Context, affected groups, harms, oversight, mitigation, remedy, and continuity.
Make the impact assessment inspectable before the system is deployed.
The fundamental-rights impact assessment must remain separate from the high-risk classification, provider risk assessment, data-protection impact assessment, deployment decision, and final legal conclusion. This workspace preserves the deployer’s context, affected persons, harm pathways, governance arrangements, mitigation, remedy, notification, and reassessment record.
Sections currently marked as having a declared evidence package.
Sections currently marked as independently reviewed.
No legal determination or authority submission is created by this state.
Identify the deployer category before assessing the impact.
Article 27 applies to specified deployers of certain high-risk systems. The selected category below is only a declaration and must be independently tested against the regulation and current official guidance.
Preserve each required layer without collapsing evidence into conclusion.
Deployer process and intended use
Describe the deployer process in which the high-risk AI system will be used and bind that process to the provider-declared intended purpose.
- What operational process will use the system?
- What decision, recommendation, prioritisation, or action can follow?
- Does the actual use remain within the provider-declared intended purpose?
- Which people and organisational roles control the process?
- Process map
- System identity and version
- Provider instructions for use
- Deployment-context record
- Decision and action pathway
- A vendor description does not prove the actual deployment context.
- An intended-purpose statement does not prove the system is used accordingly.
Period and frequency of use
Preserve how long, how often, and under which operating conditions the high-risk AI system is intended to be used.
- When will deployment begin and end?
- Is use continuous, periodic, event-triggered, or discretionary?
- How many people or decisions may be affected?
- Are peak, emergency, or exceptional conditions materially different?
- Deployment schedule
- Frequency and volume estimates
- Operating-condition record
- Exceptional-use procedure
- Change history
- A pilot-period assessment does not automatically cover scaled deployment.
- Average use does not represent exceptional or peak conditions.
Affected natural persons and groups
Identify the categories of natural persons and groups likely to be affected in the specific context of use.
- Who is directly subject to the system?
- Who may be indirectly affected by its outputs?
- Are children, disabled persons, workers, patients, applicants, consumers, migrants, or other vulnerable groups involved?
- Could effects differ across demographic or social groups?
- Affected-person inventory
- Group and vulnerability analysis
- Direct and indirect impact map
- Stakeholder input
- Population and context data
- A general user persona does not prove all affected groups were considered.
- Absence of complaints does not prove absence of impact.
Specific risks of harm to fundamental rights
Identify specific harm pathways for the affected persons and groups, taking account of provider information and the actual context of use.
- Which rights could be affected?
- How could the system create, amplify, or conceal harm?
- What is the severity, likelihood, duration, and reversibility of each harm?
- Could errors compound through downstream human or automated decisions?
- Fundamental-rights risk register
- Provider limitation evidence
- Historical and contextual evidence
- Severity and likelihood method
- Downstream consequence map
- A generic risk list does not prove context-specific analysis.
- Low model error does not prove low fundamental-rights impact.
Human oversight and governance arrangements
Define who can understand, challenge, intervene, override, stop, and accept responsibility for system use.
- Who is authorised to oversee the system?
- What information does the overseer receive?
- Can the person intervene before harm becomes consequential?
- How are automation bias, workload, and conflicts of interest addressed?
- Oversight authority record
- Competency evidence
- Intervention and stop controls
- Escalation procedure
- Override and outcome logs
- A named human does not prove effective oversight.
- An override button does not prove a person can use it meaningfully.
Measures for preventing and responding to harm
Preserve technical, organisational, procedural, and human measures that prevent harm or respond when risk materialises.
- Which preventive controls apply before the system is used?
- Which thresholds trigger HOLD, suspension, review, or withdrawal?
- What happens when harm or elevated risk is detected?
- Who verifies that corrective measures worked?
- Mitigation plan
- Declared thresholds
- Suspension and withdrawal route
- Corrective-action record
- Post-intervention verification
- A planned mitigation does not prove implementation.
- Implementation does not prove effectiveness without outcome evidence.
Complaint, explanation, contest, and remedy pathways
Describe how affected persons can obtain information, submit complaints, challenge outcomes, seek human review, and access remedy.
- How is an affected person informed?
