How to Conduct a Fundamental Rights Impact Assessment (FRIA)
The AI Act requires deployers of high-risk AI systems to conduct Fundamental Rights Impact Assessments. This guide explains who needs one, what it covers, and how to conduct it.
What Is a FRIA?
A Fundamental Rights Impact Assessment (FRIA) is a structured evaluation required under Article 27 of the EU AI Act. It assesses the potential impact of a high-risk AI system on the fundamental rights of individuals who may be affected by its use.
The FRIA is distinct from the provider's conformity assessment. While the provider evaluates whether the system meets technical requirements, the deployer must assess how the system's use in their specific context may affect fundamental rights—including the right to non-discrimination, privacy, fair trial, and dignity.
Who Must Conduct a FRIA?
Not every deployer of a high-risk AI system needs a FRIA. The obligation applies specifically to bodies governed by public law (government agencies, public authorities), private entities providing public services (utilities, healthcare providers, education institutions), deployers of AI systems for credit scoring or creditworthiness evaluation, and deployers of AI systems for risk assessment and pricing in life and health insurance.
When to Conduct the Assessment
The FRIA must be performed before putting the high-risk AI system into use. It should be updated when the AI system undergoes significant changes or updates, the deployment context changes, new risks are identified through monitoring or incident reports, and at least annually as part of ongoing governance practices.
Core Elements of a FRIA
1. Description of the Deployer's Processes
Document the specific processes in which the high-risk AI system will be used. This includes the purpose, scope, and operational context of deployment. Be specific: rather than "HR screening," describe exactly which stage of recruitment, which candidate pools, and which decision-making steps involve the AI system.
2. Frequency and Duration of Use
Specify how often the system will be used and over what time period. Continuous, always-on systems pose different risk profiles than systems used periodically for batch processing.
3. Categories of Affected Persons
Identify all groups of natural persons likely to be affected by the system's operation. Consider both direct users and individuals whose data or decisions are processed by the system. Pay particular attention to vulnerable groups—children, elderly persons, persons with disabilities, and economically disadvantaged individuals.
4. Specific Risks of Harm
Assess the specific risks to fundamental rights of the identified categories of persons. The Charter of Fundamental Rights of the European Union provides the framework, including Article 1 (Human dignity), Article 8 (Protection of personal data), Article 21 (Non-discrimination), Article 24 (Rights of the child), Article 35 (Healthcare access), and Article 47 (Right to an effective remedy and fair trial).
5. Human Oversight Measures
Describe the human oversight mechanisms in place—who reviews AI outputs, how frequently, with what authority to override, and what training they have received. Document the escalation process for flagged decisions.
6. Mitigation and Governance Measures
For each identified risk, document the measures taken to mitigate it. This includes technical safeguards (bias detection, fairness constraints), organizational measures (review boards, appeal processes), and monitoring mechanisms (performance dashboards, complaint tracking).
Notification to the National Authority
After completing the FRIA, deployers must submit a summary of the assessment to the relevant national market surveillance authority. The Commission is expected to provide standardized forms for this purpose.
Getting Started
Begin by creating a registry of all high-risk AI systems your organization deploys. For each system, determine whether a FRIA is required based on the criteria above. Then assemble a cross-functional team—legal, technical, ethics, and domain experts—to conduct the assessment systematically.
Need support with your FRIA? Browse our directory to find consultants experienced in fundamental rights assessments and AI governance.