A digital bank deployed an AI model to accelerate personal loan decisions after completing a DPIA and security review. Six months later, analysis showed that applicants from certain postal codes were rejected at nearly twice the average rate, despite the model not using nationality as an input.
The assessments had addressed privacy, security, and data protection but had not examined potential impacts on fair access to credit, discrimination, or individuals’ ability to challenge decisions.
This highlights the distinction between a Data Protection Impact Assessment (DPIA) and a Fundamental Rights Impact Assessment (FRIA). For applicable high-risk AI systems under the EU AI Act, a FRIA provides an additional assessment of how the system may affect fundamental rights before deployment.
What Is A Fundamental Rights Impact Assessment (FRIA) Under The EU AI Act?
A Fundamental Rights Impact Assessment (FRIA) is a documented evaluation that certain deployers of high-risk AI systems must complete to identify how the system could harm people’s fundamental rights and how those risks will be managed. The requirement comes from Article 27 of the EU Artificial Intelligence Act. The rights in scope come from the EU Charter of Fundamental Rights, including non-discrimination, human dignity, privacy, data protection, and the right to an effective remedy. A FRIA looks at how the AI system will be used in a specific organization, on specific people, in a specific context. This deployment focus separates it from the provider’s technical risk management, which examines the system in general.
Who Needs To Conduct A FRIA Under Article 27?
A FRIA is required from deployers of high-risk AI systems listed in Annex III of the EU AI Act when they fall into one of two groups. The first group covers bodies governed by public law and private entities that provide public services, such as education, healthcare, housing, and social services.
The second group covers any deployer using AI to evaluate creditworthiness or establish credit scores, or to assess risk and set pricing for life and health insurance. High-risk systems used as safety components in critical infrastructure are excluded from this obligation.
The duty can also reach organizations outside the EU, because the Act applies to deployers located in other countries when their AI system’s output is used in the Union. Global banks, insurers, and service providers with EU customers should therefore map their AI use cases early.
When Must A FRIA Be Completed Under The EU AI Act?
A FRIA must be completed before a high-risk AI system is put into use for the first time, and it must be updated whenever any key element of the assessment changes. The deadline for Annex III high-risk obligations has moved under the Digital Omnibus on AI, which entered into force on 27 July 2026. According to the Council of the EU, stand-alone high-risk AI systems now fall under the new rules from 2 December 2027. Deployers can rely on a previous FRIA or an existing assessment by the provider for similar cases, as long as it remains accurate. Organizations should treat the extra time as preparation time, since credit, insurance, and public sector AI deployments often take many months to inventory and assess properly.
What Should A FRIA Include?
A FRIA must include six core elements that describe the AI system’s use, the people it affects, the risks they face, and the safeguards in place. Article 27 of the EU AI Act lists them as follows:
- A description of the deployer’s processes in which the high-risk AI system will be used, in line with its intended purpose.
- The period and the frequency with which the system will be used.
- The categories of natural persons and groups likely to be affected in the specific context of use.
- The specific risks of harm likely to affect those people or groups, informed by the provider’s instructions for use.
- A description of the human oversight measures implemented according to the instructions for use.
- The measures to take if risks materialize, including internal governance arrangements and complaint mechanisms..
Once the assessment is complete, deployers must notify the relevant market surveillance authority of the results using the template questionnaire developed by the EU AI Office.
What Is The Difference Between A FRIA And A DPIA?
A DPIA under GDPR assesses risks to personal data and privacy, while a FRIA assesses the wider impact of a high-risk AI system on all fundamental rights, including equality, dignity, and access to essential services. The EU AI Act allows a FRIA to complement an existing DPIA, so teams should connect the two instead of duplicating effort.
| Aspect | DPIA (GDPR Article 35) | FRIA (EU AI Act Article 27) |
| Trigger | High-risk processing of personal data | Deployment of certain Annex III high-risk AI systems |
| Rights in scope | Privacy and data protection | All Charter rights, including non-discrimination and effective remedy |
| Who performs it | Data controller | Qualifying AI deployer |
| Notification | Prior consultation only when high residual risk remains | Results notified to the market surveillance authority |
How Do You Conduct A FRIA Step By Step?
You conduct a FRIA by inventorying your AI use cases, confirming which ones qualify, assessing rights risks with affected stakeholders, documenting safeguards, and notifying the authority before first use. In the AI governance programs our consultants support, this five-step sequence works well:
- Build an AI inventory: list every AI system in use, including embedded vendor AI and tools adopted outside IT.
- Classify and scope: confirm which systems are high-risk under Annex III and whether your organization falls within Article 27.
- Assess rights impacts: combine provider documentation, model testing results, and input from legal, compliance, and affected user groups.
- Define safeguards: document human oversight, escalation paths, complaint handling, and remediation steps.
- Notify and monitor: submit the results, then review the FRIA whenever the model, data, or use context changes.
Many deployers also need to assess AI embedded in vendor products, which makes third-party risk management a practical input to the FRIA.
| Identify your high-risk AI use cases and get FRIA-ready with Ampcus Cyber’s AI risk assessment and management services. |
People Also Ask
Is a FRIA mandatory for all AI systems?
A FRIA is mandatory only for certain deployers of high-risk AI systems listed in Annex III of the EU AI Act. Most general business AI tools, such as chatbots and productivity assistants, do not require one.
Do AI providers need to conduct a FRIA?
The FRIA obligation falls on deployers, the organizations that use a high-risk AI system under their authority. Providers carry separate duties, such as risk management, technical documentation, and conformity assessment.
Can a DPIA replace a FRIA?
A DPIA cannot fully replace a FRIA, because a DPIA focuses on personal data risks. The EU AI Act allows the FRIA to complement an existing DPIA where both assessments overlap.
Does the EU AI Act apply to companies in India or the US?
The EU AI Act can apply to companies outside the EU when their AI systems or outputs are used in the EU. Deployers serving EU customers should assess whether the FRIA obligation applies to them.
How often should a FRIA be updated?
A FRIA should be updated whenever an assessed element changes, such as the system’s purpose, affected groups, or oversight measures. Many organizations also review FRIAs annually as part of AI governance.
Enjoyed reading this blog? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn.









