Skip to main content
Notifications
You're all caught up.
View all notifications
Backsplice
  • Product
  • Watney AI
  • Why us
  • Pricing
  • Docs
  • Security
  • About
  • Log in
  • Talk to sales
Log in Talk to sales
← Docs
← All documentation

AI Impact Assessments

An impact assessment records who an AI system affects, how it could help or harm them, and what is done about it. Each AI system can have two:

  • An AI impact assessment (AIIA): purpose and context, affected stakeholders, intended benefits, potential harms (for example unfair treatment, loss of privacy, unsafe outcomes or security failures), likelihood and severity, mitigations, residual impact, human oversight, monitoring and review, and consultation.
  • A fundamental rights impact assessment (FRIA), whose six sections follow the six points of Article 27(1) of the EU AI Act: the processes in which the system is used, the period and frequency of use, the people and groups likely to be affected, the specific risks of harm, the human oversight measures, and the measures to be taken if the risks materialize, including internal governance and complaint mechanisms. Each section quotes the point it answers.

Open them from the Impact assessments panel on the system's page, or from the Impact assessments register, which lists every system in your inventory (except retired and rejected ones) with where each assessment stands. The register is linked from the top of the AI Systems page and from each system's Impact assessments panel, and the command palette (Cmd+K, or Ctrl+K) opens it too.

Does Article 27 apply to us?

That is for your organization to determine, with its counsel where needed; nothing in Backsplice is legal advice. When a system's record says your organization is its deployer and classes it as high-risk under Annex III, the system's page shows a note that Article 27 may apply. The note does not conclude anything: Article 27(1) names deployers that are bodies governed by public law or private entities providing public services, and deployers of the systems in points 5(b) and (c) of Annex III (evaluating people's creditworthiness or establishing their credit score, other than to detect financial fraud, and risk assessment and pricing in life and health insurance), and it leaves out systems intended to be used in the area in point 2 of Annex III, critical infrastructure. The registry records neither whether the deployer is a body governed by public law or a private entity providing public services, nor which Annex III point a system is in, so a person decides.

Under Article 27(4), as amended by Regulation (EU) 2026/1744, where an obligation is already met by a data protection impact assessment, the deployer may cross-reference it or include relevant parts of it. You can do either in the section text.

Article 27 is in Chapter III, Section 3, which applies to systems classified as high-risk under Article 6(2) and Annex III from 2 December 2027 (Article 113, third paragraph, point (c)(i), as amended by Regulation (EU) 2026/1744). Under Article 111(2), as amended, a high-risk system placed on the market or put into service before that date is covered only if its design is significantly changed from that date, but providers and deployers of high-risk systems intended to be used by public authorities must comply by 2 August 2030.

Writing a draft

A system's impact assessments can be edited by anyone who can edit the system: an organization administrator, the system's owners, or whoever proposed it. Other members can read them, and so can an auditor whose access includes AI systems.

A section you have not written yet starts from what the system's record already says (its intended use, the people it affects, its oversight design), and the page names where that text came from. It is only a starting point: it becomes the assessment's text when you save, and you should edit it first. Every section must be written before a version can be published.

Watney does not draft impact assessments.

Approving and publishing

Publishing is an approval, and it is signed. The person who publishes approves the assessment as written: they type their full name, re-enter their password and a code from their authenticator app (or a backup code), and confirm the approval. The version records who approved it, the name they signed with, and which second factor they used. Approving needs an authenticator app; set one up in Security settings.

The system's proposer and owners cannot approve its impact assessment unless your organization allows self-approval (Settings → AI approvals), the same rule as the system's approval review. When they do, the version is marked self-approved, on the page and in the approval dossier.

A published version never changes. To change it, edit the draft (it keeps the text of the latest version) and publish again for a new version. Each version carries a tamper-evidence check, shown as Intact when the version has not been altered without the application's signing key since it was published.

A published assessment is due for review 12 months after its latest version, shown on the system's page, in the register and on the compliance calendar. This is Backsplice's review interval, not a period from any law: Article 27(2) requires the deployer, where during use it considers that any of the elements has changed or is no longer up to date, to take the necessary steps to update the information.

Notifying the market surveillance authority

On a published FRIA version, you can record that your organization notified the market surveillance authority: the date, a reference, and a note. The page quotes Article 27(3), including its exemption for the case referred to in Article 46(1). Backsplice does not send the notification, and whether your organization must is for it to decide. A recorded notification cannot be changed; to correct one, record another with a note.

Where they appear

  • The approval dossier includes the latest published version of each kind, with how it was signed and its integrity check, and says when there is none. A draft is never included.
  • The approval screen shows where each stands before an approver decides.
  • Organization administrators and auditors can download a published version as PDF, Markdown or JSON, and the register as CSV, once your organization is on a plan (downloads are not in the demo).
  • Impact assessments are never shown on your public transparency page.
Backsplice

Governance for the AI systems your organization builds, buys and runs.

NIST AI RMF 1.0 NIST AI 600-1 (Generative AI Profile) NIST Cyber AI Profile (IR 8596 initial preliminary draft) UK AI Cyber Security Code of Practice (2025) OWASP Top 10 for LLM Applications 2026 MITRE ATLAS 2026.09

View our security posture →

Product

  • Why Backsplice
  • Frameworks
  • Watney AI
  • Review & Approval
  • Governance Registers
  • Reporting
  • Integrations & API
  • Pricing

Company

  • About Us
  • Team
  • Mission
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Security

Resources

  • Documentation
  • Blog
  • Status Page

© 2026 Backsplice LLC. All rights reserved.

Backsplice provides tools to run an AI governance program; it does not confer compliance with any law or standard and does not constitute legal advice. Consult qualified legal counsel for specific compliance guidance.