PM-003HighProviderDetective
In-Operation Performance Tracking
Providers must continuously track performance indicators in operation, comparing actual performance against the baseline established during pre-market validation, and documenting trends that could indicate emerging compliance concerns.
Articles:Article 72(1)Article 15(1)
Evidence Examples
- Live performance monitoring dashboard
- Baseline vs. operational performance report
- Performance trend analysis
Standards
ISO 42001:2023 §9.1
Related controls
- PM-001Post-Market Monitoring Plan EstablishmentArticle 72(3) requires providers to establish, document, and implement a post-market monitoring plan that proportionately reflects the nature of the AI…
- PM-002Operational Data Collection SystemProviders must implement a system for collecting and analysing relevant data on the performance of high-risk AI systems throughout their operational…
- PM-004Incident Detection and Root Cause AnalysisProviders must implement automated and manual mechanisms to detect incidents and near-misses in operation, and conduct root cause analysis for significant…
- PM-005Serious Incident Reporting to AuthoritiesArticle 73(1) requires providers and deployers to report serious incidents to the relevant market surveillance authority without undue delay after…
- PM-006Corrective Action ProceduresProviders must implement documented corrective action procedures that specify how identified performance issues, incidents, and non-conformities are…
- PM-007Feedback Integration from DeployersProviders must establish channels for receiving and systematically processing feedback from deployers about AI system performance, incidents, and…
Related EU AI Act terms
- Post-Market MonitoringProactive collection and review of experience gained from the use of high-risk AI systems, to identify any need for corrective or preventive actions and ensure continued compliance throughout the system lifecycle.
- AccuracyThe requirement that high-risk AI systems achieve an appropriate level of accuracy in relation to their intended purpose, as specified in the technical documentation. Providers must declare the level of accuracy in the instructions for use.
- RobustnessThe ability of a high-risk AI system to maintain its level of performance under adverse conditions — including technical limitations, adversarial inputs, errors, or unexpected situations — or within foreseeable operating conditions outside the intended purpose.
- CybersecurityThe requirement that high-risk AI systems are resilient against attempts by third parties to alter their use, behaviour, or performance in ways that could result in risks to health, safety, or fundamental rights, including protection against data poisoning, adversarial examples, and model evasion attacks.
Upgrade when it needs to be
The free questionnaire returns preliminary signals. The Full Assessment turns real system material into a governed decision record - extraction, component separation, evidence, national overlays, and a review-ready dossier.
Start free risk preview