PM-010ÉlevéFournisseurDétectif
Examen périodique post-commercialisation
Les fournisseurs doivent effectuer des examens périodiques des données de surveillance post-commercialisation et de l'efficacité du système de surveillance, en produisant des rapports d'examen documentés qui éclairent les mises à jour de la gestion des risques, de la documentation technique et du plan de surveillance lui-même.
Articles:Article 72(3)Article 9(1)(c)
Exemples de preuves
- Periodic monitoring review report
- Review frequency schedule
- Monitoring plan update records following review
Normes
ISO 42001:2023 §9.3
Contrôles associés
- PM-001Post-Market Monitoring Plan EstablishmentArticle 72(3) requires providers to establish, document, and implement a post-market monitoring plan that proportionately reflects the nature of the AI…
- PM-002Operational Data Collection SystemProviders must implement a system for collecting and analysing relevant data on the performance of high-risk AI systems throughout their operational…
- PM-003In-Operation Performance TrackingProviders must continuously track performance indicators in operation, comparing actual performance against the baseline established during pre-market…
- PM-004Incident Detection and Root Cause AnalysisProviders must implement automated and manual mechanisms to detect incidents and near-misses in operation, and conduct root cause analysis for significant…
- PM-005Serious Incident Reporting to AuthoritiesArticle 73(1) requires providers and deployers to report serious incidents to the relevant market surveillance authority without undue delay after…
- PM-006Corrective Action ProceduresProviders must implement documented corrective action procedures that specify how identified performance issues, incidents, and non-conformities are…
Termes associés du règlement sur l’IA
- Post-Market MonitoringProactive collection and review of experience gained from the use of high-risk AI systems, to identify any need for corrective or preventive actions and ensure continued compliance throughout the system lifecycle.
- Risk Management SystemA continuous iterative process that must be established, implemented, documented, and maintained by providers of high-risk AI systems throughout the entire lifecycle. Must include identification and analysis of known and reasonably foreseeable risks, estimation of risks that may emerge from misuse, and evaluation of residual risks.
- Biometric DataPersonal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data — a special category under GDPR Article 9.
Passez à la vitesse supérieure quand la conformité doit être
Le questionnaire gratuit fournit des signaux préliminaires. L'Évaluation Complète transforme les données réelles de vos systèmes en un dossier de décision gouverné : extraction, séparation des composants, preuves, surcouches nationales et dossier prêt à être audité.
Démarrer l'aperçu gratuit des risques