Definition: Fundamental Rights Impact Assessment (FRIA)
A Fundamental Rights Impact Assessment (FRIA) is a pre-deployment review, required by Article 27 of the EU AI Act, documenting how a specific high-risk AI system affects the fundamental rights of the people it touches, before first use.
Core characteristics of Fundamental Rights Impact Assessment (FRIA)
A FRIA assesses how a system is used in context, not how it was built.
- Focuses on the deployer’s own processes and affected persons
- Covers rights beyond privacy, including non-discrimination
- Reviewed whenever the use case changes
- Results notified to the market surveillance authority
Fundamental Rights Impact Assessment (FRIA) vs. DPIA
A DPIA assesses privacy risk under GDPR Article 35 wherever processing is likely to cause high risk. A FRIA covers broader fundamental rights but applies only to the deployers Article 27 names, and Article 27(4) lets a deployer extend an existing DPIA into it instead of duplicating the work.
Importance of FRIA in enterprise AI
FRIA scope is narrow, but the organizations it hits, banks, insurers, public-service providers, deploy AI scoring tools most aggressively. A Secure Privacy survey found 78% of organizations had taken no meaningful EU AI Act compliance steps as of April 2026.
Methods and procedures for Fundamental Rights Impact Assessment (FRIA)
Three steps determine whether a FRIA is required and how it is built.
Scope determination
- Confirm public-body status or private provision of a public service
- Check for creditworthiness or insurance pricing use under Annex III 5(b) or 5(c)
- Document the scoping decision even if no FRIA is required
Drafting the six required elements
Article 27(1) lists six elements: the deployer’s processes, the period and frequency of use, the persons likely affected, the specific risks of harm, the human oversight measures, and the complaint arrangements if a risk materializes.
Notification and DPIA integration
The AI deployer notifies the market surveillance authority using the standardized template. An existing DPIA can be extended once it covers all six elements.
Important KPIs for Fundamental Rights Impact Assessment (FRIA)
FRIA readiness is measurable before any system reaches first use.
Scoping and documentation coverage
- Scoping decisions: 100% of credit, insurance, or public-service AI systems reviewed
- FRIA completion: 100% of in-scope systems assessed before first use
- Template currency: aligned with the current AI Office questionnaire
- Notification tracking: submission date and authority response logged
Strategic governance metrics
Boards overseeing regulated lending or insurance AI increasingly ask how many systems trigger Article 27, alongside AI governance reporting.
Complaint and oversight quality
A FRIA’s governance is only as strong as its complaint mechanism. Logged and resolved complaint volume, not the mechanism’s mere existence, is what regulators check.
Risk factors and controls for Fundamental Rights Impact Assessment (FRIA)
Misjudging scope entirely
The common error is assuming FRIA duties only apply to public authorities, missing that any deployer using AI for creditworthiness or insurance pricing is in scope regardless of size.
- Route credit-scoring or insurance-pricing AI through legal review against Annex III 5(b)/5(c)
- Reassess scope whenever a lending tool’s use case expands
- Keep the scoping rationale on file even when no FRIA is required
Generic risk descriptions that fail Article 27(1)
A FRIA listing abstract risk categories without naming the specific groups and harms does not satisfy Article 27.
Complaint mechanisms that exist on paper only
A complaint process nobody has tested creates false assurance, exposing the deployer to AI compliance findings during review.
Practical example
A 210-employee regional cooperative bank in Bavaria deployed an AI creditworthiness scoring tool for SME loan applications, ranking applicants on repayment risk. Legal counsel flagged the tool as an Annex III 5(b) use case, triggering Article 27 regardless of the bank’s size, so the bank extended its existing GDPR DPIA into a combined DPIA/FRIA document.
- Written scoping rationale reviewed by legal and credit risk
- Combined DPIA/FRIA document covering all six Article 27 elements
- Human review queue for applications below a confidence threshold
- Documented, tested complaint channel for disputed scores
Current developments and effects
Digital Omnibus deferral to December 2027
The Digital Omnibus, endorsed by the European Parliament in June 2026 and given final Council approval shortly after, defers Article 27 obligations from August 2, 2026 to December 2, 2027.
- Takes effect only once published in the Official Journal
- Article 26 deployer duties and Article 50 transparency stay on the original schedule
- Pausing FRIA preparation risks a compressed catch-up later
AI Office questionnaire template maturing
The EU AI Office is finalizing the standardized notification template. Deployers can already structure assessments around the six statutory elements.
German market surveillance responsibilities taking shape
Germany’s KI-MIG law designates the Bundesnetzagentur as the general market surveillance authority, with BaFin covering financial-sector AI.
Conclusion
A FRIA is narrow but consequential: most Mittelstand companies never trigger it, but banks, insurers, and public-service providers face a duty that ignorance of scope will not excuse. The Digital Omnibus deferral buys planning time, not an exemption. Extending an existing DPIA into a combined document avoids duplicating work later, and treating scoping as a standing review item keeps regulated AI deployment defensible.
Frequently Asked Questions
Who actually has to complete a Fundamental Rights Impact Assessment?
Public bodies deploying Annex III high-risk AI, private providers of public services such as education or healthcare, and any deployer using AI for creditworthiness or insurance pricing.
Does a 200-employee Mittelstand company ever need a FRIA?
Only if it deploys AI for creditworthiness scoring, insurance pricing, or as a private provider of a public service. Most manufacturers and wholesalers fall outside these categories.
How does a FRIA relate to DSGVO and the DPIA we may already have?
Article 27(4) lets a deployer extend an existing GDPR DPIA into the FRIA instead of running two assessments, so a current DPIA on a scoring tool covers most of the groundwork.
What does the Digital Omnibus deferral mean for our FRIA timeline?
The obligation moves from August 2, 2026 to December 2, 2027 once published in the Official Journal, but Article 26 and Article 50 duties stay on schedule.
Do we need our own compliance team to run a FRIA?
No dedicated department is required. Most in-scope banks and insurers combine legal or compliance staff with an external partner for the work.
What happens if an in-scope deployer skips the FRIA entirely?
Authorities can require the system withdrawn from use until a valid FRIA and notification exist. Given how narrowly Article 27 is scoped, a missing FRIA reads as a straightforward compliance failure.