Establish a risk management system for high-risk AI
Under EU AI Act, Article 9
What does it require?
Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle: identifying known and reasonably foreseeable risks to health, safety and fundamental rights, estimating and evaluating risks including from reasonably foreseeable misuse, evaluating post-market data, and adopting targeted risk-management measures, with testing before placing on the market.
Practical action
Set up a lifecycle risk register per high-risk system with test evidence and residual-risk acceptance.
Who does it apply to?
Providers of AI systems classified as high-risk under Article 6.
- Actors
- Provider / developer
- Sectors
- Cross-sector / all sectors
Applies from:
Evidence examples
- Risk register and treatment plan (register)
- Pre-market test reports (report)
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Clauses 6.1.2, 6.1.3, 8.2, 8.3 and Annex A controls on AI risk | Original editorial mapping. | high |
| NIST AI RMF 1.0 | MAP, MEASURE and MANAGE functions | The AI RMF's core functions map closely to Article 9's iterative process. | high |
Similar obligations in other instruments
- Apply minimum risk-management practices to high-impact AI — OMB M-25-21, United States
- Deployers must implement a risk management policy and programme — Colorado AI Act, Colorado (United States)
- Ensure AI systems are safe, secure and robust throughout their lifecycle — UK AI regulation framework, United Kingdom (voluntary)
- Prioritise, respond to and monitor AI risks (Manage) — NIST AI RMF, United States (voluntary)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.