Compliance Insights

AI Impact Assessment Template: How to Write a Fundamental Rights Impact Assessment

Step-by-step template for writing an EU AI Act Fundamental Rights Impact Assessment (FRIA). Includes structure, required sections, examples, and common mistakes to avoid.

AI Impact Assessment Template: How to Write a Fundamental Rights Impact Assessment

Under the EU AI Act, deployers of high-risk AI systems must conduct a Fundamental Rights Impact Assessment (FRIA) before putting the system into use. This guide provides a complete template and walkthrough.

What Is a Fundamental Rights Impact Assessment?

A FRIA evaluates how a high-risk AI system may impact the fundamental rights of individuals and groups. It's required under Article 27 of the EU AI Act for:

  • Public bodies using high-risk AI
  • Private entities providing public services
  • Organizations deploying AI in banking, insurance, or credit
  • Any deployer of high-risk AI affecting fundamental rights

When Is a FRIA Required?

You must complete a FRIA before deploying a high-risk AI system when:

  • The system makes decisions affecting individuals' access to services
  • The system processes biometric data
  • The system is used in employment contexts
  • The system affects access to education or vocational training
  • The system is used for credit scoring or insurance pricing

FRIA Template Structure

Section 1: System Description

Required elements:

  • System name and version
  • Provider and deployer information
  • Intended purpose and use cases
  • Technical architecture overview
  • Data inputs and outputs
  • Decision-making logic (at a level understandable to non-experts)

Example:

"CreditScore AI v3.2, provided by [Provider], deployed by [Bank Name] for automated preliminary credit assessment of consumer loan applications under €50,000. The system processes applicant financial history, employment data, and behavioral indicators to generate a risk score (0-1000) and preliminary approve/decline recommendation."

Section 2: Fundamental Rights Analysis

For each potentially affected right, assess:

RightRelevanceImpact LevelMitigation
Non-discrimination (Art. 21 EU Charter)HighMediumBias testing, fairness metrics
Privacy (Art. 7)HighHighData minimization, encryption
Data protection (Art. 8)HighHighDPIA completed, DPO oversight
Human dignity (Art. 1)MediumLowHuman oversight, appeal process
Effective remedy (Art. 47)HighMediumExplanation mechanism, appeal path

Section 3: Risk Assessment

For each identified risk:

Likelihood × Severity Matrix:

Low SeverityMedium SeverityHigh Severity
High LikelihoodMedium RiskHigh RiskCritical Risk
Medium LikelihoodLow RiskMedium RiskHigh Risk
Low LikelihoodMinimal RiskLow RiskMedium Risk

Document:

  • What could go wrong (risk scenarios)
  • Who would be affected (individuals, groups)
  • How severe the impact would be
  • How likely the scenario is
  • What existing controls address the risk

Section 4: Affected Groups

Identify all groups potentially impacted:

  • Direct users of the system
  • Individuals subject to AI decisions
  • Vulnerable populations (elderly, disabled, minorities, children)
  • Third parties indirectly affected

For each group, document:

  • How they interact with or are affected by the system
  • Whether they have meaningful choice or alternatives
  • Special vulnerabilities or power imbalances
  • Accessibility considerations

Section 5: Mitigation Measures

For each identified risk, document:

Technical measures:

  • Bias detection and mitigation algorithms
  • Fairness constraints in model training
  • Robustness testing against adversarial inputs
  • Privacy-enhancing technologies

Organizational measures:

  • Human oversight procedures
  • Escalation paths for edge cases
  • Regular audit schedules
  • Staff training requirements

Procedural measures:

  • Appeal and contestation mechanisms
  • Transparency and explanation processes
  • Incident response procedures
  • Stakeholder consultation processes

Section 6: Monitoring Plan

Define ongoing monitoring for:

  • Performance metrics (accuracy, fairness, robustness)
  • Compliance indicators
  • Incident tracking
  • Stakeholder feedback
  • Regulatory updates

Include:

  • Monitoring frequency
  • Responsible parties
  • Escalation thresholds
  • Review and update schedule

Section 7: Consultation Record

Document stakeholder engagement:

  • Who was consulted (DPO, affected groups, experts)
  • When consultations occurred
  • Key findings and concerns raised
  • How feedback was incorporated

Common Mistakes to Avoid

1. Generic Risk Descriptions

❌ "There is a risk of discrimination" ✅ "The system may disproportionately decline applications from applicants in postal codes with >60% minority populations due to historical lending data bias in training set v2.1"

2. Ignoring Indirect Effects

Don't just assess direct decisions. Consider:

  • Chilling effects on behavior
  • Cumulative impact across multiple AI systems
  • Long-term societal effects
  • Impact on trust in institutions

3. Treating It as a One-Time Exercise

A FRIA is a living document. Update it when:

  • The system is retrained or updated
  • New use cases are added
  • Monitoring reveals unexpected impacts
  • Regulations or guidance change

4. Insufficient Mitigation Detail

❌ "We will monitor for bias" ✅ "Monthly fairness audits using demographic parity, equalized odds, and calibration metrics across 12 protected characteristics, with automated alerts when any metric exceeds ±5% threshold, reviewed by the AI Ethics Committee within 48 hours"

Automate Your Impact Assessments

Writing a FRIA from scratch takes 40-80 hours per AI system. With GuardianCompliance AI:

  • Upload your system documentation and receive a draft FRIA in minutes
  • AI identifies affected rights based on your system's function and context
  • Risk scenarios are generated from our knowledge base of regulatory precedents
  • Mitigation measures are suggested based on industry best practices
  • Updates are tracked as your system evolves

Our platform has generated over 500 compliant FRIAs for organizations across banking, healthcare, HR, and public services.

Next Steps

  1. Assess your systems — Determine which require a FRIA with our Free AI Risk Audit
  2. Gather documentation — Collect technical specs, data flow diagrams, and existing policies
  3. Generate your FRIA — Use GuardianCompliance to produce a comprehensive draft
  4. Review and finalize — Have your DPO and legal team review the output
  5. Implement monitoring — Set up continuous compliance tracking

Start with a free risk assessment →