Article 27 of the EU AI Act requires a Fundamental Rights Impact Assessment before certain high-risk AI systems are deployed. Most organisations produce something that reads well and would not survive scrutiny.
Transmission of the completed FRIA to the market surveillance authority is mandatory. It is not an internal document you file away.
A DPIA does not satisfy Article 27. Different scope, different rights, different authority. Doing one does not discharge the other.
Free. No sales call. Unsubscribe whenever.
We email it immediately, then three short notes about what fails in real audits. Nothing else. No sharing, ever.
Because most FRIA templates circulating right now are wrong in the same two ways, and a wrong FRIA is worse than none, it creates a written record of an assessment you didn't actually perform.
This starter is the front section of the impact-assessment work in our full toolkit. If it's useful and you'd rather not build the other twenty-two documents yourself, you know where to find us. If you build your own, that's a fine outcome too.
Last week a customer told us our Risk Treatment Plan referenced treatment actions by ID without describing them. He was right. We audited the whole set, found two further defects he hadn't spotted, fixed all three, and shipped the corrected version free to every existing customer. The full account is here.