The Risk-Record Tool to Sell Before Public AI Goes Live
As public AI impact assessments approach, there is room for a small workflow tool that connects pre-deployment questions with records of errors and appeals in live operations.
Published 2026. 9. 2.
This changes the whole operating process, not just one form
On August 28, 2026, Korea renamed the Act on the Promotion of Data-Based Administration to the Act on the Promotion of AI and Data-Based Administration (인공지능 및 데이터 기반 행정 활성화에 관한 법률). The law sets a direction for public institutions using AI: they must consider personal-data protection, transparency in decision-making, and bias that repeatedly produces unfavourable outcomes for particular groups.
An impact assessment for AI that affects the public will take effect on February 28, 2027. It requires institutions to examine impacts on fundamental rights and disclose the results before deployment. AI already in operation must also be assessed and have its results disclosed within two years of the effective date, making February 28, 2029 the standard preparation deadline.
The assessment is not only about whether personal data might leak. Institutions must examine whether they can explain the decision process and its outcomes, whether performance is reliable, and whether the data and decision rules used create disadvantages for particular groups.
Work remains after the assessment. An institution must assign responsible staff, record who did what and when, monitor performance and safety, and establish a response process for errors or bias, including criteria for pausing the service.
Not every AI system follows the same process. A system may be exempt if it is clearly not a public-facing service and is not used for policy decisions concerning people’s rights or obligations, but this requires confirmation from the Minister of the Interior and Safety, the Korean government minister responsible for public administration. Reusing an AI system that has already been assessed in the same way, or testing one within a limited scope for no more than one year, may also qualify for an exemption. Institutions cannot decide this on their own; they need to confirm the applicable process.
To avoid failure, build a record flow rather than an assessment form
Consider one procurement officer in the welfare department of a county office with twelve staff members. They are buying an AI tool to classify civil complaints. They are not a developer, but they must hear the vendor’s explanation, obtain internal approval, coordinate with the personal-data officer, and later respond to residents’ complaints.
Today, they may copy the same service name and deployment purpose into roughly four places: a project plan, a document that communicates requirements to the vendor, a personal-data checklist, and meeting minutes. They search vendor materials for accuracy figures, look in another document for the source of the data used, and search email again to identify who is responsible for error response.
The problem is not just the number of documents. It is easy to miss contradictions: the deployment purpose is complaint classification, but performance-test material was created using general documents; or the vendor says a human performs the final review, while the actual screen has no option to reverse a result.
The first tool needed here is not a document generator that writes the assessment for them. It is a workspace that asks, in sequence, about the deployment purpose, residents affected, steps handled automatically, steps reviewed by a person, and harm that could result from errors—and attaches supporting evidence to each answer.
The vendor uploads the source of the data used, test results, differences in error rates between groups, how results are explained, and how a person can change a decision in the same place. When the officer changes the scope of deployment, the tool can flag items that conflict with earlier answers and show information-provision obligations missing from the procurement contract.
Once operations begin, the same tool should connect sample-check results, changes to human decisions, residents’ appeals, errors, and records of temporary suspension. That makes it possible to check in the next meeting and in public documents whether the safeguards promised during assessment are actually working.
Some work must still remain with people. Staff and the institution must decide which fundamental rights are involved, whether the system qualifies for an exemption, how severe an error must be before service is paused, and whether to accept a resident’s appeal. The tool should not replace judgment; it should keep the evidence for judgment from becoming scattered.
The easiest way for this service to fail is to offer only more “check complete” buttons. If there is no evidence to verify a vendor’s answers, and no connection to problems that emerge during operations, an assessment can be completed without preventing harm. Before building, confirm whether institutions can actually obtain vendors’ test materials and whether contracts can include obligations to provide information and notify the institution of changes.
Overseas examples also connect assessment with operational records
The Government of Canada runs an Algorithmic Impact Assessment for automated decision systems before they are deployed. It uses 65 questions about impact and 41 questions about measures to reduce harm to determine the risk level, and requires review of legal issues, privacy, explainability, and human review before live operation.
Immigration, Refugees and Citizenship Canada, the federal department that handles immigration, refugee, and citizenship matters, has published assessment results for a system that automatically sorts overseas visitor-visa applications and approves some eligibility decisions. An officer makes the final decision on whether a person may enter Canada, but the public document does not contain enough operational results, such as error rates by group or how often officers changed automated decisions. That leaves a need to connect the assessment with operational records.
The UK Home Office’s CARS(V) routes visitor-visa applications to suitable caseworkers by separating more complex cases from relatively simple ones. Applicants pay a visa processing fee, but there is no separate fee for using this routing tool, and the system does not make the final approval or refusal decision.
