AIPolicyTracker
ProcedureFree · sent to your work emailEU AI ActISO/IEC 42001

AI Post-Market Monitoring Plan

Formats: DOCX and XLSX · Version v1 · Built from dataset bb068ecd9dad · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

In brief

The AI Post-Market Monitoring Plan is a free DOCX and XLSX procedure for EU AI Act and ISO/IEC 42001. How a deployed AI system is watched after release: metrics, thresholds, frequency, owners and escalation to incident response, with the monitoring and incident duties on record. It is licensed CC BY 4.0 and is not legal advice.

Format
DOCX and XLSX · Procedure
Version
v1, built 28 Sep 2026
Duties cited
7 from 3 instruments
Rows from the records
13
Written for
Provider / developer, Deployer / user organisation, General-purpose AI model provider
Price and licence
Free · CC BY 4.0

What's inside

  • Monitoring metrics sheet with six starter metrics and alert colouring
  • Plan document: systems covered, data collected, review and escalation
  • Monitoring duties sheet: post-market monitoring and incident duties

Preview

The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.

Sheet: Monitoring metrics · 8 columns · 6 rows from the records
First rows of the Monitoring metrics sheet
AI systemMetricAlert thresholdCheckedOwnerLatest valueState ▾Action if breached
Accuracy on a held-out production sample[PLACEHOLDER: % below baseline]Monthly
Performance gap between relevant groups[PLACEHOLDER: max gap]Monthly
Input data drift[PLACEHOLDER: drift score]Weekly
Human override rate[PLACEHOLDER: % of decisions]Weekly
Complaints and appeals[PLACEHOLDER: count]Monthly
Serious incidentsAnyContinuous
Sheet: Monitoring duties · 14 columns · 7 rows from the records
First rows of the Monitoring duties sheet
DutyCategoryInstrumentJurisdictionWho it bindsNatureSource referenceApplies fromWhat it requiresEvidence a reviewer expectsISO/IEC 42001NIST AI RMFVerificationRecord
Report critical safety incidents to the Office of Emergency ServicesIncident reporting and handlingCalifornia SB 53California (United States)General-purpose AI model provider, Provider / developerLegal requirementBusiness and Professions Code, Chapter 25.1 (as added by SB 53)2026-01-01Frontier developers must report critical safety incidents to the California Office of Emergency Services within the statutory time limit after discovery, and thIncident classification and reporting procedureMANAGE 4.3Source-linkedhttps://aipolicytracker.org/obligations/us-california-sb-53-critical-safety-incident-reporting
Operate a post-market monitoring systemPost-market monitoringEU AI ActEuropean UnionProvider / developerLegal requirementArticle 722027-12-02Providers must establish and document a post-market monitoring system proportionate to the nature of the AI technology and its risks, actively and systematicallPost-market monitoring plan and periodic reportsClause 9.1 Monitoring, measurement, analysis and evaluationMANAGE 4.1, MEASURE 3.xSource-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-post-market-monitoring
Report serious incidents to market surveillance authoritiesIncident reporting and handlingEU AI ActEuropean UnionProvider / developer, Deployer / user organisationLegal requirementArticle 732027-12-02Providers of high-risk AI systems must report serious incidents to the market-surveillance authority of the Member State where the incident occurred, immediatelAI incident response procedure; Incident log and authority notificationsClause 10 Improvement; Annex A control on incident handlingMANAGE 4.3Source-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-serious-incident-reporting
Providers must take corrective action and inform the supply chain about non-conforming high-risk AIIncident reporting and handlingEU AI ActEuropean UnionProvider / developerLegal requirementArticle 202027-12-02A provider that considers, or has reason to consider, that a high-risk system it has placed on the market is not in conformity must immediately correct it, withCorrective action and recall procedure for AI systems; Non-conformity investigation recordClause 10.2; Annex A.8.4MANAGE 2.4, MANAGE 4.3Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/eu-ai-act-art-20-corrective-actions-and-information
Deployers must monitor high-risk AI, suspend use on risk and report serious incidentsPost-market monitoringEU AI ActEuropean UnionDeployer / user organisation, Public authority / government bodyLegal requirementArticle 26(5)2027-12-02Deployers must monitor a high-risk AI system's operation against the provider's instructions and feed observations to the provider under Article 72. If they havOperational monitoring log; Suspension and escalation procedureClause 9.1; Annex A.6.2.6, A.8.4MANAGE 2.4, MANAGE 4.1, MANAGE 4.3Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/eu-ai-act-art-26-5-deployer-monitoring-and-suspension
Providers of systemic-risk GPAI models must track and report serious incidents to the AI OfficeIncident reporting and handlingEU AI ActEuropean UnionGeneral-purpose AI model providerLegal requirementArticle 55(1)(c)2025-08-02Providers of general-purpose AI models with systemic risk must keep track of, document and report without undue delay to the AI Office and, where relevant, to nSerious incident tracking log for the model; AI Office incident notificationClause 10.2; Annex A.8.4MANAGE 4.3, MEASURE 3.1Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/eu-ai-act-art-55-systemic-risk-incident-reporting

Document outline (DOCX)

  1. Post-market monitoring plan
  2. Systems covered
  3. Data collected
  4. Review and escalation
  5. The duties this plan serves
  6. Report critical safety incidents to the Office of Emergency Services
  7. Operate a post-market monitoring system
  8. Report serious incidents to market surveillance authorities
  9. Providers must take corrective action and inform the supply chain about non-conforming high-risk AI
  10. Deployers must monitor high-risk AI, suspend use on risk and report serious incidents
  11. Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office
  12. Implement reasonable security safeguards and notify breaches

How to use it

  1. 1Request the files. Enter your name, company and work email in the form on this page. The DOCX and XLSX download links arrive by email and work for 7 days.
  2. 2Read the README page. It states the version (v1), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
  3. 3Fill in your rows. Complete the "Monitoring metrics" sheet for your own systems. Dropdowns, formulas and colour rules are already set.
  4. 4Check the duties against your situation. The "Monitoring metrics" and "Monitoring duties" sheets list the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
  5. 5Complete the document. Work through the DOCX sections (Post-market monitoring plan, The duties this plan serves) and replace each placeholder with your organisation's answer.
  6. 6Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.

Duties this template covers (7)

Each is cited in the file with its source reference and a link back to the record.

Legal basis

  • EU AI Act European Union · Partially applicable

Version history

Versions of AI Post-Market Monitoring Plan
VersionBuiltDatasetWhat changed
v1bb068ecd9dadFirst version, built from dataset bb068ecd9dad.

Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.

Frequently asked questions

What is in the AI Post-Market Monitoring Plan?

Monitoring metrics sheet with six starter metrics and alert colouring. Plan document: systems covered, data collected, review and escalation. Monitoring duties sheet: post-market monitoring and incident duties.

Which duties does it cite?

7 recorded duties from California SB 53, EU AI Act and India DPDP Act, including Business and Professions Code, Chapter 25.1 (as added by SB 53), Article 72, Article 73, Article 20, Article 26(5) and Article 55(1)(c). Each row links to the record, and the record to the official source.

Who is it for?

The duties it cites fall on provider / developer, deployer / user organisation and general-purpose ai model provider. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.

Is it free?

Yes. Request the DOCX and XLSX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

How will I know when it changes?

Version v1 was built on 28 September 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.

Does completing it make us compliant?

No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.

Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.