PM-007MediumProviderDetective
Feedback Integration from Deployers
Providers must establish channels for receiving and systematically processing feedback from deployers about AI system performance, incidents, and concerns, integrating relevant insights into the risk management and post-market monitoring systems.
Articles:Article 72(1)Article 26(6)
Evidence Examples
- Deployer feedback channel description
- Feedback analysis procedure
- Feedback-to-action traceability log
Standards
ISO 42001:2023 §9.1
Related controls
- PM-001Post-Market Monitoring Plan EstablishmentArticle 72(3) requires providers to establish, document, and implement a post-market monitoring plan that proportionately reflects the nature of the AI…
- PM-002Operational Data Collection SystemProviders must implement a system for collecting and analysing relevant data on the performance of high-risk AI systems throughout their operational…
- PM-003In-Operation Performance TrackingProviders must continuously track performance indicators in operation, comparing actual performance against the baseline established during pre-market…
- PM-004Incident Detection and Root Cause AnalysisProviders must implement automated and manual mechanisms to detect incidents and near-misses in operation, and conduct root cause analysis for significant…
- PM-005Serious Incident Reporting to AuthoritiesArticle 73(1) requires providers and deployers to report serious incidents to the relevant market surveillance authority without undue delay after…
- PM-006Corrective Action ProceduresProviders must implement documented corrective action procedures that specify how identified performance issues, incidents, and non-conformities are…
Related EU AI Act terms
- Post-Market MonitoringProactive collection and review of experience gained from the use of high-risk AI systems, to identify any need for corrective or preventive actions and ensure continued compliance throughout the system lifecycle.
- Logging CapabilitiesThe automatic recording of events by a high-risk AI system during its operation — required under Article 12 to enable monitoring of its operation, post-hoc investigation of incidents, and to support the post-market monitoring obligations of providers and deployers.
- Human OversightMeasures built into high-risk AI systems enabling natural persons to understand, monitor, and — where necessary — override or shut down the system. Must be proportionate to the risks and must ensure that deployers can intervene in the system's output before it takes effect.
Upgrade when it needs to be
The free questionnaire returns preliminary signals. The Full Assessment turns real system material into a governed decision record - extraction, component separation, evidence, national overlays, and a review-ready dossier.
Start free risk preview