Template · Article 27 · Applies with the Annex III high-risk regime from 2 December 2027
EU AI Act FRIA Template (Fundamental Rights Impact Assessment)
A fundamental rights impact assessment (FRIA) is the assessment that Article 27 of the EU AI Act (Regulation (EU) 2024/1689) requires certain deployers of Annex III high-risk AI systems to perform before first use: public bodies, private entities providing public services, and any deployer using AI for creditworthiness assessment or life and health insurance pricing (Annex III points 5(b)–(c)). It covers the deployment process, affected persons, specific risks of harm, human oversight and the measures taken if risks materialise (Article 27(1)(a)–(f)), with the results notified to the market surveillance authority. Following the Digital Omnibus, the Annex III regime — including Article 27 — applies from 2 December 2027.
Last reviewed: 26 August 2026 · Applies with the Annex III high-risk regime from 2 December 2027 · Included in the kit as 20_FRIA_Template.docx
What this document is
Document 20 of the RegShelf kit is a complete FRIA working template structured around the six assessment elements of Article 27(1)(a)–(f), with fill-in tables for each, a scope test up front, and a condensed worked example (a municipal housing-benefit triage tool) showing the expected level of detail. One fact the template is explicit about: Article 27(5) obliges the AI Office to develop a template questionnaire for the notification, including through an automated tool — neither has been published as of mid-2026. Until they are, an internal template like this one is what deployers in scope can actually use, reconciling with the official structure once it is released.
Who needs it
Fewer organisations than the acronym's popularity suggests — the template's first section exists to tell many SMEs they are out of scope. Article 27 applies only to deployers of Annex III high-risk systems (other than critical-infrastructure systems) who are: bodies governed by public law (municipalities, public schools, public hospitals, social-security institutions); private entities providing public services such as education, healthcare, social services or housing — a private clinic or housing association can be caught; or any deployer, public or private, of systems evaluating creditworthiness or pricing life and health insurance for natural persons. A purely private company outside those categories does not owe a FRIA — though the template works as a voluntary risk exercise.
What the law requires — precisely
For deployers in scope, the assessment must be completed before the first use of the system and must cover the elements of Article 27(1): (a) the deployer's processes in which the system will be used; (b) the period and frequency of use; (c) the categories of natural persons and groups likely to be affected; (d) the specific risks of harm to those groups, taking into account the provider's instructions for use; (e) the implementation of human oversight measures; and (f) the measures to be taken where risks materialise, including internal governance and complaint mechanisms. Article 27(3) requires notifying the market surveillance authority of the results (a narrow exemption exists for the Article 46(1) urgent-use procedure). You may rely on an earlier FRIA or a provider's impact assessment covering a similar use, but must update it when any relevant element changes — and a GDPR DPIA for the same processing complements rather than replaces the FRIA.
What's inside the RegShelf template
Twelve sections and eight tables:
- Scope test — the three deployer categories, in plain terms, so you first establish whether Article 27 applies to you at all;
- A four-step SME process — assign an owner, gather the provider's Article 13 instructions for use, involve the staff who run the process, reuse your DPIA facts;
- Assessment identification and deployment-process description tables (Art. 27(1)(a)–(b));
- Affected persons table with vulnerable-group flags (children, older people, persons with disabilities, financial distress, limited language proficiency);
- A Charter rights checklist — eleven rights commonly engaged by Annex III systems, from non-discrimination (Art. 21) to good administration (Art. 41), each marked relevant or not with reasons;
- Risk-of-harm table (likelihood, severity, driver), human oversight implementation matching your Article 26(2) set-up, and measures-if-risks-materialise including escalation, suspension criteria, redress and complaints;
- Conclusion and sign-off, the authority notification step, and the worked mini-example.
How to use it
Run the Section 1 scope test first and record the outcome either way — "not in scope, and why" is itself valuable evidence. If in scope, complete Sections 3–10 before first use, drawing risks from the provider's documented limitations, then notify your market surveillance authority in the form it indicates until the official Article 27(5) questionnaire exists. Keep the FRIA with your AI system inventory and align the oversight section with your human oversight SOP. Review whenever the system, your process or the affected groups change.
Related reading
- Risk Classification Assessment template
- Human Oversight Protocol template
- Timeline & deadlines
- Article 50 transparency
Frequently asked
Who must carry out a FRIA under the EU AI Act?+
Deployers of Annex III high-risk systems (except critical-infrastructure systems) that are bodies governed by public law or private entities providing public services — plus any deployer, public or private, using high-risk AI to evaluate creditworthiness or to price life and health insurance for natural persons. Most purely private companies outside those cases do not owe a FRIA.
Is there an official EU FRIA template?+
Not yet. Article 27(5) obliges the AI Office to develop a template questionnaire, including through an automated tool, but as of August 2026 neither has been published. Deployers in scope can use an internal template such as this one and reconcile with the official structure once released.
When does the FRIA obligation start to apply?+
With the Annex III high-risk regime — from 2 December 2027, following the Digital Omnibus (Regulation (EU) 2026/1744). The assessment must then be completed before the first use of the system in the deployment context, with results notified to the market surveillance authority.
Is a FRIA the same as a GDPR DPIA?+
No. A DPIA (Article 35 GDPR) assesses risks to personal data where processing is likely to result in a high risk; a FRIA assesses impacts on the full range of Charter fundamental rights in a specific deployment. They complement each other — Article 27 expressly allows building on a DPIA carried out for the same processing — but one does not discharge the other.
Primary sources
- Regulation (EU) 2024/1689 (consolidated)
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- AI Act Explorer — Article 27 (fundamental rights impact assessment)
This template ships in the EU AI Act Kit
24 fill-in documents in Word and Excel — launch price €149, twelve months of updates included.
See the full kit