ARTICLE 27 FRIA WORKSPACE

Make the impact assessment inspectable before the system is deployed.

The fundamental-rights impact assessment must remain separate from the high-risk classification, provider risk assessment, data-protection impact assessment, deployment decision, and final legal conclusion. This workspace preserves the deployer’s context, affected persons, harm pathways, governance arrangements, mitigation, remedy, notification, and reassessment record.

Assessment architecture, not legal advice.

This page does not determine Article 27 applicability, complete an official questionnaire, notify an authority, validate evidence, or certify lawful deployment.

Assessment sections10

Context, affected groups, harms, oversight, mitigation, remedy, and continuity.

Evidence declared0

Sections currently marked as having a declared evidence package.

Review declared0

Sections currently marked as independently reviewed.

Current stateAPPLICABILITY REVIEW

No legal determination or authority submission is created by this state.

STEP 01 · APPLICABILITY CONTEXT

Identify the deployer category before assessing the impact.

Article 27 applies to specified deployers of certain high-risk systems. The selected category below is only a declaration and must be independently tested against the regulation and current official guidance.

Declared applicability contextOther or uncertain
Assessment stateAPPLICABILITY REVIEW
STEP 02 · ASSESSMENT RECORD

Preserve each required layer without collapsing evidence into conclusion.

10 section(s)
01PROCESS
EVIDENCE OPENREVIEW OPEN

Deployer process and intended use

Describe the deployer process in which the high-risk AI system will be used and bind that process to the provider-declared intended purpose.

Questions to resolve
  • What operational process will use the system?
  • What decision, recommendation, prioritisation, or action can follow?
  • Does the actual use remain within the provider-declared intended purpose?
  • Which people and organisational roles control the process?
Evidence to preserve
  • Process map
  • System identity and version
  • Provider instructions for use
  • Deployment-context record
  • Decision and action pathway
Claims this layer cannot support alone
  • A vendor description does not prove the actual deployment context.
  • An intended-purpose statement does not prove the system is used accordingly.
02DURATION
EVIDENCE OPENREVIEW OPEN

Period and frequency of use

Preserve how long, how often, and under which operating conditions the high-risk AI system is intended to be used.

Questions to resolve
  • When will deployment begin and end?
  • Is use continuous, periodic, event-triggered, or discretionary?
  • How many people or decisions may be affected?
  • Are peak, emergency, or exceptional conditions materially different?
Evidence to preserve
  • Deployment schedule
  • Frequency and volume estimates
  • Operating-condition record
  • Exceptional-use procedure
  • Change history
Claims this layer cannot support alone
  • A pilot-period assessment does not automatically cover scaled deployment.
  • Average use does not represent exceptional or peak conditions.
03AFFECTED
EVIDENCE OPENREVIEW OPEN

Affected natural persons and groups

Identify the categories of natural persons and groups likely to be affected in the specific context of use.

Questions to resolve
  • Who is directly subject to the system?
  • Who may be indirectly affected by its outputs?
  • Are children, disabled persons, workers, patients, applicants, consumers, migrants, or other vulnerable groups involved?
  • Could effects differ across demographic or social groups?
Evidence to preserve
  • Affected-person inventory
  • Group and vulnerability analysis
  • Direct and indirect impact map
  • Stakeholder input
  • Population and context data
Claims this layer cannot support alone
  • A general user persona does not prove all affected groups were considered.
  • Absence of complaints does not prove absence of impact.
04HARMS
EVIDENCE OPENREVIEW OPEN

Specific risks of harm to fundamental rights

Identify specific harm pathways for the affected persons and groups, taking account of provider information and the actual context of use.

Questions to resolve
  • Which rights could be affected?
  • How could the system create, amplify, or conceal harm?
  • What is the severity, likelihood, duration, and reversibility of each harm?
  • Could errors compound through downstream human or automated decisions?
Evidence to preserve
  • Fundamental-rights risk register
  • Provider limitation evidence
  • Historical and contextual evidence
  • Severity and likelihood method
  • Downstream consequence map
Claims this layer cannot support alone
  • A generic risk list does not prove context-specific analysis.
  • Low model error does not prove low fundamental-rights impact.
05OVERSIGHT
EVIDENCE OPENREVIEW OPEN

Human oversight and governance arrangements

Define who can understand, challenge, intervene, override, stop, and accept responsibility for system use.

Questions to resolve
  • Who is authorised to oversee the system?
  • What information does the overseer receive?
  • Can the person intervene before harm becomes consequential?
  • How are automation bias, workload, and conflicts of interest addressed?
Evidence to preserve
  • Oversight authority record
  • Competency evidence
  • Intervention and stop controls
  • Escalation procedure
  • Override and outcome logs
Claims this layer cannot support alone
  • A named human does not prove effective oversight.
  • An override button does not prove a person can use it meaningfully.
06MITIGATION
EVIDENCE OPENREVIEW OPEN

Measures for preventing and responding to harm

Preserve technical, organisational, procedural, and human measures that prevent harm or respond when risk materialises.

