Fundamental Rights Impact Assessment (FRIA) — Article 27
How to conduct a Fundamental Rights Impact Assessment under EU AI Act Article 27. Methodology, who must conduct one, and FRIA worksheet template.
A Fundamental Rights Impact Assessment (FRIA) is a structured analysis required by EU AI Act Article 27 for deployers of high-risk AI systems that are bodies governed by public law or private entities providing public services. The FRIA documents how the AI system may affect fundamental rights — including dignity, equality, privacy, and non-discrimination — before the system is put into operation. It must be submitted to the relevant market surveillance authority. Enforcement begins August 2, 2026 with fines up to €15 million or 3% of turnover.
Who Must Conduct a FRIA?
Article 27 mandates a FRIA for deployers of Annex III high-risk AI systems who are:
Bodies governed by public law
Government agencies, municipalities, public universities, public hospitals, and similar entities subject to public law.
Private entities providing public services
Private organisations delivering public services on behalf of the state — social benefit administrators, employment agencies, regulated utilities.
Note: Private companies deploying high-risk AI in employment contexts (e.g. HR screening, worker monitoring) are not automatically covered by Article 27 unless they constitute public-sector bodies or delegated service providers. However, many will still conduct voluntary FRIAs for due-diligence purposes.
7-Step FRIA Methodology
Describe the AI System and Deployment Context
Document the AI system's name, version, intended purpose, and the specific deployment context — including the population affected, decision types, and geographic scope. Reference the provider's Annex IV documentation where available.
Identify Relevant Fundamental Rights
Map the deployment context to the Charter of Fundamental Rights of the EU. Identify which rights are potentially at stake — including human dignity (Art 1), non-discrimination (Art 21), data protection (Art 8), fair trial (Art 47), and rights of the child (Art 24).
Assess the Risk of Fundamental Rights Violations
For each identified right, assess the likelihood and severity of potential violations. Consider direct impacts (decisions by the AI system) and indirect impacts (reliance by human decision-makers). Document the evidence base for each assessment.
Review Data Processing and GDPR Obligations
Assess whether the AI system processes personal data. If so, determine whether a DPIA under GDPR Article 35 is also required. Identify lawful bases for processing and document data minimisation measures. Note FRIA and DPIA overlap to avoid duplicating work.
Design Mitigation Measures
For each material fundamental rights risk, identify concrete mitigation measures: human review requirements, appeal mechanisms, data correction rights, audit logging for affected decisions, transparency notices to affected persons.
Consult Affected Groups and Representatives
Article 27(5) encourages consultation with workers' representatives for employment-context AI. Document consultations conducted, feedback received, and how it influenced the FRIA conclusions.
Document, Register, and Notify
Finalise the FRIA document and register it in the EU AI Act database under Article 49. Notify the competent market surveillance authority as required by Article 27(7). Retain the FRIA for the duration of the system's operation plus 10 years.
FRIA Worksheet Template
Scanara includes a structured FRIA worksheet in the compliance dossier — pre-populated with your system's deployment context from the scan, with guidance notes for each Article 27 element. Export as PDF or DOCX for regulatory submission.
Get the FRIA worksheet →How Scanara Automates FRIA Preparation
Deployer context detection
Scanara identifies deployer-specific obligations in your codebase — flagging missing transparency notices, appeal mechanisms, and human oversight implementations required under Article 26/27.
FRIA template generation
Auto-populate the FRIA worksheet with system details from your Annex IV technical file, leaving only context-specific narrative fields for your team to complete.
DPIA overlap flagging
Scanara flags where a DPIA is also likely required under GDPR Art 35, helping you coordinate both assessments and eliminate duplication across your compliance programme.
Frequently Asked Questions
How Scanara Helps
Scanara automates EU AI Act compliance from code to dossier. Connect your GitHub repos and get compliance reports in minutes.