Risk management system
The risk management system is a continuous, documented, testing-based process spanning the entire lifecycle of a high-risk AI system, which identifies, evaluates and mitigates the risks the system poses to the health, safety and fundamental rights of third persons. It does not manage organisational risk — it protects a different interest than ISO 31000 or ISO/IEC 42001, and neither creates a presumption of conformity, since neither is a harmonised standard.
The requirements are set out in Article 9(1)–(10). The system's purpose is deliberately narrow: it does not manage the company's business or financial risks, but specifically what the system may pose to the health, safety and fundamental rights of third parties — customers, employees, affected individuals. The process must accompany the system's entire lifecycle, from design through placing on the market to continuous monitoring, and requires regular review and updating. Good corporate risk-management practice — ISO 31000 or ISO/IEC 42001 — can provide a useful organisational framework, but does not legally substitute for the Article 9 obligation, since the protected interest differs, and neither standard is harmonised within the meaning of the AI Act, so applying them does not on its own create a presumption of conformity under Article 40.
An existing ISO 31000 or ISO/IEC 42001 process is a good starting point, but not enough on its own — the risk-management documentation must specifically focus on the health and fundamental rights of affected third parties, not the company's business risks.
Need documented AI-literacy training?
Article 4 is a duty of diligence: what counts is not knowledge in the abstract, but demonstrable, documented effort. Our starter package lets you begin free.
Start freeRelated terms
- High-risk AI systemAn AI system is high-risk if it is a safety component of, or is itself, a product covered by the Union product-safety legislation listed in Annex I, or if it falls within one of the eight areas and listed use cases of Annex III. Classification attaches to the intended purpose, not to the underlying technology.
- Data governanceData governance covers eight practices applicable to the training, validation and testing data sets of a high-risk AI system, and the substantive standard that data sets be relevant, sufficiently representative, and, to the best extent possible, free of errors and complete. The legislator does not demand flawless data sets, but documented diligence proportionate to the intended purpose.
- Technical documentationTechnical documentation is the record demonstrating a high-risk AI system's compliance, covering the nine points of Annex IV, which must be drawn up before placing on the market, kept up to date, and retained for ten years. It is the record from which a regulator can later reconstruct how the system and its classification decision came about.
- Harmonised standardA harmonised standard is a technical standard developed on the basis of a Union standardisation request, whose application creates a presumption of conformity: a provider that follows it is presumed to meet the corresponding requirement. As of mid-2026, harmonised standards covering the AI Act's high-risk requirements had not yet been finalised, so the presumption of conformity is not currently available.
Related questions in the knowledge base (Hungarian)
- Mit követel az AI Act kockázatkezelési rendszere, és miben más, mint az ISO 42001?A 9. cikk nem szervezeti kockázatot kezel, hanem azt, amit a rendszer harmadik személyek egészségére, biztonságára és alapjogaira jelent — folyamatos, a teljes életciklusra kiterjedő, dokumentált és tesztelésre alapozott folyamatban. Az ISO 31000 és az ISO/IEC 42001 más alanyt véd, és egyik sem harmonizált szabvány, így megfelelőségi vélelmet nem keletkeztet.
- Mi a szolgáltató kötelezettségeinek teljes listája magas kockázatú AI-rendszernél?A 16. cikk tizenkét pontban sorolja fel őket, két rétegben. A termék-réteg a 8–15. cikk: kockázatkezelés, adatkormányzás, műszaki dokumentáció, naplózás, átláthatóság, emberi felügyelet, pontosság és kiberbiztonság. A szervezeti réteg a 17–21., 43. és 47–49. cikk: minőségirányítás, dokumentumőrzés tíz évig, megfelelőségértékelés, EU-megfelelőségi nyilatkozat, CE-jelölés és regisztráció.