TD-009HighProviderPreventive
Change Management Procedures
Providers must document procedures for managing changes to the AI system that could affect its compliance status, triggering re-assessment when a modification is substantial and potentially requiring new conformity assessment.
Articles:Article 11(3)Article 43(4)
Evidence Examples
- Change management procedure document
- Change impact classification criteria
- Re-assessment trigger log
Standards
ISO 42001:2023 §6.3ISO/IEC 27001:2022 §6.3
Related controls
- TD-001AI System Description and General InformationArticle 11 and Annex IV require that technical documentation includes a general description of the AI system covering its intended purpose, the persons…
- TD-002Design Specifications and ArchitectureProviders must document the overall design logic of the AI system, including the algorithms and associated design choices, the key design parameters, and…
- TD-003Development Process DocumentationTechnical documentation must describe the methods and steps performed for the development of the AI system, including data collection, labelling, model…
- TD-004Validation and Testing Approach DocumentationProviders must document the validation and testing procedures applied to the AI system prior to placing it on the market, including the metrics used, the…
- TD-005System Monitoring Plan DocumentationTechnical documentation must include a plan describing the measures for monitoring the AI system in operation, the data to be collected, the performance…
- TD-006Accuracy Metrics and Performance DocumentationProviders must document the accuracy, robustness, and cybersecurity metrics for which the high-risk AI system was designed and the relevant testing…
Related EU AI Act terms
- Conformity AssessmentThe process of verifying whether a high-risk AI system complies with the requirements set out in Chapter III Section 2 of the Regulation. Can be conducted through internal control (Annex VI) or with involvement of a notified body (Annex VII).
- Technical DocumentationThe documentation that providers of high-risk AI systems must draw up before placing the system on the market, containing all necessary information to assess compliance with the Regulation, including a general description, design specifications, training data information, risk management records, and performance metrics. Content requirements are set out in Annex IV.
Upgrade when it needs to be
The free questionnaire returns preliminary signals. The Full Assessment turns real system material into a governed decision record - extraction, component separation, evidence, national overlays, and a review-ready dossier.
Start free risk preview