Compliance Insights
AI Impact Assessment Template: How to Write a Fundamental Rights Impact Assessment
Step-by-step template for writing an EU AI Act Fundamental Rights Impact Assessment (FRIA). Includes structure, required sections, examples, and common mistakes to avoid.
AI Impact Assessment Template: How to Write a Fundamental Rights Impact Assessment
Under the EU AI Act, deployers of high-risk AI systems must conduct a Fundamental Rights Impact Assessment (FRIA) before putting the system into use. This guide provides a complete template and walkthrough.
What Is a Fundamental Rights Impact Assessment?
A FRIA evaluates how a high-risk AI system may impact the fundamental rights of individuals and groups. It's required under Article 27 of the EU AI Act for:
- Public bodies using high-risk AI
- Private entities providing public services
- Organizations deploying AI in banking, insurance, or credit
- Any deployer of high-risk AI affecting fundamental rights
When Is a FRIA Required?
You must complete a FRIA before deploying a high-risk AI system when:
- The system makes decisions affecting individuals' access to services
- The system processes biometric data
- The system is used in employment contexts
- The system affects access to education or vocational training
- The system is used for credit scoring or insurance pricing
FRIA Template Structure
Section 1: System Description
Required elements:
- System name and version
- Provider and deployer information
- Intended purpose and use cases
- Technical architecture overview
- Data inputs and outputs
- Decision-making logic (at a level understandable to non-experts)
Example:
"CreditScore AI v3.2, provided by [Provider], deployed by [Bank Name] for automated preliminary credit assessment of consumer loan applications under €50,000. The system processes applicant financial history, employment data, and behavioral indicators to generate a risk score (0-1000) and preliminary approve/decline recommendation."
Section 2: Fundamental Rights Analysis
For each potentially affected right, assess:
| Right | Relevance | Impact Level | Mitigation |
|---|---|---|---|
| Non-discrimination (Art. 21 EU Charter) | High | Medium | Bias testing, fairness metrics |
| Privacy (Art. 7) | High | High | Data minimization, encryption |
| Data protection (Art. 8) | High | High | DPIA completed, DPO oversight |
| Human dignity (Art. 1) | Medium | Low | Human oversight, appeal process |
| Effective remedy (Art. 47) | High | Medium | Explanation mechanism, appeal path |
Section 3: Risk Assessment
For each identified risk:
Likelihood × Severity Matrix:
| Low Severity | Medium Severity | High Severity | |
|---|---|---|---|
| High Likelihood | Medium Risk | High Risk | Critical Risk |
| Medium Likelihood | Low Risk | Medium Risk | High Risk |
| Low Likelihood | Minimal Risk | Low Risk | Medium Risk |
Document:
- What could go wrong (risk scenarios)
- Who would be affected (individuals, groups)
- How severe the impact would be
- How likely the scenario is
- What existing controls address the risk
Section 4: Affected Groups
Identify all groups potentially impacted:
- Direct users of the system
- Individuals subject to AI decisions
- Vulnerable populations (elderly, disabled, minorities, children)
- Third parties indirectly affected
For each group, document:
- How they interact with or are affected by the system
- Whether they have meaningful choice or alternatives
- Special vulnerabilities or power imbalances
- Accessibility considerations
Section 5: Mitigation Measures
For each identified risk, document:
Technical measures:
- Bias detection and mitigation algorithms
- Fairness constraints in model training
- Robustness testing against adversarial inputs
- Privacy-enhancing technologies
Organizational measures:
- Human oversight procedures
- Escalation paths for edge cases
- Regular audit schedules
- Staff training requirements
Procedural measures:
- Appeal and contestation mechanisms
- Transparency and explanation processes
- Incident response procedures
- Stakeholder consultation processes
Section 6: Monitoring Plan
Define ongoing monitoring for:
- Performance metrics (accuracy, fairness, robustness)
- Compliance indicators
- Incident tracking
- Stakeholder feedback
- Regulatory updates
Include:
- Monitoring frequency
- Responsible parties
- Escalation thresholds
- Review and update schedule
Section 7: Consultation Record
Document stakeholder engagement:
- Who was consulted (DPO, affected groups, experts)
- When consultations occurred
- Key findings and concerns raised
- How feedback was incorporated
Common Mistakes to Avoid
1. Generic Risk Descriptions
❌ "There is a risk of discrimination" ✅ "The system may disproportionately decline applications from applicants in postal codes with >60% minority populations due to historical lending data bias in training set v2.1"
2. Ignoring Indirect Effects
Don't just assess direct decisions. Consider:
- Chilling effects on behavior
- Cumulative impact across multiple AI systems
- Long-term societal effects
- Impact on trust in institutions
3. Treating It as a One-Time Exercise
A FRIA is a living document. Update it when:
- The system is retrained or updated
- New use cases are added
- Monitoring reveals unexpected impacts
- Regulations or guidance change
4. Insufficient Mitigation Detail
❌ "We will monitor for bias" ✅ "Monthly fairness audits using demographic parity, equalized odds, and calibration metrics across 12 protected characteristics, with automated alerts when any metric exceeds ±5% threshold, reviewed by the AI Ethics Committee within 48 hours"
Automate Your Impact Assessments
Writing a FRIA from scratch takes 40-80 hours per AI system. With GuardianCompliance AI:
- Upload your system documentation and receive a draft FRIA in minutes
- AI identifies affected rights based on your system's function and context
- Risk scenarios are generated from our knowledge base of regulatory precedents
- Mitigation measures are suggested based on industry best practices
- Updates are tracked as your system evolves
Our platform has generated over 500 compliant FRIAs for organizations across banking, healthcare, HR, and public services.
Next Steps
- Assess your systems — Determine which require a FRIA with our Free AI Risk Audit
- Gather documentation — Collect technical specs, data flow diagrams, and existing policies
- Generate your FRIA — Use GuardianCompliance to produce a comprehensive draft
- Review and finalize — Have your DPO and legal team review the output
- Implement monitoring — Set up continuous compliance tracking