The risk management system required for high-risk AI (Article 9)
In short
Article 9 is the foundation the rest of a high-risk AI system’s compliance package sits on. It requires a risk management system to be established, implemented, documented, and maintained as a continuous process across the system’s entire lifecycle, not a one-off document produced before launch and then filed away.
What the process must actually do
Article 9(2) requires the process to:
- Identify and analyse known and reasonably foreseeable risks to health, safety, and fundamental rights.
- Estimate and evaluate risks that may emerge from both the system’s intended use and reasonably foreseeable misuse.
- Evaluate other risks based on analysis of data gathered from the post-market monitoring system (Article 72).
- Adopt suitable, targeted risk management measures to address the risks identified.
Testing against defined thresholds
Article 9(6)-(8) requires the system to be tested throughout development and prior to being placed on the market or put into service, against preliminarily defined metrics and probabilistic thresholds appropriate to its intended purpose. Testing is not a single pre-launch event, it must continue to validate that the system performs consistently for its intended purpose and remains within the identified risk profile.
Eliminate risk by design first, mitigate second
Article 9(5) sets an order of preference for risk mitigation: eliminate or reduce risk through design and development as far as technically feasible, then implement adequate mitigation and control measures for risks that cannot be eliminated, and only then rely on information disclosure and training as a residual safeguard. A compliance package that leans entirely on user warnings or documentation, without having first attempted a design fix, does not satisfy this ordering.
Integrating with existing risk processes
Where an organisation already operates a risk management process under other EU legislation (financial services, medical devices, or another sectoral regime) Article 9(10) allows the AI-specific risk analysis to be integrated into that existing process rather than duplicated as a separate parallel system, provided the integration genuinely addresses the Article 9(2) requirements.
Who is responsible
The risk management system is a provider obligation. Deployers do not have to build their own risk management system, but they cannot simply assume one exists, Article 26 requires deployers to use the system in accordance with the provider’s instructions and to feed back real-world risk signals (unexpected outputs, near-misses, complaints), which is precisely the kind of post-market data Article 9(2)(c) expects providers to fold back into the risk register.
In practice, the most common gap is not the absence of a risk document, but the absence of a named, accountable owner who actually revisits it, Article 9 describes a continuous process, and a market surveillance authority will look for evidence of ongoing re-assessment, not just the existence of an initial risk register.
Frequently asked questions
- Is the Article 9 risk management system a one-off document?
- No. Article 9 requires a continuous process, established, implemented, documented, and maintained across the system's entire lifecycle. A market surveillance authority looks for evidence of ongoing re-assessment, not just an initial risk register.
- In what order must risks be mitigated under Article 9?
- Article 9(5) sets a mandatory order: eliminate or reduce risk through design and development as far as technically feasible first, then apply mitigation and control measures for risks that remain, and only then rely on information disclosure and user training as a residual safeguard.
- Is the risk management system a provider or a deployer obligation?
- It is a provider obligation. Deployers don't build their own, but under Article 26 they must use the system in accordance with the provider's instructions and feed back real-world risk signals, which providers fold back into the process under Article 9(2)(c).
Related guides
Not sure where your company stands?
Our free assessment gives you an indicative result in minutes (free and anonymous) no account needed.
Start the free check