FRIA Scoping - Who Must Conduct It and When (Post-Omnibus VII Timing)
The AI Governance Committee meets in eleven days. The agenda has one substantive item: "FRIA scoping decision: which of our 47 high-risk systems get FRIAs, when do they get them, and who signs the cover memo." The general counsel wants a list. The CFO wants budget. The Chief AI Officer wants a defensible answer to the question: "Why are we doing some FRIAs in 2026 when the deadline moved to Dec 2, 2027?" This lesson is the L3 playbook for that meeting: Article 27's two-category test walked in regulator-grade detail, the post-Omnibus VII timing nuance that separates legally-required FRIA dates from operate-it-now management practice, and the FRIA trigger memo that turns 47 systems into a defensible board artifact.
Article 27 in Full - The Two-Category Test the Statute Actually Imposes
Article 27 of the EU AI Act creates the Fundamental Rights Impact Assessment obligation. Read the text carefully, because most program documents quote it loosely and create downstream confusion. Article 27(1) reads, in operational paraphrase: deployers that are bodies governed by public law, or private operators providing public services, and deployers of high-risk AI systems referred to in Annex III other than §2 (critical infrastructure), shall conduct an assessment of the impact on fundamental rights that the use of such system may produce. The same Article 27(1) extends the obligation to deployers of Annex III §5(b) creditworthiness scoring and Annex III §5(c) life and health insurance risk assessment and pricing regardless of public-body status.
The text creates two distinct deployer categories, both of which trigger FRIA. The categories are not equivalent and not interchangeable. They are answered separately for each system in the portfolio:
- Category A - Public bodies and private operators providing public services, deploying any Annex III non-§2 system. The qualifying deployer test is the public-body / public-service-operator status. The qualifying system test is Annex III membership except §2 critical infrastructure. The §2 exclusion is deliberate, the harmonization-standard / safety-component nature of §2 systems drives a different obligation set focused on Article 9 risk management and Annex I conformity, not on fundamental-rights impact at the deployer level.
- Category B - Any deployer of Annex III §5(b) creditworthiness scoring or Annex III §5(c) life/health insurance risk assessment and pricing systems. The qualifying system test is membership in §5(b) or §5(c). The deployer category is irrelevant: private-sector banks, fintech lenders, life insurers, health insurers, and any other deployer of these specific systems falls within the FRIA obligation regardless of whether they are public-body status.
The two categories overlap at the edge, a public hospital deploying a §5(c) health insurance risk assessment system is in both Category A and Category B simultaneously, but the analytical discipline is to test each system against both categories separately and document the rationale. The downstream FRIA obligation is identical whichever category triggers it; the analytical record matters because regulators will ask the question "why is this system in your FRIA backlog" and the right answer cites Article 27(1) with the specific category.
A third analytical bucket is necessary for completeness: Excluded - Annex III §2 critical-infrastructure deployers. Article 27 specifically carves §2 out of the FRIA obligation. A grid-load-balancing AI safety component, a water-supply demand-forecasting AI in closed-loop operation, a road-traffic intelligent transport system. These are Annex III §2 high-risk systems with full Article 9 risk-management, Article 14 human-oversight, and Article 15 robustness/cybersecurity obligations, but they do not trigger Article 27 FRIA. The conformity package for §2 systems is built around Annex IV technical documentation and NIS 2 cybersecurity integration; the deployer-side fundamental-rights impact assessment is not part of the §2 obligation set.
Post-Omnibus VII Timing Nuance - Why Some FRIAs Wait and Others Do Not
Omnibus VII moved the stand-alone Annex III applicability date from Aug 2, 2026 to Dec 2, 2027. The narrow legal effect: high-risk AI systems classified under Annex III now face their core obligations (Annex IV technical documentation, Article 47 EU declaration of conformity, Article 71 EU database registration, CE marking) on the Dec 2, 2027 date rather than the original Aug 2, 2026 date. Article 27 sits on top of the high-risk classification, Article 27(1) references Article 6 high-risk membership, so the natural reading is that FRIA timing tracks the Annex III timing for systems caught by the stand-alone date slip.
