PM-004CríticoProveedorDetective
Detección de incidentes y análisis de causas raíz
Los proveedores deben implantar mecanismos automatizados y manuales para detectar incidentes y cuasiincidentes en funcionamiento, y realizar análisis de causas raíz de los incidentes significativos para identificar problemas sistémicos y prevenir su recurrencia.
Artículos:Article 72(1)Article 73(1)
Ejemplos de evidencia
- Incident detection system configuration
- Root cause analysis report template
- Incident investigation records
Normas
ISO 42001:2023 §10.2ISO/IEC 27035-1
Controles relacionados
- PM-001Post-Market Monitoring Plan EstablishmentArticle 72(3) requires providers to establish, document, and implement a post-market monitoring plan that proportionately reflects the nature of the AI…
- PM-002Operational Data Collection SystemProviders must implement a system for collecting and analysing relevant data on the performance of high-risk AI systems throughout their operational…
- PM-003In-Operation Performance TrackingProviders must continuously track performance indicators in operation, comparing actual performance against the baseline established during pre-market…
- PM-005Serious Incident Reporting to AuthoritiesArticle 73(1) requires providers and deployers to report serious incidents to the relevant market surveillance authority without undue delay after…
- PM-006Corrective Action ProceduresProviders must implement documented corrective action procedures that specify how identified performance issues, incidents, and non-conformities are…
- PM-007Feedback Integration from DeployersProviders must establish channels for receiving and systematically processing feedback from deployers about AI system performance, incidents, and…
Términos relacionados de la Ley de IA
- Post-Market MonitoringProactive collection and review of experience gained from the use of high-risk AI systems, to identify any need for corrective or preventive actions and ensure continued compliance throughout the system lifecycle.
- Serious IncidentAn incident or malfunction of a high-risk AI system that directly or indirectly leads to the death of a person or serious damage to a person's health, a serious and irreversible disruption of the management of critical infrastructure, a breach of obligations under Union law protecting fundamental rights, or serious damage to property or the environment.
Actualice cuando la conformidad deba ser
El cuestionario gratuito ofrece señales preliminares. La Evaluación Completa convierte la documentación real del sistema en un expediente de decisión auditable: extracción, separación de componentes, evidencias, normativas nacionales y dossier listo para auditoría.
Iniciar vista previa gratuita de riesgos