AIPolicyTracker
Legal requirement AI risk management South Korea In force

Operators of high-impact AI must establish and operate a risk management plan

Context fileUnder Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, Article 34(1)

Source-linked Open official source

What does it require?

An AI business operator that provides high-impact AI, or a product or service using it, must establish and operate a plan for managing the risks of that AI. High-impact AI is AI used in areas such as energy, drinking water, health care and medical devices, nuclear safety, biometric analysis for criminal investigation, decisions on recruitment or loans, transport, public services and education, where it may materially affect life, safety or fundamental rights.

Practical action

Classify systems against the high-impact areas and write a risk management plan for each one before launch.

Who does it apply to?

AI business operators providing high-impact AI or products and services based on it; operators may ask the ministry to confirm whether a system is high-impact under Article 33.

Applies from:

Which controls meet this duty?

Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.

  • satisfiesProcessAI system owner · once per ai system
    AI risk assessment and lifecycle risk register

    Serves 12 recorded duties · evidence: AI system risk assessment, Per-system AI risk register, Residual-risk acceptance

    Per-system risk plan with identified risks and treatments.

  • supportsProcessAI governance lead · continuous
    AI system inventory and classification

    Serves 11 recorded duties · evidence: AI system register, Risk-tier classification sign-off, AI intake and classification procedure

    Classification of systems against the high-impact list.

What evidence would a reviewer expect?

Evidence examples
EvidenceTypeNotes
High-impact AI risk management plandocument
High-impact classification recordrecord

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

See every South Korea duty mapped this way →

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 42001:2023Clause 6.1.2, 6.1.3, 8.1Risk assessment, treatment and operational planning.medium
NIST AI RMF 1.0MAP 1.5, MANAGE 1.3Risk tolerance and treatment.medium

Cite this record

AIPolicyTracker (2026). “Operators of high-impact AI must establish and operate a risk management plan (Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust)”. https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-risk-management-plan (accessed 24 September 2026). Data licensed CC BY 4.0.

Cite the official text alongside it: Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust (AI Basic Act, Act No. 20676), Korea Ministry of Government Legislation, National Law Information Center, https://www.law.go.kr/lsInfoP.do?lsiSeq=268543.

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.