EU AI ACT · OPERATING ENVIRONMENTKnow what applies · prove why · preserve change? LEARN THIS PAGE
EU AI ACT · ARTICLE 27 · FRIA · FUNDAMENTAL RIGHTS

A FRIA IS NOT A FORM.
IT IS A RECORD OF WHY THIS DEPLOYMENT REMAINS JUSTIFIABLE.

Article 27 requires certain deployers of high-risk AI systems to assess the fundamental-rights impact of the actual context in which the system will be used. The assessment must connect the deployment process, affected people, specific risks, human oversight, mitigation, complaints, notification and later changes into one reviewable record.

BOUNDARYThis page is educational and operational guidance. It is not legal advice, certification, conformity assessment or regulatory approval.
CURRENT SOURCE ANCHOR

EUR-Lex · Regulation (EU) 2024/1689 · Article 27

Article 27 requires covered public-law bodies, private entities providing public services, and deployers of specified creditworthiness and life/health-insurance high-risk systems to perform a fundamental-rights impact assessment before first use. The assessment must be updated when relevant elements change and generally notified to the market surveillance authority.

OPEN OFFICIAL EU SOURCE ↗
WHAT BUSINESSES NEED TO ESTABLISH

Do not start with a generic checklist.

Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.

01

DOES ARTICLE 27 APPLY TO THIS DEPLOYER AND THIS HIGH-RISK SYSTEM?

FRIA is not universal. It applies before deployment of covered Article 6(2) high-risk systems to bodies governed by public law, private entities providing public services, and deployers of certain creditworthiness and life/health-insurance systems. Annex III point 2 critical-infrastructure systems are excluded from Article 27(1).

02

IS THIS THE FIRST USE OR HAS THE CONTEXT CHANGED?

The Article 27 duty applies to first use. A deployer may rely on a prior FRIA in similar cases, but the record must be updated when the processes, affected groups, risks, oversight, mitigation or other relevant elements change or become stale.

03

DOES THE ASSESSMENT COVER THE ACTUAL CONTEXT OF USE?

A FRIA must describe the deployer process, duration and frequency of use, affected categories of persons and groups, specific fundamental-rights risks, human-oversight measures, and measures for materialised risks including governance and complaint mechanisms.

04

CAN THE FRIA BE PROVEN TO THE MARKET SURVEILLANCE AUTHORITY?

After completing the assessment, the deployer must notify the market surveillance authority of the results using the applicable template, subject to the Regulation’s stated exception. Preserve the completed assessment, notification state, source evidence and later updates.

THE TA-14 OPERATING ROUTE

Turn the question into a governed record.

The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.

01

Confirm scope before drafting the assessment

Identify the high-risk system, Article 6 route, Annex III category, deployer type, intended purpose and whether the deployment falls within Article 27. Do not build a FRIA merely because the organisation uses AI.

02

Map the real deployment context and affected groups

Document where and how the system is used, how often, for how long, who may be affected, which groups may be vulnerable, and what provider information under Article 13 is relevant to the assessment.

03

Connect risks to oversight, mitigation, complaints and redress

For each material fundamental-rights risk, preserve the human-oversight measure, governance control, intervention path, complaint mechanism, mitigation measure and accountable decision-maker.

04

Notify, preserve and revalidate the FRIA

Record the market-surveillance notification state, coordinate overlapping DPIA evidence where applicable, and update the FRIA whenever the deployment context or Article 27 elements change or are no longer current.

READY TO OPERATE · START PAID ACCESS NOW

Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.

1–3 AI systems

Evidence Passport

$19/MO

Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.

START EVIDENCE PASSPORT
Up to 10 AI systems

Compliance Workspace

$49/MO

Coordinate evidence, owners, documentation, incidents and team compliance work in one governed workspace.

START COMPLIANCE WORKSPACE
Up to 25 AI systems

Governance Pro

$99/MO

Operate broader high-risk, GPAI, FRIA, post-market and material-change governance across a growing portfolio.

START GOVERNANCE PRO
Up to 50 AI systems

Institution

$499/MO

Run institutional governance with expanded users, authority workflows, examiner rooms and portfolio reporting.

START INSTITUTION
Need an independent human readiness examination?A governed readiness review is separate from software access and starts at $750.
REQUEST READINESS REVIEW →
START WITH ONE SYSTEM

Not ready to subscribe? Classify first.

Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.

COMMON QUESTIONS

Questions businesses are asking now.

Who must conduct a FRIA under the EU AI Act?

Article 27 covers deployers of specified Article 6(2) high-risk systems that are bodies governed by public law or private entities providing public services, plus deployers of the high-risk systems in Annex III points 5(b) and 5(c), covering creditworthiness/credit scoring and life or health insurance risk assessment and pricing.

Does every high-risk AI system require a FRIA?

No. Article 27 has a specific scope. It applies to covered deployers and Article 6(2) high-risk systems, with an express exception for systems in Annex III point 2 concerning critical infrastructure.

What must a FRIA contain?

Article 27 requires the deployer process, intended duration and frequency of use, affected categories of persons and groups, specific risks of harm to fundamental rights, implementation of human oversight, and measures for materialised risks including internal governance and complaint mechanisms.

Can an existing DPIA replace the FRIA?

Not automatically. Where Article 27 obligations are already met through a GDPR or law-enforcement data-protection impact assessment, the FRIA complements that DPIA rather than duplicating the same work.

Does the FRIA have to be updated?

Yes. Article 27 applies to first use and requires the deployer to update the assessment information if relevant elements change or are no longer up to date. Similar cases may rely on previous FRIAs or existing provider impact assessments where appropriate.

Must the FRIA be sent to an authority?

After the assessment is performed, Article 27 requires the deployer to notify the market surveillance authority of the results using the applicable template, subject to the Regulation’s stated exception for certain Article 46(1) cases.

Does TA-14 certify a FRIA as legally sufficient?

No. TA-14 can preserve the FRIA scope decision, evidence, affected-group analysis, risk-to-control mapping, notification state, updates, gaps and revalidation history. It does not provide legal advice, certification, conformity assessment or regulatory approval.

EU AI ACT WORLD · TA-14 AUTHORITY GOVERNANCE INSTITUTION

Understand the requirement. Preserve the evidence. Revalidate when reality changes.

TA-14 Exchange Activity

Public network activity

Live cumulative activity recorded across the public Exchange surface.

Refreshing public totals

···

Visitors

Recorded public visitors

···

Page Views

Recorded Exchange views