The Fundamental Rights Impact Assessment
Your system is going into a process that can change someone's life. Can you show what that use may do to them - before it does it?
Organisations that deploy AI in processes affecting people are increasingly expected to show the impact on individuals and groups. Not whether the model scores well. Whether this use, in this process, can harm people who never agreed to be a test case.
In the EU, Article 27 of the AI Act gives that expectation a name and a deadline: a fundamental rights impact assessment (FRIA) before certain high-risk systems are put into use. If you place systems on the Union market, or you deploy them in Union processes, that duty can follow you even if your head office is somewhere else.
The assessment is not a review of the technology in the abstract. It is a review of your use. The rights in view are those protected in applicable law - in the Union, including the Charter of Fundamental Rights. Dignity. Non-discrimination. Privacy and data protection. Education. Work. Social security. A fair hearing. An effective remedy. Other jurisdictions protect the same ground under constitutions, human-rights instruments and data-protection law. The EU FRIA is the most detailed statutory template currently in force. It is also the one you cannot bluff with a vendor brochure.
Who must carry out a FRIA
Not every organisation that uses AI. Not every high-risk system.
Under Article 27 the duty falls on deployers of high-risk systems referred to in Article 6(2) - Annex III systems - where the deployer is:
- a body governed by public law, or
- a private entity providing public services, or
- a deployer of systems in Annex III points 5(b) and 5(c): creditworthiness assessment or credit scoring; risk assessment and pricing for natural persons in life and health insurance.
Critical infrastructure systems under Annex III point 2 are excluded from this Article 27 duty. Everything else in scope is not.
The FRIA is a deployer duty. You use the system under your authority. You own the assessment. The provider must give you the information you need - especially the instructions for use. That information supports the work. It does not move the duty onto the vendor. Buying the system does not buy you an exemption.
When it must be done
Before first use.
Not after the pilot becomes the process. Not after the first complaint. Before the system is relied on.
In similar cases you may rely on a FRIA already done, or on impact work the provider has already produced. Similar is not identical. If the process, the people, the risks, the oversight or the response measures are different, the old assessment does not cover the new use.
If any required element changes during use, you update the assessment. A FRIA that is left on the procurement file while the system moves is an expired record of a different operation.
When the assessment is done, you notify the market surveillance authority of the results, using the template provided for that purpose.
A data protection impact assessment - GDPR or national equivalent - does not replace this. Privacy is part of the rights picture. It is not the whole picture. A DPIA can sit beside a FRIA. It cannot stand in for one.
What the assessment must contain
Article 27 lists six elements. They are also a usable structure for organisations that are not formally in scope and still need a record they can defend.
(a) The processes in which the system will be used
The actual workflow. The decision. The stage at which a person is scored, ranked, admitted, refused or priced. Not the product page.
(b) Period and frequency of use
How long. How often. A tool used once in a controlled review is not the same as a system that scores people every day.
(c) Who is likely to be affected
Applicants. Claimants. Pupils. Employees. Customers. Groups already at a disadvantage. "Users" is not a category of the harmed.
(d) Specific risks of harm
The harm this use may cause these people in this setting - taking account of what the provider has told you. Unfair exclusion from credit, work or a public service. A decision nobody can explain. A remedy nobody can reach. Generic "AI risk" is not an answer.
(e) Human oversight
How oversight will be implemented, according to the instructions for use. Named people. Competence. Training. Authority. Support. A human who cannot override the output is not oversight. They are a witness.
(f) Measures if the risks materialise
What you will do when the harm is no longer theoretical. Who can stop the use. How a person complains. Where accountability sits when the model has already acted.
How the FRIA relates to other duties
The FRIA does not replace a provider's quality management system. It does not replace the operational duties of the organisation that runs the system. Those remain.
It sits beside other impact work. A supplier assessment asks whether the third-party arrangement can support lawful and safe use. A DPIA or personal-information impact assessment asks what the processing does to privacy. An ISO/IEC 42005 assessment asks what the system may do to people and society. Where Article 27 applies, the FRIA is the rights-specific piece that still has to be completed in your setting.
A complete FRIA draws on:
- the provider's instructions and the information needed to understand the system
- your description of the process and the people in it
- the oversight that will actually be applied
- the complaint and response path that will exist if harm occurs
If any of those is missing, you do not have an assessment. You have a gap with a title.
What "done properly" looks like
An assessment that can be stood behind will:
- describe the real process
- state how long and how often the system will be used
- name the people and groups likely to be affected
- set out specific risks of harm to those people
- describe oversight as it will be implemented
- set out what happens when those risks materialise, including how complaints are handled
- be finished before first use
- be updated when the facts change
- be notified to the competent authority where that is required
That is what Article 27 requires of the deployers inside its scope.
For everyone else, it is still the difference between hoping the system is safe for people and being able to show you looked - before the decision was already made.
Ready to turn this assessment into a working process?
Explore the Platform