Article 9: the risk management system
This is the spine of the high-risk regime. Almost every other requirement produces evidence that feeds into it or measures that come out of it. It is also the article most often answered with an existing enterprise risk register, which does not work, because Article 9 assesses risk to people, not risk to you.
The four steps
Article 9(2) defines the process. It is continuous and iterative, planned and run across the entire lifecycle, and requires regular systematic review and updating, not an annual assessment.
| Step | What it actually means | |
|---|---|---|
| (a) | Identify and analyse known and reasonably foreseeable risks the system can pose to health, safety or fundamental rights when used in accordance with its intended purpose | Fundamental rights is the phrase that breaks reuse of an existing register. Discrimination, privacy, dignity, effective remedy, freedom of expression, these are the risk categories, and most enterprise registers contain none of them. |
| (b) | Estimate and evaluate risks under intended purpose and under conditions of reasonably foreseeable misuse | You must model the user acting against your instructions. A CV screener used to rank rather than parse. A triage tool relied on as a diagnosis. |
| (c) | Evaluate other risks arising from the data gathered by post-market monitoring | This is the loop back from Article 72. A risk file with no post-market input is by definition incomplete once the system is live. |
| (d) | Adopt appropriate and targeted risk management measures | Targeted. Generic controls copied across a portfolio will not read as targeted to an assessor. |
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
The Article 9(5) hierarchy — in order
- Eliminate or reduce by design and development, as far as technically feasible.
- Mitigate and control risks that cannot be eliminated.
- Inform under Article 13, and where appropriate train deployers.
The most common failure
Teams reach for step 3 first, because a warning in the instructions for use costs nothing and a design change costs a quarter. Article 9(5) puts information last for exactly that reason. A risk file where the dominant treatment is “documented in the user guidance” invites the question of what was technically feasible and was not done.
Expert analysis. No enforcement decisions exist on how strictly “as far as technically feasible” will be read.
Residual risk must be judged acceptable. That judgement is a decision by a named person with a recorded rationale, not a colour on a heat map. It is also the single artefact most likely to be examined if something goes wrong.
Article 9(6) requires testing to identify the most appropriate and targeted measures, against prior defined metrics and probabilistic thresholds appropriate to the intended purpose. Article 9(8) requires explicit consideration of adverse impact on persons under 18 and, as appropriate, other vulnerable groups.
What it is not
| Your existing process | Why it does not satisfy Article 9 on its own |
|---|---|
| Enterprise risk register | Assesses risk to the organisation. Article 9 assesses risk to persons. |
| ISO/IEC 27001 risk treatment | Security risk only. No fundamental rights dimension, no foreseeable-misuse limb. |
| DPIA under GDPR Art. 35 | Overlaps usefully but is bounded by personal data processing. Article 9 covers safety and rights risks with no personal data at all. |
| ISO/IEC 23894 | Good guidance and structurally compatible. But it is guidance, not a harmonised standard — no Article 40 presumption. Standards status → |
| ISO/IEC 42001 clause 6.1 + Annex A | Gives the management system that houses Article 9. Does not produce the per-system risk file. Mapping → |
Status labels on this page
Verified fact: The four process steps, the 9(5) hierarchy, the testing requirement, and the under-18 provision.
Expert analysis: The claim that a warning-led treatment profile invites challenge, and the comparison table above.
Unsettled: How strictly ‘technically feasible’ and ‘acceptable residual risk’ will be interpreted. No enforcement decisions exist.
The risk file is the deliverable
Article 9 is assessed on what you can produce: a per-system risk file with identified risks, foreseeable misuse, treatment measures in hierarchy order, test results against defined metrics, and a named acceptance of residual risk.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Questions
What does Article 9 of the EU AI Act require?
Article 9 requires providers of high-risk AI systems to establish, implement, document and maintain a risk management system as a continuous iterative process planned and run throughout the entire lifecycle of the system, requiring regular systematic review and updating. It comprises identification and analysis of known and reasonably foreseeable risks to health, safety and fundamental rights; estimation and evaluation of risks emerging under intended use and under reasonably foreseeable misuse; evaluation of risks emerging from post-market monitoring data; and adoption of appropriate and targeted risk management measures.
Is an ISO 31000 or ISO 23894 risk process enough for Article 9?
Not on its own. Article 9 differs from generic enterprise risk management in three ways: the risks assessed are risks to health, safety and fundamental rights of persons rather than risks to the organisation; the assessment must cover reasonably foreseeable misuse as well as intended use; and residual risk must be judged acceptable, with the measures applied in a prescribed order. ISO/IEC 23894 gives useful guidance on AI risk management and maps well onto the process, but conformity is assessed against Article 9, not against the standard.
What is the order of risk management measures under Article 9?
Article 9(5) sets a hierarchy. First, eliminate or reduce risks as far as technically feasible through adequate design and development. Second, where the risk cannot be eliminated, implement adequate mitigation and control measures. Third, provide information under Article 13 and, where appropriate, training to deployers. Information and training are the last resort, not the first answer.
Does Article 9 require considering children?
Yes. Article 9(8) requires that when implementing the risk management system, providers give consideration to whether, in view of its intended purpose, the high-risk AI system is likely to have an adverse impact on persons under the age of 18 and, as appropriate, other vulnerable groups.
Obligations, article by article
- Art. 5 prohibitions
- Art. 4 AI literacy
- Art. 50 transparency
- Art. 10 data governance
- Art. 11 / Annex IV
- Arts. 12–13 logging
- Art. 14 human oversight
- Art. 15 accuracy & security
- Art. 17 QMS
- Arts. 43–48 conformity
- Art. 49 registration
- Art. 57 sandboxes
- Open source
- Art. 72 monitoring
- Art. 73 incidents
- Arts. 51–56 GPAI
- Art. 99 penalties
- Compliance checklist
- FRIA template (Art. 27)
- When Annex III does not apply →