The Article 27 FRIA Template
The Fundamental Rights Impact Assessment is mandatory before first deployment of high-risk AI systems in covered contexts. This page explains exactly who must complete it, what it must contain, and how to structure a defensible assessment.
Updated April 2026 · Article 27 · Regulation (EU) 2024/1689
Get the free FRIA starter, the Article 27 skeleton you can build on today
A structured FRIA starter mapping every Article 27(1) requirement, the risks to fundamental rights you must assess, and the submission step most teams miss. Delivered as a PDF the moment you submit. No cost.
A Word template with every Article 27(1) section pre-drafted, plus a market-surveillance submission checklist. Included in the bundles below.
Take the free 5-minute Risk Classifier, article-grounded scoring against Article 5, 6, Annex III, and Article 50.
1. Who Is Required to Complete a FRIA
Article 27(1) imposes the FRIA obligation on deployers of high-risk AI systems referred to in Article 6(2), i.e. systems falling within Annex III, in the following circumstances:
- (a) Bodies governed by public law, or private entities providing public services
- (b) Deployers of high-risk AI systems referred to in Annex III point 5(b) and (c), i.e. creditworthiness / credit scoring, and risk assessment / pricing for life and health insurance
In practice, the FRIA net captures a broad population:
| Organisation Type | In Scope? | Typical FRIA Trigger |
|---|---|---|
| National government agencies, ministries | Yes | Any deployment of high-risk AI for public services |
| Regional / local authorities | Yes | Welfare eligibility, licensing, permitting |
| Public hospitals, schools, universities | Yes | AI in admissions, triage, performance assessment |
| Publicly-contracted service providers (e.g. NHS contractors, utility concessions) | Yes | AI-assisted decisions affecting service recipients |
| Banks, lenders, mortgage providers | Yes | Any AI-assisted creditworthiness or credit scoring decision (Annex III 5(b)) |
| Life and health insurers | Yes | Risk assessment or pricing for natural persons (Annex III 5(c)) |
| Employers using AI in recruitment, performance, termination decisions | Yes, effectively | Annex III point 4 systems; FRIA explicitly recommended by AI Office guidance |
| Private SaaS vendors providing AI tools to in-scope deployers | Indirectly | Contractual obligation to support deployer's FRIA via documentation |
2. What the FRIA Must Contain (Article 27(1) Checklist)
A compliant FRIA must address each of the following elements. These are not optional sections, each one must be documented with specific, system-level detail.
- Description of the deployer's processes, how the high-risk AI system will be used in line with its intended purpose
- Period and frequency of use, for how long and how often the AI system will be deployed
- Categories of natural persons and groups likely to be affected by its use in the specific context
- Specific risks of harm likely to impact the identified categories of natural persons or groups of persons, taking into account the information given by the provider pursuant to Article 13
- Description of human oversight measures, per the instructions for use
- Measures to be taken in case those risks materialise, including arrangements for internal governance and complaint mechanisms
3. The FRIA Template Structure (Section-by-Section)
A defensible FRIA template must walk the deployer through each Article 27(1) requirement. The following structure is drawn from the template in our full compliance bundle:
Section 1, System Identification
- AI system name, version, and provider
- Annex III domain and use case classification
- Date of assessment, assessor, and sign-off
- Planned date of first deployment
- Related documentation (Art. 13 instructions for use, Art. 9 risk management records)
Section 2, Deployment Context (Art. 27(1)(a), (b))
- Narrative description of the deployer's process and how the AI fits within it
- Specific decisions or determinations the AI contributes to
- Period of deployment (pilot / phased / full)
- Frequency (per transaction / per application / per period)
- Geographic scope
Section 3, Affected Persons (Art. 27(1)(c))
- Identified categories of natural persons affected (e.g. applicants, recipients, employees)
- Groups with heightened vulnerability (minors, persons with disabilities, migrant populations, protected characteristics under Art. 21 Charter)
- Estimated numbers of affected persons per deployment period
- Specific known vulnerabilities relevant to the deployment context
Section 4, Risk Analysis (Art. 27(1)(d))
- Specific risks of harm to each identified category
- Cross-reference to Art. 13 information from the provider
- Risk scoring methodology (likelihood × severity)
- Fundamental rights specifically engaged (Charter of Fundamental Rights of the EU), dignity, non-discrimination, fair trial, private life, etc.
