Fundamental Rights Impact Assessment (FRIA): Who Needs One and How to Do It

Quick answer: A Fundamental Rights Impact Assessment (FRIA) is required by Article 27 of the EU AI Act before deploying certain high-risk AI systems. It applies to deployers that are public bodies or private entities providing public services, plus deployers of high-risk systems used for credit scoring and life/health insurance pricing (Annex III, points 5(b) and 5(c)). The FRIA documents how the system will be used, who it affects, what fundamental-rights harms could occur, and what human oversight and remedies are in place. With the post-Omnibus timeline, Annex III high-risk obligations — FRIA included — apply by 2 December 2027. If you already do GDPR DPIAs, a FRIA extends that muscle rather than building a new one.

"Fundamental rights impact assessment" sounds like something only a ministry needs. For most SMBs that's true — but the credit and insurance hooks pull in fintechs, lenders, brokers, and insurtechs, and anyone delivering outsourced public services.

Who Actually Needs a FRIA

Article 27 catches three groups of deployers of high-risk AI systems:

  1. Bodies governed by public law — government agencies, municipalities, public universities and hospitals.
  2. Private operators providing public services — private firms running education, healthcare, social services, housing eligibility, or benefits-adjacent functions.
  3. Deployers of two specific Annex III systems regardless of sector: AI for creditworthiness assessment / credit scoring of natural persons (except fraud detection), and AI for risk assessment and pricing in life and health insurance.

Quick self-test for SMBs

  • A fintech using an AI credit-scoring model on consumer loan applicants → FRIA required.
  • An insurtech pricing health policies with ML → FRIA required.
  • A private company running AI-assisted eligibility checks for a government benefits program → FRIA required.
  • A 40-person agency using an AI résumé screener → high-risk deployer with other obligations, but no FRIA (employment isn't on the Article 27 list, and you're not a public-service provider).
  • A retailer using AI product recommendations → not high-risk at all. (Unsure of your tiers? Start with the four risk categories.)

What the FRIA Must Contain

Required element What you actually write
Deployment description The processes the system will be used in, its intended purpose, how it fits your workflow
Period and frequency of use Continuous? Per application? Seasonal campaigns?
Categories of affected persons Loan applicants, policyholders, benefit recipients — including vulnerable groups
Specific risks of harm Which fundamental rights could be impacted and how
Human oversight measures Who reviews outputs, with what authority and training, per the provider's instructions for use
Measures if risks materialize Internal escalation, correction and redress paths, complaint handling

The Rights Analysis: Where People Get Stuck

For the systems Article 27 targets, the recurring rights are:

  • Non-discrimination — does the model produce systematically worse outcomes for protected groups?
  • Private and family life / data protection — what personal data feeds the system; is it necessary and proportionate?
  • Access to essential services / social protection — what happens to someone wrongly denied credit or priced out of insurance?
  • Effective remedy — can an affected person understand, contest, and correct a decision?
  • Human dignity — is anyone reduced to a fully automated decision with no meaningful human involvement?

For each, write three sentences: the plausible harm, who bears it, and the mitigation. Resist the urge to write "no risk identified" across the board — an assessment finding zero risks in a credit-scoring deployment reads as an assessment nobody performed.

Don't start from a blank page: the EU AI Act SME Compliance Kit ($149) includes a structured FRIA template with the Article 27 elements, prompts for the rights analysis, and the notification step — plus the classification guide that tells you whether you need one at all.

FRIA vs DPIA: Reuse What You Have

If the deployment involves personal data (it almost certainly does), you likely owe a GDPR DPIA too. The AI Act anticipates this: the FRIA complements the DPIA, and overlapping content can be reused.

  • DPIA covers: lawful basis, data minimization, security, data-subject rights.
  • FRIA adds: the wider rights lens (discrimination, access to services, remedy), affected-person categories, oversight design, and the harm-materialization plan.

Run them as one exercise with two outputs. Your DPO or privacy lead should be in the room; so should whoever owns the risk register, because FRIA findings are register rows with a legal citation attached.

A Practical 5-Step Method

  1. Confirm scope — high-risk classification first, then the Article 27 deployer test. Document the conclusion even if it's "not required".
  2. Gather inputs — the provider's instructions for use and technical documentation, your process maps, your existing DPIA.
  3. Run a structured workshop (half a day for a single system): walk the six required elements with the system owner, a frontline user, and privacy/legal.
  4. Write it up against the Article 27 elements; have the human-oversight owner sign their section.
  5. Notify, file, and diarize — submit the notification, store the FRIA with your governance records, and set review triggers: model changes, new affected groups, incident reports.

Cost reality: an SMB's first FRIA, template-assisted, is roughly 2–4 person-days. The consultant alternative is typically a five-figure engagement for the same document.

FAQ

Who is required to do a FRIA under the EU AI Act?

Deployers of high-risk AI systems that are public bodies or private entities providing public services, plus any deployer using high-risk AI for credit scoring or life/health insurance risk pricing (Annex III 5(b) and 5(c)).

When does the FRIA obligation apply?

It travels with the Annex III high-risk obligations, deferred to 2 December 2027 by the 2026 Omnibus agreement. The assessment is due before first deployment of an in-scope system and must be kept up to date.

Is a FRIA the same as a DPIA?

No, but they overlap. The DPIA (GDPR) focuses on personal-data risks; the FRIA covers the broader fundamental-rights picture. Article 27 explicitly allows building the FRIA on top of an existing DPIA.

What happens if we skip a required FRIA?

Non-compliance with deployer obligations falls in the standard penalty band — up to €15m or 3% of global turnover — and a missing FRIA badly weakens your position in any complaint or incident involving the system.


In scope, or not sure? The EU AI Act SME Compliance Kit ($149) bundles the FRIA template with the risk classification guide and per-role obligation checklists — or get the complete document stack in the Complete AI Compliance Stack ($199).

This article is for general information only and is not legal advice. Consult qualified counsel for your specific situation.