Skip to content
EU AI Regulation DecodedKnowledge Platform

Run a lifecycle risk-management system

Establish, implement, document and maintain a continuous risk-management system: identify and evaluate known and reasonably foreseeable risks, adopt targeted mitigation, and test throughout the lifecycle.

Last reviewed 2026-07-30Version 1Primary sources 1Status Under editorial review
Applies to
Provider
Scope
High-risk (Annex III use case), High-risk (Annex I regulated product)
Applies from
2027-12-02 — Stand-alone high-risk (Annex III) obligations apply
Derives from
Article 9
Primary source
Art. 9 AIA

Evidence an auditor expects

Audit red flags

Fails an audit

FAQ

What evidence do I need for Article 9?
Risk-management file, Annex IV technical file. Each should be contemporaneous, versioned, and traceable to the system version.

When does “Run a lifecycle risk-management system” apply?
From 2027-12-02 — Stand-alone high-risk (Annex III) obligations apply. It applies to: Provider.

What fails an audit here?
Documentation created after the fact rather than contemporaneously with the decision — national competent authorities apply the contemporaneous standard.; No clear version control / traceability between document versions and system versions.

Legal source

Art. 9 AIA

Stay audit-ready as the Act changes

EU AI Regulation Decoded tracks each obligation and the evidence auditors expect — one practitioner email a week.

Subscribe — free, weekly

Not legal advice. This is a practitioner reference generated from a cited knowledge base built on the primary legal text and official Commission guidance. Verify against the cited primary sources before relying on it for a compliance decision. See editorial standards & methodology.