New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
Documentation

EU AI Act

Fundamental Rights Impact Assessment

The Fundamental Rights Impact Assessment is frequently missed, because unlike most of the AI Act's heavy obligations it sits with the deployer rather than the provider. If it applies to you, it must be done before the system is put into use.

Transcript

The Fundamental Rights Impact Assessment is the Article 27 duty deployers owe before putting certain high-risk systems into use. It is frequently missed, because it sits with the deployer rather than the provider.

Open Governance & Docs and switch to the Assessments tab. Risk classification and the fundamental rights assessment live side by side, because one informs the other.

Switch from Risk Assessment to FRIA. The system list shows every registered system, and any high-risk deployment is where you start.

Open a system's assessment. You are walked through the impact questions one at a time, covering rights affected, safeguards, and who is impacted.

Answer each question. The assessment captures your reasoning, not just a tick box, so the document is defensible later.

Submit the assessment. It is recorded against the system and feeds the documentation set, so the Article 27 duty becomes part of the system's compliance record.

The completed FRIA attaches to the system, alongside its risk classification and technical documentation, ready for regulators and deployers to review together.

Why this is required

Article 27 applies to deployers that are bodies governed by public law, or private entities providing public services, and to any deployer using a high-risk system for credit scoring or creditworthiness evaluation, or for risk assessment and pricing in life and health insurance.

It is not a data protection impact assessment. A DPIA under GDPR Article 35 asks what a processing operation does to personal data. A FRIA asks a broader question: what this system does to people's fundamental rights: dignity, non-discrimination, access to essential services, and the right to an effective remedy. Article 27(4) allows you to build on an existing DPIA rather than duplicate it, but it does not let you substitute one for the other.

The assessment exists because high-risk systems in these contexts make decisions people cannot easily contest or escape. Someone refused credit, insurance or a public service by an automated process needs the organisation deploying it to have thought about the harm in advance.

What EuroCompliant does

The assessment follows Article 27(1) directly, so the completed record maps onto the provision rather than needing translation for a regulator.

It captures the deployer's processes for using the system, the period and frequency of intended use, the categories of natural persons likely to be affected, the specific risks of harm to them, the human oversight measures in place, and the measures to be taken if those risks materialise, including internal governance and complaint mechanisms.

Completed assessments attach to the system and feed its documentation set.

Walking through it

1

Confirm Article 27 applies

Check your organisation type and the system's use case. Public bodies, private providers of public services, credit scoring and life or health insurance pricing are the triggers.

Open /compliance-docs →
2

Complete the assessment before deployment

Article 27 requires it prior to putting the system into use, not as a retrospective record.

3

Notify the market surveillance authority

Article 27(3) requires you to notify the authority of the results of the assessment.

4

Keep it current

Article 27(2) requires you to update the assessment if any of its elements are no longer up to date.

The law

Frequently asked

We already did a DPIA. Is that enough?

No, but it is not wasted. Article 27(4) says that where any of the FRIA obligations are already met through the DPIA, the FRIA complements it. You still need the fundamental-rights analysis the DPIA does not cover.

Do we need a new FRIA for every similar case?

No. Article 27(2) provides that in similar cases the deployer may rely on a previously conducted assessment or an existing one carried out by the provider, updated as necessary.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial