EU AI ActArt. 27

The fundamental-rights impact assessment (FRIA): who owes it, and how to run one

The fundamental-rights impact assessment (FRIA) is the AI Act obligation that surprises deployers, because it lands on the user of a system, not just its builder. Under Article 27, certain deployers of high-risk AI must assess the impact on people's rights before they go live. Here's who owes it and how to run one that means something.

Who actually has to do it

The FRIA is a deployer obligation, and it doesn't apply to every deployer of every high-risk system — it's targeted, notably at public bodies and certain private deployers providing public services, and at specific high-risk uses such as some credit and insurance-related systems. The first step is therefore honest scoping: does your deployment fall into the categories that trigger a FRIA? If not, you may still choose to do one as good practice — but know whether it's a legal duty or a voluntary strength.

What it must cover

A FRIA looks outward, at the people affected. It should describe the deployer's processes in which the system is used, the period and frequency of use, the categories of people likely to be affected, the specific risks of harm to their fundamental rights, the human-oversight measures in place, and what you'll do if a risk materialises. The emphasis is on who could be harmed and how — not on your own liability, which is the risk register's job.

How it connects to what you may already have

If you've done an ISO 42001 impact assessment, you're most of the way there — the FRIA is a rights-focused, AI-Act-shaped version of the same outward-looking analysis. Building the two together avoids duplicated effort and produces one coherent story about who your system affects. That overlap is a large part of why running ISO 42001 and AI Act readiness in parallel is so much more efficient than treating them as separate projects.

Why it's worth doing well

A FRIA done as a box-tick reads as one. A FRIA done honestly is often the document that most impresses a sceptical buyer or regulator, because it shows you thought seriously about the people on the other end of your model. It's also your best evidence, if something goes wrong, that you foresaw the risk and had a plan — which is exactly what "responsible deployment" is supposed to mean.

The takeaway. Not every deployer owes a FRIA — check whether yours is in scope first. But if you do (or choose to), run it as a genuine analysis of who your system could affect, reuse your ISO 42001 impact assessment, and treat it as evidence of foresight rather than a form.
BJ

Former IBM and Deloitte strategy consultant, now advising mid-market companies on AI governance. Founder of Govern42.

Questions about your ISO 42001 or EU AI Act programme? Email me directly: bigjay11@gmail.com

Educational orientation, not legal advice. EU AI Act references current as of September 2026. For binding interpretation of your obligations, consult qualified counsel.