VeritomeHelp Center
/

FRIA: the fundamental-rights impact assessment, step by step

Who must run an Art. 27 FRIA, what the assessment covers, when to revisit it, and how Veritome generates the report per system.

Updated 08.07.2026

Before putting certain high-risk systems into service, deployers must assess the impact on the fundamental rights of the people the system affects (Art. 27).

Who must run one

  • Deployers that are bodies governed by public law, or private operators providing public services — across Annex III areas such as biometrics, education, employment, law enforcement, migration and justice.
  • Any deployer of a creditworthiness or credit-scoring system (Annex III 5(b)) or a life and health insurance risk-and-pricing system (5(c)) — public or private.

Veritome's rules engine encodes exactly this: the FRIA tab appears only for high-risk DEPLOYER systems where your organisation is flagged as a public body or public-service provider in a covered Annex III area, or the system sits in essential services. Providers never see it.

What the assessment covers

The FRIA editor mirrors the Art. 27(1) structure:

  1. Deployer Processes — how the system is used in your workflows.
  2. Temporal Scope — period of use and frequency.
  3. Affected Persons — categories (employees, applicants, customers, citizens…) and an estimated count. When you pick a category, Veritome pre-populates suggested risks matched to your system's Annex III area.
  4. Risk Identification — specific harms per affected group.
  5. Human Oversight Measures — narrative plus a checklist: trained operator, override mechanism, review schedule, escalation procedure.
  6. Mitigation Measures — what you put in place if risks materialise.
  7. Authority NotificationArt. 27(3) requires notifying the market surveillance authority of the results.

Generating the report

Save draft stores your answers on the system's Art. 27 obligation, and Export PDF renders the A4 FRIA report. Because the assessment is built with Aria's assistance, the export ships marked as AI-assisted by default (Art. 50).

When to update it

Update the FRIA when any element changes — new user groups, new purpose, changed oversight. Veritome also auto-schedules an annual Fundamental Rights Impact Assessment Review for FRIA-scoped organisations, and completing a review appends a tamper-evident entry to the system's regulator dossier.

Need to act on this?Open Veritome