Short answer. A Fundamental Rights Impact Assessment (FRIA) is a documented evaluation that a deployer of a high-risk AI system must complete before putting the system into use, set out in Article 27 of the EU AI Act (Regulation (EU) 2024/1689). It records 6 specific elements, from the people the system affects to the human-oversight measures, and the deployer must notify the national market surveillance authority of the result. The duty falls on three groups: public authorities, private bodies that provide public services, and any deployer using AI to assess creditworthiness or to price life and health insurance. The obligation applies from 2 August 2026, the date the high-risk rules take effect.
A FRIA is a structured analysis the deployer writes about its own use of a specific high-risk AI system, in its own context, before the first real decision is made. The deployer keeps it current as the deployment changes. The provider that built the system carries its own obligations under the Act, while the FRIA belongs to the deployer, because the deployer chooses where the system runs, on whom, and how. A bank that licenses a third-party credit-scoring model is the deployer, so the bank writes the FRIA, even though it did not build the model.
The assessment forces concrete answers. It names the processes the system feeds, the people it will judge, the harms it could cause, and the human checks that catch those harms. Article 27 also makes it a living document: when a deployment changes in a material way, the FRIA is updated rather than reused as-is. The AI Office is preparing a standard template and an automated questionnaire under Article 27(5), but that template is not yet published, and the substantive duties in Article 27(1) already apply without it.
For banks and insurers in Slovakia, the Czech Republic, and Austria, the FRIA is not an edge case. Article 27 names their core use cases directly: assessing the creditworthiness of natural persons, and risk assessment and pricing in life and health insurance. These are the systems a financial firm most wants to automate, and they are exactly the ones that trigger a mandatory FRIA. The FRIA is required on top of the high-risk obligations the provider already meets under Annex III, not instead of them.
The timing compounds the pressure. The high-risk regime, and with it the FRIA duty, applies from 2 August 2026. A financial entity also sits under DORA, which has applied since 17 January 2025 and treats a bought-in AI service as ICT third-party risk. The same credit-scoring model can therefore pull a bank into three documentation streams at once: the provider’s conformity file, the deployer’s FRIA, and the DORA resilience record. A firm that builds these together writes each fact once. A firm that treats them separately writes the same facts three times and reconciles the gaps under audit.
A FRIA is a mandatory pre-deployment assessment under Article 27 of the EU AI Act for deployers of high-risk AI systems.
The duty sits with the deployer, the organisation that uses a high-risk AI system under its own authority, not the provider that builds it. Article 27 then narrows the group. Three categories must complete a FRIA: bodies governed by public law, private operators providing public services such as healthcare, education, or social benefits, and any deployer that runs a high-risk system to assess the creditworthiness or credit score of individuals, or to price and assess risk for life and health insurance. A commercial bank and a life insurer both land in the third category by name. The financial sector is inside the FRIA perimeter whether or not it provides a public service.
Article 27(1) lists what the assessment has to contain, and each point is mandatory. The deployer documents (a) the processes in which the high-risk system will be used in line with its intended purpose, (b) the period and frequency of intended use, (c) the categories of natural persons and groups likely to be affected, (d) the specific risks of harm to those people, using the information the provider supplied under Article 13, (e) the human-oversight measures in place, drawn from the instructions for use, and (f) the steps to take if the risks materialise, including internal governance and complaint mechanisms. The list reads as a design brief for accountable AI: name the use, name the people, name the harm, name the human check, name the remedy.
A Data Protection Impact Assessment under the GDPR asks whether personal data is processed lawfully and safely. A FRIA asks a wider question: whether the system treats people fairly across the full set of rights in the EU Charter, including non-discrimination, human dignity, and the right to an effective remedy. The two overlap, and Article 27(4) lets a deployer build on an existing DPIA rather than repeat it, so the FRIA complements the data assessment where the two meet. The difference in focus is the point. A DPIA can pass while a model still produces a biased outcome, because lawful data can still drive an unfair decision. The FRIA is the assessment that examines the decision, not only the data behind it.
The FRIA duty applies from 2 August 2026, the date the EU AI Act’s high-risk obligations take effect, and that is the binding date today. In late 2025 the European Commission proposed a Digital Omnibus package that would push several high-risk deadlines later, with reporting pointing toward 2 December 2027, but that change is a proposal and is not law until it is adopted and published in the Official Journal. A financial firm plans against the date in force, 2 August 2026, and treats any extension as relief it has not yet received. Building the FRIA capability early is also the cheaper path, because the assessment rests on documentation a well-run firm should hold anyway.
Start with an inventory of AI use cases and flag every system that touches creditworthiness, credit scoring, or life and health insurance pricing, because those demand a FRIA by name. For each one, gather the provider’s Article 13 information, map the affected customer groups, and write down the human-oversight design and the complaint route a customer can use to challenge a decision. Align the FRIA with the existing DPIA so the two share a single evidence base. Identify which national market surveillance authority will receive the notification, since the deployer must report the FRIA result to it. A firm that reaches 2 August 2026 with this structure files a FRIA in days. A firm that starts from nothing spends months reconstructing how its own systems decide.
A FRIA is only as strong as the system it describes, and most AI programs are weakest exactly where the assessment looks: logged decisions, real human oversight, and a documented path for a person to contest an outcome. Ableneo builds regulated AI for that scrutiny from the first release, across financial-sector clients in Central Europe including ČSOB, Erste, and UNIQA. About 80% of Ableneo projects reach production, against an industry pattern of pilots that stall before they meet a control, and that rate comes from designing governance into the build rather than bolting it on for an audit. Our work on AI transformation aligns the people, the data, and the system, so a FRIA confirms a design that already holds rather than exposing one that does not.
Key takeaways
Planning AI in a regulated business? Ableneo takes systems from classification to governed production.