Build a board-ready risk heatmap in minutes — free, no account required

Open tool

Impact Assessment

Fundamental Rights Impact Assessment

What this control does

Perform, approve, update and notify qualifying FRIAs before high-risk AI deployment.

How to implement

For deployers and uses within Article 27, complete a fundamental rights impact assessment (FRIA) before the first relevant use. Describe the process, duration, affected people, potential harms, oversight and response arrangements. Use provider information and assign actions to address identified risks. Notify the relevant authority where required and update changed information. A data protection impact assessment (DPIA) is a separate assessment. Reuse relevant work only where it actually meets the corresponding FRIA requirements, with clear cross-references. Also check any separate FRIA trigger for permitted real-time biometric use under Article 5. Do not infer that every high-risk deployment requires a FRIA.

Suggested timing and triggers

Before the first applicable use; when relevant assessment information changes; at any separate statutory trigger.

Evidence examples

FRIA applicability decision and completed assessment Provider information and affected-group analysis Oversight, complaints and risk-response arrangements Cross-reference to a DPIA where relevant Review, update and required notification records

How to check this control

Sample a qualifying use. Check that the assessment preceded it, considers the actual affected groups and leads to assigned actions. Test whether changed circumstances updated the assessment and whether any required notification is evidenced.

Recognized by G2 as a Leader

Trusted by customers and rated highly across all categories

Fundamental Rights Impact Assessment | EU AI Act Suggested Control | Tracker Networks