Impact Assessment
Fundamental Rights Impact Assessment
What this control does
Perform, approve, update and notify qualifying FRIAs before high-risk AI deployment.
How to implement
For deployers and uses within Article 27, complete a fundamental rights impact assessment (FRIA) before the first relevant use. Describe the process, duration, affected people, potential harms, oversight and response arrangements. Use provider information and assign actions to address identified risks. Notify the relevant authority where required and update changed information. A data protection impact assessment (DPIA) is a separate assessment. Reuse relevant work only where it actually meets the corresponding FRIA requirements, with clear cross-references. Also check any separate FRIA trigger for permitted real-time biometric use under Article 5. Do not infer that every high-risk deployment requires a FRIA.
Suggested timing and triggers
Before the first applicable use; when relevant assessment information changes; at any separate statutory trigger.
Evidence examples
FRIA applicability decision and completed assessment Provider information and affected-group analysis Oversight, complaints and risk-response arrangements Cross-reference to a DPIA where relevant Review, update and required notification records
How to check this control
Sample a qualifying use. Check that the assessment preceded it, considers the actual affected groups and leads to assigned actions. Test whether changed circumstances updated the assessment and whether any required notification is evidenced.
Related EU AI Act obligations
Article 5(2)
Complete a Fundamental Rights Impact Assessment and Register the System Before Permitted Use
Sub-obligation of Article 5(1)(h), 5(2)-(7): Do Not Use Real-Time Remote Biometric Identification in Public Spaces for Law Enforcement Except Where Specifically Permitted
Article 27
Conduct a Fundamental Rights Impact Assessment Before Applicable High-Risk AI Deployment
Article 27(1)(a)-(c)
Document the Intended Process, Use Period and Frequency, and Affected Persons in the FRIA
Sub-obligation of Article 27: Conduct a Fundamental Rights Impact Assessment Before Applicable High-Risk AI Deployment
Article 27(1)(d)-(e)
Assess Fundamental Rights Risks and Document Human Oversight in the FRIA
Sub-obligation of Article 27: Conduct a Fundamental Rights Impact Assessment Before Applicable High-Risk AI Deployment
Article 27(1)(f)
Define FRIA Mitigation, Internal Governance and Complaint Arrangements
Sub-obligation of Article 27: Conduct a Fundamental Rights Impact Assessment Before Applicable High-Risk AI Deployment
Article 27(2)
Update the Fundamental Rights Impact Assessment When Relevant Circumstances Change
Sub-obligation of Article 27: Conduct a Fundamental Rights Impact Assessment Before Applicable High-Risk AI Deployment
Article 27(3)
Notify the Market-Surveillance Authority of the FRIA Results
Sub-obligation of Article 27: Conduct a Fundamental Rights Impact Assessment Before Applicable High-Risk AI Deployment