FRIA in plain language: probably not you, but know when it is
Edition 10. A reading time of about 5 minutes.
The hook
The fundamental rights impact assessment, the FRIA, has a reputation as the heaviest thing in the AI Act, and a lot of compliance anxiety attaches to it. Here is the part nobody leads with: for most private employers using an AI hiring tool, the FRIA is not your obligation at all. The useful skill is telling whether you are inside or outside it, so you neither do work the law does not ask for, nor miss it on the day you actually fall in.
What this means
Article 27 does not apply to every deployer of a high-risk system. It applies to a narrow set: bodies governed by public law and private entities providing public services, plus deployers of two specific Annex III categories, creditworthiness and credit scoring, and risk assessment and pricing in life and health insurance (AI Act, Article 27). An ordinary private-sector employer using an AI hiring tool falls outside that list, unless it also happens to be one of those public-service or financial-scoring deployers.
When it does apply, the FRIA is a real piece of work, due before first use. It describes how and how often the system will be used, the categories of people likely to be affected, the specific risks of harm to them, the human oversight in place, and the mitigation and complaint mechanisms, and the deployer must notify the market surveillance authority of the results (AI Act, Article 27). That is a substantial obligation, which is exactly why it matters that it is not yours by default.
So the honest read for a private employer: the FRIA is probably not on your list. But its contents are a good way to think, even when you are not required to file one.
What to do with this
Four steps, starting with the one that saves you the most work.
- Check which side you are on. Are you a public body, a private entity providing a public service, or a deployer of credit scoring or insurance risk systems? If none of those, the Article 27 FRIA is not your obligation.
- If you are outside it, do not file one "to be safe." It is not required, and the same effort returns far more in the obligations that are yours, the oversight, monitoring, and records from earlier editions.
- Borrow the checklist anyway. Quietly asking who is affected, what could go wrong for them, what oversight exists, and how someone complains is a sharp, voluntary self-assessment, and it doubles as evidence that you took the decision seriously.
- If you are inside it, do the FRIA before first use and notify the authority. Note that a previous assessment can be reused for similar cases, so it is not a fresh project every time.
The point is not to dodge work; it is to spend your compliance effort where the law actually puts it. For most hiring teams, that means a strong oversight habit and a clean evidence trail, not a FRIA filing.
This is educational material and a starting point, not legal advice. The EU AI Act is still being amended, and the high-risk timeline rests on an agreement that is not yet final law. For whether your organisation falls within the Article 27 FRIA obligation, consult a qualified lawyer. Signato is not a law firm and does not certify compliance.
AI that drafts at scale can also send the wrong thing at scale. See the Signato chamber block a forbidden send before it happens: run the free local trial, no card, nothing leaves your machine.
Every claim here is traced to the primary regulation and checked by a person before it goes out. We tell you what is settled, what is still open, and what to do next. How we work.
Know someone who hires in the EU? Forward this to them.