HomeCybersecurityAI Fundamental Rights Impact Assessment

⚖️ AI Fundamental Rights Impact Assessment (FRIA)

Guided questionnaire for the Fundamental Rights Impact Assessment required by Article 27 of the EU AI Act (Regulation (EU) 2024/1689) from certain deployers of high-risk AI systems — deployment process, affected persons, specific risks of harm, human oversight and mitigation measures — with a completeness score and an exportable FRIA report. 100% on-device.

Deployer & AI system
Regulation last reviewed: 9 Jul 2026
Article 27(1) required elements

Article 27(1) lists the elements a deployer's Fundamental Rights Impact Assessment must cover before putting a high-risk AI system into use. Complete each element below in your own words — the generated report compiles them into a single FRIA document.

Art. 27(1)(a)

Deployer's process description

Describe the process(es) in which the high-risk AI system will be used, in line with its intended purpose.

Art. 27(1)(b)

Period of time & frequency of use

The period of time within which, and the frequency with which, the system is intended to be used.

Art. 27(1)(c)

Categories of natural persons & groups likely affected

Select every category of person or group that could be affected by the use of this AI system in this specific context.

Art. 27(1)(d)

Specific risks of harm

Select the fundamental rights that could specifically be harmed for the persons/groups identified above, taking into account the provider's instructions for use.

Art. 27(1)(e)

Human oversight measures

Describe the implementation of human oversight measures, according to the AI system's instructions for use.

Art. 27(1)(f)

Risk-mitigation & governance measures

Measures to be taken if the identified risks materialize, including internal governance arrangements and complaint mechanisms.

Completeness

⚠️ This tool is a self-assessment aid based on Article 27 of Regulation (EU) 2024/1689 (the EU AI Act). It uses a representative structure of the required elements, not the full legal text, and it is not legal advice. Whether Article 27 obligates your organization to conduct a FRIA depends on your exact role, the specific high-risk AI system and its Annex III use case — confirm applicability, the notification requirement to your market surveillance authority, and the interplay with any GDPR Data Protection Impact Assessment with qualified counsel. Nothing you enter here leaves your browser.