RM-002KritischAnbieterPräventiv
Bekannte und vorhersehbare Risiken identifizieren
Anbieter müssen bekannte und vernünftigerweise vorhersehbare Risiken identifizieren und analysieren, die das Hochrisiko-KI-System für Gesundheit, Sicherheit oder Grundrechte birgt, wenn es bestimmungsgemäß und unter vernünftigerweise vorhersehbaren Fehlanwendungsbedingungen verwendet wird.
Artikel:Article 9(2)(a)Article 9(4)
Nachweisbeispiele
- Risk identification register
- Misuse scenario analysis
- Threat modelling report
Normen
ISO 42001:2023 §6.1.2ISO/IEC 23894
Verwandte Kontrollen
- RM-001Establish Risk Management SystemArticle 9(1) requires providers to establish, implement, document, and maintain a risk management system as a continuous iterative process throughout the…
- RM-003Risk Estimation and Probability AssessmentProviders must estimate and evaluate the likelihood and severity of potential harm, taking into account the intended purpose, foreseeable misuse, and the…
- RM-004Risk Evaluation Against Acceptance CriteriaProviders must evaluate identified risks against pre-defined risk acceptance criteria and document the rationale for accepting residual risks that cannot…
- RM-005Implement Risk Treatment MeasuresProviders must adopt suitable risk management measures to address identified risks, prioritising the elimination or reduction of risk at design stage…
- RM-006Testing for Risk Management PurposesArticle 9(7) requires that high-risk AI systems are tested to identify the most appropriate risk management measures and to verify that the system…
- RM-007Residual Risk Documentation and DisclosureProviders must document residual risks that users need to be informed of and include relevant information in the system instructions for use, enabling…
Verwandte KI-VO-Begriffe
- Risk Management SystemA continuous iterative process that must be established, implemented, documented, and maintained by providers of high-risk AI systems throughout the entire lifecycle. Must include identification and analysis of known and reasonably foreseeable risks, estimation of risks that may emerge from misuse, and evaluation of residual risks.
- Biometric DataPersonal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data — a special category under GDPR Article 9.
Erweitern Sie, wenn Nachweise rechtskräftig sein müssen.
Der kostenlose Fragebogen liefert erste Signale. Die Vollständige Bewertung verwandelt reale Systemdaten in einen auditierten Entscheidungsnachweis: Faktenextraktion, Komponententrennung, Nachweise, nationale Vorgaben und ein prüffähiges Dossier.
Kostenlose Risikovorschau starten