivered as a cloud platform. Request a walkthrough of the assessment for a named high-risk system, or download the brochure.