EU AI Act · Art. 27

Fundamental rights impact assessment (FRIA)

Assess the impact on fundamental rights before first use: processes, categories of affected persons, risks, oversight, and mitigation. Triggered for public bodies and private providers of public services, and for any deployer using high-risk AI for creditworthiness or life/health insurance pricing (Annex III 5(b)-(c)); critical-infrastructure systems are excepted.

What do you actually have to do?

Assess the impact on fundamental rights before first use: processes, categories of affected persons, risks, oversight, and mitigation. Triggered for public bodies and private providers of public services, and for any deployer using high-risk AI for creditworthiness or life/health insurance pricing (Annex III 5(b)-(c)); critical-infrastructure systems are excepted.

Statutory basis: Art. 27 — https://artificialintelligenceact.eu/article/27/

Who does this apply to?

  • Deployer

When does it apply?

  • 2027-12-02 — 2 December 2027 (deferred by the Digital Omnibus)

Does ISO 42001 or NIST AI RMF cover this duty?

Requirement-level mappings from Shieldra's crosswalk pack (v2026.07.30). Partial mappings contribute evidence but deliberately do not count as coverage.

Mapped requirementStrengthWhy (and what’s missing)
ISO/IEC 42001 6.1.4PartialA one-shot pre-use FRIA contributes to 6.1.4 but is not its repeatable lifecycle impact-assessment process; reverse misses Art. 27 prescribed fields and the authority notification.
ISO/IEC 42001 A.5PartialA single FRIA contributes to A.5 but not its established lifecycle assessment process across the AI portfolio; reverse misses Art. 27 content and the market-surveillance notification.
ISO/IEC 42001 8.4PartialRe-performing impact assessments on significant change keeps a FRIA current, but the initial pre-use assessment must exist first.
NIST AI RMF MAP-5.1PartialA documented likelihood-and-magnitude assessment of harms to affected people is the analytical core of a FRIA, but Art. 27 prescribes processes, affected-person categories, oversight, and mitigation content.

Disclaimer

Compliance guidance, not legal advice. Confirm obligations with counsel. Pack verified 2026-09-16.

Frequently asked questions

What does "Fundamental rights impact assessment (FRIA)" require?

Assess the impact on fundamental rights before first use: processes, categories of affected persons, risks, oversight, and mitigation. Triggered for public bodies and private providers of public services, and for any deployer using high-risk AI for creditworthiness or life/health insurance pricing (Annex III 5(b)-(c)); critical-infrastructure systems are excepted.

When does this obligation apply?

2 December 2027 (deferred by the Digital Omnibus)

Who does this obligation apply to?

The deployer role under the EU AI Act. Statutory basis: Art. 27.