RK-009CritiqueFournisseur & DéployeurDétectif
Journalisation des incidents et quasi-incidents
Les fournisseurs et déployeurs doivent journaliser tous les incidents, quasi-incidents et incidents graves impliquant le système d’IA, avec suffisamment de détails pour soutenir l’analyse des causes racines et répondre aux obligations de notification de l’article 73.
Articles:Article 12(1)Article 73(1)
Exemples de preuves
- Incident log with timestamps and severity
- Near-miss reporting procedure
- Serious incident report template
Normes
ISO 42001:2023 §10.2ISO/IEC 27035-1
Contrôles associés
- RK-001Automatic Event Logging CapabilityArticle 12(1) requires that high-risk AI systems are designed and developed with automatic logging capabilities, enabling the reconstruction of events…
- RK-002Log Integrity and Tamper ProtectionProviders must ensure that logs are protected against tampering, unauthorised deletion, or modification, using cryptographic integrity controls,…
- RK-003Log Retention for Minimum 10 YearsArticle 18(1) requires that providers retain technical documentation and logs for at least 10 years after the high-risk AI system is placed on the market…
- RK-004Log Accessibility for Competent AuthoritiesProviders must ensure that event logs are accessible to competent national authorities and market surveillance authorities upon request, with procedures…
- RK-005Event Traceability and ReconstructionLogs must enable the tracing and reconstruction of decision events to understand the inputs processed, the outputs generated, and the conditions under…
- RK-006Performance and Operational Metrics LoggingProviders must log performance and operational metrics relevant to verifying that the AI system operates within the parameters established in the…
Termes associés du règlement sur l’IA
- Logging CapabilitiesThe automatic recording of events by a high-risk AI system during its operation — required under Article 12 to enable monitoring of its operation, post-hoc investigation of incidents, and to support the post-market monitoring obligations of providers and deployers.
- Serious IncidentAn incident or malfunction of a high-risk AI system that directly or indirectly leads to the death of a person or serious damage to a person's health, a serious and irreversible disruption of the management of critical infrastructure, a breach of obligations under Union law protecting fundamental rights, or serious damage to property or the environment.
Passez à la vitesse supérieure quand la conformité doit être
Le questionnaire gratuit fournit des signaux préliminaires. L'Évaluation Complète transforme les données réelles de vos systèmes en un dossier de décision gouverné : extraction, séparation des composants, preuves, surcouches nationales et dossier prêt à être audité.
Démarrer l'aperçu gratuit des risques