Questions to resolve
  • Which preventive controls apply before the system is used?
  • Which thresholds trigger HOLD, suspension, review, or withdrawal?
  • What happens when harm or elevated risk is detected?
  • Who verifies that corrective measures worked?
Evidence to preserve
  • Mitigation plan
  • Declared thresholds
  • Suspension and withdrawal route
  • Corrective-action record
  • Post-intervention verification
Claims this layer cannot support alone
  • A planned mitigation does not prove implementation.
  • Implementation does not prove effectiveness without outcome evidence.
07COMPLAINTS
EVIDENCE OPENREVIEW OPEN

Complaint, explanation, contest, and remedy pathways

Describe how affected persons can obtain information, submit complaints, challenge outcomes, seek human review, and access remedy.

Questions to resolve
  • How is an affected person informed?
  • How can the person contest or seek review of an outcome?
  • Is the pathway accessible, timely, and understandable?
  • How are complaint outcomes and corrective actions preserved?
Evidence to preserve
  • Notice and explanation process
  • Complaint channel
  • Human-review procedure
  • Remedy and redress record
  • Complaint outcome logs
Claims this layer cannot support alone
  • A contact form does not prove an effective remedy pathway.
  • An explanation does not prove the underlying decision was lawful or correct.
08STAKEHOLDERS
EVIDENCE OPENREVIEW OPEN

Stakeholder and independent-expert involvement

Preserve relevant participation by representatives of affected groups, independent experts, civil society, workers, or other stakeholders where appropriate.

Questions to resolve
  • Which affected groups were invited to contribute?
  • Were independent experts involved?
  • What concerns, objections, or alternatives were raised?
  • How did stakeholder input change the assessment or deployment?
Evidence to preserve
  • Stakeholder map
  • Consultation invitations
  • Meeting and submission records
  • Objection and response log
  • Resulting change record
Claims this layer cannot support alone
  • Consultation does not transfer accountability to participants.
  • Attendance does not prove concerns were addressed.
09NOTIFICATION
EVIDENCE OPENREVIEW OPEN

Authority notification and related assessments

Preserve the notification route and identify where a data-protection impact assessment or other assessment already addresses part of the obligation.

Questions to resolve
  • Which market-surveillance authority is relevant?
  • What assessment result must be notified?
  • Has a DPIA already addressed overlapping issues?
  • How does the FRIA complement rather than duplicate that assessment?
Evidence to preserve
  • Authority identity
  • Notification package
  • Submission and receipt record
  • DPIA or related assessment map
  • Overlap and gap analysis
Claims this layer cannot support alone
  • Preparing a notification does not prove submission.
  • A DPIA does not automatically satisfy every FRIA requirement.
10REASSESSMENT
EVIDENCE OPENREVIEW OPEN

Change monitoring and reassessment

Define the changes that invalidate or reopen the assessment and preserve the resulting review, correction, or suspension.

Questions to resolve
  • Which system, process, population, purpose, or operating changes trigger reassessment?
  • How are changes detected?
  • Can deployment continue while reassessment is incomplete?
  • How are superseded assessments retained?
Evidence to preserve
  • Change-trigger register
  • Version and deployment monitoring
  • Reassessment procedure
  • Suspension decision record
  • Supersession history
Claims this layer cannot support alone
  • A completed assessment does not remain valid after every material change.
  • Version history alone does not prove impacts were reassessed.
FUNDAMENTAL-RIGHTS LENS

The assessment should test concrete pathways of impact.

Human dignity

Could the system objectify, manipulate, stigmatise, or deny meaningful human agency?

Equality and non-discrimination

Could performance, data, thresholds, or deployment create unequal treatment or indirect discrimination?

Privacy and data protection

Could collection, inference, combination, retention, or disclosure exceed justified boundaries?

Freedom of expression and information

Could ranking, moderation, generation, or access controls suppress or distort lawful expression or information?

Fair working conditions

Could monitoring, evaluation, allocation, discipline, or termination routes create unjustified worker harm?

Access to services and social protection

Could the system improperly restrict healthcare, education, housing, credit, insurance, or public benefits?

Effective remedy and fair process

Can affected persons understand, contest, correct, and obtain meaningful human review?

Rights of children and vulnerable persons

Are age, dependency, disability, power imbalance, and heightened susceptibility addressed?

FRIA GOVERNANCE CHAIN

The assessment must remain connected to deployment authority and outcome.

01

Applicability

Establish whether the deployer, system, and use context fall within the Article 27 route.

02

Context record

Preserve process, duration, frequency, system identity, intended purpose, and deployment conditions.

03

Affected parties

Identify people and groups exposed directly or indirectly to consequential effects.

04

Harm and mitigation

Map rights risks, thresholds, oversight, controls, complaint, remedy, and response.

05

Review and notification

Preserve independent challenge, corrections, related assessments, and authority notification.

06

Deployment outcome

Record ALLOW, HOLD, DENY, ESCALATE, condition, suspension, reassessment, or withdrawal.

CONNECTED WORKSPACES

Move the impact record into review, governance, and preserved execution.

THE RECORD IS NOT THE DETERMINATION

A completed form does not prove that fundamental rights are protected.

The assessment must remain tied to the actual system, version, deployer process, affected population, risk pathways, implemented controls, complaint and remedy routes, independent review, notification, change history, and deployment outcome.

TA-14 Exchange Activity

Public activity recorded across the Exchange

Visitors

Page Views