FRIA template — Article 27
The fundamental rights impact assessment is a deployer obligation with prescribed contents, performed before first use, and notified to a market surveillance authority. This page sets out the structure and what goes in each section.
Do you owe one?
| If you are… | Then… |
|---|---|
| A body governed by public law, deploying an Annex III high-risk system | Yes |
| A private entity providing public services, deploying one | Yes |
| Deploying an Annex III point 5(b) creditworthiness or credit scoring system | Yes: regardless of sector |
| Deploying an Annex III point 5(c) life or health insurance risk and pricing system | Yes: regardless of sector |
| The provider of a high-risk system | No, this is a deployer obligation |
| A commercial deployer outside 5(b) and 5(c) and not providing public services | No |
Timing and reuse
Performed prior to the first use. Where the system is used across similar deployments, the assessment may build on a previously conducted one. It must be updated where any of its elements change. The results are notified to the market surveillance authority: a different regulator from your data protection authority.
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
The six sections
Article 27(1) prescribes the contents. Structure your document to them so an assessor can map it without translation.
| What Article 27 requires | What to actually write | |
|---|---|---|
| 1 | A description of the deployer’s processes in which the system will be used, in line with its intended purpose | The workflow, end to end. Where the output enters, who sees it, what happens next. Not a description of the system: a description of your process. |
| 2 | The period of time and frequency for which the system is intended to be used | Continuous or campaign-based, volume per period, and any planned review point. Frequently left vague; it should not be. |
| 3 | The categories of natural persons and groups likely to be affected in the specific context | The section that distinguishes a FRIA from a DPIA. Name the groups, including those affected differentially, not just “data subjects”. |
| 4 | The specific risks of harm likely to have an impact on those categories, taking account of the information the provider gave under Article 13 | Per group, not in aggregate. Pull the declared accuracy, known limitations and foreseeable risk circumstances from the instructions for use. |
| 5 | A description of the implementation of human oversight measures, according to the instructions for use | Who oversees, with what competence, training and authority to override. Article 26(2) language. Not a job title. |
| 6 | The measures to be taken if the risks materialise, including internal governance arrangements and complaint mechanisms | Escalation path, suspension trigger and authority, how an affected person complains, and who answers. |
Section 3 is where the work is
Sections 1, 2 and 5 are descriptive and most organisations can write them from existing material. Section 3, categories of persons and groups likely to be affected, is the one that requires analysis nobody has usually done.
Practical recommendation. Build it from three angles: who is subject to the decision; who is affected indirectly (dependants, households, communities); and which groups may experience the system differently because of a characteristic. That last angle is what Section 4 then has to address per group, and it is the reason a DPIA framed around uniform processing does not substitute.
A DPIA does not discharge this
Article 27(4) provides that where FRIA obligations are already met through a DPIA under GDPR Article 35, the FRIA complements that DPIA. Duplication avoidance, not substitution. Run one assessment producing two outputs for two authorities. Full comparison →
Before you draft your own structure
The AI Office is to develop a template questionnaire, including through an automated tool, to facilitate compliance in a simplified manner. Check whether it has been published, adopting an official structure is cheaper than defending a bespoke one.
Status labels on this page
Verified fact: Who owes a FRIA, the six prescribed elements, the timing and update duties, the notification to the market surveillance authority, and the Art. 27(4) complementarity provision.
Expert analysis: The three-angle approach to Section 3 and the observation about which sections carry the real work.
Unsettled: The content and publication status of the AI Office template questionnaire.
The FRIA is one artefact in a set
It sits alongside the AI system inventory, the classification assessment and the oversight records. Deployers who have those already find the FRIA a short exercise; deployers who do not find it a discovery project.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Frequently asked
What is a FRIA under the EU AI Act?
A fundamental rights impact assessment under Article 27. Certain deployers of high-risk AI systems must perform it before first use and notify the market surveillance authority of the results. It covers the deployer's processes in which the system will be used, the period and frequency of intended use, the categories of natural persons and groups likely to be affected, the specific risks of harm to those categories, the human oversight measures, and the measures to be taken if the risks materialise including governance arrangements and complaint mechanisms.
Who has to do a FRIA?
Deployers that are bodies governed by public law, deployers that are private entities providing public services, and deployers of high-risk AI systems listed in Annex III point 5(b) on creditworthiness evaluation and credit scoring and point 5(c) on risk assessment and pricing in life and health insurance. It is a deployer obligation, not a provider obligation.
When must the FRIA be done?
Prior to the first use of the high-risk AI system. The obligation sits in Chapter III Section 3 and applies from 2 December 2027 for stand-alone Annex III systems following Regulation (EU) 2026/1744. Where the system is used across similar deployments the assessment may be built on a previously conducted one, and it must be updated where any of its elements change.
Is there an official FRIA template?
The AI Office is to develop a template questionnaire, including through an automated tool, to facilitate deployers in complying with Article 27 in a simplified manner. Check whether it has been published before drafting your own structure.
Obligations, article by article
- Art. 5 prohibitions
- Art. 4 AI literacy
- Art. 50 transparency
- Art. 9 risk management
- Art. 10 data governance
- Art. 11 / Annex IV
- Arts. 12–13 logging
- Art. 14 human oversight
- Art. 15 accuracy & security
- Art. 17 QMS
- Arts. 43–48 conformity
- Art. 49 registration
- Art. 57 sandboxes
- Open source
- Art. 72 monitoring
- Art. 73 incidents
- Arts. 51–56 GPAI
- Art. 99 penalties
- Compliance checklist
- When Annex III does not apply →