That is the legal reading for most systems. It is not the legal reading for Category B systems (§5(b) creditworthiness and §5(c) life/health insurance). The Article 27(1) text creates a specific obligation for §5(b)/§5(c) deployers that does not depend on the broader Annex III stand-alone timing. The Commission's pre-Omnibus VII guidance treated §5(b)/§5(c) FRIA as a deployer-side obligation that attaches as a function of the system's classification, not as a function of the broader transitional schedule. Post-Omnibus VII guidance has not contradicted that reading; the §5(b)/§5(c) FRIA obligation remains on the Aug 2, 2026 track in practice.
The same reasoning applies, with more analytical work, to Category A systems where the deployer is a public body or private operator providing public services. Article 27 imposes the FRIA obligation as a function of the deployer category combined with Annex III membership; the obligation is not contingent on the stand-alone Annex III conformity-assessment timeline. Mature programs treat Category A FRIA as also on the Aug 2, 2026 capability track, because (a) the legal reading supports it, (b) the operational risk of being wrong is high, and (c) the public-body / public-service deployer profile is intrinsically transparency-sensitive and benefits from early FRIA artifacts.
The practical decomposition for the AI Governance Committee:
- Legally-required FRIA date: Aug 2, 2026 track: Category B §5(b) and §5(c) deployers, regardless of public-body status. Public-body and public-service-operator deployers of Category A systems where the obligation reading is supported by the Article 27(1) construction.
- Legally-required FRIA date: Dec 2, 2027 track: Private-sector, non-§5(b)/§5(c) deployers of Category A Annex III non-§2 systems, where the FRIA obligation arrives with the stand-alone Annex III applicability date.
- Excluded from FRIA: Annex III §2 critical-infrastructure deployers (any deployer category).
- Operate-it-now management practice: All FRIA-eligible systems, regardless of legal deadline. The board-defensible posture is to operationalize FRIA capability in 2026 and to populate the FRIA backlog across 2026-2027 rather than to defer all non-§5(b)/§5(c) work to the legal deadline. The reasoning: (a) the FRIA artifact is a complex multidisciplinary document requiring legal + product + data-science + ethics + affected-stakeholder input that does not scale on a regulatory deadline; (b) board oversight bodies expect mature FRIA practice ahead of legal mandate; (c) post-market monitoring under Article 72 depends on the FRIA's baseline harm-identification, so FRIA-then-monitor is the logical sequence; (d) regulator engagement under voluntary cooperation pre-deadline is materially advantaged by having FRIA artifacts already in hand.
Twelve Worked Examples - Category Classification and FRIA Timing
The two-category test against representative deployer scenarios. Each row carries the deployer type, the Annex III sub-category, the FRIA category (A, B, both, or excluded), the legally-required FRIA date, and the operate-now recommendation.
- Public hospital deploying Annex III §5(a) public-assistance triage AI. Deployer is a body governed by public law. Annex III sub-category is §5(a) (non-§2). Category A applies. Legally-required FRIA date, Aug 2, 2026 track (Category A public-body reading). Operate-now: yes, FRIA capability operational by Aug 2, 2026; FRIA artifact for this system completed in FY26.
- Public university deploying Annex III §3 admission scoring AI. Deployer is a body governed by public law. Annex III sub-category is §3 admission (non-§2). Category A applies. Legally-required FRIA date, Aug 2, 2026 track (Category A public-body reading). Some programs read this as Dec 2, 2027 conservatively; the defensible mature position is Aug 2, 2026 capability with FRIA artifact completion across FY26-FY27. Operate-now: yes, capability by Aug 2, 2026; artifact completion sequenced.
