FRIA: the fundamental-rights impact assessment, step by step
Who must run an Art. 27 FRIA, what the assessment covers, the Art. 27(3) notification and the Art. 27(4) link to the DPIA, when to revisit it, and how Veritome generates the report per system.
Before putting certain high-risk systems into service, deployers must assess the impact on the fundamental rights of the people the system affects (Art. 27(1)). It is a deployer duty for Annex III systems and applies from 2 December 2027.
Who must run one
- Deployers that are bodies governed by public law, or private operators providing public services — for Annex III systems other than critical infrastructure.
- Any deployer of a creditworthiness or credit-scoring system (Annex III 5(b)) or a life and health insurance risk-assessment and pricing system (5(c)) — public or private.
Veritome's rules engine encodes this conservatively: the FRIA appears only for high-risk deployer systems where your organisation is flagged as a public body or public-service provider in a covered Annex III area, or the system sits in essential services (Annex III point 5, applied whole — which deliberately over-includes private deployers under points 5(a) and 5(d), who sit outside Art. 27(1); mark those not applicable with a note). Providers never see it.
What the assessment covers
The FRIA editor mirrors the Art. 27(1) structure, points (a) to (f):
- Deployer processes — how the system is used in line with its intended purpose, in your workflows.
- Temporal scope — the period and frequency of use.
- Affected persons — the categories of natural persons and groups likely to be affected (employees, applicants, customers, citizens, patients, students…) and an estimated count. When you pick a category, Veritome pre-populates suggested risks matched to your system's Annex III area.
- Risk identification — the specific risks of harm to those groups, read against the provider's instructions for use.
- Human oversight measures — narrative plus a checklist: trained operator assigned, override mechanism available, regular review schedule, escalation procedure documented.
- Mitigation measures — what you put in place if the risks materialise, including governance and complaint arrangements.
- Authority notification — Art. 27(3) requires you to notify the market-surveillance authority of the results, using the questionnaire the AI Office provides (Art. 27(5)); the editor records the notification date.
The assessment is done before first use and applies to the first use of the system; you may rely on one already carried out by the provider or in a similar case, and update it if any element changes (Art. 27(2)).
The DPIA link — Art. 27(4)
Where any of the Art. 27 obligations is already met through a data protection impact assessment under GDPR Art. 35, the FRIA complements that DPIA — you may draw the overlapping parts from it. Veritome shows that route on the FRIA obligation as a statutory reuse card: it explains the route and lets you record the arrangement you rely on, and it changes nothing else — not the status, not a percentage, not coverage. The mapping the other way, FRIA answers into the DPIA's four pillars, is the DPIA overlap workspace.
Generating the report
Save draft stores your answers on the system's Art. 27 obligation, and Export PDF renders the A4 FRIA report. Where Aria helped draft it, the export says so.
When to update it
Update the FRIA when any element changes — new user groups, new purpose, changed oversight. Veritome auto-schedules an annual Fundamental Rights Impact Assessment Review for FRIA-scoped organisations, and completing a review appends a tamper-evident entry to the system's regulator dossier.