Services
Fundamental Rights Impact Assessment
Structured Article 27 FRIAs for deployers of in-scope high-risk systems — identify, analyse, and mitigate effects on fundamental rights, with signed outcomes that sit alongside DPIA and QMS evidence.
The service
Article 27 of the EU AI Act requires certain deployers of high-risk AI systems — notably public bodies and private operators of essential services in defined cases — to carry out a fundamental rights impact assessment before putting the system into use. This is not a duty on every high-risk provider, and it is not the same exercise as an ISO/IEC 42005 system impact assessment.
We run the FRIA with you on the privacy-assurance and QMS tools already on this server: structured evaluation, documented outcomes and mitigations, sign-off, and a file that sits next to the DPIA and the QMS/AIMS record for that system.
What the assessment produces
- Description of the process, intended purpose, and period of use
- Categories of persons likely to be affected and the rights at stake
- Identification and analysis of reasonably foreseeable adverse effects on fundamental rights
- Human-oversight measures and risk-mitigation already in place or required
- Signed residual-impact decision, action plan, and evidence pack linked to the system inventory
How it relates to other assessments
- ISO/IEC 42005 — broader impact on individuals, groups, and societies; we reuse context and residual analysis where it is valid. Facilitated 42005 work is a separate service.
- DPIA — personal-data risks under the GDPR. The data-protection platform runs DPIA, FRIA, and ISO/IEC TR 27563 packs in one assurance programme.
- QMS / AIMS — FRIA outcomes feed risk treatment, human oversight, and post-market monitoring on the EN 18286 and ISO/IEC 42001 systems.
Who it is for
- Deployers in scope of Article 27 (public authorities and designated private operators)
- Providers supporting a deployer customer that must complete a FRIA
- DPO, legal, and AI governance teams that need the FRIA, DPIA, and QMS file to tell one story
Operational modules live on the Data Protection Platform (privacy assurance packs) and in the QMS design for fundamental-rights assessments.