- Private bank deploying Annex III §5(b) credit scoring AI. Deployer is a private-sector entity, not public-body. Annex III sub-category is §5(b). Category B applies. Legally-required FRIA date, Aug 2, 2026 track (Category B is regardless of public-body status). Operate-now: yes, FRIA capability operational by Aug 2, 2026; FRIA artifact for this system completed in FY26 with Article 86 right-to-explanation design integrated; Article 27(3) notification to national supervisory authority on completion.
- Private life insurer deploying Annex III §5(c) underwriting AI. Deployer is a private-sector entity. Annex III sub-category is §5(c). Category B applies. Legally-required FRIA date, Aug 2, 2026 track. Operate-now: yes, FRIA capability by Aug 2, 2026; FRIA artifact in FY26 with Solvency II model-risk overlay integration; Article 86 right-to-explanation design where applicable; Article 27(3) notification on completion.
- Private health insurer deploying Annex III §5(c) pricing AI. Deployer is a private-sector entity. Annex III sub-category is §5(c). Category B applies. Legally-required FRIA date, Aug 2, 2026 track. Operate-now: yes, FRIA capability by Aug 2, 2026; FRIA artifact in FY26 with national-health-regulator overlay where applicable.
- Private-sector HR-tech vendor selling §4 employment AI to a private-sector employer. Deployer is a private-sector entity. Annex III sub-category is §4 (non-§2). Public-service-overlap analysis: the private-sector employer typically does not provide public services unless the employer is a delegated-public-service provider. Category A does not apply on standard private-employer use. Legally-required FRIA date: Dec 2, 2027 track (private deployer, non-§5(b)/§5(c), Annex III stand-alone date). Operate-now recommendation: yes, capability by Aug 2, 2026 for board-defensible posture; FRIA artifact in FY26-FY27 sequenced against the Dec 2, 2027 deadline. Note that the HR-tech vendor (provider) does not itself trigger FRIA, provider obligations under Article 16 attach independently; FRIA is a deployer obligation.
- Private-sector HR-tech vendor selling §4 employment AI to a public-service employer (e.g., national-rail operator, public-healthcare-system employer, public-utility employer where the entity is a private operator providing public services). Deployer is a private operator providing public services. Annex III sub-category is §4. Category A applies. Legally-required FRIA date, Aug 2, 2026 track. Operate-now: yes; FRIA artifact in FY26. Note that the same vendor's product faces different FRIA timing depending on which customer deploys it, the procurement-driven analysis is per-deployer, not per-product.
- Public-sector employer (national agency, ministry, public university HR function) deploying Annex III §4 employment AI internally for civil-service recruitment. Deployer is a body governed by public law. Annex III sub-category is §4. Category A applies. Legally-required FRIA date, Aug 2, 2026 track. Operate-now: yes; FRIA artifact in FY26 with civil-service-law overlay (works-council consultation in some Member States, additional national-employment-law transparency requirements).
- Border-control authority deploying Annex III §7 application-routing AI for asylum cases. Deployer is a body governed by public law (or a private contractor acting on behalf of public authority). Annex III sub-category is §7. Category A applies. Legally-required FRIA date, Aug 2, 2026 track. Operate-now: yes; FRIA artifact in FY26 with fundamental-rights overlay (CJEU, ECHR), national-implementing-law overlay, and Article 27(3) notification on completion. §7 systems are intrinsically transparency-sensitive and benefit substantially from completed FRIA in advance of operational deployment.
- Judicial decision-support tool deployed at a court (Annex III §8). Deployer is a body governed by public law. Annex III sub-category is §8. Category A applies. Legally-required FRIA date, Aug 2, 2026 track. Operate-now: yes; FRIA artifact in FY26 with judicial-independence overlay, national-judicial-rules overlay, and heightened Article 14 human-oversight expectations integrated.
