QM-006CríticoProveedorPreventivo
Procedimientos de ensayo y validación previos a la comercialización
Los proveedores deben aplicar procedimientos documentados para el ensayo y la validación previos a la comercialización de los sistemas de IA de alto riesgo, incluidas las métricas que deben alcanzarse, los entornos de ensayo y los criterios de aceptación que deben cumplirse antes de la puesta en el mercado.
Artículos:Article 17(1)(e)Article 9(7)Article 15
Ejemplos de evidencia
- Pre-market validation protocol
- Release acceptance criteria document
- Validation completion sign-off record
Normas
ISO 42001:2023 §8.4ISO 9001:2015 §8.6
Controles relacionados
- QM-001Quality Management System EstablishmentArticle 17(1) requires providers of high-risk AI systems to put in place a quality management system that ensures compliance with the requirements of the…
- QM-002Regulatory Compliance StrategyProviders must establish and document a strategy for achieving and maintaining compliance with applicable regulatory requirements, including the EU AI…
- QM-003Design Control ProceduresProviders must implement documented design control procedures that ensure regulatory and performance requirements are systematically incorporated from the…
- QM-004Data Management ProceduresProviders must have documented data management procedures covering the acquisition, preparation, use, and retention of data throughout the AI system…
- QM-005Staff Training and Competency ProceduresArticle 17(1)(d) requires providers to implement procedures for training personnel involved in AI system development, testing, and monitoring, with…
- QM-007Post-Market Monitoring PlanArticle 17(1)(f) requires providers to implement a post-market monitoring plan that specifies the data to be collected, the monitoring frequency, the…
Términos relacionados de la Ley de IA
- Quality Management SystemA documented system that providers of high-risk AI systems must establish, implement, document, and maintain covering: the regulatory compliance strategy, design and development processes, data governance procedures, risk management, post-market monitoring, and incident reporting.
- Risk Management SystemA continuous iterative process that must be established, implemented, documented, and maintained by providers of high-risk AI systems throughout the entire lifecycle. Must include identification and analysis of known and reasonably foreseeable risks, estimation of risks that may emerge from misuse, and evaluation of residual risks.
- AccuracyThe requirement that high-risk AI systems achieve an appropriate level of accuracy in relation to their intended purpose, as specified in the technical documentation. Providers must declare the level of accuracy in the instructions for use.
- RobustnessThe ability of a high-risk AI system to maintain its level of performance under adverse conditions — including technical limitations, adversarial inputs, errors, or unexpected situations — or within foreseeable operating conditions outside the intended purpose.
- CybersecurityThe requirement that high-risk AI systems are resilient against attempts by third parties to alter their use, behaviour, or performance in ways that could result in risks to health, safety, or fundamental rights, including protection against data poisoning, adversarial examples, and model evasion attacks.
- Biometric DataPersonal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data — a special category under GDPR Article 9.
Actualice cuando la conformidad deba ser
El cuestionario gratuito ofrece señales preliminares. La Evaluación Completa convierte la documentación real del sistema en un expediente de decisión auditable: extracción, separación de componentes, evidencias, normativas nacionales y dossier listo para auditoría.
Iniciar vista previa gratuita de riesgos