Regulation explainerPublic Sector
Algorithmic transparency and impact assessments for public bodies: one evidence pack, four regimes
A public body using AI may owe a published transparency record, a data protection impact assessment, an equality analysis and, depending on where it operates, a fundamental rights impact assessment, a federal AI impact assessment or a Canadian Algorithmic Impact Assessment. The questions overlap far more than the forms suggest. This page sets the regimes side by side and shows how to gather the evidence once.
On this page
Why public bodies answer for algorithms differently
A company that uses a scoring model answers mainly to data protection and consumer law. A public body answers to more. It can act only within its legal powers, its decisions can be challenged on grounds of fairness and rationality, and people often have no alternative provider to turn to. In Great Britain, the Public Sector Equality Duty also requires public authorities to have due regard to eliminating discrimination and advancing equality of opportunity when they exercise their functions8.
Freedom of information adds a practical point: documents about an algorithm may be requested and published whether or not you planned it. Write them as if the people affected will read them.
Transparency and assessment regimes compared for public-sector AI
Scope tests differ, so check each one against the tool, not the organisation alone.
Algorithmic Transparency Recording Standard (ATRS), mandatory scope and exemptions policy
United Kingdom (central government)Applies whenMinisterial and non-ministerial departments, and arm's-length bodies that provide public or frontline services or routinely deal with the public, use a tool that significantly influences a decision with public effect or interacts directly with the public, once it reaches pilot or production1.
- Publish a record in the ATRS repository: a summary tier for the general public and a detailed tier covering ownership, deployment context, models, data and risks2.
- Redact using the test of what you would release under a freedom of information request, rather than withholding the record outright1.
- Update the record when the tool changes and mark it retired when it is withdrawn.
EU AI Act (Regulation (EU) 2024/1689): duties of public deployers
European UnionApplies whenBodies governed by public law, and private bodies providing public services, deploy a high-risk system listed in Annex III, other than critical infrastructure systems3.
- Complete a fundamental rights impact assessment before first use and notify the market surveillance authority of the results (Article 27).
- Public-authority deployers register their use in the EU database and must not use an unregistered system (Article 26 and Article 49).
- Assign human oversight to competent staff and inform people that a high-risk system is used in decisions about them (Article 26).
- These duties apply from 2 December 2027, after the Digital Omnibus on AI moved the stand-alone high-risk deadline4.
OMB memorandum: Accelerating Federal Use of AI through Innovation, Governance, and Public Trust
United States (federal executive agencies)Applies whenMemorandum M-25-21 applies when an agency uses high-impact AI, meaning AI whose output is a principal basis for decisions or actions with a legal, material, binding or significant effect on rights or safety5.
Directive on Automated Decision-Making and the Algorithmic Impact Assessment
Canada (federal institutions)Applies whenA system fully or partly automates an administrative decision affecting someone's legal rights, privileges or interests, including systems that only inform an officer7.
What each regime asks you to evidence
Each row shows one fact requested in four formats, which is why one evidence pack works.
| Evidence | UK ATRS record | EU fundamental rights impact assessment | US AI impact assessment | Canadian AIA |
|---|---|---|---|---|
| Purpose and benefit | Description and rationale, what it replaced | The deployer's process the system supports | Intended purpose and expected benefit against current process | Project and decision questions |
| People affected | Deployment context and who uses the tool | Categories of people and groups likely affected | Impacts on privacy, civil rights and civil liberties | Impact questions on rights, health and economic interests |
| Data and model | Model, development data and operational data sheets | Not itemised; drawn from provider documentation | Data quality and fitness for purpose, protected classes | Algorithm, system and data questions |
| Human role and recourse | Degree of automation and appeal routes | Human oversight measures and complaint mechanisms | Human oversight, remedies and appeals | Consultation and de-risking questions |
| Where it goes | Published on GOV.UK | Sent to the market surveillance authority | Agency records; use case listed in public inventory | Published on the Open Government Portal |
Summarised from the published templates and memoranda cited on this page. The Canadian tool alone has 65 risk and 41 mitigation questions6.