- Regional energy operator deploying Annex III §2 grid-AI for load balancing. Deployer is a public-utility operator (or private operator providing public services). Annex III sub-category is §2 critical infrastructure. EXCLUDED from Article 27 FRIA. The §2 exclusion controls regardless of deployer category. The §2 system carries full Article 9 risk-management, Article 14 human-oversight, Article 15 robustness, NIS 2 cybersecurity, and potentially Annex I CE-marking if integrated; but the deployer-side FRIA obligation does not attach. Document the excluded classification in the FRIA trigger memo with the Article 27(1) §2-exclusion citation so the absence of FRIA is defensibly recorded.
- Private edtech vendor deploying Annex III §3 proctoring AI to private-sector customer-certification programs. Deployer is a private-sector entity. Annex III sub-category is §3 proctoring (non-§2). Public-service-overlap analysis: the private-sector certification program typically does not provide public services unless the certification is a delegated public function (e.g., a regulator-delegated certification). Category A does not apply on standard private-certification use. Legally-required FRIA date, Dec 2, 2027 track. Operate-now: yes, capability by Aug 2, 2026 for board-defensible posture; FRIA artifact sequenced against Dec 2, 2027 deadline; candidate-disclosure design integrated with the FRIA work.
Twelve systems, twelve classifications. The pattern: Category A applies broadly to public-body and public-service-provider deployers; Category B applies specifically to §5(b)/§5(c) deployers; §2 critical-infrastructure deployers are excluded; private-sector non-§5(b)/§5(c) deployers in non-public-service contexts are on the Dec 2, 2027 stand-alone track. The operate-now recommendation is yes for all FRIA-eligible categories because the legal-deadline distinction is regulatorily defensible but operationally fragile.
The FRIA Trigger Memo for the AI Governance Committee
The L3 artifact for this lesson is the FRIA trigger memo: the document the AI Governance Committee uses to decide which systems get FRIAs, when, and who owns each one. The memo has two components: a per-system spreadsheet with the classification and timing detail, and an executive summary that explains the methodology, the timing nuance, and the budget implications. The combined artifact runs 8-15 pages depending on portfolio size and is the kind of document a general counsel signs off on before the committee meeting.
The spreadsheet columns:
- System identifier, Unique system ID from the AI inventory.
- System name, Human-readable.
- Deployer type, Body governed by public law / private operator providing public services / private-sector / mixed (with mixed-use analysis explanation).
- Annex III sub-category: §1(a)/§1(b)/§1(c), §2 (excluded), §3 (admission/learning/placement/proctoring), §4 (recruitment/promotion/task-allocation/monitoring), §5(a)/§5(b)/§5(c)/§5(d)/§5(e), §6 (risk-assessment/polygraph/evidence/predictive-policing/profiling), §7 (polygraph/risk-assessment/application-examination/identification), §8 (judicial/election).
- FRIA category classification, Category A / Category B / Both / Excluded (with §2-exclusion citation) / Not Annex III.
- Legally-required FRIA date: Aug 2, 2026 / Dec 2, 2027 / Excluded.
- Operate-now recommendation, Yes (capability + artifact in FY26) / Yes (capability FY26, artifact FY26-FY27 sequenced) / N/A (excluded).
- FRIA owner: Named individual (Chief AI Officer delegate, Product owner, AI Risk Manager).
- FRIA artifact target completion date, Specific quarter (Q1 2026 / Q2 2026 / Q3 2026 / Q4 2026 / Q1 2027 / Q2 2027 / Q3 2027 / Q4 2027).
- Article 27(3) notification readiness, Yes / No / N/A.
- Article 86 right-to-explanation integration, Required for §5(b)/§5(c); other rows N/A or scoped.
- Cross-references: Annex IV file row, ISO 42001 risk-register entry, NIST AI RMF Map 5 entry, GDPR Article 35 DPIA combined where applicable.
