The Article 27 FRIA Template

The Fundamental Rights Impact Assessment is mandatory before first deployment of high-risk AI systems in covered contexts. This page explains exactly who must complete it, what it must contain, and how to structure a defensible assessment.

Updated April 2026 · Article 27 · Regulation (EU) 2024/1689

Free Resource

Get the free FRIA starter, the Article 27 skeleton you can build on today

A structured FRIA starter mapping every Article 27(1) requirement, the risks to fundamental rights you must assess, and the submission step most teams miss. Delivered as a PDF the moment you submit. No cost.

No spam. The complete ready-to-deploy Word template is available below from $149.

Need the ready-to-use FRIA template, not just the framework?

A Word template with every Article 27(1) section pre-drafted, plus a market-surveillance submission checklist. Included in the bundles below.

Get the FRIA template →
→ Not sure how this affects your AI system?

Take the free 5-minute Risk Classifier, article-grounded scoring against Article 5, 6, Annex III, and Article 50.

Run the classifier →
Timing note (April 2026): The European AI Office has not yet published an official FRIA template (required under Article 27(5)). In the absence of a published template, deployers must draw up their own structured assessment meeting all Article 27(1) requirements. This page walks through what a defensible template must contain.

1. Who Is Required to Complete a FRIA

Article 27(1) imposes the FRIA obligation on deployers of high-risk AI systems referred to in Article 6(2), i.e. systems falling within Annex III, in the following circumstances:

  • (a) Bodies governed by public law, or private entities providing public services
  • (b) Deployers of high-risk AI systems referred to in Annex III point 5(b) and (c), i.e. creditworthiness / credit scoring, and risk assessment / pricing for life and health insurance

In practice, the FRIA net captures a broad population:

Organisation Type In Scope? Typical FRIA Trigger
National government agencies, ministries Yes Any deployment of high-risk AI for public services
Regional / local authorities Yes Welfare eligibility, licensing, permitting
Public hospitals, schools, universities Yes AI in admissions, triage, performance assessment
Publicly-contracted service providers (e.g. NHS contractors, utility concessions) Yes AI-assisted decisions affecting service recipients
Banks, lenders, mortgage providers Yes Any AI-assisted creditworthiness or credit scoring decision (Annex III 5(b))
Life and health insurers Yes Risk assessment or pricing for natural persons (Annex III 5(c))
Employers using AI in recruitment, performance, termination decisions Yes, effectively Annex III point 4 systems; FRIA explicitly recommended by AI Office guidance
Private SaaS vendors providing AI tools to in-scope deployers Indirectly Contractual obligation to support deployer's FRIA via documentation

2. What the FRIA Must Contain (Article 27(1) Checklist)

A compliant FRIA must address each of the following elements. These are not optional sections, each one must be documented with specific, system-level detail.

Mandatory content under Article 27(1):
  1. Description of the deployer's processes, how the high-risk AI system will be used in line with its intended purpose
  2. Period and frequency of use, for how long and how often the AI system will be deployed
  3. Categories of natural persons and groups likely to be affected by its use in the specific context
  4. Specific risks of harm likely to impact the identified categories of natural persons or groups of persons, taking into account the information given by the provider pursuant to Article 13
  5. Description of human oversight measures, per the instructions for use
  6. Measures to be taken in case those risks materialise, including arrangements for internal governance and complaint mechanisms

3. The FRIA Template Structure (Section-by-Section)

A defensible FRIA template must walk the deployer through each Article 27(1) requirement. The following structure is drawn from the template in our full compliance bundle:

Section 1, System Identification

  • AI system name, version, and provider
  • Annex III domain and use case classification
  • Date of assessment, assessor, and sign-off
  • Planned date of first deployment
  • Related documentation (Art. 13 instructions for use, Art. 9 risk management records)

Section 2, Deployment Context (Art. 27(1)(a), (b))

  • Narrative description of the deployer's process and how the AI fits within it
  • Specific decisions or determinations the AI contributes to
  • Period of deployment (pilot / phased / full)
  • Frequency (per transaction / per application / per period)
  • Geographic scope

Section 3, Affected Persons (Art. 27(1)(c))

  • Identified categories of natural persons affected (e.g. applicants, recipients, employees)
  • Groups with heightened vulnerability (minors, persons with disabilities, migrant populations, protected characteristics under Art. 21 Charter)
  • Estimated numbers of affected persons per deployment period
  • Specific known vulnerabilities relevant to the deployment context

Section 4, Risk Analysis (Art. 27(1)(d))