- How can the person contest or seek review of an outcome?
- Is the pathway accessible, timely, and understandable?
- How are complaint outcomes and corrective actions preserved?
- Notice and explanation process
- Complaint channel
- Human-review procedure
- Remedy and redress record
- Complaint outcome logs
- A contact form does not prove an effective remedy pathway.
- An explanation does not prove the underlying decision was lawful or correct.
Stakeholder and independent-expert involvement
Preserve relevant participation by representatives of affected groups, independent experts, civil society, workers, or other stakeholders where appropriate.
- Which affected groups were invited to contribute?
- Were independent experts involved?
- What concerns, objections, or alternatives were raised?
- How did stakeholder input change the assessment or deployment?
- Stakeholder map
- Consultation invitations
- Meeting and submission records
- Objection and response log
- Resulting change record
- Consultation does not transfer accountability to participants.
- Attendance does not prove concerns were addressed.
Authority notification and related assessments
Preserve the notification route and identify where a data-protection impact assessment or other assessment already addresses part of the obligation.
- Which market-surveillance authority is relevant?
- What assessment result must be notified?
- Has a DPIA already addressed overlapping issues?
- How does the FRIA complement rather than duplicate that assessment?
- Authority identity
- Notification package
- Submission and receipt record
- DPIA or related assessment map
- Overlap and gap analysis
- Preparing a notification does not prove submission.
- A DPIA does not automatically satisfy every FRIA requirement.
Change monitoring and reassessment
Define the changes that invalidate or reopen the assessment and preserve the resulting review, correction, or suspension.
- Which system, process, population, purpose, or operating changes trigger reassessment?
- How are changes detected?
- Can deployment continue while reassessment is incomplete?
- How are superseded assessments retained?
- Change-trigger register
- Version and deployment monitoring
- Reassessment procedure
- Suspension decision record
- Supersession history
- A completed assessment does not remain valid after every material change.
- Version history alone does not prove impacts were reassessed.
The assessment should test concrete pathways of impact.
Human dignity
Could the system objectify, manipulate, stigmatise, or deny meaningful human agency?
Equality and non-discrimination
Could performance, data, thresholds, or deployment create unequal treatment or indirect discrimination?
Privacy and data protection
Could collection, inference, combination, retention, or disclosure exceed justified boundaries?
Freedom of expression and information
Could ranking, moderation, generation, or access controls suppress or distort lawful expression or information?
Fair working conditions
Could monitoring, evaluation, allocation, discipline, or termination routes create unjustified worker harm?
Access to services and social protection
Could the system improperly restrict healthcare, education, housing, credit, insurance, or public benefits?
Effective remedy and fair process
Can affected persons understand, contest, correct, and obtain meaningful human review?
Rights of children and vulnerable persons
Are age, dependency, disability, power imbalance, and heightened susceptibility addressed?
The assessment must remain connected to deployment authority and outcome.
Applicability
Establish whether the deployer, system, and use context fall within the Article 27 route.
Context record
Preserve process, duration, frequency, system identity, intended purpose, and deployment conditions.
Affected parties
Identify people and groups exposed directly or indirectly to consequential effects.
Harm and mitigation
Map rights risks, thresholds, oversight, controls, complaint, remedy, and response.
Review and notification
Preserve independent challenge, corrections, related assessments, and authority notification.
Deployment outcome
Record ALLOW, HOLD, DENY, ESCALATE, condition, suspension, reassessment, or withdrawal.
Move the impact record into review, governance, and preserved execution.
High-Risk Systems
Return to classification, lifecycle duties, conformity, deployment, and monitoring.
02Governed Records
Preserve affected-party, harm, mitigation, consultation, notification, and outcome records.
03Governance Routes
Convert risks and mitigations into explicit gates, thresholds, holds, escalation, and outcomes.
04Independent Review
Find legal, rights, sector, accessibility, labour, data-protection, and technical specialists.
05Post a FRIA Need
Create a bounded opportunity for assessment, affected-party analysis, evidence mapping, or review.
A completed form does not prove that fundamental rights are protected.
The assessment must remain tied to the actual system, version, deployer process, affected population, risk pathways, implemented controls, complaint and remedy routes, independent review, notification, change history, and deployment outcome.