Article 27 Live High-Risk AI obligations apply now — FRIA required before deployment
Days
:
Hours
:
Mins
:
Secs
Until 2 August 2028 full enforcement deadline
EU AI Act Bridge Series · Article 27 · FRIA Compliance Pack

A high-risk AI system cannot go live without a completed FRIA.
Most organisations have neither.

A high-risk AI system cannot go live without a completed Fundamental Rights Impact Assessment. Most organisations have neither the FRIA nor the documented confirmation that they don't need one. Either gap is a governance failure.

The EU AI Act FRIA Pack closes both gaps in one purchase. Two self-contained documents — the scored readiness checker and the complete eight-dimension workbook — that produce a signed, regulatorily-complete compliance record. Built to the exact Article 27 specification. Aligned to ISO/IEC 42001:2023, ITIL 4, and IEC 82079-1:2012.

One-time purchase · No subscription · Instant download · Print-ready PDF

Regulation (EU) 2024/1689 ISO/IEC 42001:2023 ITIL 4 Aligned IEC 82079-1:2012 EU Charter of Fundamental Rights Article 27(1)(a)–(h) Complete Article 27(3) Notification
The Legal Obligation

When Does Article 27 Apply — and What Does It Require?

Article 27 of Regulation (EU) 2024/1689 creates a mandatory pre-deployment assessment obligation for deployers of High-Risk AI systems. The obligation has two routes: a trigger assessment (Part A) and, if triggered, a full eight-dimension FRIA (Part B).

Route A — Non-Trigger Confirmation

When no High-Risk AI system is in scope

If your Annex III classification register records Not High-Risk for all AI systems, and Article 27(2) does not apply, you need a signed non-trigger confirmation — not silence.

  • Documents that Article 27 was assessed, not skipped
  • Signed by the COLP or designated AI Governance Lead
  • Sets review triggers for future classification changes
  • Takes approximately 30 minutes to complete
  • Required for audit defence — absence is a governance gap
Route B — Full FRIA Required

When a High-Risk AI system is in scope

If any AI system is classified as High-Risk under Annex III, or falls within the Article 27(2) extended scope, a full eight-dimension FRIA shall be completed before that system enters service.

  • Eight mandatory dimensions — Art. 27(1)(a) through (h)
  • Full EU Charter rights assessment across ten Charter articles
  • Mitigation register for all MEDIUM and HIGH risks
  • DPIA coordination documentation
  • Article 27(3) competent authority notification determination
  • Dual sign-off: COLP and AI Risk Owner

Trigger Matrix — Which Route Applies to You?

Deployer Type
AI System Classification
FRIA Requirement
Public body / public-law entity
Any Annex III High-Risk system
Full FRIA — Part B required
Private operator providing public services
Any Annex III High-Risk system
Full FRIA — Part B required
Private-sector deployer
AI used for creditworthiness, insurance risk, or employment decisions (Art. 27(2))
Extended scope — FRIA likely required
Any deployer
All AI systems classified Not High-Risk; Art. 27(2) not engaged
Part A non-trigger confirmation required
Any deployer
No assessment completed; no documentation
Governance failure — either route required

Important — Article 27(3) Notification

Where the FRIA identifies a significant risk of infringement of fundamental rights, Article 27(3) requires deployers to notify the relevant market surveillance authority. This obligation — absent from most FRIA templates — is included in the UNUS London workbook as a mandatory completion section.

The Pack

Two Documents. One Compliance Position.

The FRIA Pack contains a scored pre-assessment readiness checker and the complete Article 27 FRIA workbook. Use the checklist first to identify any prerequisite gaps, then open the workbook and complete either the non-trigger confirmation or the full eight-dimension assessment.

WKBK-AIMS-FRIA-001 v2.0

EU AI Act FRIA Workbook

Part A — Trigger Assessment: Article 27(1) and 27(2) scope, classification register summary, signed non-trigger confirmation
Dimension A — Deployer Processes: Operational description with worked example
Dimension B — Time & Frequency: Deployment period, volume, scale-up triggers
Dimension C — Affected Persons: Full stakeholder mapping with vulnerability factors
Dimension D — Rights Risks: Full EU Charter matrix across ten Charter articles (Arts. 1, 7, 8, 11, 12, 21, 24, 35, 41, 47) with likelihood / severity / residual risk assessment
Dimension E — Human Oversight: HITL procedure documentation
Dimension F — Materialisation: Quantitative pathway analysis with worked example
Dimension G — Mitigations: Owned, dated mitigation register with post-mitigation risk rating
Dimension H — DPIA Coordination: UK GDPR / EU GDPR Art. 35 coordination block
Section B9 — Article 27(3): Competent authority notification determination
ISO/IEC 42001:2023 alignment panels in every dimension
ITIL 4 practice mapping (Risk Management, Change Enablement, Service Validation, Continual Improvement)
Real-time completion score bar — 8-dimension progress tracking
FRIA Review Schedule with dated, owned review triggers
Dual sign-off block: COLP and AI Risk Owner
12-item pre-filing QA checklist
Full print-to-PDF styles — A4, with page headers and document references
TOOLKIT-AIMS-FRIA-001-CL v1.0

