Colorado Artificial Intelligence Act (proposed SB 24-205)
Colorado AI Act: Deployer Duties (6-1-1703)

Colorado Artificial Intelligence Act (proposed SB 24-205) CO-AIA-1703-3: Impact Assessment

The deployer must complete an impact assessment for each high-risk AI system annually and within 90 days after any intentional and substantial modification; the assessment must cover purpose, intended use, benefits, discrimination risks and mitigation, data categories processed, outputs, monitoring and transparency measures; retained for at least three years.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • AIRMF-MS-1.1 Approaches and metrics for measurement of AI risks enumerated during the MAP function are selected for implementation starting with the most significant AI risks, and the risks or trustworthiness characteristics that will not or cannot be measured are properly documented

OECD AI Principles · 1 control

  • OECDAI-7 Third-Party AI Audit, Impact Assessments, and Metrics for Trustworthy AI

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Colorado AI Act: Deployer Duties (6-1-1703)

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.