FRIA: the AI Act’s fundamental rights impact assessment, explained
The FRIA (Fundamental Rights Impact Assessment) is an assessment that Article 27 of the AI Act requires before using certain high-risk systems. It does not affect everyone, but it does affect public bodies and some companies. Here is how to know if it applies and what it must contain.
What it is, simply
It is like the impact study before building a road: before using a system that can affect people’s rights (access to credit, to a public service), you must think about who it affects, how, and what you will do if something goes wrong.
Who must do it
- Bodies governed by public law.
- Private entities providing public services.
- Deployers of certain high-risk systems: creditworthiness assessment or credit scoring of individuals, and pricing in life and health insurance.
Check the text of Article 27 and Annex III for your case.
What it must include
- Description of the processes where the system will be used and its purpose.
- Period and frequency of use.
- Categories of people likely to be affected.
- Specific risks of harm to those people.
- Human oversight measures.
- Measures if the risks materialise, including internal governance and complaint mechanisms.
Relation to the DPIA
If you already do a data protection impact assessment, you can reuse much of the information and complete it with analysis of other rights (non-discrimination, access to services, among others).
Where to start
- Inventory your AI systems and classify their risk.
- Identify whether any falls under Article 27.
- Prepare a template that reuses your DPIA.
Frequently asked questions
Who must do the FRIA?
Public bodies, private entities providing public services and deployers of certain high-risk systems.
Is it the same as a DPIA?
No: the FRIA covers fundamental rights generally.
Informational content, not legal advice.
What's your Data Governance maturity?
Free assessment with your priority gaps, plus the self-assessment quiz and savings calculator on the Data Governance path.