Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Who owes a fundamental rights impact assessment under EU AI Act Article 27 and what it must contain

Fundamental Rights Impact Assessment: 7 Proven Steps for Article 27

The fundamental rights impact assessment is the EU AI Act obligation that falls on the organisation using a high-risk AI system rather than the one that built it. Almost all AI Act commentary is written for providers, so deployers routinely discover this one late.

It also changed in July 2026, in a way that makes it materially cheaper to produce if you already run data protection impact assessments.

Who owes a fundamental rights impact assessment

Who owes a fundamental rights impact assessment under EU AI Act Article 27 and what it must contain

Article 27(1) reaches a narrower set of deployers than most summaries suggest. It applies to:

  • bodies governed by public law;
  • private entities providing public services; and
  • deployers of high-risk systems under Annex III points 5(b) and 5(c) — evaluating creditworthiness or establishing a credit score, and risk assessment and pricing for life and health insurance.

Point 5(b) expressly excludes AI used to detect financial fraud. And there is a carve-out at the other end: high-risk systems used in the area listed in Annex III point 2, critical infrastructure, are outside Article 27 entirely.

So a bank running an AI credit-scoring model owes a fundamental rights impact assessment. The same bank running an AI fraud-detection model does not — a distinction worth confirming before scoping anything.

The phrase “private entities providing public services” is where most of the argument sits. It is not defined in the operative text, and organisations delivering outsourced healthcare, education, housing or welfare functions should assume it reaches them rather than assume it does not.

The six elements the assessment must contain

Article 27(1) is explicit about content. The fundamental rights impact assessment consists of:

  • (a) a description of the deployer’s processes in which the system will be used, in line with its intended purpose;
  • (b) the period of time within which, and the frequency with which, the system is intended to be used;
  • (c) the categories of natural persons and groups likely to be affected in the specific context;
  • (d) the specific risks of harm likely to affect those groups, taking into account the information the provider gives you under Article 13;
  • (e) a description of the implementation of human oversight measures, according to the instructions for use;
  • (f) the measures to be taken if those risks materialise, including arrangements for internal governance and complaint mechanisms.

Two of these are quietly demanding. Element (c) requires you to identify affected groups in the specific context, which is a different exercise from listing data subjects. And element (f) requires a complaint mechanism — a fundamental rights impact assessment that describes risks without giving an affected person a route to raise one is incomplete on the face of the Article.

Element (d) is also the point at which provider documentation becomes load-bearing. Article 13 information is an input to your assessment, so a provider who supplies thin instructions for use has made your obligation harder, and that is a procurement conversation.

When it has to be done, and redone

Article 27(2) ties the obligation to the first use of the high-risk AI system. In similar cases, a deployer may rely on previously conducted fundamental rights impact assessments, or on existing impact assessments carried out by the provider.

But if, during use, the deployer considers that any of the paragraph 1 elements has changed or is no longer up to date, it must take the necessary steps to update the information.

That makes it a living document keyed to change rather than to a calendar. New user group, new decision threshold, new deployment context — each is a trigger, and none of them shows up in an annual review cycle.

You have to notify the regulator

This is the provision that surprises people. Under Article 27(3), once the assessment has been performed the deployer shall notify the market surveillance authority of its results, submitting the filled-out template as part of the notification.

A fundamental rights impact assessment is not an internal record you produce on request. It goes to the regulator as a matter of course. Deployers in the situation referred to in Article 46(1) — the derogation from conformity assessment procedure — may be exempt from that notification.

Under Article 27(5), the AI Office is to develop a template questionnaire, including through an automated tool, to help deployers comply in a simplified manner.

What changed in 2026, and why it matters

Regulation (EU) 2026/1744 — the Digital Omnibus on AI, in force from 27 July 2026 — amended Article 27(4) and (5).

The original paragraph 4 said that where obligations were already met through a DPIA under Article 35 GDPR, the fundamental rights impact assessment shall complement that assessment. The replacement is more useful: the deployer may include cross-references to the relevant sections of that data protection impact assessment, or include relevant parts of it, in the fundamental rights impact assessment.

“Complement” implied a separate document sitting beside the DPIA. Cross-referencing means one assessment can carry the shared analysis and the other can point at it. For organisations with mature DPIA practice, that removes a duplication nobody wanted.

The amended paragraph 5 carries the same idea into the AI Office template, which must where relevant let deployers cross-reference the DPIA.

The two are still different instruments. A DPIA asks about risks to personal data; the fundamental rights impact assessment asks about risks to rights — non-discrimination, access to services, effective remedy — which can be engaged by a system processing very little personal data at all.

When this actually bites

Obligations for Annex III high-risk systems now apply from 2 December 2027, postponed from 2 August 2026 by the same omnibus regulation. Product-embedded high-risk systems under Annex I follow on 2 August 2028.

That is not as much room as it sounds, because the assessment depends on provider documentation and on a complaint mechanism you have to design, staff and test.

How the fundamental rights impact assessment connects

Area Connection
DPIA Since the 2026 amendment you may cross-reference it rather than duplicate the analysis
EU AI Act risk categories Annex III is what makes a system high-risk, and points 5(b) and 5(c) are what pull private deployers in
EU AI Act deadlines The 2 December 2027 date this obligation runs to
ISO 42001 vs the EU AI Act The management system that turns a one-off assessment into a repeatable process with owners

Where to start

  1. Establish whether you are a deployer in scope — public body, private provider of public services, credit scoring or life and health insurance pricing.
  2. Check the exclusions: fraud detection under 5(b) and critical infrastructure under Annex III point 2.
  3. Get the Article 13 information from your provider in writing, because element (d) depends on it.
  4. Identify affected groups, not just data subjects, in the specific deployment context.
  5. Build the complaint mechanism, since element (f) requires one and it takes longest.
  6. Reuse your DPIA by cross-reference under the amended paragraph 4.
  7. Plan for notification to the market surveillance authority, not just for an internal file.

This guide reflects Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, read on EUR-Lex at 16 August 2026. The AI Office template under Article 27(5) will shape the format — check whether it has been published before designing your own.

The EU AI Act Toolkit provides 60 editable templates covering the deployer obligations, the fundamental rights impact assessment, the human oversight records and the complaint handling arrangements Article 27 requires.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.