Digital Practice Kits for organisationsEditable templates and work tools
KI PraxisPilot · EU AI Act · Fundamental Rights Impact Assessment

Conduct a FRIA for High-Risk AI – EU AI Act Practice Kit

Assess whether your planned or existing high-risk AI deployment requires a Fundamental Rights Impact Assessment (FRIA), work through affected persons, potential harms, human oversight and safeguards, and document the decision, approval, evidence and reassessment path.

Implement more efficiently & reduce setup effortStart directly with a prepared FRIA working and evidence structure — less time spent turning Article 27 requirements into your own process and templates.
  • Assess applicability before deployment document the high-risk/deployment context and route unclear applicability questions to specialist review.
  • Work through impacts & safeguards connect affected persons, harm scenarios, provider evidence, human oversight and operational safeguards.
  • Close approval & evidence prepare the deployment decision, information/complaint/redress planning, evidence index and monitoring/reassessment path.
13 working materials1 Deployment Cockpit3 AI assistants1 complete sample case
Product at a glance

A deployer-side work system for Fundamental Rights Impact Assessment

The Practice Kit is designed for organisations that need to determine whether a concrete high-risk AI deployment falls within the FRIA requirements of Article 27 of Regulation (EU) 2024/1689 (EU AI Act) and, where applicable, perform and document the assessment before deployment.

Product typeDigital B2B Practice Kit
Designed forOrganisations that need to assess and document FRIA relevance, fundamental-rights impacts, safeguards and decision readiness for a concrete planned or existing high-risk AI deployment.
File formatsPDF · XLSX · DOCX · MD · ZIP
Price€349.00 incl. VAT
ProviderSP Services GmbH
DeliveryDigital download

What does the Practice Kit help us work through?

Whether the deployment enters the Article 27 FRIA route and, where it does, the concrete process/use, duration and frequency, affected persons or groups, potential harms, provider information, human oversight, safeguards, information/complaint/redress measures and approval/evidence status.

From the starting point to a documented work status

From applicability to monitored deployment decision

Starting point

For planned or existing high-risk AI deployments, process data, provider documents, fundamental-rights risks, safeguards, specialist reviews and approvals are often held separately. Connect them to assess FRIA applicability and identify open points before the deployment decision.

Outcome

Connect applicability and context, affected groups, harm scenarios, human oversight, evidence, specialist reviews, the human deployment decision, monitoring and reassessment in one traceable case.

Assess FRIA applicability before building a full assessment file

Use a dedicated applicability/specialist-routing check so that unresolved high-risk or Article 27 questions are visible rather than hidden inside the assessment.

Tie fundamental-rights analysis to the real process

Map the actual deployment process, decision points, affected persons and operational context instead of assessing the AI system only in the abstract.

Request the provider evidence you actually need

Use the Provider Evidence Request / Gap List to connect Article 13/provider information and other technical facts to the deployer's assessment.

Turn affected-person analysis into concrete harm scenarios

Use a structured workshop to identify affected natural persons or groups of persons, plausible harm pathways and evidence gaps without pretending to automate fundamental-rights judgement.

Operationalise human oversight and safeguards

Translate oversight and safeguards into responsibilities, intervention points, competence, escalation and evidence.

Preserve the decision and reopen it when facts change

Connect the FRIA Working Assessment to specialist cross-review, deployment decision, evidence index, monitoring and the FRIA-CURRENT revalidation check.

Implement more efficiently

A prepared structure for your own implementation

FRIA applicability, affected groups, harm scenarios, human oversight, safeguards, evidence, specialist reviews, approval and reassessment form a prepared workflow for your deployment case.

Reduce preparation effort

Prepared processes, work tools and evidence structures help reduce internal research and setup effort.

Use your internal expertise

Use your team's existing expertise within a structured working process.

Bring in specialist expertise where needed

Individual legal, privacy, technical and specialist questions remain with the responsible functions. External support can focus on questions that require an individual review or decision.

Subject-matter reference

Tasks & requirements

The overview covers the AI Act and FRIA topics addressed by this Practice Kit and connects them to tasks, work tools and evidence. It is not a complete AI Act requirements list or a confirmation of conformity or completeness.

Quellenbasis

Regulation (EU) 2024/1689 (EU AI Act), particularly Articles 26 and 27. The included requirements mapping and specialist guidance support the working assessment. Verify the current legal position and applicable guidance before an actual deployment approval.

Is the AI system/use in a high-risk route relevant to the FRIA assessment?

EU AI Act Article 6(2), Annex III and Article 27, depending on the concrete system and deployment.

Document the working classification inputs and route unresolved high-risk or applicability questions to specialist review.

Work tools: FRIA Navigator; FRIA Working Assessment; Evidence & Approval Index

Outcome / evidence: A documented case status with responsibilities, open questions and evidence references.

Are the deployment conditions and provider instructions understood?

Article 26(1) and relevant provider information.

Record how the deployer intends to use the system and identify gaps between the intended deployment and the information/instructions available from the provider.

