Regulation explainerPublic Sector

Algorithmic transparency and impact assessments for public bodies: one evidence pack, four regimes

A public body using AI may owe a published transparency record, a data protection impact assessment, an equality analysis and, depending on where it operates, a fundamental rights impact assessment, a federal AI impact assessment or a Canadian Algorithmic Impact Assessment. The questions overlap far more than the forms suggest. This page sets the regimes side by side and shows how to gather the evidence once.

Reviewed 8 min read

On this page
  1. Why public bodies answer for algorithms differently
  2. Transparency and assessment regimes compared for public-sector AI
  3. What each regime asks you to evidence
  4. When each assessment falls due across the delivery lifecycle
  5. Building one evidence pack for several regimes
  6. Questions and answers
  7. Sources

Why public bodies answer for algorithms differently

A company that uses a scoring model answers mainly to data protection and consumer law. A public body answers to more. It can act only within its legal powers, its decisions can be challenged on grounds of fairness and rationality, and people often have no alternative provider to turn to. In Great Britain, the Public Sector Equality Duty also requires public authorities to have due regard to eliminating discrimination and advancing equality of opportunity when they exercise their functions8.

Freedom of information adds a practical point: documents about an algorithm may be requested and published whether or not you planned it. Write them as if the people affected will read them.

Transparency and assessment regimes compared for public-sector AI

Scope tests differ, so check each one against the tool, not the organisation alone.

Algorithmic Transparency Recording Standard (ATRS), mandatory scope and exemptions policy

United Kingdom (central government)

Applies whenMinisterial and non-ministerial departments, and arm's-length bodies that provide public or frontline services or routinely deal with the public, use a tool that significantly influences a decision with public effect or interacts directly with the public, once it reaches pilot or production1.

  • Publish a record in the ATRS repository: a summary tier for the general public and a detailed tier covering ownership, deployment context, models, data and risks2.
  • Redact using the test of what you would release under a freedom of information request, rather than withholding the record outright1.
  • Update the record when the tool changes and mark it retired when it is withdrawn.

EU AI Act (Regulation (EU) 2024/1689): duties of public deployers

European Union

Applies whenBodies governed by public law, and private bodies providing public services, deploy a high-risk system listed in Annex III, other than critical infrastructure systems3.

  • Complete a fundamental rights impact assessment before first use and notify the market surveillance authority of the results (Article 27).
  • Public-authority deployers register their use in the EU database and must not use an unregistered system (Article 26 and Article 49).
  • Assign human oversight to competent staff and inform people that a high-risk system is used in decisions about them (Article 26).
  • These duties apply from 2 December 2027, after the Digital Omnibus on AI moved the stand-alone high-risk deadline4.

OMB memorandum: Accelerating Federal Use of AI through Innovation, Governance, and Public Trust

United States (federal executive agencies)

Applies whenMemorandum M-25-21 applies when an agency uses high-impact AI, meaning AI whose output is a principal basis for decisions or actions with a legal, material, binding or significant effect on rights or safety5.

  • Inventory AI use cases at least annually and post a public version5.
  • Before deployment, test and complete an AI impact assessment, including an independent internal review and signed risk acceptance5.
  • Monitor in operation, train operators, provide human review and appeal, and take public feedback5.

Directive on Automated Decision-Making and the Algorithmic Impact Assessment

Canada (federal institutions)

Applies whenA system fully or partly automates an administrative decision affecting someone's legal rights, privileges or interests, including systems that only inform an officer7.

  • Complete the Algorithmic Impact Assessment at the start of design and again before production6.
  • Publish the final results on the Open Government Portal in both official languages6.
  • Apply the mitigation measures that the resulting impact level, from I to IV, requires.

What each regime asks you to evidence

Each row shows one fact requested in four formats, which is why one evidence pack works.

EvidenceUK ATRS recordEU fundamental rights impact assessmentUS AI impact assessmentCanadian AIA
Purpose and benefitDescription and rationale, what it replacedThe deployer's process the system supportsIntended purpose and expected benefit against current processProject and decision questions
People affectedDeployment context and who uses the toolCategories of people and groups likely affectedImpacts on privacy, civil rights and civil libertiesImpact questions on rights, health and economic interests
Data and modelModel, development data and operational data sheetsNot itemised; drawn from provider documentationData quality and fitness for purpose, protected classesAlgorithm, system and data questions
Human role and recourseDegree of automation and appeal routesHuman oversight measures and complaint mechanismsHuman oversight, remedies and appealsConsultation and de-risking questions
Where it goesPublished on GOV.UKSent to the market surveillance authorityAgency records; use case listed in public inventoryPublished on the Open Government Portal

Summarised from the published templates and memoranda cited on this page. The Canadian tool alone has 65 risk and 41 mitigation questions6.

