Skip to main content
FRIA
4 min readUpdated 2026-02-15

Generating FRIA Reports

How to generate, review, and share audit-ready FRIA reports from Klarvo — including PDF output structure, approval workflows, and notification to market surveillance authorities.

Generating FRIA Reports

After completing the FRIA Wizard, Klarvo generates a professional, audit-ready report that can be shared with leadership, auditors, and market surveillance authorities.

Report Structure

The FRIA Report PDF follows a structured format aligned to Article 27:

SectionContent
Cover PageTitle, organisation, AI system name, date, confidentiality marking
Document ControlVersion number, revision history, approvals
Executive SummaryOne-page overview: system, risks identified, overall conclusion
1. Process DescriptionHow the AI is used, decision points, workflow integration
2. Time Period & FrequencyDuration, frequency, scale of affected persons
3. Affected CategoriesWho is affected, vulnerable groups, notification approach
4. Fundamental Rights RisksRight-by-right analysis with likelihood/severity ratings
5. Human OversightOversight model, competence, authority to intervene
6. Mitigations & GovernanceRisk mitigations, governance arrangements, complaint mechanism, monitoring plan
7. Conclusion & ApprovalApprove / Approve with Mitigations / Do Not Deploy
8. Notification StatusWhether authority notification is required and its status
AppendixFull questionnaire answers, evidence references

Generating the Report

  • Complete all sections of the FRIA Wizard
  • Navigate to the FRIA detail page for your assessment
  • Click ExportFRIA Report (PDF)
  • The report generates with your organization branding and document control
  • Download or share via secure link
  • Approval Workflow

    Before sharing externally, FRIA reports should go through approval:

  • Author completes the FRIA Wizard → Draft status
  • Reviewer reviews risk analysis and mitigations → May request changes
  • Approver signs off → Approved status with name and date recorded
  • Report generated → Final version with approval metadata embedded
  • Multiple approvers can be assigned for critical systems.

    Authority Notification

    If notification to the market surveillance authority is required:

  • The FRIA report includes a notification-ready data section with all required fields
  • Export the report as PDF
  • Submit to your national market surveillance authority using their prescribed channel
  • Upload the submission confirmation back to Klarvo as evidence
  • Record the notification date and reference number
  • Version Control

    FRIAs are living documents. When you update a FRIA:

  • The previous version is preserved in full
  • A new version is created with change reasons documented
  • The version history is included in the report's Document Control section
  • All versions remain accessible for audit purposes
  • FRIA Result Summary

    In addition to the full report, Klarvo generates a one-page FRIA summary — ideal for:

  • Board/leadership briefings
  • Quick reference during audits
  • Internal communication about AI risk posture
  • Best Practices

    Complete before deployment: FRIA must be done before first use — don't deploy and backfill
    📋 Get formal approval: An unapproved FRIA has limited compliance value
    📤 Notify when required: Don't skip authority notification if it applies
    🔄 Update on changes: Material changes require a FRIA update, not a new FRIA from scratch
    📁 Store in Evidence Vault: Link the FRIA report to the AI system and relevant controls