Who needs a FRIA under Article 27 — and who doesn't
The fundamental rights impact assessment is one of the most misunderstood duties in the AI Act. Teams either assume every high-risk deployer needs one, or miss that they are captured. The scoping rule is narrow and specific — here it is, operationally.
Updated July 24, 2026 · Informational guidance, not legal advice
The scoping rule
Article 27 requires a fundamental rights impact assessment before the first use of a high-risk AI system listed in Annex III — but only from three kinds of deployers: bodies governed by public law, private entities providing public services (think education, healthcare, social services, housing), and deployers of two specific Annex III point 5 systems — creditworthiness and credit scoring under 5(b) (except financial fraud detection) and life and health insurance risk assessment and pricing under 5(c).
Everyone else deploying high-risk AI — a private B2B company running an internal HR screening tool, for instance — does not owe a FRIA. That team still carries the full Article 26 load: assigned human oversight, monitoring, log retention, worker notification. FRIA is a subset question layered on top of Article 26 for the deployers it captures, not a general high-risk requirement.
The two common scoping mistakes
Over-scoping: assuming every high-risk deployment needs a FRIA and burning weeks producing assessments nobody required. Under-scoping: public-service-adjacent companies — edtech selling into schools, healthtech operating patient-facing systems, fintech scoring credit — concluding "we're private, so it doesn't apply" when the public-services or 5(b)/5(c) prongs capture them.
What the assessment must contain
Article 27 is prescriptive about content. The assessment sets out:
- The deployer's processes in which the high-risk system will be used, in line with its intended purpose.
- The period of time and frequency in which the system is intended to be used.
- The categories of natural persons and groups likely to be affected by its use.
- The specific risks of harm likely to have an impact on those categories of persons or groups.
- A description of the human oversight measures, per the provider's instructions for use.
- The measures to be taken where those risks materialise — internal governance arrangements and complaint mechanisms included.
Once complete, the deployer notifies the market surveillance authority of the outcome; the AI Office is to provide a template questionnaire to make this submission standard. And the FRIA is not one-and-done: when any of the assessed elements changes — new process, new affected population, new risk — the deployer updates it.
FRIA and your existing DPIA
If the deployment processes personal data, chances are a GDPR Article 35 data protection impact assessment already exists or is underway. Article 27 anticipates this: where a DPIA already covers some of the required elements, the FRIA complements it. In practice that means building the FRIA on top of the DPIA — reusing the process descriptions and affected-person categories, then adding what the DPIA does not ask: the fundamental-rights risk framing, oversight measures from the instructions for use, and the materialisation plan.
- Start from the DPIA's inventory of processing operations and affected groups — do not re-derive them.
- Add the AI-specific elements: intended purpose alignment, frequency and period of use, oversight assignments.
- Keep the two assessments cross-referenced in your record, each with an owner and a review date, so a change to one triggers a look at the other.
Running it as a record, not a ritual
The failure mode with impact assessments is well known from GDPR practice: a document produced once, filed, and never reopened. Article 27's update duty makes that posture untenable — the assessment is tied to elements that change routinely in a living product. The operational answer is the same one that works for the rest of the AI Act: the FRIA is an evidence item in the system's register entry, with a named owner, a review cadence, and a visible staleness flag when the system's use has drifted from what was assessed.
Before first use means before first use
The assessment is a precondition, not a catch-up task. Article 27 applies from December 2, 2027 following the Digital Omnibus deferral, but for systems going live before then the FRIA belongs on the launch checklist alongside oversight assignment and log-retention configuration — not in the quarter after the obligation attaches.
Find out which obligations actually capture you
The free Attevera assessment walks Articles 4, 5, 6, and 50 plus Annex I and III for your situation — including whether the Article 27 FRIA prongs apply. No signup.
Run the free assessmentFrequently asked questions
We are a private SaaS company deploying a high-risk hiring tool internally. Do we need a FRIA?
Under Article 27's scoping, no — unless you are providing public services or the system is a 5(b) credit or 5(c) life/health insurance system. Your Article 26 deployer duties still apply in full. This is informational guidance, not legal advice; if you sit near the public-services boundary, have counsel confirm.
Does selling software to a public body make us subject to Article 27?
The FRIA duty sits on the deployer — the organization using the system under its authority. If a public body deploys your product, the FRIA is theirs to perform, but expect procurement to ask you for the inputs: intended purpose, instructions for use, and oversight measures. Being able to hand over a clean packet is a sales asset.
Can we just extend our DPIA instead of writing a separate FRIA?
The Act expects the FRIA to complement an existing DPIA rather than duplicate it — you can build on the DPIA's content, but the Article 27 elements (frequency and period of use, specific fundamental-rights risks, oversight measures, materialisation plan) must actually be covered and the market surveillance authority notified of the outcome.
How often does the FRIA need updating?
There is no fixed interval — the trigger is change. New processes, new categories of affected persons, changed oversight arrangements, or a shifted intended purpose all require the assessment to be brought current. A periodic review cadence is the practical way to catch drift before it becomes a gap.