When each assessment falls due across the delivery lifecycle

01Discovery02Procurement03Design04Pilot05Live service06Change or retire
  1. Discovery

    Classify the tool, identify the regimes in scope and open the evidence pack.

  2. Procurement

    Write disclosure and testing duties into the tender so suppliers know what you will publish.

  3. Design

    Complete the first impact assessment while the human role and appeal route can still change.

  4. Pilot

    Publish the transparency record once the tool reaches real users; finish pre-deployment testing.

  5. Live service

    Monitor outcomes by group, review overrides and appeals, and keep records current.

  6. Change or retire

    Reassess on material change, such as a new model or population, and mark retired tools.

Conceptual timing of transparency and impact assessment work. Exact triggers differ by regime.

Building one evidence pack for several regimes

The pack is a living folder owned by the service, not a document written by compliance at the end.

  1. Classify the tool at intake

    Record what the tool does, which decision it touches and how directly, then list every regime and internal policy that could apply.

    Output
    Scope note naming the assessments due
    Owner
    Digital or data lead
  2. Fix the legal basis and the decision boundary

    Confirm the power being exercised and the lawful basis for any personal data, and write down what the tool may never decide alone.

    Output
    Legal basis note
    Owner
    Legal adviser
  3. Describe the system once

    Capture purpose, architecture, models, data sources, suppliers and versions in a single description that every output reuses.

    Output
    System description
    Owner
    Product owner with the supplier
  4. Test on your own population

    Measure accuracy and error rates on local data, broken down by the groups your equality analysis identifies, before and after launch.

    Output
    Test report
    Owner
    Data science
  5. Design the human role and the appeal route

    Specify who reviews outputs, what they can override, how people are told and how they challenge a result.

    Output
    Oversight and recourse design
    Owner
    Service owner
  6. Generate each regime's output

    Fill the transparency record, impact assessment and equality analysis from the pack, so the documents never contradict each other.

    Output
    Regime-specific documents
    Owner
    Data protection officer or transparency lead
  7. Sign off, publish and set review triggers

    A named senior owner accepts the residual risk; publish what is due and diarise reviews for model, data or scope changes.

    Output
    Signed risk acceptance and review schedule
    Owner
    Senior responsible owner

Questions and answers

Does a government chatbot need an ATRS record?

If the organisation is within the mandatory scope, usually yes. The policy covers tools that interact directly with the general public as well as those that influence decisions, and records are due once a tool reaches pilot or production. Bodies outside the mandate, such as local authorities, are encouraged to use the standard, and a public chatbot is often the easiest record to write because its data and decision role are simple.

Is a fundamental rights impact assessment the same as a DPIA?

No. A data protection impact assessment focuses on risks from processing personal data, while the AI Act's fundamental rights impact assessment covers wider rights such as non-discrimination and access to services. The AI Act lets the two overlap: where a DPIA already meets part of the obligation, the fundamental rights assessment complements it rather than repeating it. In practice one evidence pack can feed both.

What if a supplier will not disclose model details?

Deal with it before contract award. The ATRS policy expects buyers to set transparency expectations in tender documents and work with suppliers early, and it treats commercial sensitivity as grounds to reduce detail, not to skip the record. US federal guidance allows testing by querying a service and observing outputs where source code and data are unavailable. If a supplier still refuses, weigh that against the duties you carry.

How often should an algorithmic impact assessment be updated?

Whenever the system changes materially and on a fixed review cycle in between. Material changes include a new or retrained model, a new population, new data sources, or a shift from advisory to automated use. Canada expects more frequent reviews for higher-impact or high-volume systems, and the US memorandum requires a reassessment schedule in the assessment itself. Tie reviews to your change process.

Sources

  1. Algorithmic Transparency Recording Standard (ATRS): mandatory scope and exemptions policy — GOV.UK · checked 10 October 2026
  2. Algorithmic Transparency Recording Standard: guidance for public sector bodies — GOV.UK · checked 10 October 2026
  3. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
  4. The AI digital omnibus regulation has been published, redefining deadlines — Garrigues · checked 10 October 2026
  5. M-25-21: Accelerating Federal Use of AI through Innovation, Governance, and Public Trust — Office of Management and Budget · checked 10 October 2026
  6. Algorithmic Impact Assessment tool — Government of Canada · checked 10 October 2026
  7. Guide on the scope of the Directive on Automated Decision-Making — Government of Canada · checked 10 October 2026
  8. Equality Act 2010, section 149: Public sector equality duty — legislation.gov.uk · checked 10 October 2026

More in Public Sector

Back to Public Sector

Next step

Send us the AI tool you need to assess and publish

Describe the tool, the decision it touches and where you operate. We will reply with the regimes likely in scope and what an evidence pack for it would need to contain.

Discuss an impact assessment