RM-013MedioProveedorPreventivo
Roles y responsabilidades en la gestión de riesgos
Los proveedores deben asignar roles y responsabilidades claros para las actividades de gestión de riesgos, asegurándose de que el personal encargado cuente con la competencia, recursos y autoridad necesarios para cumplir sus obligaciones.
Artículos:Article 9(1)Article 17(1)(f)
Ejemplos de evidencia
- RACI matrix for risk management
- Job descriptions with risk responsibilities
- Competency assessment records
Normas
ISO 42001:2023 §5.3ISO 31000:2018 §5.4.2
Controles relacionados
- RM-001Establish Risk Management SystemArticle 9(1) requires providers to establish, implement, document, and maintain a risk management system as a continuous iterative process throughout the…
- RM-002Identify Known and Foreseeable RisksProviders must identify and analyse known and foreseeable risks that the high-risk AI system may pose to health, safety, or fundamental rights when used…
- RM-003Risk Estimation and Probability AssessmentProviders must estimate and evaluate the likelihood and severity of potential harm, taking into account the intended purpose, foreseeable misuse, and the…
- RM-004Risk Evaluation Against Acceptance CriteriaProviders must evaluate identified risks against pre-defined risk acceptance criteria and document the rationale for accepting residual risks that cannot…
- RM-005Implement Risk Treatment MeasuresProviders must adopt suitable risk management measures to address identified risks, prioritising the elimination or reduction of risk at design stage…
- RM-006Testing for Risk Management PurposesArticle 9(7) requires that high-risk AI systems are tested to identify the most appropriate risk management measures and to verify that the system…
Términos relacionados de la Ley de IA
- Quality Management SystemA documented system that providers of high-risk AI systems must establish, implement, document, and maintain covering: the regulatory compliance strategy, design and development processes, data governance procedures, risk management, post-market monitoring, and incident reporting.
- Risk Management SystemA continuous iterative process that must be established, implemented, documented, and maintained by providers of high-risk AI systems throughout the entire lifecycle. Must include identification and analysis of known and reasonably foreseeable risks, estimation of risks that may emerge from misuse, and evaluation of residual risks.
- Biometric DataPersonal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data — a special category under GDPR Article 9.
Actualice cuando la conformidad deba ser
El cuestionario gratuito ofrece señales preliminares. La Evaluación Completa convierte la documentación real del sistema en un expediente de decisión auditable: extracción, separación de componentes, evidencias, normativas nacionales y dossier listo para auditoría.
Iniciar vista previa gratuita de riesgos