EU AI Act · Art. 27
Fundamental rights impact assessment (FRIA)
Assess the impact on fundamental rights before first use: processes, categories of affected persons, risks, oversight, and mitigation. Triggered for public bodies and private providers of public services, and for any deployer using high-risk AI for creditworthiness or life/health insurance pricing (Annex III 5(b)-(c)); critical-infrastructure systems are excepted.
By the Shieldra Compliance Team · Last updated 2026-07-29
What do you actually have to do?
Assess the impact on fundamental rights before first use: processes, categories of affected persons, risks, oversight, and mitigation. Triggered for public bodies and private providers of public services, and for any deployer using high-risk AI for creditworthiness or life/health insurance pricing (Annex III 5(b)-(c)); critical-infrastructure systems are excepted.
Statutory basis: Art. 27 — https://artificialintelligenceact.eu/article/27/
When does it apply?
- 2027-12-02 — deferred to 2 December 2027 (Digital Omnibus)
Does ISO 42001 or NIST AI RMF cover this duty?
Requirement-level mappings from Shieldra's crosswalk pack (v2026.07.30). Partial mappings contribute evidence but deliberately do not count as coverage.
| Mapped requirement | Strength | Why (and what’s missing) |
|---|
| ISO/IEC 42001 6.1.4 | Partial | A one-shot pre-use FRIA contributes to 6.1.4 but is not its repeatable lifecycle impact-assessment process; reverse misses Art. 27 prescribed fields and the authority notification. |
| ISO/IEC 42001 A.5 | Partial | A single FRIA contributes to A.5 but not its established lifecycle assessment process across the AI portfolio; reverse misses Art. 27 content and the market-surveillance notification. |
| ISO/IEC 42001 8.4 | Partial | Re-performing impact assessments on significant change keeps a FRIA current, but the initial pre-use assessment must exist first. |
| NIST AI RMF MAP-5.1 | Partial | A documented likelihood-and-magnitude assessment of harms to affected people is the analytical core of a FRIA, but Art. 27 prescribes processes, affected-person categories, oversight, and mitigation content. |
Disclaimer
Compliance guidance, not legal advice. Confirm obligations with counsel. Pack verified 2026-07-29.
Frequently asked questions
What does "Fundamental rights impact assessment (FRIA)" require?
Assess the impact on fundamental rights before first use: processes, categories of affected persons, risks, oversight, and mitigation. Triggered for public bodies and private providers of public services, and for any deployer using high-risk AI for creditworthiness or life/health insurance pricing (Annex III 5(b)-(c)); critical-infrastructure systems are excepted.
When does this obligation apply?
deferred to 2 December 2027 (Digital Omnibus)
Who does this obligation apply to?
The deployer role under the EU AI Act. Statutory basis: Art. 27.