When each assessment falls due across the delivery lifecycle
- Discovery
Classify the tool, identify the regimes in scope and open the evidence pack.
- Procurement
Write disclosure and testing duties into the tender so suppliers know what you will publish.
- Design
Complete the first impact assessment while the human role and appeal route can still change.
- Pilot
Publish the transparency record once the tool reaches real users; finish pre-deployment testing.
- Live service
Monitor outcomes by group, review overrides and appeals, and keep records current.
- Change or retire
Reassess on material change, such as a new model or population, and mark retired tools.
Building one evidence pack for several regimes
The pack is a living folder owned by the service, not a document written by compliance at the end.
Classify the tool at intake
Record what the tool does, which decision it touches and how directly, then list every regime and internal policy that could apply.
Fix the legal basis and the decision boundary
Confirm the power being exercised and the lawful basis for any personal data, and write down what the tool may never decide alone.
Describe the system once
Capture purpose, architecture, models, data sources, suppliers and versions in a single description that every output reuses.
Test on your own population
Measure accuracy and error rates on local data, broken down by the groups your equality analysis identifies, before and after launch.
Design the human role and the appeal route
Specify who reviews outputs, what they can override, how people are told and how they challenge a result.
Generate each regime's output
Fill the transparency record, impact assessment and equality analysis from the pack, so the documents never contradict each other.
Sign off, publish and set review triggers
A named senior owner accepts the residual risk; publish what is due and diarise reviews for model, data or scope changes.
Questions and answers
Does a government chatbot need an ATRS record?
If the organisation is within the mandatory scope, usually yes. The policy covers tools that interact directly with the general public as well as those that influence decisions, and records are due once a tool reaches pilot or production. Bodies outside the mandate, such as local authorities, are encouraged to use the standard, and a public chatbot is often the easiest record to write because its data and decision role are simple.
Is a fundamental rights impact assessment the same as a DPIA?
No. A data protection impact assessment focuses on risks from processing personal data, while the AI Act's fundamental rights impact assessment covers wider rights such as non-discrimination and access to services. The AI Act lets the two overlap: where a DPIA already meets part of the obligation, the fundamental rights assessment complements it rather than repeating it. In practice one evidence pack can feed both.
What if a supplier will not disclose model details?
Deal with it before contract award. The ATRS policy expects buyers to set transparency expectations in tender documents and work with suppliers early, and it treats commercial sensitivity as grounds to reduce detail, not to skip the record. US federal guidance allows testing by querying a service and observing outputs where source code and data are unavailable. If a supplier still refuses, weigh that against the duties you carry.
How often should an algorithmic impact assessment be updated?
Whenever the system changes materially and on a fixed review cycle in between. Material changes include a new or retrained model, a new population, new data sources, or a shift from advisory to automated use. Canada expects more frequent reviews for higher-impact or high-volume systems, and the US memorandum requires a reassessment schedule in the assessment itself. Tie reviews to your change process.
Sources
- Algorithmic Transparency Recording Standard (ATRS): mandatory scope and exemptions policy — GOV.UK · checked 10 October 2026
- Algorithmic Transparency Recording Standard: guidance for public sector bodies — GOV.UK · checked 10 October 2026
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
- The AI digital omnibus regulation has been published, redefining deadlines — Garrigues · checked 10 October 2026
- M-25-21: Accelerating Federal Use of AI through Innovation, Governance, and Public Trust — Office of Management and Budget · checked 10 October 2026
- Algorithmic Impact Assessment tool — Government of Canada · checked 10 October 2026
- Guide on the scope of the Directive on Automated Decision-Making — Government of Canada · checked 10 October 2026
- Equality Act 2010, section 149: Public sector equality duty — legislation.gov.uk · checked 10 October 2026