FRIA-as-Code

FRIA-as-Code A workflow diagram generated by Archify. 01 / Layer 02 Inventory & Transparency 02 / Layer 01 Govern-as-Code 03 / Reviewer 04 / DPIA cross-reference Capture as data Assess and mitigate Approve and record Intake data · questionnaire · Layer 02 Inventory & Transparency › Capture as data Intake data questionnaire FRIA record · machine-readable · Layer 02 Inventory & Transparency › Approve and record FRIA record machine-readable Risk assessment · risks to rights · Layer 01 Govern-as-Code › Assess and mitigate Risk assessment risks to rights Mitigations · one per risk · Layer 01 Govern-as-Code › Assess and mitigate Mitigations one per risk Approval gate · sign-off · Layer 01 Govern-as-Code › Approve and record Approval gate sign-off Reviewer · human role · Reviewer › Approve and record Reviewer human role DPIA · GDPR Art. 35 · DPIA cross-reference › Capture as data DPIA GDPR Art. 35 mitigate reuse record assess review decides Legend Agent logic Policy Context / trace External system

A rights assessment that lives

  • • Intended use, affected groups and risks to rights as structured data
  • • Re-opened on significant change, not filed once as a document
  • • The EU AI Act Art. 27 FRIA and its DPIA cross-reference set the scope

Mitigations tie to controls

  • • Every risk links to the control that implements its mitigation
  • • The DPIA cross-reference means shared elements are written once
  • • A named reviewer signs off residual risk at one gate

First step

  • • Run it before deploying a high-risk system
  • • Keep the record where the auditor looks