Article 9: Risk management system
Praxikon tracks Article 9 (Risk management system) under the EU AI Act, citing the source for every statement.
Application dates
- : Requirements for high-risk systems listed in Annex III
- : Requirements for high-risk systems linked to Annex I
Article 9 is the risk-management foundation for high-risk AI. Organisations must not only identify risks, but also mitigate, test, monitor and document them.
Official text
Source: EUR-Lex, Regulation (EU) 2024/1689. Text reproduced verbatim.
Download AI Act (PDF) →Official guidance on this article
4- Commission Implementing Decision C(2025) 3871 of 23.6.2025 on a standardisation request to CEN and CENELEC as regards high-risk AI systems in support of Regulation (EU) 2024/1689 and repealing Implementing Decision C(2023) 3215Explicitly requests a standard for the risk management system so that providers can implement the open standard of Article 9 with a concrete methodologyPublishedImplementing actEuropean Commission23 Jun 2025
- ISO/IEC 42005:2025 Information technology - Artificial intelligence (AI) - AI system impact assessmentSupplements the risk management system of Article 9 with an explicit focus on impacts on individuals and groups, making the risk process broader than product safety alone.PublishedStandardISO/IEC JTC 1/SC 42, Dutch adoption by NEN1 Jun 2025
- EN ISO/IEC 23894:2024 Information technology - Artificial intelligence - Guidance on risk managementCurrently provides a usable methodology for the risk management system of Article 9, as a bridge while the European prescriptive standard prEN 18228 remains in draft phase.PublishedStandardISO/IEC JTC 1/SC 42, European adoption through CEN-CENELEC, Dutch adoption by NEN1 Feb 2024
- prEN 18228 Artificial intelligence - Risk management (draft European standard, public enquiry)Provides the process that providers must follow to meet the obligation under Article 9 to maintain a risk management system throughout the entire lifecycle, including risks to fundamental rights.DraftStandardCEN-CENELEC JTC 21, national consultation through NEN18 May 2026
What does this mean for you?
Provider+
Deployer+
SME / Startup+
Public Sector+
Compliance checklist
- Risk management system established and documented
- Risk identification and analysis performed
- Risk mitigation measures implemented
- Residual risks assessed and deemed acceptable
- Testing procedures performed before deployment
- Continuous monitoring system established
Want to save your progress? Create an account
Related recitals
The risk-management system should consist of a continuous, iterative process that is planned and run throughout the entire lifecycle of a high-risk AI system. That process should be aimed at identifyi…
Requirements should apply to high-risk AI systems as regards risk management, the quality and relevance of data sets used, technical documentation and record-keeping, transparency and the provision of…
High-quality data and access to high-quality data plays a vital role in providing structure and in ensuring the performance of many AI systems, especially when techniques involving the training of mod…
Related tools
Related enforcement
No enforcement actions for this article yet. Follow developments via the Enforcement Tracker.
Related blog posts
Cross-references
Annexes
Frequently asked questions
What does the risk management system for AI entail?+
Is a risk assessment one-time or ongoing?+
What documentation does Article 9 of the AI Act require?+
How often must the risk management system be updated?+
What is the difference between a DPIA (GDPR) and the risk management system of Article 9?+
Do I need to explicitly document residual risks?+
Can I combine the AI Act risk management system with ISO 31000 or ISO 23894?+
What Article 9 requires in practice
Connections
What connects to Article 9 AI Act
Themes where this returns
The counterpart in the other law
GDPR interpretation that also applies here
- EDPB Template for Data Protection Impact Assessment
2026-04-14 · under consultation, European Data Protection Board (EDPB) · via Assessing risks in advance: DPIA and FRIA
- Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is likely to result in a high risk
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB) · via Assessing risks in advance: DPIA and FRIA
- Consultation on the draft list of processing operations for which no DPIA is required (Dutch DPA)
2026-06-24 · under consultation, Autoriteit Persoonsgegevens (AP) · via Assessing risks in advance: DPIA and FRIA
- The Hague District Court cuts DPA fine on police for mobile camera cars without completed DPIA to 30,000 euros
2024-10-08 · status not established, Rechtbank Den Haag · via Assessing risks in advance: DPIA and FRIA
- Decision on the list of processing operations for which a DPIA is mandatory (Dutch DPA)
2019-11-27 · in force, Autoriteit Persoonsgegevens (AP) · via Assessing risks in advance: DPIA and FRIA
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default
2020-10-20 · final, European Data Protection Board (EDPB) · via Privacy by design and risk management by design