Work tools: Provider Evidence Request / Gap List

Outcome / evidence: A documented case status with responsibilities, open questions and evidence references.

Are input data, monitoring and logs under deployer control addressed?

Article 26, including relevant obligations such as paragraphs (4), (5) and (6) where applicable.

Connect operational controls, monitoring, suspension/escalation and log/evidence availability to the deployment case.

Work tools: FRIA Navigator; FRIA Working Assessment; Evidence & Approval Index

Outcome / evidence: A documented case status with responsibilities, open questions and evidence references.

Which natural persons or groups of persons are likely to be affected?

Article 27(1)(c).

Identify affected persons/groups in the concrete process, including indirect effects where they are relevant to the assessment.

Work tools: Affected Persons / Harm Scenario Workshop; FRIA Working Assessment

Outcome / evidence: A documented case status with responsibilities, open questions and evidence references.

What specific risks of harm need to be assessed in the actual deployment context?

Article 27(1)(a) and (d), taking account of information supplied by the provider under Article 13 where relevant.

Translate the real process and decision/use context into plausible fundamental-rights harm scenarios and evidence needs.

Work tools: FRIA Navigator; FRIA Working Assessment; Evidence & Approval Index

Outcome / evidence: A documented case status with responsibilities, open questions and evidence references.

What human oversight and safeguards are required in the deployment?

Article 27(1)(e) and (f), together with applicable deployer obligations.

Define responsibilities, intervention/escalation points, operational safeguards and evidence instead of relying on a generic statement that “a human is involved”.

Work tools: Human Oversight / Deployment Control Plan

Outcome / evidence: A documented case status with responsibilities, open questions and evidence references.

How are information, complaint/redress and deployment decision points documented?

Article 27(1)(f), relevant Article 26 information duties and the concrete deployment context.

Plan the operational information and complaint/redress interfaces and connect them to the approval decision and evidence package.

Work tools: Information / Complaint / Redress Plan

Outcome / evidence: A documented case status with responsibilities, open questions and evidence references.

When must the FRIA be updated or revalidated, and what external handover/notification steps are relevant?

Article 27(2)–(5) as applicable.

Use monitoring and revalidation triggers, preserve the evidence needed for any required external interface, and verify the current official template/authority route before live use.

Work tools: FRIA Navigator; FRIA Working Assessment; Evidence & Approval Index

Outcome / evidence: A documented case status with responsibilities, open questions and evidence references.

Package contents

What is included

Coordinated work tools for structured independent implementation.

FRIA Navigator

HTML

A browser-based guidance path for applicability, assessment, specialist routing, decision and reassessment.

FRIA Implementation Checklist

XLSX

An editable Excel checklist for status, actions, responsibilities, evidence and closure.

FRIA Deployment Cockpit

XLSX

A central Excel working view for the deployment case, assessment status, actions, evidence and approvals.

13 working materials

PDF · DOCX · XLSX

Applicability / Specialist Routing Check; Process-to-Decision Canvas; Provider Evidence Request / Gap List; Affected Persons / Harm Scenario Workshop; Human Oversight / Deployment Control Plan; FRIA Working Assessment; Cross-Review / Specialist Brief; Information / Complaint / Redress Plan; Deployment Decision Brief; Monitoring / Reassessment Protocol; FRIA-CURRENT Revalidation Check; FRIA Implementation Checklist; Evidence & Approval Index

Complete sample case

PDF · DOCX · XLSX

A populated deployment case with corresponding worked materials for orientation across the end-to-end FRIA workflow.

3 AI assistants

MD · PDF

Process / Affected Persons / FRIA Assistant; Deployment Control Assistant; Complaint / Review / Reassessment Assistant

Practical handbook, legal-status/source documentation and requirements mapping

PDF · DOCX · XLSX

Supporting documentation for applying the working system and keeping time-dependent legal/source questions visible.

Explore the work tools

Previews from the supplied work tools

The previews show key components of the supplied work tools.

Reusable working process

A controlled path from applicability to reassessment

Assess FRIA relevance for a high-risk AI deployment, review fundamental-rights impacts and document safeguards, approvals and evidence.

The working sequence connects assessment, specialist review, decision and reassessment.
Phase 1

Phase 1 — Applicability & deployment context

Record the AI system, intended deployment and process. Perform the applicability/specialist-routing pre-check and map the process-to-decision flow before making assessment conclusions.
Record the result, open issues and evidence in the case file.
Documented result and next working step.
Phase 2

Phase 2 — Affected persons, evidence & harm scenarios

Request missing provider evidence, identify affected natural persons or groups of persons and develop deployment-specific harm scenarios and evidence needs.
Record the result, open issues and evidence in the case file.
Documented result and next working step.
Phase 3

Phase 3 — Human oversight, safeguards & assessment

Define operational human oversight and safeguards, complete the FRIA Working Assessment and route unresolved issues through specialist cross-review.
Record the result, open issues and evidence in the case file.
Documented result and next working step.
Phase 4

Phase 4 — Decision, redress, evidence & monitoring

Prepare information/complaint/redress planning, document the deployment decision, complete the evidence/approval index and establish monitoring and reassessment triggers, including FRIA-CURRENT revalidation.
Record the result, open issues and evidence in the case file.
Documented result and next working step.
Quick start

Start with your first case

Open START HERE, create a working copy and follow the next steps for your own case.

