For Heads-of · Practitioner
Fundamental Rights Impact Assessment Worksheet
An EU AI Act Article 27 worksheet structured against the six elements the Article actually requires, with the scope determination most assessments skip and the regulator notification most templates omit.
- fria
- eu-ai-act
- article-27
- impact assessment
- compliance
Why this tool exists
Let an in-scope deployer complete a fundamental rights impact assessment that can be shown to be complete against the statutory text. Each section maps to one lettered element of Article 27(1), in statutory order, so that transposing the assessment into the AI Office template questionnaire promised by Article 27(5) becomes a mapping exercise instead of a rewrite.
How it's used
Used before a high-risk AI system is put into use by a public body, a private entity providing public services, or any deployer of an Annex III 5(b) credit scoring system or 5(c) life and health insurance pricing system. Also used by organisations outside Article 27 who need a proportionate impact assessment under ISO/IEC 42001 Clause 6.1.4, and by anyone who needs a defensible record that they considered the question and concluded they were out of scope.
What you get
Eleven working sections across 12 pages: a scope determination, system and process description, period and frequency of use, affected persons with a fundamental rights checklist, a harm analysis table, human oversight measures, response measures and complaint mechanism, DPIA mapping, a notification record, version control, and an appendix tracing every section to its Article 27(1) element.
The section most templates skip
Section 1 establishes whether Article 27 binds you at all. It is written to work when the answer is no, because a recorded scope determination is a genuine governance artefact and it stops the question being re-litigated every time somebody reads a headline.
The step most templates omit
Article 27(3) requires the deployer to notify the market surveillance authority on completion, submitting the filled-out template. An assessment sitting in a governance folder does not discharge Article 27. Section 9 records the authority, any exemption relied on, and the submission itself.
Two things that catch people out
Element (d) depends on the provider's Article 13 information package, so an incomplete package from your vendor blocks your own compliance and becomes a procurement conversation with a lead time. Element (f) asks for a complaint mechanism, which is an operational build with owners and service levels rather than a paragraph.
A note on timing
Article 27 sits in Chapter III, Section 3. The AI Omnibus deferred Chapter III obligations for stand-alone Annex III systems to 2 December 2027. On the structural reading Article 27 moves with them, and the worksheet says so rather than asserting a date. Confirm the current position against the consolidated text before relying on any deadline.
Further reading
See the companion article, AI Impact Assessments Compared, for how a FRIA differs from a DPIA and an AIA, and the AI impact assessment process control for the procedural counterpart.
Available formats
Downloads route through a short-lived signed link.
Framework and clause references
| Framework | Clause | Title |
|---|---|---|
| ISO/IEC 42001:2023 | Annex A.5 | Assessing impacts of AI systems |
| EU AI Act | Article 27 | Fundamental rights impact assessment |
| ISO/IEC 42001:2023 | Clause 6 | Planning & risk |