PM-010AltoFornitoreInvestigativo
Revisione periodica post-commercializzazione
I fornitori devono condurre revisioni periodiche dei dati di monitoraggio post-commercializzazione e dell'efficacia del sistema di monitoraggio, producendo rapporti di revisione documentati che informino gli aggiornamenti della gestione dei rischi, della documentazione tecnica e del piano di monitoraggio stesso.
Articoli:Article 72(3)Article 9(1)(c)
Esempi di prove
- Periodic monitoring review report
- Review frequency schedule
- Monitoring plan update records following review
Norme
ISO 42001:2023 §9.3
Controlli correlati
- PM-001Post-Market Monitoring Plan EstablishmentArticle 72(3) requires providers to establish, document, and implement a post-market monitoring plan that proportionately reflects the nature of the AI…
- PM-002Operational Data Collection SystemProviders must implement a system for collecting and analysing relevant data on the performance of high-risk AI systems throughout their operational…
- PM-003In-Operation Performance TrackingProviders must continuously track performance indicators in operation, comparing actual performance against the baseline established during pre-market…
- PM-004Incident Detection and Root Cause AnalysisProviders must implement automated and manual mechanisms to detect incidents and near-misses in operation, and conduct root cause analysis for significant…
- PM-005Serious Incident Reporting to AuthoritiesArticle 73(1) requires providers and deployers to report serious incidents to the relevant market surveillance authority without undue delay after…
- PM-006Corrective Action ProceduresProviders must implement documented corrective action procedures that specify how identified performance issues, incidents, and non-conformities are…
Termini correlati del Regolamento IA
- Post-Market MonitoringProactive collection and review of experience gained from the use of high-risk AI systems, to identify any need for corrective or preventive actions and ensure continued compliance throughout the system lifecycle.
- Risk Management SystemA continuous iterative process that must be established, implemented, documented, and maintained by providers of high-risk AI systems throughout the entire lifecycle. Must include identification and analysis of known and reasonably foreseeable risks, estimation of risks that may emerge from misuse, and evaluation of residual risks.
- Biometric DataPersonal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data — a special category under GDPR Article 9.
Passa alla versione completa quando la conformità deve essere
Il questionario gratuito fornisce segnali preliminari. La Valutazione Completa trasforma i dati reali di sistema in un fascicolo decisionale governato: estrazione, separazione componenti, prove, sovrapposizioni nazionali e dossier pronto per audit.
Avvia anteprima gratuita del rischio