PM-010AltoProveedorDetective
Revisión periódica poscomercialización
Los proveedores deben realizar revisiones periódicas de los datos de vigilancia poscomercialización y de la eficacia del sistema de vigilancia, elaborando informes de revisión documentados que sirvan de base para actualizar la gestión de riesgos, la documentación técnica y el propio plan de vigilancia.
Artículos:Article 72(3)Article 9(1)(c)
Ejemplos de evidencia
- Periodic monitoring review report
- Review frequency schedule
- Monitoring plan update records following review
Normas
ISO 42001:2023 §9.3
Controles relacionados
- PM-001Post-Market Monitoring Plan EstablishmentArticle 72(3) requires providers to establish, document, and implement a post-market monitoring plan that proportionately reflects the nature of the AI…
- PM-002Operational Data Collection SystemProviders must implement a system for collecting and analysing relevant data on the performance of high-risk AI systems throughout their operational…
- PM-003In-Operation Performance TrackingProviders must continuously track performance indicators in operation, comparing actual performance against the baseline established during pre-market…
- PM-004Incident Detection and Root Cause AnalysisProviders must implement automated and manual mechanisms to detect incidents and near-misses in operation, and conduct root cause analysis for significant…
- PM-005Serious Incident Reporting to AuthoritiesArticle 73(1) requires providers and deployers to report serious incidents to the relevant market surveillance authority without undue delay after…
- PM-006Corrective Action ProceduresProviders must implement documented corrective action procedures that specify how identified performance issues, incidents, and non-conformities are…
Términos relacionados de la Ley de IA
- Post-Market MonitoringProactive collection and review of experience gained from the use of high-risk AI systems, to identify any need for corrective or preventive actions and ensure continued compliance throughout the system lifecycle.
- Risk Management SystemA continuous iterative process that must be established, implemented, documented, and maintained by providers of high-risk AI systems throughout the entire lifecycle. Must include identification and analysis of known and reasonably foreseeable risks, estimation of risks that may emerge from misuse, and evaluation of residual risks.
- Biometric DataPersonal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data — a special category under GDPR Article 9.
Actualice cuando la conformidad deba ser
El cuestionario gratuito ofrece señales preliminares. La Evaluación Completa convierte la documentación real del sistema en un expediente de decisión auditable: extracción, separación de componentes, evidencias, normativas nacionales y dossier listo para auditoría.
Iniciar vista previa gratuita de riesgos