What Is a FRIA?
A FRIA is a fundamental rights impact assessment required under Article 27 of the EU AI Act. It's carried out before certain high-risk systems go into operation and maps how the system could affect people's rights. Public bodies and some private organizations are covered, and the assessment complements the data protection assessment with a fundamental-rights perspective.
FRIA is one of those abbreviations in the EU AI Act that’s easy to overlook until it suddenly becomes a requirement. It stands for Fundamental Rights Impact Assessment, and it’s governed by Article 27. Here’s what it is, who it applies to, and how it relates to the data protection assessment you might already be doing.
What a FRIA Is
A FRIA is a structured assessment of how an AI system could affect people’s fundamental rights, carried out before the system goes into operation. Where a technical review asks whether the system works, a FRIA asks what the system does to the people it affects – and whether it puts rights like non-discrimination, privacy, or the right to fair treatment at risk.
The point is to catch such risks in advance, while the design can still be changed, instead of discovering them once the system is already affecting real people.
Who It Applies To
The obligation is scoped, and it’s important to know whether it applies to you. A FRIA is required of public bodies and certain private organizations before they put a high-risk system under the regulation’s Annex III into operation.
Two conditions therefore have to be met at the same time: that you belong to the circle of bodies covered, and that the system is classified as high-risk. Annex III lists the use cases that count as high-risk – including certain systems in recruitment, education, credit assessment, and the exercise of public authority. If both conditions are met, the assessment has to be done before deployment.
It’s worth pausing on the word “before.” The requirement isn’t to document after the fact that the system was appropriate, but to do the assessment while the choice is still open. If your application lands close to one of the categories in Annex III, the safe approach is to prepare a FRIA early, even if the final classification isn’t locked in yet.
The Relationship to a DPIA
If you already work with data protection, you know the DPIA, the impact assessment under GDPR. A common question is how a FRIA relates to it. The answer is that they complement each other.
A DPIA focuses on risks to personal data: how data is collected, processed, and protected. A FRIA widens the lens to fundamental rights more broadly – including ones that don’t concern personal data, such as the risk of discrimination or a restricted right to a fair process. They overlap, but cover different things.
The practical advice is therefore clear: run them in the same workflow instead of as two separate tracks. Much of the mapping work – who’s affected, what data, what risks – is shared. Splitting it into two disconnected processes creates duplicate work and a risk that the assessments contradict each other.
Have the Template Ready Before the High-Risk Case Comes Up
One pattern is worth highlighting. In all four vendor walkthroughs in our material, the vendor puts the FRIA template on the buyer’s desk as an unchecked box – a commitment pointed out as yours, not theirs. In other words: the vendor reminds you that a FRIA might be needed, but the assessment itself is yours.
The conclusion is to have the template ready in advance. A concrete scenario: a project is underway, and late in the process it turns out the system falls under Annex III. If the FRIA template is already on hand, it becomes a natural part of the design work. If it’s missing, it instead becomes a brake right before launch, when time is tightest. Preparation moves the assessment from the final stretch to the drawing board.
What the Assessment Documents
Concretely, a FRIA documents four things: which groups are affected by the system, what risks exist to their rights, how human oversight is designed, and what escalation path applies when something goes wrong. Together, that forms a traceable record showing that the risks were weighed before the system was put into use.
Note that an empty template isn’t a completed FRIA. It only becomes a genuine record once it’s filled with your reality – your groups, your workflows, your oversight. Want help setting up your AI work so this kind of assessment becomes part of the design from the start? Read more about our work with AI or get in touch.
Frequently asked questions
Who is required to carry out a FRIA?
A FRIA is required of public bodies and certain private organizations before they put a high-risk system under Annex III into operation. The requirement therefore follows from two things at once: that you're that kind of body, and that the system is high-risk. If both are met, the assessment must be done before deployment, not after.
What's the difference between a FRIA and a DPIA?
A DPIA assesses risks to personal data under GDPR. A FRIA widens the lens to fundamental rights more broadly, such as non-discrimination and the right to a fair process. They overlap but aren't the same thing. The practical advice is to run them in the same workflow instead of as two separate tracks.
What should a FRIA document?
The assessment describes which groups are affected by the system, what risks exist to their rights, how human oversight is designed, and what escalation path applies when something goes wrong. The goal is a traceable record showing that the risks were weighed before the system was put into use.
When in the project should the FRIA be done?
Before the high-risk system goes into operation, but in practice it pays to have the template ready far earlier. All four vendor walkthroughs in our material put the FRIA template on the buyer's desk as an unchecked box. Have it ready before the high-risk case comes up, and it becomes part of the design instead of a brake right before launch.
Is it enough for the vendor to provide a FRIA template?
No. The vendor can provide a template, but the assessment is the buyer's responsibility and has to be filled with your reality: your groups, your workflows, your oversight. An empty template isn't a completed FRIA. It only becomes a genuine record once you've actually gone through how your specific system affects rights.