Home · EU AI Act · Articles · Article 27
EU AI Act · Engineering reference

Article 27 — Fundamental Rights Impact Assessment (FRIA)

Public-sector deployers and certain essential-services deployers must conduct a Fundamental Rights Impact Assessment before first deployment.

Audit-survivable
17%
of 50 EU-exposed enterprises in MindMap's 2026 readiness benchmark

What the Article requires

Article 27 obliges specific deployer categories — public-sector bodies, private bodies providing public services, deployers of credit-scoring and insurance-pricing AI — to perform a Fundamental Rights Impact Assessment before first use of a high-risk AI system. The assessment must describe deployment processes, the categories of natural persons affected, specific risks of harm to affected persons, human-oversight measures, and the measures to be taken if risks materialise.

In engineering terms

FRIAs sit alongside DPIAs (under GDPR Article 35) but are more focused on fundamental rights — non-discrimination, dignity, freedom of expression, fair trial — rather than data-protection narrowly. Template-and-fill works once an enterprise has done one or two; the first one is the hardest. MindMap maintains a FRIA template developed against the Council of Europe FRIA framework that maps cleanly to the EU AI Act's specific requirements.

Compliance checklist

  • ✓FRIA performed before first deployment of in-scope high-risk AI
  • ✓Deployment process description
  • ✓Categories of natural persons affected identified
  • ✓Specific risks of harm catalogued
  • ✓Human-oversight measures matched to risks
  • ✓Risk-materialisation response plan

Terms used here

EU AI ActAnnex III high-risk AI

All Articles in the reference · The EU AI Act compliance architecture

Need audit-survivable evidence for Article 27?

MindMap runs a 90-day path from standing start to audit-survivable evidence. Talk to the engineering team.

Download the whitepaper →Check your tier →Book a scoping call →