EU AI Act Art. 9: risk management system
Risk management system across the high-risk lifecycle
AIGE-OBL-EUAIA-ART9. Drawn from chapter 08.
Text alternative
- Clause: EU AI Act, Art. 9.
- Duty holder: Provider.
- Applies from: 2027-12-02, Deferred.
- Artefact: Risk register as code.
- Layers: Layer 01, Layer 03.
- Evidence record: Risk register entry, +8 more.
- Record schemas: Risk register entry , Eval result , Design record , Go/no-go decision , Policy card , Test plan , Use-case record , Test report , Post-market monitoring plan .
- The same topic in 24 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-EUAIA-ART9- Instrument
- EU AI Act (post-Omnibus) law
- Compared side by side
- ISO 42001 vs EU AI Act · NIST AI RMF vs EU AI Act
- Clause
- Art. 9
- Duty holder
- Provider
- Authority
- National MSA
- Applies from
- Deferred · Annex III
- Later dates
-
- Applies to Annex I embedded (product safety-component) systems
- Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))
- System class
- High-risk (Annex III) · High-risk (Annex I)
The artefact that evidences it
Risk register as code; threat models; linkage to FRIA and eval results.
Patterns that build it
- Policy Card (layer 1)
- Adversarial Red-Team Suite (layer 3)
- FRIA-as-Code (layer 1 and 2)
- Downstream Use Register (layer 2 and 1)
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Risk management
- ISO 42001 6.1.2 AI risk assessment (core)
- ISO 42001 6.1.3 AI risk treatment (core)
- ISO 42001 8.2 AI risk assessment (operation) (core)
- ISO 42001 8.3 AI risk treatment (operation) (core)
- NIST AI RMF MAP 1 MAP 1: Context is established and understood (core)
- NIST AI RMF MAP 5 MAP 5: Impacts to individuals, groups, communities, organizations, and society are characterized (core)
- NIST AI RMF MANAGE 1 MANAGE 1: AI risks based on assessments and other analytical output are prioritized, responded to, and managed (core)
- TC260 Framework 3.0 TC260 2 Classification of AI safety risks (core)
- TC260 Framework 3.0 TC260 Summary table Risks × technological × governance measures (core)
- ISO 23894 23894 6.4 Risk assessment (core) (clause not verified)
- ISO 23894 23894 6.5 Risk treatment (core) (clause not verified)
- NIST AI RMF GOVERN 1.3 GOVERN 1.3: Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization's risk tolerance (core)
- NIST AI RMF MAP 1.5 MAP 1.5: Organizational risk tolerances are determined and documented (core)
- NIST AI RMF MANAGE 1.3 MANAGE 1.3: Responses to the AI risks deemed high priority, as identified by the MAP function, are developed, planned, and documented (core)
- NIST AI RMF MANAGE 1.4 MANAGE 1.4: Negative residual risks to both downstream acquirers of AI systems and end users are documented (core)
- NIST AI RMF MEASURE 3 MEASURE 3: Mechanisms for tracking identified AI risks over time are in place (core)
- CSA AICM GRC-02 Risk Management Program (core)
- Korea AI Act Art. 34(1)(1) Risk management plan for high-impact AI (core)
- UK ATRS ATRS 2.5.2 Risks and mitigations (core)
- Singapore Agentic Agentic 2.1 Assess and bound the risks upfront (core)
- CoE Convention CoE Art. 16 Risk and impact management framework (core)
- prEN 18228 prEN 18228 AI risk management (draft; supports Art. 9) (core) (clause not verified)
- GAO AI Accountability 1.6 Risk management: implement an AI-specific risk management plan to systematically identify, analyze, and mitigate risks (core)
- ISO 42001 A.6 AI system life cycle
- NIST AI RMF MEASURE 2 MEASURE 2: AI systems are evaluated for trustworthy characteristics
- TC260 Framework 3.0 TC260 5.3.19 Re-assessment on material change
- China GenAI Measures GenAI Art. 17 Security assessment and algorithm filing
- China Algo. Rec. AlgoRec Art. 27 Security assessment
- EU AI Act Art. 3 Definitions
- ISO 42001 6.1.4 AI system impact assessment
- ISO 23894 23894 6.6 Monitoring and review (clause not verified)
- GPAI Code Safety C1 Commitment 1: Safety and Security Framework
- GPAI Code Safety C3 Commitment 3: Systemic risk analysis
- CSA AICM MDS-12 Open Model Risk Assessment
- OECD AI Principles OECD 1.5(c) Systematic risk management at each lifecycle phase
Impact assessment
- EU AI Act Art. 27 Fundamental rights impact assessment for high-risk AI systems (core)
- ISO 42001 6.1.4 AI system impact assessment (core)
- ISO 42001 8.4 AI system impact assessment (operation) (core)
- ISO 42001 A.5 Assessing impacts of AI systems (core)
- NIST AI RMF MAP 3 MAP 3: AI capabilities, targeted usage, goals, and expected benefits and costs are understood (core)
- NIST AI RMF MAP 5 MAP 5: Impacts to individuals, groups, communities, organizations, and society are characterized (core)
- TC260 Framework 3.0 TC260 Appendix 1 Grading principles (core)
