RM-007ÉlevéFournisseurPréventif
Documentation et divulgation des risques résiduels
Les fournisseurs doivent documenter les risques résiduels dont les utilisateurs doivent être informés et inclure les informations pertinentes dans les instructions d’utilisation du système, permettant ainsi aux déployeurs de gérer de manière appropriée les risques restants.
Articles:Article 9(2)(d)Article 13(1)
Exemples de preuves
- Residual risk statement in IFU
- Residual risk register
- User notification documentation
Normes
ISO 42001:2023 §6.1.3
Contrôles associés
- RM-001Establish Risk Management SystemArticle 9(1) requires providers to establish, implement, document, and maintain a risk management system as a continuous iterative process throughout the…
- RM-002Identify Known and Foreseeable RisksProviders must identify and analyse known and foreseeable risks that the high-risk AI system may pose to health, safety, or fundamental rights when used…
- RM-003Risk Estimation and Probability AssessmentProviders must estimate and evaluate the likelihood and severity of potential harm, taking into account the intended purpose, foreseeable misuse, and the…
- RM-004Risk Evaluation Against Acceptance CriteriaProviders must evaluate identified risks against pre-defined risk acceptance criteria and document the rationale for accepting residual risks that cannot…
- RM-005Implement Risk Treatment MeasuresProviders must adopt suitable risk management measures to address identified risks, prioritising the elimination or reduction of risk at design stage…
- RM-006Testing for Risk Management PurposesArticle 9(7) requires that high-risk AI systems are tested to identify the most appropriate risk management measures and to verify that the system…
Termes associés du règlement sur l’IA
- Instructions for UseInformation provided by the provider of a high-risk AI system to inform deployers about the system's intended purpose, performance characteristics, limitations, maintenance requirements, human oversight mechanisms, and the technical measures needed to ensure the system can be effectively overseen by natural persons.
- Risk Management SystemA continuous iterative process that must be established, implemented, documented, and maintained by providers of high-risk AI systems throughout the entire lifecycle. Must include identification and analysis of known and reasonably foreseeable risks, estimation of risks that may emerge from misuse, and evaluation of residual risks.
- Transparency RequirementsObligations under Article 13 requiring that high-risk AI systems are designed to ensure that their operation is sufficiently transparent to enable deployers to interpret the system's output and use it appropriately, and under Article 50 for specific systems (chatbots, synthetic content) to notify persons they are interacting with AI.
- Biometric DataPersonal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data — a special category under GDPR Article 9.
Passez à la vitesse supérieure quand la conformité doit être
Le questionnaire gratuit fournit des signaux préliminaires. L'Évaluation Complète transforme les données réelles de vos systèmes en un dossier de décision gouverné : extraction, séparation des composants, preuves, surcouches nationales et dossier prêt à être audité.
Démarrer l'aperçu gratuit des risques