Quick answer: A Fundamental Rights Impact Assessment (FRIA) is required by Article 27 of the EU AI Act before deploying certain high-risk AI systems. It applies to deployers that are public bodies or private entities providing public services, plus deployers of high-risk systems used for credit scoring and life/health insurance pricing (Annex III, points 5(b) and 5(c)). The FRIA documents how the system will be used, who it affects, what fundamental-rights harms could occur, and what human oversight and remedies are in place. With the post-Omnibus timeline, Annex III high-risk obligations — FRIA included — apply by 2 December 2027. If you already do GDPR DPIAs, a FRIA extends that muscle rather than building a new one.
"Fundamental rights impact assessment" sounds like something only a ministry needs. For most SMBs that's true — but the credit and insurance hooks pull in fintechs, lenders, brokers, and insurtechs, and anyone delivering outsourced public services.
Who Actually Needs a FRIA
Article 27 catches three groups of deployers of high-risk AI systems:
- Bodies governed by public law — government agencies, municipalities, public universities and hospitals.
- Private operators providing public services — private firms running education, healthcare, social services, housing eligibility, or benefits-adjacent functions.
- Deployers of two specific Annex III systems regardless of sector: AI for creditworthiness assessment / credit scoring of natural persons (except fraud detection), and AI for risk assessment and pricing in life and health insurance.
Quick self-test for SMBs
- A fintech using an AI credit-scoring model on consumer loan applicants → FRIA required.
- An insurtech pricing health policies with ML → FRIA required.
- A private company running AI-assisted eligibility checks for a government benefits program → FRIA required.
- A 40-person agency using an AI résumé screener → high-risk deployer with other obligations, but no FRIA (employment isn't on the Article 27 list, and you're not a public-service provider).
- A retailer using AI product recommendations → not high-risk at all. (Unsure of your tiers? Start with the four risk categories.)
What the FRIA Must Contain
| Required element | What you actually write |
|---|---|
| Deployment description | The processes the system will be used in, its intended purpose, how it fits your workflow |
| Period and frequency of use | Continuous? Per application? Seasonal campaigns? |
| Categories of affected persons | Loan applicants, policyholders, benefit recipients — including vulnerable groups |
| Specific risks of harm | Which fundamental rights could be impacted and how |
| Human oversight measures | Who reviews outputs, with what authority and training, per the provider's instructions for use |
| Measures if risks materialize | Internal escalation, correction and redress paths, complaint handling |
The Rights Analysis: Where People Get Stuck
For the systems Article 27 targets, the recurring rights are:
- Non-discrimination — does the model produce systematically worse outcomes for protected groups?
- Private and family life / data protection — what personal data feeds the system; is it necessary and proportionate?
- Access to essential services / social protection — what happens to someone wrongly denied credit or priced out of insurance?
- Effective remedy — can an affected person understand, contest, and correct a decision?
- Human dignity — is anyone reduced to a fully automated decision with no meaningful human involvement?
For each, write three sentences: the plausible harm, who bears it, and the mitigation. Resist the urge to write "no risk identified" across the board — an assessment finding zero risks in a credit-scoring deployment reads as an assessment nobody performed.
Don't start from a blank page: the EU AI Act SME Compliance Kit ($149) includes a structured FRIA template with the Article 27 elements, prompts for the rights analysis, and the notification step — plus the classification guide that tells you whether you need one at all.
FRIA vs DPIA: Reuse What You Have
If the deployment involves personal data (it almost certainly does), you likely owe a GDPR DPIA too. The AI Act anticipates this: the FRIA complements the DPIA, and overlapping content can be reused.
- DPIA covers: lawful basis, data minimization, security, data-subject rights.
- FRIA adds: the wider rights lens (discrimination, access to services, remedy), affected-person categories, oversight design, and the harm-materialization plan.
Run them as one exercise with two outputs. Your DPO or privacy lead should be in the room; so should whoever owns the risk register, because FRIA findings are register rows with a legal citation attached.
A Practical 5-Step Method
- Confirm scope — high-risk classification first, then the Article 27 deployer test. Document the conclusion even if it's "not required".
- Gather inputs — the provider's instructions for use and technical documentation, your process maps, your existing DPIA.
- Run a structured workshop (half a day for a single system): walk the six required elements with the system owner, a frontline user, and privacy/legal.
- Write it up against the Article 27 elements; have the human-oversight owner sign their section.
- Notify, file, and diarize — submit the notification, store the FRIA with your governance records, and set review triggers: model changes, new affected groups, incident reports.
Cost reality: an SMB's first FRIA, template-assisted, is roughly 2–4 person-days. The consultant alternative is typically a five-figure engagement for the same document.
FAQ
Who is required to do a FRIA under the EU AI Act?
Deployers of high-risk AI systems that are public bodies or private entities providing public services, plus any deployer using high-risk AI for credit scoring or life/health insurance risk pricing (Annex III 5(b) and 5(c)).
When does the FRIA obligation apply?
It travels with the Annex III high-risk obligations, deferred to 2 December 2027 by the 2026 Omnibus agreement. The assessment is due before first deployment of an in-scope system and must be kept up to date.
Is a FRIA the same as a DPIA?
No, but they overlap. The DPIA (GDPR) focuses on personal-data risks; the FRIA covers the broader fundamental-rights picture. Article 27 explicitly allows building the FRIA on top of an existing DPIA.
What happens if we skip a required FRIA?
Non-compliance with deployer obligations falls in the standard penalty band — up to €15m or 3% of global turnover — and a missing FRIA badly weakens your position in any complaint or incident involving the system.
In scope, or not sure? The EU AI Act SME Compliance Kit ($149) bundles the FRIA template with the risk classification guide and per-role obligation checklists — or get the complete document stack in the Complete AI Compliance Stack ($199).
This article is for general information only and is not legal advice. Consult qualified counsel for your specific situation.