Skip to main content
Notifications
You're all caught up.
View all notifications
Backsplice
  • Product
  • Watney AI
  • Why us
  • Pricing
  • Docs
  • Security
  • About
  • Log in
  • Talk to sales
Log in Talk to sales
← Docs
← All documentation

Management Reviews

A management review is leadership's periodic look at the AI governance program: is it working, what has changed, and what should change next. Management Reviews keeps each one as a record you can show an auditor.

A review

Each review has a title, the date it was held, a chair, the members who attended and any other attendees without an account. Tick the inputs the review considered and note what was said about each:

  • status of actions from previous management reviews;
  • changes in internal and external issues that affect the program;
  • AI system performance and monitoring results;
  • incidents, nonconformities and corrective actions;
  • internal and external audit results;
  • the status of the AI risk register and risk treatment;
  • feedback from users, affected people and other stakeholders;
  • opportunities for improvement.

Then record the minutes, the decisions about changes and the next review date.

The program's numbers

The review shows the program as it stands: the program score (only once it is scored), open findings by risk, open AI risks, incidents discovered in the review period, AI systems by lifecycle stage, and how many actions from earlier reviews are still open. The period runs from the last finalized review to this one (or the twelve months before it, for the first review). On a draft these numbers are live; finalizing freezes them as of that day.

Draft, then finalized

A review starts as a draft, which any member who can write may edit. An org admin finalizes it once it names a chair, marks at least one input as considered and has minutes. A finalized review cannot be edited or deleted, and it carries an integrity stamp: its page and PDF say whether it is unchanged since it was finalized. A draft can be deleted by an org admin.

Actions

Each follow-up the review decides is an action: a remediation task, assigned, reminded and closed with the rest of your tasks. Actions can be added to a draft or a finalized review. The next review lists the earlier reviews' actions and their status.

The calendar

The compliance calendar shows when the next review is due: the date the last review set, or a year after it, or a year after your organization was set up if none has been held. While a draft is being prepared, the calendar shows the draft's date instead. The Internal audit of the AI governance program is an annual activity in the compliance calendar's catalog. A new organization starts with it on the calendar; if yours does not show it, an admin adopts it from the activity catalog under Manage activities. Record each audit there, with its report as evidence, and bring the results to the next review.

Exports

Admins and auditors can export the register as CSV and any review as a PDF.

Who can do what

Every member can read the reviews, and members who can write can draft them and add actions. Only an org admin can finalize or delete a draft. An auditor with an active engagement can read them, read-only.

Backsplice

Governance for the AI systems your organization builds, buys and runs.

NIST AI RMF 1.0 NIST AI 600-1 (Generative AI Profile) NIST Cyber AI Profile (IR 8596 initial preliminary draft) UK AI Cyber Security Code of Practice (2025) OWASP Top 10 for LLM Applications 2026 MITRE ATLAS 2026.09

View our security posture →

Product

  • Why Backsplice
  • Frameworks
  • Watney AI
  • Review & Approval
  • Governance Registers
  • Reporting
  • Integrations & API
  • Pricing

Company

  • About Us
  • Team
  • Mission
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Security

Resources

  • Documentation
  • Blog
  • Status Page

© 2026 Backsplice LLC. All rights reserved.

Backsplice provides tools to run an AI governance program; it does not confer compliance with any law or standard and does not constitute legal advice. Consult qualified legal counsel for specific compliance guidance.