EU AI ACT · ARTICLE 27 · WITH ARTICLE 35 GDPR
The assessment you’ll file
before you deploy.
Article 27 requires a fundamental rights impact assessment before first use of certain high-risk AI systems, with the result notified to your market surveillance authority. The obligation applies from 2 December 2027 for Annex III systems. Where a GDPR DPIA exists, the FRIA complements it rather than repeating it.
Not an internal document.
A notified one.
Article 27(3) requires the deployer to notify the market surveillance authority of the assessment’s results, submitting a template developed by the AI Office. This is not a file-and-forget exercise — it is a regulatory submission, and it is read.
It applies before first use. Article 27(2) ties the obligation to the first deployment of the system. A deployer may rely on a previous assessment in similar cases, but where the elements change or fall out of date, it must be updated. Getting it right the first time is cheaper than revisiting it.
Your DPIA does not cover it. Article 27(4) is explicit: where obligations are already met through an Article 35 GDPR assessment, the FRIA complements that assessment. Complements, not duplicates and not replaces. Two instruments, one exercise, if they are run together.
And the scope is wider than most assume. It reaches bodies governed by public law and private entities providing public services — but also any deployer of AI used for creditworthiness assessment or for risk pricing in life and health insurance, whether public or not.
The six elements Article 27 requires
Set out in the Regulation itself. We build each one to a standard that survives being read by a regulator.
Element (a)
Your processes, described
A description of the deployer’s processes in which the high-risk system will be used, in line with its intended purpose. Most organisations discover here that the documented process and the actual process have drifted apart.
- Is the system being used as the provider intended?
- Does your documented process match what staff actually do?
Element (b)
Period and frequency of use
Over what period, and how often, each high-risk system is intended to be used. Specific enough to be meaningful — a pilot, a seasonal deployment, and continuous operation are materially different risk profiles.
- Is this a trial, a phased rollout, or permanent operation?
- How often does the system actually run?
Element (c)
Who is affected
The categories of natural persons and groups likely to be affected by use of the system in the specific context. Not users — affected persons. In public service delivery those are rarely the same population.
- Who is subject to decisions this system supports?
- Are any of those groups already disadvantaged in this process?
Element (d)
Specific risks of harm
The specific risks of harm likely to impact those categories, taking into account the information the provider must give under Article 13. This means reading the provider’s documentation properly rather than accepting a vendor summary.
- What has the provider actually disclosed about limitations?
- What harms are plausible in your context, not in general?
Element (e)
Human oversight, as implemented
A description of how human oversight measures are implemented, according to the instructions for use. Not the policy — the implementation. Who exercises oversight, with what authority, and whether they can act on it.
- Can the named person actually override or halt the system?
- Do they have the time and standing to do it?
Element (f)
What happens when risks materialise
The measures to be taken if those risks materialise, including internal governance arrangements and complaint mechanisms. This is the element most often left thin — and the one a regulator can test simply by asking a person how to complain.
- How does an affected person raise a concern?
- Who receives it, and what are they empowered to do?
Scope and engagement
Priced on scope. You know the full number before anything starts.
The scope
Priced on scope
Scoped per high-risk system, which is how Article 27 structures the obligation. Complexity depends on the affected population, the provider documentation available, and whether an Article 35 DPIA already exists to build on.
Assessed on a scoping call, quoted as a fixed fee before any work begins.
Run together
FRIA and DPIA as one exercise
Article 27(4) makes the FRIA complementary to an Article 35 GDPR assessment. Where you have a DPIA, we build on it. Where you need both, we run them as a single exercise rather than two overlapping ones.
One set of interviews. One evidence base. Two instruments that reference each other properly.
Before this
Classification first
A FRIA only applies to systems that are high-risk under Article 6(2) and to deployers within Article 27’s categories. If you have not established either, the High-Risk AI Readiness Assessment comes first — and the Article 4 Literacy Scan before that.
We will tell you on the call if you are further back in the sequence than you thought.
The terms
How it runs
Remote delivery, with a turnaround agreed at scoping and a matching turnaround expected on your side for information requests. Misses move the delivery date day for day. The €2,800 Article 4 Scan fee credits against engagements of €10,000 or more contracted within 90 days.
Clear on both sides. That is what makes a fixed date deliverable.
What you receive
A completed assessment ready for submission, and the governance work it depends on.
Completed FRIA
All six elements of Article 27(1) addressed, evidenced, and written to be read by a regulator rather than filed internally.
Notification pack
The assessment prepared against the AI Office template format for submission to your market surveillance authority under Article 27(3).
DPIA integration
Where an Article 35 DPIA exists, a mapping showing what it already covers and where the FRIA complements it — so neither document contradicts the other.
Oversight implementation record
Element (e) done properly: who holds oversight authority, what they can actually do, and the evidence that the arrangement is real.
Complaint mechanism design
Element (f): the route an affected person takes, who receives it, what they are empowered to do, and how it is recorded.
Update triggers
Article 27(2) requires updating when elements change. We define what counts as a change and what should prompt a review, so it does not quietly go out of date.
Who this applies to
- Bodies governed by public law deploying high-risk AI systems under Article 6(2)
- Private entities providing public services — the obligation follows the function, not the ownership
- Any deployer of AI used to evaluate creditworthiness or establish credit scores, under Annex III point 5(b)
- Any deployer of AI used for risk assessment and pricing in life and health insurance, under Annex III point 5(c)
- Organisations with an existing GDPR DPIA who need to know what it does and does not already cover
- Law firms advising on Article 27 whose clients need the assessment built and the evidence assembled
Not covered by this obligation
Article 27(1) excludes high-risk systems intended for use in the area listed at point 2 of Annex III. If your systems fall there, the FRIA obligation does not attach — though other deployer obligations under Article 26 still do.
Whether your organisation and your systems fall within Article 27 is a legal determination. We prepare the analysis that supports it; your counsel confirms it.
Scope of engagement — please read
Connext does not provide legal advice. Nothing in our deliverables constitutes a legal opinion or a determination of regulatory status.
Classification and applicability are legal determinations. Whether an AI system falls within a given obligation, and whether any measure is sufficient to satisfy it, remain the responsibility of the client and its legal counsel. Our analysis is prepared to support that determination — it does not replace it.
Deliverables should be reviewed by qualified counsel in the relevant jurisdiction before you rely on them. Connext accepts no liability for any consequence arising from a decision not to obtain that review, or from reliance on our deliverables without it.
START THE CONVERSATION
Find out what you need to file.
A 45-minute scoping call. We’ll establish whether Article 27 attaches to your organisation and your systems, what an existing DPIA already covers, and what a FRIA would involve. If you’re earlier in the sequence than you thought, we’ll say so.
BOOK A 45-MINUTE CALLOr email hello@connextbusinesssolutions.com — a short question doesn’t need a meeting. Remote-first across Canada, the United States, Europe, and Asia Pacific.