GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

AIG-046 Fundamental Rights Impact Assessment

Tier 2+AIDeployerhigh-risk-annex-iii

Description

Where regulation requires an assessment of the effect a deployed AI system has on fundamental rights, a completed assessment exists before the system is first used. It covers the organisation's own processes the system is used in and the purpose it is used for, the period and frequency of the intended use, the categories of people and groups likely to be affected in that context, the specific risks of harm to those categories drawn from the information the provider supplies, how the human oversight measures in the instructions for use are implemented and the measures to be taken if a risk materialises, including the internal governance arrangements and the route by which a person complains. Where the completed assessment has to be notified to a competent authority, the notification is made on the form that authority publishes and is recorded with its date. A further use of the same system in materially the same context relies on the existing assessment, and a change to any element the assessment covers produces an updated assessment before the changed use begins.

Rationale

Most of the content is a reading of the deployer's own processes against information only the provider holds, so the instructions for use, the description of the risks and the oversight measures are obtained under AIG-032 and AIG-034 before the assessment can be completed. Boundary with AIG-006: that assessment is about a system the organisation builds or operates and is reviewed on material change; this one is about the use a deployer puts someone else's system to, has a fixed element list, triggers on first use and ends in a filing. Boundary with DAT-013: the data protection impact assessment is an artefact, not a competing obligation. Where it already covers an element, the assessment cross-references that section, which is the cheapest route for a deployer that has one; the elements it does not cover are what remains to be written. Deployer seat (ADR-031).

Applicability (9 profiles)

SaaS AI Providerstablenot-applicableout of scope

The fundamental rights impact assessment of Art.27 is owed by the deployer about the use it makes of the system. A provider's duty is to supply the information the assessment draws on, which AIG-034 carries.

Enterprise AI Deployerstableconditionalrisk class duty

Condition: ai_risk_class in high-risk-annex-iii and the deployer is a body governed by public law or a private entity providing a public service, or the system is used to assess creditworthiness or to price and assess risk in life or health insurance

Art.27 binds public-law bodies, private entities providing public services and deployers of the Annex III point 5(b) and (c) systems, excluding the point 2 area. The assessment is due before first use and its result is notified to the market surveillance authority. Where the deployer holds a data protection impact assessment covering an element, Art.27(4) lets it cross-reference that section, so DAT-013 supplies part of the artefact. The provider's instructions for use, its risk description and its oversight measures are obtained under AIG-032 and AIG-034.

GPAI Model Providerstablenot-applicableout of scope

Deployer-seat duty (enterprise-ai-deployer).

High-Risk Provider (EU)stablenot-applicableout of scope

The fundamental rights impact assessment of Art.27 is owed by the deployer about the use it makes of the system. A provider's duty is to supply the information the assessment draws on, which AIG-034 carries.

Public Body Deployer (EU)stablerequiredrole duty

The second of the two seats. Art.27 binds deployers that are bodies governed by public law or private entities providing public services, before the first use of a high-risk Annex III system, with the Annex III point 2 area excluded. Art.27(1) fixes six elements: the deployer's processes the system will be used in, the period and frequency of intended use, the categories of natural persons and groups likely to be affected in that context, the specific risks of harm to those categories taking account of the information the provider gives under Art.13, the implementation of the human oversight measures according to the instructions for use and the measures to be taken if those risks materialise, including the internal governance arrangements and the complaint mechanisms. Art.27(3) requires the result to be notified to the market surveillance authority on the filled-out template referred to in Art.27(5), which the AI Office develops. Art.27(4) lets the deployer cross-reference the relevant sections of a data protection impact assessment instead of repeating them, so DAT-013 supplies part of the artefact and AIG-006 the rest. The provider inputs are obtained under AIG-032 and AIG-034. A further use in materially the same context relies on the assessment already performed. The Annex III points 5(b) and (c) arm of Art.27, creditworthiness and the pricing and risk assessment of life and health insurance, binds a deployer that is neither seat and stays on the base profile's conditional row.

Data Act Cloud Provider (EU)stablenot-applicableout of scope

The fundamental rights impact assessment of Art.27 is owed by the deployer about the use it makes of the system. A provider's duty is to supply the information the assessment draws on, which AIG-034 carries.