The executive summary (2-3 pages) walks: (a) the Article 27 two-category test and how it was applied; (b) the post-Omnibus VII timing nuance with the §5(b)/§5(c) and public-body / public-service-operator FRIA acceleration explained; (c) the operate-now management practice and the board-defensible rationale; (d) the §2 exclusion and how it is recorded; (e) the per-quarter completion schedule across FY26-FY27; (f) the budget implications (typical FRIA artifact cost in the €25K-€75K range per system depending on complexity, with §5(b)/§5(c) and §7 typically toward the upper end due to overlay obligations); (g) the governance touchpoints (AI Governance Committee quarterly review, board AI Risk Committee semi-annual review, general counsel sign-off per artifact).
Article 27(3) Notification to National Supervisory Authority
Article 27(3) requires the deployer, upon completing the FRIA, to notify the national supervisory authority of the results. The notification is not an approval-seeking submission. It is a notification, and the supervisory authority does not approve or reject the FRIA. The notification creates a record at the regulator and establishes the deployer's compliance posture. The implementing detail varies by Member State and is being progressively clarified through Commission guidance and national-authority practice notes through 2026-2027.
The notification typically includes: (a) the system identifier and deployer identification; (b) the Annex III sub-category and FRIA category classification; (c) a summary of the FRIA methodology (identification of affected persons, identification of impacts on fundamental rights, mitigation measures, monitoring plan); (d) the FRIA artifact itself or a link to a deployer-hosted copy with appropriate access controls; (e) the date of completion; (f) the named FRIA owner and signing authority. The notification format is being progressively standardized by national supervisory authorities; deployers should track the per-Member-State template requirement and adapt accordingly.
Programs deploying across multiple Member States must address per-jurisdiction notification, a single FRIA artifact may need to be notified to multiple national supervisory authorities depending on the system's deployment footprint. The cross-jurisdictional notification analysis is part of the FRIA trigger memo's operational planning and benefits from advance engagement with each national supervisory authority's specific template and submission channel.
Cross-Walks - EU AI Act + ISO 42001 + NIST AI RMF + GDPR
The FRIA trigger memo's defensibility increases when it cross-walks the Article 27 obligation to the broader governance-framework landscape. The cross-walks the L3 practitioner builds:
- EU AI Act Article 27 + Article 27(3) notification + Article 14 human oversight + Article 9 risk management. The FRIA integrates with Article 14 (human-reviewer design at decision points), Article 9 (risk-management-system identification of harms), and Article 27(3) (post-completion notification). The integrated read produces a single governance artifact rather than four parallel artifacts.
- EU AI Act Annex III §1-§8 + Omnibus VII timeline. The trigger memo cites the specific Annex III sub-category per row and the post-Omnibus VII applicability date (Aug 2, 2026 for §5(b)/§5(c) and Category A public-body deployers; Dec 2, 2027 stand-alone for non-§5(b)/§5(c) private deployers).
- ISO 42001 Annex A.5 (responsible AI use) + A.6 (third-party relationships). The FRIA's affected-stakeholder analysis maps to A.5 controls. The third-party-deployment analysis (where a vendor's system is deployed by an in-scope deployer) maps to A.6 controls. The ISO 42001 audit binder benefits from the FRIA trigger memo as supporting evidence.
- NIST AI RMF Map 5 (impacts on individuals, groups, society, planet). The Map 5 function in the NIST AI RMF aligns directly with the Article 27 FRIA fundamental-rights-impact analysis. Programs running both EU AI Act and NIST AI RMF should produce a single combined impact-analysis artifact rather than two parallel artifacts.
- GDPR Article 35 DPIA. A high-risk AI system that processes personal data triggers both a GDPR Article 35 DPIA and an EU AI Act Article 27 FRIA. The combined DPIA/FRIA template is the recommended pattern for FRIA-eligible systems with personal-data processing, particularly §5(b)/§5(c) systems and §1 biometric systems. The combined template is a single 30-50 page artifact that addresses both regimes with shared analysis where appropriate and regime-specific sections where required.
