Article 9risk managementhigh-risk

    Building an EU AI Act Risk Management System (Article 9)

    Ready 4 AI Act · March 19, 2026 · Last updated July 31, 2026

    Cover image for "Building an EU AI Act Risk Management System (Article 9)"

    What Article 9 requires

    Article 9 of the EU AI Act requires every provider of a high-risk AI system to establish, implement, document, and maintain a risk management system — a continuous, iterative process across the entire lifecycle, with regular systematic review.

    This is not a one-off risk assessment.

    The four mandatory steps

    1. Identify and analyse known and reasonably foreseeable risks to health, safety, and fundamental rights.
    2. Estimate and evaluate risks under intended use and reasonably foreseeable misuse.
    3. Evaluate other risks from post-market monitoring data.
    4. Adopt appropriate and targeted risk management measures.

    The hierarchy of measures (Article 9(5))

    • Eliminate or reduce risks through adequate design and development.
    • Where not possible, implement mitigation and control measures.
    • Provide information and training to deployers.

    Residual risk acceptance must be documented.

    Vulnerable groups

    Article 9(9) requires specific consideration of impact on persons under 18 and other vulnerable groups — not optional.

    A workable operating model

    Risk register

    One row per risk: description, harm type, likelihood, severity, affected group, owner, mitigation, residual risk, review date.

    Design decision log

    Every design choice made because of a risk, traceable to the register entry it addresses.

    Test and validation evidence

    Bias, robustness, adversarial testing with documented methodology.

    Post-market monitoring feed

    Every serious incident (Article 73) triggers reopening the analysis.

    Cadence

    • Continuous incident-driven updates.
    • Quarterly register review.
    • Annual full re-evaluation, signed at management level.
    • Event-driven on substantial modification (Article 43).

    What auditors will ask for

    • The written procedure.
    • The current register with change history.
    • Evidence of the last annual review.
    • Trace from at least one incident to a register update.
    • Evidence of vulnerable-group analysis.

    Related: High-risk AI systems guide · EU AI Act overview · Free readiness assessment

    Reviewed by Ready 4 AI Act EU - Editorial team. This article is journalistic information, not legal advice.

    Not sure where you stand?

    Take the free readiness assessment and get a personalised report.

    Start free assessment