AI Act · Governance

IAMA, DPIA and FRIA: which impact assessment do you need — and when?

7 min read · by Mohamed Chilh

Three assessments, a lot of overlap. Run them separately and you do duplicate work. Here is how to keep the overview.

Three abbreviations circulate around the responsible use of data and algorithms and are easily confused: DPIA, IAMA and FRIA. They have a different starting point but overlap strongly. Understand the distinction and you avoid duplicate work.

What they are

Where they overlap

At their core all three ask the same questions: what does this system do, who does it affect, what risks does it bring, and how do we control them? The DPIA looks through a privacy lens, the IAMA and FRIA more broadly at fundamental rights and diligence. In practice you answer largely the same questions — three times, if you're not careful.

The combined approach

Smarter is to run them as one process: one analysis of the system and its impact, from which you derive the specific parts of the DPIA, IAMA and FRIA. That saves time, avoids contradictory outcomes, and gives the board and the regulator one coherent story instead of three separate documents.

Want to know quickly what applies to you? Try the DPIA/IAMA/FRIA decision helper — five questions, an instant indicative view.

When do you start

The core principle is: before deployment, not after. An impact assessment afterwards is an accountability exercise; beforehand it is a design choice that makes the system better. For high-risk AI in government, the AI Act also makes this a hard precondition.

The bottom line

DPIA, IAMA and FRIA are not bureaucracy but the same discipline from three angles. Combine them, do them early, and you keep a grip — on the risks and on the workload.

This article is general information, not legal or organisational advice for your specific situation.

Read more
Need advice?

Talk it through with NIYA.

‹ Back to Insights