- Consideration of cumulative and interacting risks across the affected population
Section 5, Human Oversight Measures (Art. 27(1)(e))
- Description of human oversight measures implemented per provider's Art. 13 instructions
- Identity and competence of designated oversight personnel
- Authority of oversight personnel to override, halt, or reverse AI outputs
- Escalation path for contested outputs
- Training provided to oversight personnel; refresh cadence
Section 6, Risk Treatment and Governance (Art. 27(1)(f))
- Mitigating measures and controls for each identified risk
- Internal governance arrangements, who owns the system, who approves deployment changes
- Complaint mechanism available to affected persons, intake channels, response SLAs, right of explanation under Art. 86
- Incident response and reporting arrangements (Art. 73)
- Review cadence for the FRIA itself, at what events or intervals it will be updated
Section 7, Notification to Authority (Art. 27(3))
- Designated national market surveillance authority
- Transmission method and date
- Retention reference and internal document management location
4. When the FRIA Must Be Submitted
Article 27(3) requires that the FRIA be notified to the national market surveillance authority before first deployment. The Act does not specify an advance notice period; practical guidance from early Member State implementations suggests at least 30 calendar days to allow authorities to raise questions.
5. FRIA vs DPIA, Running Them in Parallel
High-risk AI systems that process personal data will almost always trigger both a FRIA (Art. 27 EU AI Act) and a DPIA (Art. 35 GDPR). The two assessments share many inputs but differ substantively:
| Dimension | FRIA (Art. 27 EU AI Act) | DPIA (Art. 35 GDPR) |
|---|---|---|
| Trigger | High-risk AI system deployed in specified contexts | Processing likely to result in high risk to rights/freedoms |
| Scope | Fundamental rights impacts (full Charter) | Personal data protection impacts |
| Timing | Before first deployment | Before processing starts |
| Authority | National AI market surveillance authority | National data protection supervisory authority |
| Consultation | Not mandatory to consult authority unless high residual risk | Art. 36 GDPR prior consultation if high residual risk |
| Content overlap | Deployment description, affected persons, risks, mitigations, ~60-70% of inputs can be shared. | |
Practical approach: build one shared evidence base, produce two formatted deliverables. Track which sections map to which regulation in an evidence register.
6. Getting the FRIA Template You Can Actually Use
The structural walkthrough above is the legal framework. The practical deliverable, a Word template with every Article 27(1) section pre-drafted, space to record your system-specific inputs, and a submission checklist for the market surveillance authority, is included in our compliance bundles:
5 essential compliance documents. Includes the Article 27 FRIA Starter alongside the 58-point checklist, Annex III classification matrix, AI system inventory template, and board briefing.
Purchase Checklist Pack, $149 →All 11 compliance documents. FRIA Starter plus Annex IV technical documentation checklist, ISO 42001 mapping matrix, vendor AI readiness questionnaire, LLM governance policy, GPAI checklist, and post-August monitoring calendar.
Purchase Full Bundle, $499 →7. Frequently Asked Questions
Article 27 addresses deployers. However, providers have parallel obligations under Article 9 (risk management) and Article 13 (instructions for use) to supply the information that deployers need for their FRIA. Providers should not assume they are untouched by the FRIA obligation, their documentation substantially enables or undermines the deployer's ability to comply.
Article 27(2) requires updates when any of the FRIA elements change or when the deployer considers the elements are no longer up to date. In practice, schedule formal FRIA reviews at minimum annually, and on material triggers: system version changes, new affected-person categories, new use contexts, or post-incident.
The Act does not require FRIA publication. FRIAs are submitted to the market surveillance authority and retained by the deployer. However, Article 86 grants affected persons a right to explanation of individual decision-making that may require the deployer to share relevant FRIA sections on request. Some Member States may impose transparency requirements on public-sector FRIAs beyond the Act's baseline.
Article 99(4) brings Article 27 non-compliance within the €15M / 3% global turnover penalty tier. The practical consequence often precedes the fine: a market surveillance authority enquiry triggered by a complaint will request the FRIA, and its absence is a standalone finding of non-compliance.
The Complete Article 27 FRIA Template Pack
Don't start from scratch. Our FRIA Starter template walks through every Article 27(1) requirement with drafted prompts, example language, and a submission checklist for the market surveillance authority. Microsoft Word format, customise with your deployment details.