Public sector organizations and part of the private sector face a new assessment duty under the EU AI Act: the fundamental rights impact assessment, or FRIA. Article 27 of Regulation (EU) 2024/1689 requires certain deployers of high-risk AI systems to assess, before first use, what consequences that use may have for the fundamental rights of the people affected. Under the regulation's original timetable, this obligation applies from 2 August 2026. This article covers who the FRIA applies to, what it must contain, how notification to the supervisory authority works and how to combine the assessment in practice with a DPIA and with the impact assessment under ISO 42001.
Who is required to carry out a FRIA
The FRIA is a deployer obligation. The provider of the system does not have to perform it; the organization putting the system to use does, provided it falls into one of the categories of Article 27(1). There are three.
First, bodies governed by public law: government bodies and organizations under public law. Second, private entities providing public services. The recitals to the regulation mention services in education, healthcare, social services, housing and the administration of justice as examples. A private school or healthcare institution deploying a high-risk system is therefore covered as well. Third, regardless of sector: deployers of two specific types of high-risk systems listed in Annex III, point 5(b) and (c). These are systems for creditworthiness evaluation and credit scoring of natural persons, and systems for risk assessment and pricing in life and health insurance. Banks and insurers using such systems must carry out a FRIA even though they provide no public service.
There is one exception: high-risk systems intended to be used as safety components in critical infrastructure (Annex III, point 2) are exempt from the FRIA obligation.
Not sure whether your AI system qualifies as high-risk? Start with the self-assessment on our AI Act page (see the Dutch site: www.secureaudit.nl/ai-act-check).
The six elements of the FRIA
Article 27(1) prescribes what the assessment must contain as a minimum. Six elements, summarized in our own words.
One: a description of the deployer's processes in which the high-risk system will be used, in line with the system's intended purpose. This means your concrete use of the system, in your own processes. Two: the period within which and the frequency with which the system is intended to be used. Three: the categories of natural persons and groups likely to be affected by its use in the specific context. Four: the specific risks of harm to those persons or groups. Here you must use the information the provider supplies with the system under Article 13, such as the instructions for use and the known limitations. Five: a description of how human oversight is implemented, according to the instructions for use. Six: the measures to be taken if those risks materialize, including the internal governance arrangements and the complaint mechanism.
That last element in particular is underestimated. A FRIA that names risks but does not settle who intervenes when outcomes look wrong, and where an affected person can lodge a complaint, is not finished.
Timing: before first use, then keep it current
The assessment must be performed before the system is used for the first time (paragraphs 1 and 2). The obligation applies to the first use; you do not repeat the FRIA for every run. In similar cases, the deployer may also rely on a previously conducted FRIA or on an existing impact assessment carried out by the provider. If you roll out the same system in the same way at a second location, you do not have to start from scratch.
In return there is a duty to keep the assessment current. If any of the assessed elements changes, for example because the system is used for a new target group or the oversight process is adjusted, the deployer must update the information (paragraph 2). That makes the FRIA a living document, just like a DPIA.
Notifying the market surveillance authority
Once the assessment has been performed, the deployer must notify the market surveillance authority of the results, submitting the filled-out template as part of the notification (paragraph 3). That template comes from the AI Office, which under paragraph 5 develops a questionnaire, including through an automated tool, to make compliance simpler. There is a narrow exemption from the notification duty for the situation of Article 46(1), the emergency procedure under which a system may be put into use for exceptional public security reasons without a completed conformity assessment.
The notification duty means the FRIA does not remain an internal document. The supervisory authority can hold the assessment against the actual use of the system. A FRIA that does not cover how the system is really used will stand out immediately.
FRIA and DPIA: complement rather than duplicate
Many organizations required to carry out a FRIA have already done a data protection impact assessment for the same system under Article 35 GDPR. Article 27(4) governs the overlap: where an obligation under Article 27 is already met through the DPIA, the FRIA complements that DPIA. You do not redo the work, but the FRIA looks wider than the DPIA. A DPIA focuses on the protection of personal data. The FRIA concerns all fundamental rights that may be at stake: non-discrimination, human dignity, access to essential services, effective judicial protection. In practice it works well to run both assessments in one project, with the DPIA as a component and the FRIA as the wider framework.
The link with ISO 42001
Organizations with an AI management system under ISO/IEC 42001 already have a hook for the FRIA. Clause 6.1.4 and Annex A.5 of that standard require an AI system impact assessment covering the consequences for individuals, groups and society, and ISO/IEC 42005 provides a methodology for it. The FRIA can be set up as a deepening of that assessment: the same system description and the same stakeholder analysis, extended with the six mandatory elements of Article 27 and the notification process towards the supervisory authority. If the impact assessment is already embedded as a recurring process, the FRIA mainly adds the fundamental rights analysis and the governance elements.
Where you should stand now
Under the regulation's original timetable the obligation applies from 2 August 2026; discussions are still ongoing in Brussels about shifting parts of the timeline for high-risk systems, which we covered earlier. Do not wait for that. Take stock of which of your AI systems qualify as high-risk and in which role you use them, determine whether your organization falls into one of the three FRIA categories, and decide per system whether an existing DPIA or a provider impact assessment can serve as the starting point. Secure Audit supports organizations in setting up the FRIA as part of a broader AI governance process. Contact us for a no-obligation conversation.
Source: Regulation (EU) 2024/1689 (AI Act), Article 27, via EUR-Lex: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
Frequently asked questions
Who must carry out a FRIA?+
Deployers of high-risk AI systems that are bodies governed by public law or private entities providing public services, and in addition all deployers of systems for creditworthiness evaluation or credit scoring and for risk assessment and pricing in life and health insurance (Annex III, point 5(b) and (c)).
When does the FRIA have to be ready?+
Before the first use of the high-risk system. After that the assessment must be kept current: if an assessed element changes, you update the FRIA. In similar cases you may build on a previous FRIA or on an impact assessment carried out by the provider.
Do I have to notify anyone of the FRIA?+
Yes. Article 27(3) requires notifying the market surveillance authority of the results, submitting the filled-out AI Office template. Only in the emergency situation of Article 46(1) can an exemption from the notification duty apply.
I already have a DPIA. Is that enough?+
Not entirely. Where the DPIA already meets obligations under Article 27, the FRIA complements it. The FRIA does look wider than data protection: non-discrimination, access to services and judicial protection are also in scope. Preferably run both assessments in a single project.
Is there a mandatory format?+
The AI Office develops a template with a questionnaire under Article 27(5), including as an automated tool. You use the filled-out template when notifying the market surveillance authority.
Need help with compliance?
Need to comply with ISO 27001, ISO 42001, NEN 7510, NIS2 or DORA, or do you need a SOC 2 report? We guide you through the entire process: from gap analysis to implementation.
Explore Compliance ServicesAbout the author
Partner | IT Auditor