- China GenAI Measures GenAI Art. 17 Security assessment (core)
- GDPR Art. 35 Data protection impact assessment (core)
- ISO 42005 42005 5.8 Performing the AI system impact assessment (core) (clause not verified)
- ISO 42005 42005 6.8 Actual and reasonably foreseeable impacts (core) (clause not verified)
- CSA AICM GRC-10 AI Impact Assessment (core)
- Korea AI Act Art. 35 Impact assessment (best-effort duty) (core)
- UK ATRS ATRS 2.5.1 Impact assessments (core)
- TC260 Framework 3.0 TC260 2.2 Safety risks in the application of AI
- GDPR Art. 36 Prior consultation
- ISO 42005 42005 5.12 Monitoring and review (clause not verified)
- CSA AICM DSP-09 Data Protection Impact Assessment
- CoE Convention CoE Art. 16 Risk and impact management framework
- GAO AI Accountability 1.5 Stakeholder involvement: include diverse perspectives from a community of stakeholders throughout the AI life cycle
Robustness, security and evaluations
- EU AI Act Art. 15 Accuracy, robustness and cybersecurity (core)
- EU AI Act Art. 55 Obligations for providers of general-purpose AI models with systemic risk (core)
- ISO 42001 A.6 AI system life cycle (core)
- NIST AI RMF MEASURE 2 MEASURE 2: AI systems are evaluated for trustworthy characteristics (core)
- TC260 Framework 3.0 TC260 3 Technological countermeasures (core)
- TC260 Framework 3.0 TC260 App. 2 II.6 Sandbox validation and red teaming (core)
- China Deep Synthesis DeepSyn Art. 15 Technology management and algorithm verification (core)
- China Deep Synthesis DeepSyn Art. 20 Security assessment of new products (core)
- GB/T 45654 GB/T 45654 Security assessment Security-assessment requirements for generative AI services (core) (clause not verified)
- GPAI Code Safety 3.2 Measure 3.2: Model evaluations (core)
- NIST AI RMF MEASURE 2.7 MEASURE 2.7: AI system security and resilience as identified in the MAP function are evaluated and documented (core)
- CSA AICM MDS-06 Adversarial Attack Analysis (core)
- CSA AICM MDS-07 Robustness against Adversarial Attack / Model Hardening (core)
- Singapore GenAI GenAI 5 Testing and Assurance (core)
- Singapore GenAI GenAI 6 Security (core)
- Singapore Agentic Agentic 2.3.2 Before deploying, test agents (core)
- CoE Convention CoE Art. 16(2)(g) Testing before first use and when significantly modified (core)
- OECD AI Principles OECD 1.4 Robustness, security and safety (core)
- G7 Code G7 Action 1 Identify, evaluate and mitigate risks across the lifecycle, including testing (core)
- GAO AI Accountability 3.7 Assessment: assess performance against defined metrics to ensure the AI system functions as intended and is sufficiently robust (core)
- EU AI Act Art. 60 Testing of high-risk AI systems in real-world conditions outside AI regulatory sandboxes
- ISO 42001 9.1 Monitoring, measurement, analysis and evaluation
- TC260 Framework 3.0 TC260 5.3.14 Resilience
- China GenAI Measures GenAI Art. 17 Security assessment
- EU AI Act Art. 15(3) Declared accuracy levels and metrics
- EU AI Act Art. 42(3) Presumption of conformity for cybersecurity (Cyber Resilience Act)
- GPAI Code Safety C6 Commitment 6: Security mitigations
- GDPR Art. 32 Security of processing
- NIST AI RMF MEASURE 2.1 MEASURE 2.1: Test sets, metrics, and details about the tools used during TEVV are documented
- NIST AI RMF MEASURE 1 MEASURE 1: Appropriate methods and metrics are identified and applied
- CSA AICM AIS-05 Application Security Testing
- OWASP LLM LLM01:2026 Prompt Injection
- OWASP Agentic ASI05 Unexpected Code Execution (RCE)
- Korea AI Act Art. 32(1) Safety duties for AI above the compute threshold
- GAO AI Accountability 3.2 Metrics: define performance metrics that are precise, consistent, and reproducible
Open controls that evidence it
Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.
-
AIGE-CTL-EVAL-009Evaluation Validity Checks (Evaluation environment profile) -
AIGE-CTL-DATA-012Registered Downstream Consumers of Outputs (Data admission and privacy profile) -
AIGE-CTL-ASSURE-001Test Plan Frozen Before Evaluation (Assurance and evidence profile) -
AIGE-CTL-ASSURE-003Signed Test Report Against the Plan (Assurance and evidence profile) -
AIGE-CTL-DEPLOY-008Monitoring plan with thresholds, owners and consequences (Deployment and monitoring profile)
Source
Chapter 08, section EU AI Act, post-Omnibus, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-euaia-art9.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). EU AI Act Art. 9: risk management system (AIGE-OBL-EUAIA-ART9). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{EU AI Act Art. 9: risk management system (AIGE-OBL-EUAIA-ART9)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9},
note = {Version 0.5.0}
}