Six Common FRIA Scoping Mistakes - And How to Catch Them
Mistake 1 - Confusing Category A and Category B
Category A applies to public-body / public-service-provider deployers of Annex III non-§2 systems. Category B applies to any deployer of §5(b)/§5(c). The most common error: applying Category A reasoning to a private-sector bank deploying §5(b) and concluding "we're not a public body, so FRIA does not apply." The correct read is that Category B catches the private-sector bank by virtue of the §5(b) classification alone. The trigger memo should classify systems against both categories separately and explicitly.
Mistake 2 - Missing the §2 Critical-Infrastructure Exclusion
Annex III §2 critical-infrastructure systems are explicitly excluded from Article 27 FRIA. Programs that include §2 systems in the FRIA backlog have over-tiered the obligation set: and create wasted FRIA-artifact work that does not serve the §2 obligation set (which centers on Annex IV technical documentation, NIS 2 cybersecurity, and Annex I conformity where integrated). The trigger memo should record the §2 exclusion explicitly with the Article 27(1) citation so the absence of FRIA is defensibly documented.
Mistake 3 - Assuming All FRIAs Wait for Dec 2, 2027
Programs reading "Omnibus VII moved Annex III to Dec 2, 2027" and concluding that all FRIA obligations defer to that date are wrong for §5(b)/§5(c) Category B deployers and for Category A public-body / public-service-provider deployers under the defensible reading. The trigger memo's legally-required-date column should distinguish Aug 2, 2026 track rows from Dec 2, 2027 track rows explicitly. Audit-committee defensibility depends on this distinction being clear.
Mistake 4 - Assuming All FRIAs Are on the Aug 2, 2026 Track
The mirror-image mistake: treating every Annex III system's FRIA as legally required by Aug 2, 2026. This over-accelerates the work and creates schedule pressure that compromises FRIA artifact quality. The defensible reading is that non-§5(b)/§5(c) private-sector deployers of Category A Annex III non-§2 systems where no public-service overlap exists are on the Dec 2, 2027 stand-alone track. The operate-now recommendation is to build capability by Aug 2, 2026 and sequence artifact completion across FY26-FY27, but the legal-deadline distinction matters for resource allocation and for regulator-engagement positioning.
Mistake 5 - Missing the Private-Operator-Providing-Public-Services Analysis
Article 27 catches private operators providing public services even when they are not public bodies. The analytical work is to identify whether a private deployer's use case is a public-service provision: a private rail operator running national-rail services, a private utility delivering essential services, a private healthcare provider operating under public-healthcare contract, a private contractor running a delegated public function. The trigger memo's per-row deployer-type classification should explicitly address this analysis where the deployer is private but the use case may be public-service provision.
Mistake 6 - Missing Article 27(3) Notification to National Supervisory Authority
Article 27(3) requires post-completion notification of the FRIA to the national supervisory authority. The notification is not optional, and the format / channel is per-Member-State. Programs that complete the FRIA artifact but skip the notification step have not completed the Article 27 obligation. The trigger memo should track notification-readiness per row and the per-jurisdiction submission status. Multi-Member-State deployers should plan for multi-jurisdiction notification as part of the operational schedule.
The Board-Defensible Posture - Operate Now, Document the Reasoning
The L3 practitioner's role in this lesson is to produce the FRIA trigger memo that lets the AI Governance Committee make a defensible decision: and to be able to defend it in front of the board AI Risk Committee, the external auditor (Schellman / A-LIGN / BSI / KPMG), and the regulator on inquiry. The board-defensible posture has four elements:
- Distinguish legally-required dates from operate-now recommendations: explicitly, in writing, with the Article 27(1) two-category test cited per row.
- Operate FRIA capability in 2026 regardless of legal-deadline distinction: because the capability build (methodology, templates, training, governance) does not scale on a regulatory deadline and the board expects mature practice ahead of mandate.