FRIA Readiness Checker

12 scored questions — 6 on Part A readiness, 6 on Part B readiness
Maximum score: 24 points — real-time scoring as you answer
Part A readiness: Classification register status, Article 27(2) scope assessment, FRIA lead designation, monitoring process, deadline awareness
Part B readiness: Operational documentation, stakeholder mapping, legal input access, HITL procedure, DPIA status, sign-off authority confirmation
Four verdict bands: Ready / Mostly Ready / Significant Preparation Required / Foundational Work Needed
Priority action list — specific, sequenced actions for every gap identified
Real-time progress bar with colour-coded score fill
Score breakdown by Part A and Part B
Print-to-PDF function — produce a readiness assessment record
Same UNUS London design system — consistent brand across all pack documents
Who It's For

Four Buyer Types. One Pack Solves All Four Pain Points.

The FRIA Pack is built for the individuals in regulated organisations who carry the practical burden of Article 27 compliance — whether or not they have an AI governance team behind them.

Data Protection Officer

DPO / Privacy Lead

Article 27 adds a new pre-deployment gate that the DPIA process doesn't cover — creating a gap in the DPO's existing workflow
DPIA tools don't produce a FRIA — a separate, structured document is required to satisfy Article 27
EU Charter rights assessment requires a broader lens than data protection law alone
The FRIA and DPIA must be coordinated but not confused — Dimension H documents the relationship precisely
Chief Information Officer

CIO / Technology Lead

AI system deployments are moving faster than governance frameworks — the FRIA is the pre-deployment gate that IT needs to enforce
No standardised ITIL-aligned Change Enablement artefact exists for High-Risk AI deployments — this workbook is that artefact
Vendor AI systems are arriving with EU AI Act compliance claims — the CIO needs an independent assessment framework
Board and audit committee are asking for evidence of AI governance — a signed FRIA is that evidence
General Counsel / Legal Lead

GC / Legal Director

Article 27 creates a statutory obligation — but most legal teams do not have a document that satisfies it
The EU Charter rights assessment in Dimension D requires legal input — a workbook that structures that assessment is essential
The Article 27(3) notification obligation is almost universally overlooked — this workbook surfaces it explicitly
Regulatory investigations and litigation over AI outputs are increasing — a signed FRIA is the primary documentary defence
Compliance Officer / AI Risk Owner

Compliance Lead / AI Risk Owner

The EU AI Act compliance deadline applies now — organisations with High-Risk AI systems already in service without a FRIA are actively non-compliant
Existing compliance frameworks (ISO 27001, ISO 9001) do not cover Article 27 — ISO/IEC 42001 does, and this workbook maps to it
The "we don't have any High-Risk AI" position needs to be documented — Part A is that document
Supervisory authorities will ask for the FRIA during AI audits — having a blank where the document should be is a critical finding
Get the Pack

Two Routes to Access

Purchase directly for instant access, or access free as a UNUS London Governance Academy member inside Skool.

One-Time Purchase · Instant Access

EU AI Act FRIA Pack

£97
One-time · No subscription · No upsells
What you get
WKBK-AIMS-FRIA-001 v2.0 — Complete Article 27 FRIA Workbook (interactive HTML, print-to-PDF)
TOOLKIT-AIMS-FRIA-001-CL — Scored Readiness Checker (12 questions, 24-point score, priority action list)
All eight Article 27(1) dimensions — complete and ready to use
Article 27(3) competent authority notification block — included, not an add-on
ISO/IEC 42001:2023 alignment panels throughout
Instant download — no waiting, no email gate
Purchase Now — £97

Secure checkout via ClickBank · VAT may apply · 60-day guarantee

🛡
60-Day Money-Back Guarantee

If you are not satisfied with this pack for any reason, ClickBank's 60-day no-questions-asked refund guarantee applies. Contact ClickBank directly at clickbank.com/support — no justification required.

Governance Academy Member Access · Free

Already a UNUS London Academy Member?

Free
Included in your Academy membership · No additional purchase

The FRIA Workbook and Readiness Checker are available inside the UNUS London Governance Academy on Skool, as part of the EU AI Act Bridge Series.

01 Log in to Skool — Go to skool.com/unuslondon and sign in with your Academy account
02 Navigate to the EU AI Act Bridge Series — Open the Classroom tab and select the EU AI Act Bridge Series module
03 Open the FRIA Workbook module — Download WKBK-AIMS-FRIA-001 and TOOLKIT-AIMS-FRIA-001-CL from the module resources
Access on Skool →

Not yet a member? Join the Governance Academy

Frequently Asked Questions

Your Questions, Answered Directly

It depends on two things. First, Article 27(1) applies directly to bodies governed by public law and private operators providing public services — so a firm contracted to provide legal aid (a public service) likely falls within scope. Second, Article 27(2) extends the obligation to certain private-sector deployers where AI systems are used for creditworthiness assessments, insurance risk scoring, or employment-related decisions. If neither applies, Article 27 does not currently require a full FRIA — but you still need a documented non-trigger confirmation (Part A) to evidence that the assessment was made. A private firm that simply has no documentation is not in a defensible position if a deployment decision is later challenged.

