AI governance legal support
AI impact assessments
An AI impact assessment has to describe the system as built, not as pitched. We work from the technical documentation, assess the risks that frameworks and regulators actually ask about, and document the oversight and mitigations in place.
- Published price
- $1,500–5,000 / assessment
- Turnaround
- 5 business days
- Without us
- $10,000–40,000
Fixed per unit, not hourly. No minimum engagement. Quoted before we start.
What you receive
A completed impact assessment for the specific AI system, risks and mitigations documented.
- A complete assessment covering intended purpose, users, and the decisions the system affects
- Data provenance and training data documentation to the extent it can be established
- Accuracy, robustness and bias risks assessed, with the testing evidence available recorded
- Human oversight arrangements documented, including what a reviewer can actually override
- Transparency and disclosure obligations identified for the deployment context
- A mitigation plan with owners and a residual risk statement
What it costs, and what it replaces
Both figures are published ranges for the same unit of work. Ours is fixed before we start; if our process gets faster, that is our gain and your price does not move.
How engagements are structured →- Adnah Legal
- $1,500–5,000 / assessment
- Typical cost without us
- $10,000–40,000 / assessment
Roughly 87% lower at the midpoint of each published range.
How the work runs
01
System characterisation
We characterise the system as deployed: what it does, what it decides, who it affects, and where a human is genuinely in the loop rather than nominally attached to the process.
02
Data and provenance
Training and input data provenance is documented as far as it can be established, and where a vendor will not disclose it, that gap is recorded as a gap rather than glossed.
03
Risk assessment
Accuracy, robustness, bias and misuse risks are assessed against the deployment context, with whatever testing evidence exists recorded and its absence noted where there is none.
04
Oversight and mitigation
Human oversight is documented in operational terms, mitigations are mapped to risks with owners, and residual risk is stated plainly for sign-off.
What we need from you
- Technical documentation for the system, including model cards or vendor documentation
- The intended purpose and deployment context
- Testing, evaluation or bias assessment results, where any exist
- The framework or regulation you are assessing against
What we check before delivery
- The system description is reconciled against technical documentation, not the vendor's marketing
- Claims about accuracy are recorded only where evidence exists; otherwise the absence is stated
- Human oversight is assessed as operated, including whether a reviewer has time and information to intervene
- Every risk has a mapped mitigation or an explicit, documented acceptance
When firms send us this
- Deploying a vendor AI system into a regulated process
- Internal build requiring assessment before release
- Customer or procurement due diligence demanding documented assessment
- Preparing for obligations under emerging AI regulation
Questions about ai impact assessments
What framework do you assess against?
Whichever you name — the EU AI Act's requirements, the NIST AI Risk Management Framework, an internal standard, or a combination. Tell us the target and the assessment is structured to it.
What if the vendor will not disclose training data?
That is common, and the gap is documented as a gap along with what was requested and refused. An assessment that invents provenance is worse than one that records the limit of what is knowable.
Do you also do the DPIA?
Yes, where personal data is involved, and we draft both together so they describe the same system consistently.
Firms who send us this usually also send
More in AI governance legal support
All ai governance legal support services →This service
Send one and judge the output.
AI impact assessments at $1,500–5,000 per assessment, 5 business days. No minimum, no scoping call, no onboarding cycle.