Fundamental Rights Impact Assessment
A FRIA before first use, not after the first complaint.
What Is Fundamental Rights Impact Assessment?
Learn how Article 27 of the EU AI Act requires public bodies, public-service providers, and credit or insurance scoring deployers using high-risk AI to conduct a Fundamental Rights Impact Assessment before first use. Complete a FRIA for an automated social housing benefit eligibility system, assessing impacts on non-discrimination, privacy, effective remedy, and human dignity.
What You'll Learn in Fundamental Rights Impact Assessment
- Understand when and why a FRIA is required under Article 27 of the EU AI Act
- Distinguish between a FRIA and a GDPR Data Protection Impact Assessment
- Identify all categories of affected persons for a high-risk AI system
- Assess which fundamental rights are impacted by an AI system making benefit eligibility decisions
- Define appropriate mitigation measures and monitoring plans for ongoing compliance
Fundamental Rights Impact Assessment — Training Steps
-
Article 27: Fundamental Rights Impact Assessment
Article 27 of the EU AI Act requires certain deployers of high-risk AI systems (public bodies, private entities providing public services, and deployers of credit-scoring or life and health insurance AI) to conduct a Fundamental Rights Impact Assessment before first use. A social housing benefit system run for municipal councils is in scope: it decides eligibility for public assistance (Annex III 5(a)). A FRIA examines how the AI system might affect fundamental rights - dignity, non-discrimination, privacy, freedom of expression, and the right to an effective remedy. A FRIA differs from a GDPR Data Protection Impact Assessment (DPIA). While a DPIA focuses solely on data protection risks, a FRIA covers all fundamental rights. Both assessments may be required for the same system, and they can be conducted together.
-
Deployment Details
An email arrives from Petra Novak, the project manager responsible for the social housing AI deployment. She provides the details Alice needs to begin the FRIA.
-
FRIA Guidance Document
Before starting the assessment, Alice opens the FRIA guidance document linked in Petra's email. It explains each section of the assessment, the difference between a FRIA and a DPIA, and practical tips for completing each part thoroughly.
-
Open the FRIA Form
With the guidance reviewed, Alice clicks Continue to open the FRIA checklist - five sections covering the pillars of a rights impact assessment.
-
Section 1: System Description
The first section asks Alice to document the AI system's purpose, the people it affects, and the scope of its deployment. For this system, the affected persons include: Benefit applicants - many in vulnerable financial situations, directly affected by eligibility decisions. Case workers - who rely on the AI's recommendations to issue final decisions. Applicants' families - who depend on the housing benefits the applicant is seeking. The system makes decisions that directly affect access to housing - a fundamental need.
-
Section 1 Check
-
Section 2: Fundamental Rights Analysis
This is the most critical section of the FRIA. Alice must assess which fundamental rights the AI system could affect: Right to non-discrimination - the AI may discriminate based on family composition, nationality, or residential address, using these as proxy variables for protected characteristics. Right to privacy - the system processes sensitive personal data including income, employment, and family information. Right to an effective remedy - applicants must be able to challenge AI-driven rejections through a clear, accessible appeal process. Right to human dignity - automated decisions about housing access affect a fundamental aspect of a person's life and dignity.
-
Section 2 Check
-
Section 3: Risk Assessment
Alice scores each rights impact for severity and likelihood. Housing-access denial is high severity; likelihood depends on bias controls. The combined rating drives which mitigations get priority.
-
Section 3 Check
Security Framework Coverage
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
GDPR
- Art. 35 Data protection impact assessment
EU AI Act
- Art. 27 Fundamental rights impact assessment for high-risk AI systems