Agent Liability Europe

FRIA generator. A first draft of your Article 27 assessment.

Enter your deployment details and generate a structured draft fundamental rights impact assessment covering all seven elements of Article 27(1)(a) to (g) of Regulation (EU) 2024/1689. Free, and nothing leaves your browser.

Article 27 applies with the Annex III high-risk obligations from 2 December 2027. A draft now gives the assessment time to mature before it falls due.

Step 1 of 7
Organisation

Identify your organisation

This appears in the document header and establishes which Article 27 obligation category applies to you.

Please enter your organisation name.
Operator category under Article 27(1) required Select the category that describes your organisation. It determines your FRIA obligation.
Please select your operator category.
Please select the Member State of operation.
The name or role responsible for maintaining this FRIA. Please enter a contact person or role.
AI system

The AI system being deployed

Identify the high-risk AI system: what is being deployed and in what context. Everything else in the assessment rests on this.

Please enter the AI system name.
Please enter the provider name.
The task the system performs as intended by the provider, and your own purpose in deploying it. Please describe the intended purpose.
Please enter the deployment date.
Article 27(1)(a)

Process and frequency of use

Article 27(1)(a) asks for a description of the processes in which the system will be used, including the periods and frequency of use.

The workflow: who starts a request, what data goes in, how the output is used, and who acts on it. Please describe the process of use.
Estimated queries, decisions or interactions per day, week or month. Please describe the frequency of use.
Article 27(1)(b)

Deployment period and update cycle

Article 27(1)(b) asks for the period over which the system will be used and how often it is updated in that time.

The planned horizon: a fixed contract term, an indefinite licence, or a stated review point. Please state the deployment period.
How often the provider updates the model, and how often you review the deployment against this FRIA. Please describe the update frequency.
Article 27(1)(c)

Categories of persons affected

Article 27(1)(c) asks for the categories of natural persons and groups likely to be affected by the system's use in the Union.

Every category of person likely to be affected required Select at least one. Add detail in the field below.
Please select at least one category of affected persons.
Specifics, estimated numbers or geographic scope where relevant.
Article 27(1)(d) and (e)

Risks and mitigation

Article 27(1)(d) asks for the specific risks of harm to fundamental rights likely to affect those persons. Article 27(1)(e) asks how measures to mitigate those risks are implemented.

The concrete risks, such as discrimination, privacy intrusion or denial of access to services, and the rights engaged under the Charter of Fundamental Rights and the ECHR. Please describe the specific risks to fundamental rights.
For each risk above, the technical and organisational measures in place. Specific and auditable. Please describe the mitigation measures.
Article 27(1)(f) and (g)

Human oversight and complaints

Article 27(1)(f) asks for the human oversight measures. Article 27(1)(g) asks for the arrangements for internal governance and for complaints by affected persons.

Who performs oversight, their competence and authority, and how they can intervene in or override outputs. This must meet the Article 14 standard. Please describe the human oversight measures.
How affected persons raise concerns, ask for explanations or challenge an AI assisted decision, with the responsible function and the response time. Please describe the complaints mechanism.

Before you file it

This draft covers the structure of Article 27(1)(a) to (g). Where a GDPR data protection impact assessment is also required, Article 27(4) allows the FRIA to complement it, provided every element of both is present.

The Article 27 guide     The FRIA checklist