Skip to main content

Development trial ยท sample information only

Register and classify an AI use

For licensed Collaborators with permission for this task. Check the selected organisation; feature availability and record access still apply.

What you will achieve

Record what an AI-enabled asset is and how it is used in a specific processing activity. Backstory keeps these two questions separate.

Before you start

Identify the asset, supplier, relevant RoPA and accountable owner. Gather provider evidence and a description of the real use, including people affected and human oversight.

Do not treat missing information as a conclusion that something is not AI or is low risk.

Record the asset-level facts

  1. Open the asset's AI profile.
  2. Review its assessment state. If making a determination, record the assessment basis, rationale and source or rule version.
  3. For a confirmed AI asset, choose the appropriate asset category and inherent classification supported by the evidence.
  4. Record provider-evidence status and classification notes, then save.
  5. Reload the asset and verify that its identity and assessment describe the system, not just one departmental use.

Record the use context

  1. Open the relevant RoPA's AI area and select Add AI use case.
  2. Select the linked assets and their roles in this use. A primary AI system, supporting component and data source are not interchangeable.
  3. Select the applicable RoPA data entities and describe AI processing purpose.
  4. Review contextual risk, deployer scope and affected-person presence. Leave an unassessed fact visibly unassessed until the owner has evidence.
  5. Record the human oversight model, transparency arrangements, provider instructions and relevant contract or safeguard references.
  6. Select the affected people from the available categories and explain additional groups where necessary.
  7. Save and inspect the effective classification and readiness returned for the use.

The effective classification is a calculated result, not a number to edit until the desired assessment path appears.

Check it worked

Follow the use back to its RoPA, assets and people. Confirm the typed asset roles, purpose and assessment rationale. Review any Article 5 or FRIA attention items with the authorised governance owner.

If something goes wrong

Problem Next action
An asset is missing from selection Link the correct asset to the RoPA through its relationships first
Readiness is blocked Open the stated upstream record and resolve the missing fact
The effective tier is unexpected Review inherent/contextual facts and typed roles; do not override the result through unrelated fields
The use changes Revisit its assessment and connected evidence before relying on an earlier conclusion

Human judgement matters

A detected signal is not a legal determination. Likewise, high-risk classification alone does not settle whether a statutory FRIA is required. Record and review applicability separately.

What next?

For the wider context, see Manage AI governance.

Complete the applicable rights-assessment decision and start the FRIA only for the supported scope and basis.

Get help

Ask your Organisation Administrator about access or the task owner about the content. For a platform error, include this guide reference, the affected page and a sanitised message, not confidential evidence or session details.

Was this article helpful?