Bottom line: If you are unsure, Part A takes 30 minutes and gives you a signed compliance document either way. Part B is only required if the trigger is met.

No. A DPIA and a FRIA are distinct documents with different legal bases, different scopes, and different outputs. The DPIA (required under UK GDPR / EU GDPR Article 35) focuses on risks to data subjects arising from personal data processing. The FRIA (required under EU AI Act Article 27) covers the broader fundamental rights impacts of the AI system — including rights that have nothing to do with data protection: human dignity (Charter Art. 1), non-discrimination (Charter Art. 21), effective remedy (Charter Art. 47), and the rights of the child (Charter Art. 24).

Where both a DPIA and a FRIA are required for the same AI system, they shall be coordinated — Dimension H of the FRIA documents that coordination. But a DPIA does not substitute for a FRIA and cannot be presented as one to a supervisory authority.

If you have a High-Risk AI system already in service — classified under Annex III and in scope for Article 27 — and you have not completed a FRIA, then yes: you are currently non-compliant with the Regulation's pre-deployment requirement. Article 27 requires the FRIA to be completed before deployment, not after.

The practical response to this position is to complete the FRIA immediately and assess, in Dimension G, whether retroactive risk mitigation is required. A completed FRIA filed after deployment, with a documented remediation assessment, is materially stronger than no FRIA at all. Supervisory authorities will consider the remediation effort in any enforcement action — but a blank where the document should be is the worst possible position.

Do not wait. Open the workbook now and complete Part B for any High-Risk system currently in service.

The FRIA Workbook is a compliance tool — a structured template that guides your organisation through the Article 27 assessment process and produces a signed compliance record. It does not constitute legal advice and is not a substitute for qualified legal input on the specific facts of your deployment.

In particular, Dimension D (the EU Charter rights risk assessment) should involve a qualified solicitor or legal adviser with knowledge of fundamental rights law. The workbook structures and guides that assessment, but the legal judgements within it are made by the responsible individuals at your organisation — not by the template.

The workbook is built to the exact Article 27 specification and aligned to ISO/IEC 42001:2023, ITIL 4, and IEC 82079-1:2012. It has been designed to withstand supervisory scrutiny. But it is a tool, not a legal service.

A HIGH residual risk in Dimension D is a blocking condition on Part B deployment approval. The workbook is explicit on this: the AI system shall not enter service in the high-risk use case while a HIGH residual risk remains open with no closed Dimension G mitigation action.

If mitigation is not immediately achievable, you have two options. First, you can select the "Deferred — Not Approved" deployment determination and document the basis — this is a valid, signed compliance document that shows the organisation assessed the risk and made a considered decision not to deploy. Second, you can implement interim controls that reduce the residual risk to MEDIUM, document them in Dimension G with an owner and a completion deadline, and proceed to sign-off with the interim controls in place and the full mitigation action outstanding.

What you cannot do is sign off the "Approved for Deployment" determination while a HIGH residual risk exists with no mitigation. That would be a false compliance record.

The £97 one-time purchase includes both documents in the FRIA Pack: the complete FRIA Workbook (WKBK-AIMS-FRIA-001 v2.0) and the scored Readiness Checker (TOOLKIT-AIMS-FRIA-001-CL). Both are delivered as self-contained HTML files with full print-to-PDF styles — open in any modern browser, complete on screen, and print to A4 for wet signature and filing.

Purchase is processed through ClickBank. You will receive access immediately after purchase — no email gate, no waiting period, no subscription. There are no upsells: the £97 covers both documents in full.

If you are a UNUS London Governance Academy member, both documents are available free inside your Skool membership. Log in, navigate to the EU AI Act Bridge Series, and open the FRIA Workbook module.

This workbook is Gap D of the EU AI Act Bridge Series — the six-module programme covering every statutory obligation the EU AI Act creates for UK organisations deploying AI systems. The FRIA Workbook depends on REG-AIMS-CLASS-001 (the Annex III AI Classification Register, Gap B of the Series) for the classification outcomes that determine whether Article 27 is triggered.

The full Series covers: Gap A (AI Governance Framework), Gap B (Annex III Classification), Gap C (GPAI Model Assessment), Gap D (FRIA — this workbook), Gap E (Human-in-the-Loop Procedures, PROC-AIMS-HITL-001), and Gap F (Ongoing Monitoring and Annual Review). Governance Academy members have access to all six gaps within their membership.

Article 27 · Regulation (EU) 2024/1689

The obligation is active. The deadline has passed. The document doesn't write itself.

Whether your AI systems are classified as High-Risk or not, Article 27 requires a documented position. Either a signed non-trigger confirmation or a completed eight-dimension FRIA. Both are in this pack.

Get the FRIA Pack — £97 Academy Member Access — Free

One-time purchase · No subscription · Instant access · Both documents included