FRIA Guide
FRIA Guide — guidance from ComplyAI on EU AI Act, ISO 42001 and AI governance.
- EU AI Act, ISO/IEC 42001, NIST AI RMF and US state-law coverage in one platform.
- Built for AI deployers, providers, importers and distributors in scope of Regulation (EU) 2024/1689.
- HIPAA-aligned with BAA available on the Business tier for healthcare AI workloads.
What the EU AI Act actually requires for FRIA Guide
Scope is decided by Article 2 and risk tier by Articles 5 and 6 read with Annex III. Once FRIA Guide lands in the high-risk tier, Articles 9 to 15 become mandatory: a documented risk management system that runs across the whole lifecycle, data and data-governance controls covering training, validation and testing sets, technical documentation to the level of detail in Annex IV, automatic logging of events, transparency and instructions for use, effective human oversight, and demonstrated accuracy, robustness and cybersecurity. Providers then add a quality management system under Article 17, conformity assessment under Article 43, the EU declaration of conformity under Article 47, CE marking under Article 48 and registration in the EU database under Article 49. Deployers carry Article 26 duties — using the system per its instructions, assigning competent human oversight, keeping logs — and, for public bodies and certain private deployers, a fundamental rights impact assessment under Article 27.
Who is accountable, and for which evidence
The Act allocates duties by role, not by job title. A provider develops or places the system on the market under its own name and owns conformity assessment, technical documentation and post-market monitoring under Article 72. A deployer uses the system under its own authority and owns oversight, input-data suitability, worker information and incident reporting under Article 73. Importers and distributors owe verification duties under Articles 23 and 24. Substantial modification, or putting your own name on a third-party model, converts a deployer into a provider under Article 25 — the single most commonly missed reclassification. Evidence therefore has to be attributable: who approved the risk assessment, on what version of the model, against which dataset, with what test results, and when.
Penalties, timelines and what is already in force
Article 99 sets fines up to EUR 35 million or 7% of total worldwide annual turnover for prohibited practices under Article 5, up to EUR 15 million or 3% for breaches of most other obligations including the high-risk requirements, and up to EUR 7.5 million or 1% for supplying incorrect or misleading information to authorities. The applicability ladder: prohibitions and AI-literacy duties from 2 February 2025, GPAI obligations and the governance framework from 2 August 2025, Annex III high-risk obligations from 2 August 2026 — now in force — Annex I embedded high-risk products from 2 August 2027, and legacy systems already on the market brought in on their own transition path. National market surveillance authorities have investigation and product-withdrawal powers independent of any fine.
Getting FRIA Guide to defensible compliance
The practical sequence is the same regardless of sector: inventory every AI system and every embedded model, classify each one against Articles 5 and 6 with a written rationale, gap-assess against the Article 9-15 requirements, close gaps with named owners and dates, generate Annex IV technical documentation, put human oversight and logging into production, then keep it current with post-market monitoring and serious-incident reporting. ComplyAI runs that loop as software: classification with a citable rationale, control evidence collected continuously, an append-only audit chain so approvals cannot be backdated, and regulator-ready exports. ISO/IEC 42001 and NIST AI RMF controls are mapped to the same evidence, so one programme satisfies several audiences.
Frequently asked questions
Is FRIA Guide high-risk under the EU AI Act?
High-risk status comes from Article 6: either the system is a safety component of a product covered by Annex I harmonised legislation, or its intended purpose matches one of the eight Annex III areas — biometrics, critical infrastructure, education, employment, essential public and private services, law enforcement, migration and border control, or administration of justice. The narrow Article 6(3) filter can pull a system back out, but only when it is genuinely preparatory, narrow or purely improves a human decision, and that assessment must be documented and registered.
What documentation would a regulator ask for first?
In practice: the AI system inventory, the classification rationale for the system in question, the Annex IV technical documentation, the Article 9 risk management file, data-governance records for training and test data, logs proving traceability under Article 12, the human-oversight design under Article 14, accuracy and robustness test results under Article 15, and the declaration of conformity. Deployers should also hold their Article 26 usage records and, where applicable, the Article 27 fundamental rights impact assessment.
Does using a third-party model transfer the obligations?
No. Buying a model or an API does not move deployer duties onto the vendor, and rebranding or substantially modifying a third-party system makes you the provider under Article 25 with the full high-risk obligation set. GPAI model providers have their own duties under Articles 53 to 55, including technical documentation, a copyright policy, a training-content summary and, for systemic-risk models, evaluation and incident reporting — those duties sit alongside yours, not instead of them.
How long does a first compliance cycle take?
Teams that already know their AI inventory typically reach a documented classification and a gap-assessed high-risk file in weeks; teams starting from an unknown inventory spend most of their time on discovery. Automating inventory, classification and evidence collection is what compresses the timeline, because the slow part is never writing the policy — it is proving the policy was followed on a specific model version.
Your EU AI Act compliance path
- Understand: Complete EU AI Act guide — Scope, obligations, timelines and enforcement in one place.
- Classify: EU AI Act risk tiers and free classifier — Prohibited, high-risk, limited-risk or minimal, with a citable rationale.
- Plan: ComplyAI pricing and plans — Choose the plan that covers your AI inventory and evidence needs.
- Prove: EU AI Act conformity assessment checklist — Article 43 step-by-step: documentation, CE marking, registration.
Related reading
- Free EU AI Act risk classifier
- Complete EU AI Act guide
- EU AI Act deadlines and timeline
- Conformity assessment checklist
- ISO/IEC 42001 Annex A controls
- AI governance glossary
- ComplyAI pricing
- Talk to the ComplyAI team
ComplyAI is compliance software, not a law firm, and nothing here is legal advice. Verify obligations against Regulation (EU) 2024/1689 and guidance from your national competent authority.