What the Article requires
Article 27 obliges specific deployer categories — public-sector bodies, private bodies providing public services, deployers of credit-scoring and insurance-pricing AI — to perform a Fundamental Rights Impact Assessment before first use of a high-risk AI system. The assessment must describe deployment processes, the categories of natural persons affected, specific risks of harm to affected persons, human-oversight measures, and the measures to be taken if risks materialise.
In engineering terms
FRIAs sit alongside DPIAs (under GDPR Article 35) but are more focused on fundamental rights — non-discrimination, dignity, freedom of expression, fair trial — rather than data-protection narrowly. Template-and-fill works once an enterprise has done one or two; the first one is the hardest. MindMap maintains a FRIA template developed against the Council of Europe FRIA framework that maps cleanly to the EU AI Act's specific requirements.
Compliance checklist
- ✓FRIA performed before first deployment of in-scope high-risk AI
- ✓Deployment process description
- ✓Categories of natural persons affected identified
- ✓Specific risks of harm catalogued
- ✓Human-oversight measures matched to risks
- ✓Risk-materialisation response plan
Terms used here
All Articles in the reference · The EU AI Act compliance architecture
Need audit-survivable evidence for Article 27?
MindMap runs a 90-day path from standing start to audit-survivable evidence. Talk to the engineering team.