Legal requirement AI risk management European Union Partially applicable

Establish a risk management system for high-risk AI

Under EU AI Act, Article 9

Source-linked Open official source

What does it require?

Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle: identifying known and reasonably foreseeable risks to health, safety and fundamental rights, estimating and evaluating risks including from reasonably foreseeable misuse, evaluating post-market data, and adopting targeted risk-management measures, with testing before placing on the market.

Practical action

Set up a lifecycle risk register per high-risk system with test evidence and residual-risk acceptance.

Who does it apply to?

Providers of AI systems classified as high-risk under Article 6.

Applies from:

Evidence examples

  • Risk register and treatment plan (register)
  • Pre-market test reports (report)

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 42001:2023Clauses 6.1.2, 6.1.3, 8.2, 8.3 and Annex A controls on AI riskOriginal editorial mapping.high
NIST AI RMF 1.0MAP, MEASURE and MANAGE functionsThe AI RMF's core functions map closely to Article 9's iterative process.high

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.