Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Chapter III Section 3 · Article 27

FRIA template — Article 27

The fundamental rights impact assessment is a deployer obligation with prescribed contents, performed before first use, and notified to a market surveillance authority. This page sets out the structure and what goes in each section.

Art. 27Art. 27(4) complements DPIAapplies 2 Dec 2027

Do you owe one?

If you are…Then…
A body governed by public law, deploying an Annex III high-risk systemYes
A private entity providing public services, deploying oneYes
Deploying an Annex III point 5(b) creditworthiness or credit scoring systemYes: regardless of sector
Deploying an Annex III point 5(c) life or health insurance risk and pricing systemYes: regardless of sector
The provider of a high-risk systemNo, this is a deployer obligation
A commercial deployer outside 5(b) and 5(c) and not providing public servicesNo

Timing and reuse

Performed prior to the first use. Where the system is used across similar deployments, the assessment may build on a previously conducted one. It must be updated where any of its elements change. The results are notified to the market surveillance authority: a different regulator from your data protection authority.

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

The six sections

Article 27(1) prescribes the contents. Structure your document to them so an assessor can map it without translation.

 What Article 27 requiresWhat to actually write
1A description of the deployer’s processes in which the system will be used, in line with its intended purposeThe workflow, end to end. Where the output enters, who sees it, what happens next. Not a description of the system: a description of your process.
2The period of time and frequency for which the system is intended to be usedContinuous or campaign-based, volume per period, and any planned review point. Frequently left vague; it should not be.
3The categories of natural persons and groups likely to be affected in the specific contextThe section that distinguishes a FRIA from a DPIA. Name the groups, including those affected differentially, not just “data subjects”.
4The specific risks of harm likely to have an impact on those categories, taking account of the information the provider gave under Article 13Per group, not in aggregate. Pull the declared accuracy, known limitations and foreseeable risk circumstances from the instructions for use.
5A description of the implementation of human oversight measures, according to the instructions for useWho oversees, with what competence, training and authority to override. Article 26(2) language. Not a job title.
6The measures to be taken if the risks materialise, including internal governance arrangements and complaint mechanismsEscalation path, suspension trigger and authority, how an affected person complains, and who answers.

Section 3 is where the work is

Sections 1, 2 and 5 are descriptive and most organisations can write them from existing material. Section 3, categories of persons and groups likely to be affected, is the one that requires analysis nobody has usually done.

Practical recommendation. Build it from three angles: who is subject to the decision; who is affected indirectly (dependants, households, communities); and which groups may experience the system differently because of a characteristic. That last angle is what Section 4 then has to address per group, and it is the reason a DPIA framed around uniform processing does not substitute.

A DPIA does not discharge this

Article 27(4) provides that where FRIA obligations are already met through a DPIA under GDPR Article 35, the FRIA complements that DPIA. Duplication avoidance, not substitution. Run one assessment producing two outputs for two authorities. Full comparison →

Before you draft your own structure

The AI Office is to develop a template questionnaire, including through an automated tool, to facilitate compliance in a simplified manner. Check whether it has been published, adopting an official structure is cheaper than defending a bespoke one.

Status labels on this page

Verified fact: Who owes a FRIA, the six prescribed elements, the timing and update duties, the notification to the market surveillance authority, and the Art. 27(4) complementarity provision.

Expert analysis: The three-angle approach to Section 3 and the observation about which sections carry the real work.

Unsettled: The content and publication status of the AI Office template questionnaire.

Next step

The FRIA is one artefact in a set

It sits alongside the AI system inventory, the classification assessment and the oversight records. Deployers who have those already find the FRIA a short exercise; deployers who do not find it a discovery project.

Not sure where you sit?

The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.

Run the classifier →

Frequently asked

What is a FRIA under the EU AI Act?

A fundamental rights impact assessment under Article 27. Certain deployers of high-risk AI systems must perform it before first use and notify the market surveillance authority of the results. It covers the deployer's processes in which the system will be used, the period and frequency of intended use, the categories of natural persons and groups likely to be affected, the specific risks of harm to those categories, the human oversight measures, and the measures to be taken if the risks materialise including governance arrangements and complaint mechanisms.

Who has to do a FRIA?

Deployers that are bodies governed by public law, deployers that are private entities providing public services, and deployers of high-risk AI systems listed in Annex III point 5(b) on creditworthiness evaluation and credit scoring and point 5(c) on risk assessment and pricing in life and health insurance. It is a deployer obligation, not a provider obligation.

When must the FRIA be done?

Prior to the first use of the high-risk AI system. The obligation sits in Chapter III Section 3 and applies from 2 December 2027 for stand-alone Annex III systems following Regulation (EU) 2026/1744. Where the system is used across similar deployments the assessment may be built on a previously conducted one, and it must be updated where any of its elements change.

Is there an official FRIA template?

The AI Office is to develop a template questionnaire, including through an automated tool, to facilitate deployers in complying with Article 27 in a simplified manner. Check whether it has been published before drafting your own structure.