Home · EU AI Act · Articles · Article 9
EU AI Act · Engineering reference

Article 9 — Risk Management System

High-risk AI systems must operate within a continuous, documented risk-management system spanning the entire AI lifecycle.

Audit-survivable
31%
of 50 EU-exposed enterprises in MindMap's 2026 readiness benchmark

What the Article requires

Article 9 requires providers of high-risk AI systems to establish, implement, document and maintain a risk-management system that runs throughout the AI lifecycle. The system identifies foreseeable risks to health, safety and fundamental rights, evaluates risks under intended use and reasonably-foreseeable misuse, and adopts targeted risk-management measures. Critically, it is not a one-time exercise — the system is updated continuously as the AI evolves.

In engineering terms

Maps to existing enterprise risk-management frameworks but specifically extends to AI lifecycle artefacts: training-data risks, model behaviour risks, deployment-context risks, and misuse risks. Engineering teams typically bolt this onto SR 11-7 (US BFSI), the FCA SYSC framework, or analogous existing-risk taxonomies.

Compliance checklist

  • ✓Documented risk-management process specifically applied to AI systems
  • ✓Identified, evaluated and treated risks to health, safety and fundamental rights
  • ✓Risk-management decisions documented with rationale
  • ✓Continuous-update cycle, not a one-time assessment
  • ✓Integration with the existing enterprise risk function

Terms used here

EU AI ActAnnex III high-risk AI

All Articles in the reference · The EU AI Act compliance architecture

Need audit-survivable evidence for Article 9?

MindMap runs a 90-day path from standing start to audit-survivable evidence. Talk to the engineering team.

Download the whitepaper →Check your tier →Book a scoping call →