CA-010HighProviderCorrective
Non-Conformity Identification and Remediation
Providers must establish procedures for identifying non-conformities during conformity assessment or post-market surveillance, implementing corrective actions, and re-assessing compliance before re-releasing any modified system.
Articles:Article 20(1)Article 43(4)
Evidence Examples
- Non-conformity register
- Corrective action procedure
- Re-assessment after correction record
Standards
ISO 42001:2023 §10.1ISO 9001:2015 §10.2
Related controls
- CA-001Conformity Assessment Pathway SelectionArticle 43 requires providers to select the appropriate conformity assessment procedure for their high-risk AI system: internal control (Annex VI) under…
- CA-002Internal Control Assessment (Annex VI)For AI systems subject to internal control assessment, providers must verify and document that the system meets all applicable requirements of Articles…
- CA-003Third-Party Notified Body AssessmentThird-party assessment is the exception. It applies to Annex III point 1 biometric identification and categorisation systems under Article 43(1) where…
- CA-004CE Marking AffixationArticle 48 requires that providers affix the CE marking to high-risk AI systems that have successfully completed conformity assessment, certifying that…
- CA-005EU Declaration of ConformityArticle 47 requires providers to draw up an EU Declaration of Conformity for each high-risk AI system, declaring that it meets all applicable…
- CA-006Notified Body Selection and EngagementWhere third-party assessment is required, providers must select a notified body that is duly designated for the relevant Annex III category, verify its…
Related EU AI Act terms
Upgrade when it needs to be
The free questionnaire returns preliminary signals. The Full Assessment turns real system material into a governed decision record - extraction, component separation, evidence, national overlays, and a review-ready dossier.
Start free risk preview