  • 1. Create a deployment case in the FRIA Deployment Cockpit and assign a unique identifier.

  • 2. Record the intended process/use, AI system, provider, deployment owner and current high-risk/FRIA assumptions.

  • 3. Complete the Applicability / Specialist Routing Check before treating FRIA applicability as closed.

  • 4. Map the process-to-decision flow and identify affected natural persons or groups of persons.

  • 5. Open provider-evidence gaps and the first harm/safeguard work items with clear owners.

  • 6. Do not approve deployment from the template alone: complete required specialist review, decision and evidence steps and define the first reassessment trigger.

Designed for

  • organisations that need to assess whether a planned or existing high-risk AI deployment falls within Article 27;
  • AI governance, legal/compliance and risk functions coordinating a FRIA;
  • process owners and operational deployers responsible for the real deployment context;
  • privacy, information-security, HR, fundamental-rights or other specialist functions contributing to the assessment;
  • project teams that need a traceable decision, evidence and reassessment record before or during deployment.

Prerequisites

  • a concrete AI system and deployment/use case;
  • the actual process and decision/use context;
  • provider information/instructions and access to additional provider evidence where needed;
  • responsible deployment/process owners;
  • specialist support for high-risk classification, legal, privacy, security and fundamental-rights questions where required.

Not included

  • a binding determination that the AI system is or is not high-risk;
  • a binding determination that Article 27 does or does not apply;
  • legal advice, authority approval or official notification on your behalf;
  • approval to deploy the AI system;
  • a guarantee that the completed assessment is substantively sufficient for every complex or sensitive case.
Related next steps

Further Practice Kits and support

Clear before purchase

Price, licence, support and updates

Licence

The licence terms supplied with the product govern internal organisational use, editing and permitted use of completed outputs. The original template library and source files may not be redistributed outside the licensed scope.

Support

Support covers download/file access, package structure and technical product issues. It does not include individual legal, fundamental-rights, privacy, security or deployment approval unless separately agreed.

Updates

FRIA templates, official forms, authority routes and guidance can change. Revalidate the current official position before a live deployment, notification or material reassessment. Product updates are included only where explicitly stated in the product or checkout.

Frequently asked questions

Questions before purchase

Key questions about use, scope and boundaries before purchase.

Does every high-risk AI system require a FRIA?+

No. Article 27 applies to specified deployers and cases. The Practice Kit starts with an applicability/specialist-routing check precisely because high-risk status alone should not be treated as an automatic FRIA conclusion.

Does the Practice Kit make the binding high-risk or FRIA classification?+

No. It structures the facts, working assessment and escalation. Binding legal classification remains outside the product.

Is a FRIA the same as a GDPR Data Protection Impact Assessment (DPIA)?+

No. They are distinct assessments with different legal bases and purposes, although a concrete deployment may require coordinated work and reuse of relevant factual evidence. Do not treat one as an automatic substitute for the other.

What if provider evidence is missing?+

Use the Provider Evidence Request / Gap List to record the missing information, owner, request and effect on the assessment. Do not close the FRIA on unsupported assumptions.

Is human oversight covered?+

Yes. The Human Oversight / Deployment Control Plan translates oversight into concrete responsibilities, competence, intervention points, escalation and evidence for the actual deployment.

Does the package cover affected persons and harm scenarios?+

Yes. The Affected Persons / Harm Scenario Workshop and FRIA Working Assessment connect affected natural persons or groups of persons to deployment-specific potential harms, safeguards and evidence gaps.

Are complaint and redress mechanisms included?+

Yes. The Information / Complaint / Redress Plan supports implementation of the relevant operational interfaces and their connection to the deployment decision and evidence.

Does the kit submit information to an authority?+

No. It can help prepare and evidence the required working status. Any current official template, competent authority and submission/notification route must be verified for the concrete case before use.

Do the AI assistants approve the FRIA or deployment?+

No. They support structured work and drafting. Specialist review, fundamental-rights judgement and the deployment decision remain human responsibilities.

When should the assessment be reopened?+

Use the Monitoring / Reassessment Protocol and FRIA-CURRENT Revalidation Check when the process, system, provider information, affected groups, risks, safeguards, legal position or deployment conditions change materially.

Ready for the next step?

Conduct a FRIA for High-Risk AI – EU AI Act Practice Kit

Use the Practice Kit to connect applicability, deployment context, affected persons, harm scenarios, provider evidence, human oversight, safeguards, approval and reassessment without building the process and working materials from scratch.

Buy now
Conduct a FRIA for High-Risk AI – EU AI Act Practice Kit€349.00 incl. VAT
Buy now