RK-009CriticalProvider & DeployerDetective
Incident and Near-Miss Logging
Providers and deployers must log all incidents, near-misses, and serious incidents involving the AI system, with sufficient detail to support root cause analysis and to meet the reporting obligations under Article 73.
Articles:Article 12(1)Article 73(1)
Evidence Examples
- Incident log with timestamps and severity
- Near-miss reporting procedure
- Serious incident report template
Standards
ISO 42001:2023 §10.2ISO/IEC 27035-1
Related controls
- RK-001Automatic Event Logging CapabilityArticle 12(1) requires that high-risk AI systems are designed and developed with automatic logging capabilities, enabling the reconstruction of events…
- RK-002Log Integrity and Tamper ProtectionProviders must ensure that logs are protected against tampering, unauthorised deletion, or modification, using cryptographic integrity controls,…
- RK-003Log Retention for Minimum 10 YearsArticle 18(1) requires that providers retain technical documentation and logs for at least 10 years after the high-risk AI system is placed on the market…
- RK-004Log Accessibility for Competent AuthoritiesProviders must ensure that event logs are accessible to competent national authorities and market surveillance authorities upon request, with procedures…
- RK-005Event Traceability and ReconstructionLogs must enable the tracing and reconstruction of decision events to understand the inputs processed, the outputs generated, and the conditions under…
- RK-006Performance and Operational Metrics LoggingProviders must log performance and operational metrics relevant to verifying that the AI system operates within the parameters established in the…
Related EU AI Act terms
- Logging CapabilitiesThe automatic recording of events by a high-risk AI system during its operation — required under Article 12 to enable monitoring of its operation, post-hoc investigation of incidents, and to support the post-market monitoring obligations of providers and deployers.
- Serious IncidentAn incident or malfunction of a high-risk AI system that directly or indirectly leads to the death of a person or serious damage to a person's health, a serious and irreversible disruption of the management of critical infrastructure, a breach of obligations under Union law protecting fundamental rights, or serious damage to property or the environment.
Upgrade when it needs to be
The free questionnaire returns preliminary signals. The Full Assessment turns real system material into a governed decision record - extraction, component separation, evidence, national overlays, and a review-ready dossier.
Start free risk preview