According to UK government records, the tool was used for about 2.5 million applications in 2023. If a caseworker finds an issue in an application classified as simple, they can return it to the complex-case route, and the operations team reviews effectiveness monthly. Accuracy and reclassification rates have not been disclosed.
Australia’s RoboDebt is an example in the opposite direction. It calculated alleged overpayment debts using estimated income figures created by dividing welfare recipients’ annual income across periods, then demanded repayment from people subject to the system’s decision.
The approach was stopped and led to a class action and a Royal Commission inquiry. It showed how harm can grow when estimated data is directly tied to an individual debt without sufficient human review and an easy-to-understand appeal process. This is why public AI tools need to address not only documentation, but also pause criteria and records of appeal handling.
Four places to start
1. Impact-assessment starting guide
- What the service does: Uses a small set of questions to identify the likelihood that an assessment applies and list the supporting documents to prepare.
- Who uses it: A city administrative officer buying an AI civil-complaint consultation tool for the first time.
- Why now: With the February 2027 start date approaching, institutions need to identify which projects to review first.
- First screen: Four large input fields ask for the service purpose, people affected, scope of automated decision-making, and possible disadvantage.
2. Vendor evidence repository
- What the service does: Lets public institutions and vendors exchange accuracy tests, data sources, human-review methods, and change histories in one place.
- Who uses it: A business lead at an eight-person vendor that wants to supply a document-classification AI tool to public institutions.
- Why now: Institutions need material held by vendors to complete an assessment, and they need to keep receiving information that changes after deployment.
- First screen: When a procurement requirements document is uploaded, it shows three groups: materials to submit, missing materials, and information-provision items to include in the contract.
3. Operational risk log
- What the service does: Records incorrect outcomes, changes made by staff, residents’ appeals, and service pauses and restarts by date.
- Who uses it: The operational lead at a district office managing a welfare-eligibility recommendation AI tool each day.
- Why now: The risk management required by the law must continue during real operations, not stop after a pre-deployment assessment.
- First screen: Starts with four buttons: log an error, change through human judgment, receive a resident appeal, and pause the service.
4. Resident explanation and appeal notice builder
- What the service does: Creates plain-language notices explaining where AI was used and what a person decided.
- Who uses it: A community service centre officer sending welfare information based on AI recommendations.
- Why now: Published assessment results and user protection must lead to real resident understanding and the ability to raise concerns.
- First screen: Places side by side fields for what the AI did, what a person decided, whom to contact, and the appeal process established by the institution.
Why this matters where you are
Open a recent public-sector AI procurement request in your market and check whether it addresses impact assessment, bias, appeals, service pauses, and records. The legal process may differ from Korea’s, but vendors still need to supply evidence and operators still need to connect pre-deployment commitments with problems found in use. A small tool can begin by collecting those missing materials and operational records.
What to check today
Open one recent request for proposals for a public AI project and search for five terms: impact assessment, bias, appeals, service pause, and records. If three or more are missing—and are not required as separate submission documents—it may be worth building a small tool to collect the missing evidence and operational records before building an assessment-writing tool.
Sources
6 sources
Every fact in this article came from the pages below. Check them yourself.
- Act on the Promotion of AI and Data-Based AdministrationKorean Law Information CenterReferenced the law’s effective date, public-sector AI impact assessments, and transitional measures for systems already in operation.https://www.law.go.kr/LSW/lsInfoP.do?lsiSeq=283735&viewCls=lsRvsDocInfoR&utm_source=openai
- Enforcement Decree of the Act on the Promotion of AI and Data-Based AdministrationKorean Law Information CenterReferenced assessment criteria, exemptions, and risk-management requirements during operations.https://www.law.go.kr/lsInfoP.do?lsiSeq=288963&viewCls=lsRvsDocInfoR&utm_source=openai
- Legislative and Policy Tasks for Promoting AI and Data-Based AdministrationNational Assembly Research ServiceReferenced issues concerning data quality, human involvement, accountability, and safety.https://www.nars.go.kr/report/view.do?brdSeq=49532&cmsCode=CM0043&utm_source=openai
- Algorithmic Impact AssessmentGovernment of CanadaReferenced the Canadian federal government’s pre-deployment assessment questions and operating approach.https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/responsible-use-ai/algorithmic-impact-assessment.html
- How we use technology at Immigration, Refugees and Citizenship CanadaImmigration, Refugees and Citizenship CanadaReferenced automated visitor-visa eligibility decisions and review by officers.https://www.canada.ca/en/immigration-refugees-citizenship/corporate/transparency/digital-transparency-advanced-data-analytics/uses-technology.html
- Home Office Complexity Application Routing Solution (Visits)UK GovernmentReferenced visitor-visa case routing, final human decisions, usage scale, and review practices.https://www.gov.uk/algorithmic-transparency-records/home-office-complexity-application-routing-solution-visits