AI Post-Market Monitoring Plan
In brief
The AI Post-Market Monitoring Plan is a free DOCX and XLSX procedure for EU AI Act and ISO/IEC 42001. How a deployed AI system is watched after release: metrics, thresholds, frequency, owners and escalation to incident response, with the monitoring and incident duties on record. It is licensed CC BY 4.0 and is not legal advice.
- Format
- DOCX and XLSX · Procedure
- Version
- v1, built 28 Sep 2026
- Duties cited
- 7 from 3 instruments
- Rows from the records
- 13
- Frameworks
- EU AI Act, ISO/IEC 42001
- Written for
- Provider / developer, Deployer / user organisation, General-purpose AI model provider
- Price and licence
- Free · CC BY 4.0
What's inside
- Monitoring metrics sheet with six starter metrics and alert colouring
- Plan document: systems covered, data collected, review and escalation
- Monitoring duties sheet: post-market monitoring and incident duties
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Monitoring metrics
| AI system | Metric | Alert threshold | Checked | Owner | Latest value | State ▾ | Action if breached |
|---|---|---|---|---|---|---|---|
| Accuracy on a held-out production sample | [PLACEHOLDER: % below baseline] | Monthly | |||||
| Performance gap between relevant groups | [PLACEHOLDER: max gap] | Monthly | |||||
| Input data drift | [PLACEHOLDER: drift score] | Weekly | |||||
| Human override rate | [PLACEHOLDER: % of decisions] | Weekly | |||||
| Complaints and appeals | [PLACEHOLDER: count] | Monthly | |||||
| Serious incidents | Any | Continuous |
Sheet: Monitoring duties
| Duty | Category | Instrument | Jurisdiction | Who it binds | Nature | Source reference | Applies from | What it requires | Evidence a reviewer expects | ISO/IEC 42001 | NIST AI RMF | Verification | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Report critical safety incidents to the Office of Emergency Services | Incident reporting and handling | California SB 53 | California (United States) | General-purpose AI model provider, Provider / developer | Legal requirement | Business and Professions Code, Chapter 25.1 (as added by SB 53) | 2026-01-01 | Frontier developers must report critical safety incidents to the California Office of Emergency Services within the statutory time limit after discovery, and th | Incident classification and reporting procedure | MANAGE 4.3 | Source-linked | https://aipolicytracker.org/obligations/us-california-sb-53-critical-safety-incident-reporting | |
| Operate a post-market monitoring system | Post-market monitoring | EU AI Act | European Union | Provider / developer | Legal requirement | Article 72 | 2027-12-02 | Providers must establish and document a post-market monitoring system proportionate to the nature of the AI technology and its risks, actively and systematicall | Post-market monitoring plan and periodic reports | Clause 9.1 Monitoring, measurement, analysis and evaluation | MANAGE 4.1, MEASURE 3.x | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-post-market-monitoring |
| Report serious incidents to market surveillance authorities | Incident reporting and handling | EU AI Act | European Union | Provider / developer, Deployer / user organisation | Legal requirement | Article 73 | 2027-12-02 | Providers of high-risk AI systems must report serious incidents to the market-surveillance authority of the Member State where the incident occurred, immediatel | AI incident response procedure; Incident log and authority notifications | Clause 10 Improvement; Annex A control on incident handling | MANAGE 4.3 | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-serious-incident-reporting |
| Providers must take corrective action and inform the supply chain about non-conforming high-risk AI | Incident reporting and handling | EU AI Act | European Union | Provider / developer | Legal requirement | Article 20 | 2027-12-02 | A provider that considers, or has reason to consider, that a high-risk system it has placed on the market is not in conformity must immediately correct it, with | Corrective action and recall procedure for AI systems; Non-conformity investigation record | Clause 10.2; Annex A.8.4 | MANAGE 2.4, MANAGE 4.3 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/eu-ai-act-art-20-corrective-actions-and-information |
| Deployers must monitor high-risk AI, suspend use on risk and report serious incidents | Post-market monitoring | EU AI Act | European Union | Deployer / user organisation, Public authority / government body | Legal requirement | Article 26(5) | 2027-12-02 | Deployers must monitor a high-risk AI system's operation against the provider's instructions and feed observations to the provider under Article 72. If they hav | Operational monitoring log; Suspension and escalation procedure | Clause 9.1; Annex A.6.2.6, A.8.4 | MANAGE 2.4, MANAGE 4.1, MANAGE 4.3 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/eu-ai-act-art-26-5-deployer-monitoring-and-suspension |
| Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office | Incident reporting and handling | EU AI Act | European Union | General-purpose AI model provider | Legal requirement | Article 55(1)(c) | 2025-08-02 | Providers of general-purpose AI models with systemic risk must keep track of, document and report without undue delay to the AI Office and, where relevant, to n | Serious incident tracking log for the model; AI Office incident notification | Clause 10.2; Annex A.8.4 | MANAGE 4.3, MEASURE 3.1 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/eu-ai-act-art-55-systemic-risk-incident-reporting |
Document outline (DOCX)
- Post-market monitoring plan
- Systems covered
- Data collected
- Review and escalation
- The duties this plan serves
- Report critical safety incidents to the Office of Emergency Services
- Operate a post-market monitoring system
- Report serious incidents to market surveillance authorities
- Providers must take corrective action and inform the supply chain about non-conforming high-risk AI
- Deployers must monitor high-risk AI, suspend use on risk and report serious incidents
- Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office
- Implement reasonable security safeguards and notify breaches
How to use it
- 1Request the files. Enter your name, company and work email in the form on this page. The DOCX and XLSX download links arrive by email and work for 7 days.
- 2Read the README page. It states the version (v1), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
- 3Fill in your rows. Complete the "Monitoring metrics" sheet for your own systems. Dropdowns, formulas and colour rules are already set.
- 4Check the duties against your situation. The "Monitoring metrics" and "Monitoring duties" sheets list the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
- 5Complete the document. Work through the DOCX sections (Post-market monitoring plan, The duties this plan serves) and replace each placeholder with your organisation's answer.
- 6Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.
Duties this template covers (7)
Each is cited in the file with its source reference and a link back to the record.
- Report critical safety incidents to the Office of Emergency Services
- Operate a post-market monitoring system
- Report serious incidents to market surveillance authorities
- Providers must take corrective action and inform the supply chain about non-conforming high-risk AI
- Deployers must monitor high-risk AI, suspend use on risk and report serious incidents
- Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office
- Implement reasonable security safeguards and notify breaches
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | bb068ecd9dad | First version, built from dataset bb068ecd9dad. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
What is in the AI Post-Market Monitoring Plan?
Monitoring metrics sheet with six starter metrics and alert colouring. Plan document: systems covered, data collected, review and escalation. Monitoring duties sheet: post-market monitoring and incident duties.
Which duties does it cite?
7 recorded duties from California SB 53, EU AI Act and India DPDP Act, including Business and Professions Code, Chapter 25.1 (as added by SB 53), Article 72, Article 73, Article 20, Article 26(5) and Article 55(1)(c). Each row links to the record, and the record to the official source.
Who is it for?
The duties it cites fall on provider / developer, deployer / user organisation and general-purpose ai model provider. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.
Is it free?
Yes. Request the DOCX and XLSX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
How will I know when it changes?
Version v1 was built on 28 September 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.