QM-006CritiqueFournisseurPréventif
Procédures d'essai et de validation avant mise sur le marché
Les fournisseurs doivent mettre en œuvre des procédures documentées pour les essais et la validation avant commercialisation des systèmes d'IA à haut risque, précisant les métriques à atteindre, les environnements de test et les critères d'acceptation à satisfaire avant la mise sur le marché.
Articles:Article 17(1)(e)Article 9(7)Article 15
Exemples de preuves
- Pre-market validation protocol
- Release acceptance criteria document
- Validation completion sign-off record
Normes
ISO 42001:2023 §8.4ISO 9001:2015 §8.6
Contrôles associés
- QM-001Quality Management System EstablishmentArticle 17(1) requires providers of high-risk AI systems to put in place a quality management system that ensures compliance with the requirements of the…
- QM-002Regulatory Compliance StrategyProviders must establish and document a strategy for achieving and maintaining compliance with applicable regulatory requirements, including the EU AI…
- QM-003Design Control ProceduresProviders must implement documented design control procedures that ensure regulatory and performance requirements are systematically incorporated from the…
- QM-004Data Management ProceduresProviders must have documented data management procedures covering the acquisition, preparation, use, and retention of data throughout the AI system…
- QM-005Staff Training and Competency ProceduresArticle 17(1)(d) requires providers to implement procedures for training personnel involved in AI system development, testing, and monitoring, with…
- QM-007Post-Market Monitoring PlanArticle 17(1)(f) requires providers to implement a post-market monitoring plan that specifies the data to be collected, the monitoring frequency, the…
Termes associés du règlement sur l’IA
- Quality Management SystemA documented system that providers of high-risk AI systems must establish, implement, document, and maintain covering: the regulatory compliance strategy, design and development processes, data governance procedures, risk management, post-market monitoring, and incident reporting.
- Risk Management SystemA continuous iterative process that must be established, implemented, documented, and maintained by providers of high-risk AI systems throughout the entire lifecycle. Must include identification and analysis of known and reasonably foreseeable risks, estimation of risks that may emerge from misuse, and evaluation of residual risks.
- AccuracyThe requirement that high-risk AI systems achieve an appropriate level of accuracy in relation to their intended purpose, as specified in the technical documentation. Providers must declare the level of accuracy in the instructions for use.
- RobustnessThe ability of a high-risk AI system to maintain its level of performance under adverse conditions — including technical limitations, adversarial inputs, errors, or unexpected situations — or within foreseeable operating conditions outside the intended purpose.
- CybersecurityThe requirement that high-risk AI systems are resilient against attempts by third parties to alter their use, behaviour, or performance in ways that could result in risks to health, safety, or fundamental rights, including protection against data poisoning, adversarial examples, and model evasion attacks.
- Biometric DataPersonal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data — a special category under GDPR Article 9.
Passez à la vitesse supérieure quand la conformité doit être
Le questionnaire gratuit fournit des signaux préliminaires. L'Évaluation Complète transforme les données réelles de vos systèmes en un dossier de décision gouverné : extraction, séparation des composants, preuves, surcouches nationales et dossier prêt à être audité.
Démarrer l'aperçu gratuit des risques