Fundamental rights impact assessment (FRIA)
Article 27 requires deployers under public law and private entities providing public services to carry out a fundamental rights impact assessment before deploying a high-risk AI system. This assessment must analyze specific risks to affected persons and groups.
AI Act FRIA: Article 27 Impact Assessment
A FRIA assesses how a high-risk AI system may affect fundamental rights. Article 27 covers public-law bodies, private providers of public services and deployers of certain credit-scoring or life and health insurance systems. The assessment must be completed before deployment. Where a DPIA is also required, the FRIA complements it rather than replacing it.
What your FRIA file should document
Build your FRIA from your diagnostic
aiacto organises information about the use case, affected people, risks and controls into a structured FRIA file. Legal validation and the deployment decision remain your responsibility.
Frequently asked questions about FRIAs
Who must conduct a FRIA?
Article 27 covers public-law bodies, private entities providing public services and deployers of certain high-risk systems listed in points 5(b) and 5(c) of Annex III. Systems in point 2 of Annex III are excluded from this specific duty.
Does a GDPR DPIA replace a FRIA?
No. A DPIA examines personal-data processing risks; a FRIA addresses the broader fundamental-rights impact of the AI system. Evidence may be coordinated, but each requirement must remain identifiable.
When should a FRIA be updated?
It is completed before deployment and reviewed when the system, use context, affected populations or relevant risks change.
Key points
Related definitions
Check your compliance with Article 27
Our free diagnostic identifies the obligations applicable to your AI system and guides you to the necessary documentation.