GovCompass

FRIA step by step: how to conduct a Fundamental Rights Impact Assessment

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, including the 2026 Omnibus amendments.

A Fundamental Rights Impact Assessment (FRIA) under Art. 27 is conducted step by step: describe the system and its purpose, identify affected persons, assess the impact on each fundamental rights dimension, define mitigation measures, and document the residual risk before deployment.

Updated: June 2026

Introduction: the FRIA as a governance exercise

The Fundamental Rights Impact Assessmentfundamental rights impact assessmentAn assessment that certain deployers of high-risk AI must perform to identify and mitigate the system's risks to people's fundamental rights.Open full entry → (FRIAFRIAFundamental Rights Impact Assessment: required of public bodies and certain private deployers before using some high-risk AI systems under the EU AI Act.Open full entry →) required by Art. 27 of the EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → is designed to answer one fundamental question: what happens to the fundamental rights of real people when this AI systemAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → is deployed? It is not a documentation exercise, it is a structured inquiry that should genuinely change how an organization approaches AI deployment.

This guide provides a detailed, practical walkthrough of the six-step FRIA process, with specific guidance for Dutch public sector and regulated organizations.

Before you begin: who needs a FRIA?

A FRIA is required of three groups of deployersdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry →: bodies governed by public law; private operators providing public services; and all deployers of Annex IIIAnnex IIIThe EU AI Act's list of high-risk use-case areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.Open full entry → point 5(b) and 5(c) systems (creditworthiness assessment of natural personsnatural personA living human individual, as distinct from a legal person such as a company; the holder of data-protection and AI-Act rights.Open full entry →, and riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → assessment and pricing in life and health insurance), whether public or private. For our financial-sector readers this third category is the decisive one. Annex III point 2 (critical infrastructure) is excluded from the FRIA duty. Concretely this covers central and local government, public hospitals, public universities, social housing corporations, private providersproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry → of public services, and every bank or insurer running a 5(b)/(c) system.

The FRIA must be completed before deployment begins, not after. Retrospective FRIAs have no legal standing under Art. 27.

Step 1: system scoping (week 1)

Document the AI system precisely:

  • System name, vendor, version
  • Intended purpose and specific use case
  • How the system works (at a conceptual level, you do not need the source code)
  • Which decisions the system informs or makes
  • The categories of individuals it processes data about or affects
  • The scale of deployment (how many people affected per year?)
  • Whether similar systems have been used before and what happened

Output: A 1–2 page system description that the rest of the FRIA builds on.

Step 2: stakeholder mapping (week 1–2)

Identify every group whose rights could be affected by the AI system:

  • Direct subjects: individuals whose data is processed and who receive AI-influenced decisions
  • Indirect stakeholders: family members, employees, communities who may be affected by decisions made about direct subjects
  • Vulnerable groups: children, elderly, people with disabilities, people in economic hardship, who may face heightened risks
  • Protected characteristics: ethnic minority groups, LGBTQ+ individuals, religious minorities, who may face discrimination risk

Output: A stakeholder map with a narrative explanation of how each group is connected to the AI system.

Step 3: rights mapping (week 2–3)

For each stakeholder group, identify which fundamental rights are at risk. Work through the EU Charter systematically:

Charter articleRightRelevance to this AI system
Art. 1Human dignity[High/Medium/Low/None]
Art. 7–8PrivacyprivacyThe principle that personal data used by or produced through an AI system stays within the purpose and the legal basis it was collected for. Three routes cause most of the trouble: personal data in training material that was never intended for it, model output that reproduces what the model retained, and purpose creep, where a system built for one use drifts into another the original basis never covered. The GDPR governs this in full, and the EU AI Act adds data governance duties for high-risk systems (Article 10). See DPIA, purpose limitation, responsible AI.Open full entry → and data protection[Assessment]
Art. 21Non-discrimination[Assessment]
Art. 24Children's rights[Assessment]
Art. 47Right to a fair hearing[Assessment]

Output: A completed rights mapping table with brief justification for each assessment.

Step 4: risk assessment (week 3)

For each rights risk identified as High or Medium:

  • Probability: How likely is this harmharmHarm is the concrete damage an AI system causes or can cause: to a person, a group, an organization, or society. A risk is that same damage seen in advance, weighed by likelihood and severity; a harm that has occurred is remedied rather than managed.Open full entry → to occur? (1–5 scale)
  • Severity: How serious is the harm if it occurs? (1–5 scale)
  • Breadth: How many people could be affected? (1–5 scale)
  • Risk score: Probability × Severity × Breadth
  • Priority: High (score 27–125), Medium (8–26), Low (1–7)

Output: A risk matrix prioritizing the top rights risks for mitigation.

