Skip to main content

Development trial ยท sample information only

Complete a FRIA

For licensed Collaborators with permission for this task. Check the selected organisation; feature availability and record access still apply.

What you will achieve

Complete a Fundamental Rights Impact Assessment for a defined AI use, link its safeguards and obtain the authorised workflow decision.

Before you start

Confirm the AI use's RoPA, assets, affected people, applicability decision and assessment basis with the governance owner. Statutory, organisation-policy and voluntary assessments must not be represented as the same obligation.

Resolve upstream readiness issues. A confirmed prohibited use cannot be made acceptable merely by completing a FRIA.

Start with the correct scope

  1. Open the AI use in its RoPA context.
  2. Use Create FRIA when the available controls and readiness permit it.
  3. Enter a meaningful FRIA title, description and Coverage rationale.
  4. Open the created assessment and check its covered use-contexts. Do not assume it covers every use of the same asset.
  5. Confirm the reporter, approver and related processing context in the overview.

If replacing an obsolete assessment, use the available Start successor FRIA path and preserve the earlier assessment rather than disguising changed scope as the original decision.

Complete the rights assessment

Work through the assessment sections:

  1. Describe the deployer process and period/frequency of use.
  2. Identify affected persons and specific risks of harm.
  3. Explain human oversight, escalation and measures if harm materialises.
  4. Record consultation, DPIA complementarity, assumptions and evidence references.
  5. Set the next review date and mark the assessment complete only when its content is ready.

Use scope context can help populate context, but review the imported wording. Saving or marking the narrative complete does not itself approve the FRIA.

Record safeguards and obtain approval

In Risks & Safeguards, add each concrete requirement with title, type, status, due date and description. Link the operational control where one exists; check its implementation evidence separately.

Open Approval and use the available workflow transitions with the authorised actors. If there is no workflow instance, ask the administrator/support owner to resolve that configuration rather than treating completion as approval.

Check it worked

Reload the assessment. Confirm scope, saved narrative, review date, safeguards and workflow decision. Follow one safeguard to its operational control and evidence.

If something goes wrong

Problem Next action
Creation or approval is blocked Review upstream readiness and the stated governance condition
Another use seems similar Obtain an explicit coverage rationale and check eligibility before extending coverage
A safeguard is still planned Keep its status honest and assign completion work
Material facts change after approval Reassess validity and use the successor process where required

Human judgement matters

A FRIA documents an assessment of a use-context. It does not certify an AI product or prove every safeguard operates effectively.

What next?

For the wider context, see Manage AI governance.

Track safeguards and review dates, and keep the connected AI use and RoPA current.

Get help

Ask your Organisation Administrator about access or the task owner about the content. For a platform error, include this guide reference, the affected page and a sanitised message, not confidential evidence or session details.

Was this article helpful?