  • Specific risks of harm to each identified category
  • Cross-reference to Art. 13 information from the provider
  • Risk scoring methodology (likelihood × severity)
  • Fundamental rights specifically engaged (Charter of Fundamental Rights of the EU), dignity, non-discrimination, fair trial, private life, etc.
  • Consideration of cumulative and interacting risks across the affected population

Section 5, Human Oversight Measures (Art. 27(1)(e))

  • Description of human oversight measures implemented per provider's Art. 13 instructions
  • Identity and competence of designated oversight personnel
  • Authority of oversight personnel to override, halt, or reverse AI outputs
  • Escalation path for contested outputs
  • Training provided to oversight personnel; refresh cadence

Section 6, Risk Treatment and Governance (Art. 27(1)(f))

  • Mitigating measures and controls for each identified risk
  • Internal governance arrangements, who owns the system, who approves deployment changes
  • Complaint mechanism available to affected persons, intake channels, response SLAs, right of explanation under Art. 86
  • Incident response and reporting arrangements (Art. 73)
  • Review cadence for the FRIA itself, at what events or intervals it will be updated

Section 7, Notification to Authority (Art. 27(3))

  • Designated national market surveillance authority
  • Transmission method and date
  • Retention reference and internal document management location

4. When the FRIA Must Be Submitted

Article 27(3) requires that the FRIA be notified to the national market surveillance authority before first deployment. The Act does not specify an advance notice period; practical guidance from early Member State implementations suggests at least 30 calendar days to allow authorities to raise questions.

Do not conflate the FRIA with the DPIA. They are distinct legal instruments with separate submission paths. The FRIA goes to the market surveillance authority designated under the AI Act; the DPIA (where required under GDPR Art. 35) goes to the supervisory authority for data protection. Some Member States may designate the same authority for both, verify locally.

5. FRIA vs DPIA, Running Them in Parallel

High-risk AI systems that process personal data will almost always trigger both a FRIA (Art. 27 EU AI Act) and a DPIA (Art. 35 GDPR). The two assessments share many inputs but differ substantively:

Dimension FRIA (Art. 27 EU AI Act) DPIA (Art. 35 GDPR)
Trigger High-risk AI system deployed in specified contexts Processing likely to result in high risk to rights/freedoms
Scope Fundamental rights impacts (full Charter) Personal data protection impacts
Timing Before first deployment Before processing starts
Authority National AI market surveillance authority National data protection supervisory authority
Consultation Not mandatory to consult authority unless high residual risk Art. 36 GDPR prior consultation if high residual risk
Content overlap Deployment description, affected persons, risks, mitigations, ~60-70% of inputs can be shared.

Practical approach: build one shared evidence base, produce two formatted deliverables. Track which sections map to which regulation in an evidence register.

6. Getting the FRIA Template You Can Actually Use

The structural walkthrough above is the legal framework. The practical deliverable, a Word template with every Article 27(1) section pre-drafted, space to record your system-specific inputs, and a submission checklist for the market surveillance authority, is included in our compliance bundles:

Includes FRIA Starter
EU AI Act Compliance Checklist Pack
$ 149 one-time

5 essential compliance documents. Includes the Article 27 FRIA Starter alongside the 58-point checklist, Annex III classification matrix, AI system inventory template, and board briefing.

Purchase Checklist Pack, $149 →

7. Frequently Asked Questions

Article 27 addresses deployers. However, providers have parallel obligations under Article 9 (risk management) and Article 13 (instructions for use) to supply the information that deployers need for their FRIA. Providers should not assume they are untouched by the FRIA obligation, their documentation substantially enables or undermines the deployer's ability to comply.

Article 27(2) requires updates when any of the FRIA elements change or when the deployer considers the elements are no longer up to date. In practice, schedule formal FRIA reviews at minimum annually, and on material triggers: system version changes, new affected-person categories, new use contexts, or post-incident.

The Act does not require FRIA publication. FRIAs are submitted to the market surveillance authority and retained by the deployer. However, Article 86 grants affected persons a right to explanation of individual decision-making that may require the deployer to share relevant FRIA sections on request. Some Member States may impose transparency requirements on public-sector FRIAs beyond the Act's baseline.

Article 99(4) brings Article 27 non-compliance within the €15M / 3% global turnover penalty tier. The practical consequence often precedes the fine: a market surveillance authority enquiry triggered by a complaint will request the FRIA, and its absence is a standalone finding of non-compliance.

FRIA Template, Ready to Deploy

The Complete Article 27 FRIA Template Pack

Don't start from scratch. Our FRIA Starter template walks through every Article 27(1) requirement with drafted prompts, example language, and a submission checklist for the market surveillance authority. Microsoft Word format, customise with your deployment details.

Get FRIA Template, $149 → View All Products