Step 5: mitigation measures (week 3–4)

For each High and Medium priority risk: design specific, verifiable mitigation measures. Examples:

  • Non-discrimination risk: Regular algorithmic auditing for demographic parity; independent biasbiasA systematic skew in data, model behavior, or outcomes that treats one group differently from another without justification. Bias usually enters through training data that reflects historical patterns. For high-risk AI systems, Article 10 of the EU AI Act requires examination of datasets for possible biases and measures to detect, prevent, and mitigate them. See fairness, proxy discrimination.Open full entry → testing before deployment
  • Right to fair hearing: Mandatory written explanation of AI-influenced decisions; appeals process documented in procedure manual
  • Privacy risk: Data minimizationdata minimizationProcessing only data that is adequate, relevant and necessary. In ML it is implemented through pseudonymization, feature selection, synthetic data and privacy-enhancing techniques.Open full entry → review; GDPRGDPRRegulation (EU) 2016/679, the General Data Protection Regulation, the EU's law on the processing of personal data. It applies to AI wherever personal data enters training, inputs, outputs, or logs, and it operates alongside the EU AI Act rather than being replaced by it. See controller, processor, lawful basis, DPIA.Open full entry → DPIADPIAData Protection Impact Assessment: required before likely-high-risk processing (systematic profiling with significant effects, large-scale special categories, public monitoring); AI development triggers it constantly.Open full entry → with DPO sign-off
  • Dignity risk: Human override mandatory for all negative decisions affecting individuals

Each measure must have: a responsible owner, an implementation deadline, and a verification method.

Step 6: residual risk assessment and sign-off (week 4)

After applying mitigation measures, re-assess residual risksresidual riskThe risk that remains after controls have reduced it. No control reduces a risk to zero, and not every control is worth its cost, so a deliberate judgment is made: whether the cost of further control is justified by the reduction it would buy, and whether the remaining risk is acceptable against the organization's risk appetite. This is a design-level judgment, where execution reports back up and governance accepts the residual risk, calls for more control, or declines the use case. EU AI Act Art. 9(5) requires it to be judged acceptable per hazard and overall. See risk, control, risk appetite.Open full entry →. For each risk: what is the residual probability and severity after mitigation? If any residual risk remains High, consider whether deployment should proceed, and under what additional conditions.

Sign-off required from: the AI Officer, the DPO (for data-related risks), legal counsel, and the relevant management level (typically the Management Team member responsible for the affected function).

Compliance checklist

  1. Has the FRIA been completed before deployment?
  2. Does the FRIA cover all six steps?
  3. Has the stakeholder mappingstakeholder mappingSystematically identifying who is affected by a system (users, affected non-users, vulnerable groups, organization, society) and what each stands to gain or lose.Open full entry → identified vulnerable groups?
  4. Have all Charter rights been assessed (not just privacy)?
  5. Are mitigation measures specific, verifiable, and assigned to named owners?
  6. Has residual risk been assessed and documented?
  7. Has sign-off been obtained from AI Officer, DPO, and management?
  8. Is the FRIA filed and available for supervisory review?

The FRIA is core AIGP exam material; see the AIGP exam guide.

Legal referencesArt. 27GDPR
Continue withFairness
Share Share on LinkedIn

More on Fairness

AI in recruitment: risks, bias and what the EU AI Act already requires

Analysis

AI recruitment systems fall under Annex III of the EU AI Act as high-risk, which triggers the full deployer obligations of Article 26, human oversight, data quality, monitoring, log retention, and a Fundamental Rights Impact Assessment under Article 27. These duties cannot be transferred to the software vendor.

Art. 10 EU AI Act: data and data governance for high-risk AI

Reference

Art. 10 requires that the training, validation, and testing data for high-risk AI systems meets quality criteria: relevant, sufficiently representative, and as free of errors and complete as possible for the intended purpose. It also requires documented data governance practices covering collection, preparation, bias examination, and gap mitigation, and it permits the limited processing of special-category data where strictly necessary to detect and correct bias, under safeguards.

Art. 27 EU AI Act: Fundamental Rights Impact Assessment (FRIA)

Reference

Art. 27 requires certain deployers, public bodies and private deployers in defined sectors such as credit and insurance, to conduct a Fundamental Rights Impact Assessment (FRIA) before deploying a high-risk AI system, examining the impact on fundamental rights and the mitigation measures.

Art. 5 EU AI Act: all 8 prohibited AI practices explained

Reference

Art. 5 lists the eight prohibited AI practices, including subliminal manipulation, exploitation of vulnerable groups, social scoring, and untargeted facial-recognition scraping. These prohibitions are absolute, apply to every organization regardless of size, and have been in force since 2 February 2025.