Agentic Fluxus · Fundamental Rights Impact Assessment scoping document
Article 27 FRIA Template
A FRIA is required before deploying a high-risk Annex III AI when you are (a) a public body or private entity providing public services, OR (b) a deployer of Annex III(5)(b) credit-scoring or (5)(c) life/health insurance AI. This template covers the six elements Article 27(1) requires.
Section 1 — Deployment context
- AI system name + provider + version.
- Intended purpose (per provider's Article 13 instructions for use).
- Where in our pipeline the AI is used.
- Frequency of decisions per period.
- Geographical scope of use.
- Duration: pilot, scaled, indefinite.
Section 2 — Categories of affected natural persons
- Primary affected group: who the AI makes decisions about.
- Secondary affected groups: those indirectly affected.
- Vulnerable subgroups: children, elderly, those with disabilities, protected-characteristic groups.
- Estimated number of persons affected per year.
Section 3 — Specific risks of harm
- Per affected group, list the Charter rights potentially impacted: dignity, equality, privacy, data protection, fair trial, freedom of expression, child rights, worker rights.
- For each risk: severity (low / medium / high), likelihood (low / medium / high), scope (individual vs systemic).
- Distinguish individual harms from cumulative/societal harms.
Section 4 — Human oversight measures (Article 14)
- Who is the natural-person reviewer.
- What can they override.
- What training have they had.
- Escalation path when the AI is wrong.
- How is meaningful (not rubber-stamp) review demonstrated.
Section 5 — Risk mitigations
- Technical measures (filters, calibration, monitoring).
- Organisational measures (training, governance, escalation).
- Contractual measures (with provider, with downstream).
- Affected-person rights infrastructure (explanation, contestation, human review).
Section 6 — Monitoring + iteration
- Metrics tracked post-deployment to detect drift, disparate impact, new harms.
- Frequency of monitoring review.
- Threshold for re-running the FRIA on material change.
- Article 27(3) notification log: when notified MSA, by whom, reference number.
Notification
Per Article 27(3), notify the national market surveillance authority of the FRIA outcome before deployment.
Read the full FRIA guide:
https://agenticfluxus.com/blog/eu-ai-act-article-27-fria
By John Ferguson · Founder, Agentic Fluxus · agenticfluxus.com · Amsterdam, Netherlands