- Sequence FRIA artifact completion against legally-required dates with appropriate margin, Category B §5(b)/§5(c) in Q1-Q3 2026; Category A public-body / public-service-operator in Q3 2026 - Q2 2027; private-sector non-§5(b)/§5(c) in Q3 2027 - Q4 2027 against the Dec 2, 2027 deadline.
- Integrate Article 27(3) notification, Article 86 right-to-explanation, GDPR Article 35 DPIA, ISO 42001 Annex A.5/A.6, NIST AI RMF Map 5, and Article 14 human-oversight design with the FRIA work, so each FRIA artifact is the integration point for the broader governance framework rather than a stand-alone document.
The AI Governance Committee meeting in eleven days will have one substantive item. The trigger memo is what makes that meeting productive. The two-category test, the post-Omnibus VII timing nuance, the §2 exclusion, the per-system classification, the per-quarter sequencing, and the operate-now management practice, together they produce the artifact that lets the committee make a defensible decision and lets the program operate FRIA at the maturity level the post-Omnibus VII regulatory environment expects.
Key Takeaways
- Article 27 creates two FRIA deployer categories. Category A, public bodies and private operators providing public services, deploying any Annex III non-§2 system. Category B, any deployer of Annex III §5(b) creditworthiness scoring or §5(c) life/health insurance risk assessment and pricing. Test each system against both categories separately.
- Annex III §2 critical-infrastructure deployers are EXCLUDED from FRIA. The §2 exclusion is explicit in Article 27(1). Document the exclusion in the trigger memo so the absence of FRIA is defensibly recorded; the §2 obligation set centers on Annex IV, NIS 2, and Annex I conformity instead.
- Post-Omnibus VII timing nuance, §5(b)/§5(c) and public-body / public-service-operator FRIAs do NOT wait for Dec 2, 2027. Category B §5(b)/§5(c) FRIA remains on the Aug 2, 2026 track regardless of stand-alone Annex III date slip. Category A public-body / public-service-operator FRIA remains on the Aug 2, 2026 track under the defensible reading.
- Private-sector non-§5(b)/§5(c) deployers of Category A systems track the Dec 2, 2027 stand-alone date, but operate-now is the defensible posture. The legal-deadline distinction matters; the management-practice recommendation is to build FRIA capability by Aug 2, 2026 and sequence artifact completion across FY26-FY27.
- The FRIA trigger memo is the L3 artifact. Per-system spreadsheet with deployer type, Annex III sub-category, FRIA category (A/B/both/excluded), legally-required date, operate-now recommendation, owner, target completion quarter, Article 27(3) notification readiness, Article 86 integration. Executive summary with methodology, timing-nuance, budget, governance touchpoints.
- Article 27(3) requires post-completion notification to the national supervisory authority. Format and channel vary by Member State. Multi-Member-State deployers plan for multi-jurisdiction notification. Track notification-readiness per row in the trigger memo.
- Article 86 right-to-explanation integrates with §5(b)/§5(c) FRIA work. Build the explanation pathway as part of the FRIA artifact, not as a separate downstream project.
- GDPR Article 35 DPIA + EU AI Act Article 27 FRIA combine into a single template for personal-data-processing high-risk systems. Particularly relevant for §5(b)/§5(c) and §1 biometrics. The combined 30-50 page artifact addresses both regimes with shared analysis and regime-specific sections.
- ISO 42001 Annex A.5/A.6 and NIST AI RMF Map 5 cross-walk to the FRIA fundamental-rights-impact analysis. Produce a single integrated artifact rather than parallel artifacts; the cross-walk is the audit-defensible discipline.
- Six common mistakes: confusing Category A and Category B; missing the §2 exclusion; deferring all FRIAs to Dec 2, 2027; over-accelerating all FRIAs to Aug 2, 2026; missing private-operator-providing-public-services analysis; missing Article 27(3) notification. Each mistake is recoverable; each is more recoverable when caught in the trigger memo than at the audit.
Skill.re