Article 9: Risk management system
Official text
Source: EUR-Lex, Regulation (EU) 2024/1689 — text reproduced verbatim.
📥 Download AI Act (PDF)🎯 What does this mean for you?
🏭 Provider▼
🏢 Deployer▼
🏪 SME / Startup▼
🏛️ Public Sector▼
✅ Compliance Checklist
- ☐Risk management system established and documented
- ☐Risk identification and analysis performed
- ☐Risk mitigation measures implemented
- ☐Residual risks assessed and deemed acceptable
- ☐Testing procedures performed before deployment
- ☐Continuous monitoring system established
Want to save your progress? Create a free account
📖 Related Recitals
The risk-management system should consist of a continuous, iterative process that is planned and run throughout the entire lifecycle of a high-risk AI system. That process should be aimed at identifyi…
Requirements should apply to high-risk AI systems as regards risk management, the quality and relevance of data sets used, technical documentation and record-keeping, transparency and the provision of…
High-quality data and access to high-quality data plays a vital role in providing structure and in ensuring the performance of many AI systems, especially when techniques involving the training of mod…
🛠 Related tools
⚖️ Related Enforcement
No enforcement actions for this article yet. Follow developments via the Enforcement Tracker.
Cross-references
Annexes
Frequently asked questions
What does the risk management system for AI entail?▼
Is a risk assessment one-time or ongoing?▼
Do SMEs also need to comply with Article 9 of the AI Act?▼
How does Article 9 of the AI Act relate to the GDPR?▼
What are the deadlines for Article 9 of the AI Act?▼
Does Article 9 of the AI Act also apply to AI systems I purchase?▼
What is the difference between provider and deployer under Article 9 of the AI Act?▼
What documentation does Article 9 of the AI Act require?▼
How often must the risk management system be updated?▼
What is the difference between a DPIA (GDPR) and the risk management system of Article 9?▼
Do I need to explicitly document residual risks?▼
Can I combine the AI Act risk management system with ISO 31000 or ISO 23894?▼
📬 AI Act Weekly
Get the most important AI Act developments in your inbox every week.
Subscribe