A fundamental rights impact assessment is a structured process for evaluating, before and during deployment, how a system, policy, or AI application may affect people’s fundamental rights such as dignity, non-discrimination, privacy, and freedom of expression. It documents the context of use, identifies affected groups and potential harms, assesses risks, and defines mitigation and oversight measures. It has become a governance instrument for high-risk AI, complementing data protection impact assessments and broader risk assessment.

Overview

  • The assessment examines how a system or policy could affect rights such as dignity, equality, privacy, and expression.
  • It is performed before deployment and revisited as context changes, documenting affected groups and potential harms.
  • It defines mitigations, oversight arrangements, and monitoring to manage residual risk.
  • It has become a recognised governance step for high-risk AI systems.

Key aspects

  • Context analysis of where, how, and on whom a system will be used.
  • Identification of affected groups and rights at stake.
  • Risk evaluation and definition of proportionate mitigations.
  • Oversight, transparency, and ongoing monitoring obligations.

Applications

  • Pre-deployment review of high-risk public-sector AI.
  • Complementing data protection impact assessments for AI systems.
  • Procurement and due-diligence gating for sensitive deployments.
  • Documenting accountability for regulators and affected communities.

Provenance