Fundamental Rights Impact Assessment (EU AI Act Article 27)
Before deploying certain high-risk AI systems, deployers must assess the impact on fundamental rights, notify results to the market surveillance authority, and update the assessment when relevant elements change.
Why this obligation matters
Article 27 is a distinct obligation from the general risk management system in Article 9 and from a GDPR DPIA. It applies to public-sector deployers, private entities providing public services, and deployers of Annex III point 5(b) (credit-scoring) and 5(c) (life/health insurance risk assessment) high-risk systems.
What vendors typically provide
FRIA tooling typically provides templates aligned to Article 27(1)(a)-(f), risk-register workflows, human-oversight documentation, mitigation-plan tracking, and export to the notification template that the AI Office will publish under Article 27(5).
Compliance checklist
- Complete the FRIA before first use of the high-risk AI system
- Describe deployer processes where the system will be used, its purpose, and conditions of use
- Document the intended period and frequency of use
- Identify the categories of natural persons or groups likely to be affected
- Identify specific risks of harm to those categories, using information provided by the provider under Article 13
- Document human oversight measures per the instructions for use
- Specify mitigation measures including internal governance and complaint mechanisms
- Notify results to the market surveillance authority via the Article 27(5) template
- Update the assessment when relevant elements change or become out of date
Common gaps we see
A GDPR Data Protection Impact Assessment can complement but does not replace an Article 27 FRIA. Article 27(4) allows cross-referencing where relevant elements are already covered by the DPIA, but the remaining elements still require assessment.
Regulator guidance and primary sources
Vendors that support this obligation
No vendors currently tagged for this obligation.