What the Article requires
Article 9 requires providers of high-risk AI systems to establish, implement, document and maintain a risk-management system that runs throughout the AI lifecycle. The system identifies foreseeable risks to health, safety and fundamental rights, evaluates risks under intended use and reasonably-foreseeable misuse, and adopts targeted risk-management measures. Critically, it is not a one-time exercise — the system is updated continuously as the AI evolves.
In engineering terms
Maps to existing enterprise risk-management frameworks but specifically extends to AI lifecycle artefacts: training-data risks, model behaviour risks, deployment-context risks, and misuse risks. Engineering teams typically bolt this onto SR 11-7 (US BFSI), the FCA SYSC framework, or analogous existing-risk taxonomies.
Compliance checklist
- ✓Documented risk-management process specifically applied to AI systems
- ✓Identified, evaluated and treated risks to health, safety and fundamental rights
- ✓Risk-management decisions documented with rationale
- ✓Continuous-update cycle, not a one-time assessment
- ✓Integration with the existing enterprise risk function
Terms used here
All Articles in the reference · The EU AI Act compliance architecture
Need audit-survivable evidence for Article 9?
MindMap runs a 90-day path from standing start to audit-survivable evidence. Talk to the engineering team.