DORA ICT Provider (EU)stablenot-applicableout of scope

The fundamental rights impact assessment of Art.27 is owed by the deployer about the use it makes of the system. A provider's duty is to supply the information the assessment draws on, which AIG-034 carries.

HIPAA Business Associate (US)stablenot-applicableout of scope

The fundamental rights impact assessment of Art.27 is owed by the deployer about the use it makes of the system. A provider's duty is to supply the information the assessment draws on, which AIG-034 carries.

NIS2 Cloud Provider (EU)stablenot-applicableout of scope

The fundamental rights impact assessment of Art.27 is owed by the deployer about the use it makes of the system. A provider's duty is to supply the information the assessment draws on, which AIG-034 carries.

Framework Mappings (7)

GRC-10AI Impact Assessmentinformative
EU-AI-Art.27Deployer Obligations — Fundamental Rights Impact Assessmentfull
EU-AI-Art.5.2Prohibited Practices — Conditions on the Law Enforcement Use of Real-Time Remote Biometric Identificationinformative
GDPR-Art.35.1Data Protection Impact Assessment (DPIA) — Obligation to Conductinformative
GDPR-Art.35.7Data Protection Impact Assessment (DPIA) — Required Contentinformative
A.5.2AI system impact assessment processinformative
MAP 5.1Impact Likelihood and Magnitude Documentationinformative

Evidence (2)

recorddocumentmanual

Completed fundamental rights impact assessment for a named deployment, covering each element the control lists, with the cross-references it relies on and the sign-off.

Example: Fundamental rights impact assessment for the housing allocation scoring system, version 1.0, completed 22 April 2026, cross-referencing sections 4 and 6 of the DPIA of 3 March 2026.

Test: Verify: (1) the assessment is dated before the date the organisation first used the system, (2) every element the control lists carries content of its own or a cross-reference that resolves to a section which actually answers it, (3) the risks of harm name the categories of people identified earlier in the same assessment rather than generic populations, and each one has a stated measure against it, (4) the human oversight element describes how the measures in the provider's instructions for use are implemented here rather than repeating the instructions.

system_exporttechnicalautomated

Export from the AI system inventory or the assessment register listing each deployment that carries the assessment duty, with its assessment reference and date, its first-use date, the notification date and the date of the last update.

Example: Assessment register export fria-register-2026-06.csv, generated 30 June 2026, covering nine deployments.

Test: Verify: (1) every deployment flagged as carrying the duty holds an assessment reference, (2) no assessment date falls on or after its first-use date, (3) every assessment that required notification carries a notification date no earlier than its own completion date, (4) a deployment whose recorded context or use changed since the assessment carries an update dated before the change, and one relying on an earlier assessment names the assessment it relies on.

Questions (3)

boolean

Is a fundamental rights impact assessment completed before the organisation first uses a system that requires one?

Answer yes only where a completed assessment exists for every such deployment and pre-dates first use. An assessment the provider performed on its own product is not this assessment; it is an input to it. An assessment started before go-live but finished afterwards is a no.

multi

Which of the following does the assessment cover?

The processes the system is used in and the purpose it is used forThe period and frequency of the intended useThe categories of people and groups likely to be affectedThe specific risks of harm to those categoriesHow the human oversight measures in the instructions for use are implementedThe measures to be taken if a risk materialises, with the internal governance arrangementsThe route by which an affected person complainsNotification of the result to a competent authorityNone of the above

Options follow the order the assessment is normally written in. An element answered by a cross-reference to a data protection impact assessment counts, provided the section referred to answers it. Tick the notification option only where a notification was actually made, not where one is planned.

select

What triggers an update to a completed assessment?

Any change to an element the assessment covers, applied before the changed use beginsA change to the system or to the population it reaches, applied before the changed use beginsA scheduled review at a defined intervalA change noticed at the next auditCompleted assessments are not updated

Options run from the most responsive trigger to the least. Answer on what has actually caused an update, not on what the procedure lists. A scheduled review with no change-driven trigger is the third option even where the interval is short.