{
  "node_id": "eu-ai-act-risk-management-system",
  "title": "EU AI Act - Risk Management System for High-Risk AI Systems (Article 9)",
  "domain": "AI Governance & Law",
  "version": "1.0.0",
  "last_updated": "2026-04-28",
  "bluf": "EU AI Act (Regulation 2024/1689) Article 9 requires providers of high-risk AI systems to establish, implement, document, and maintain a risk management system throughout the entire lifecycle of the high-risk AI system; the Article 9 risk management system must be a continuous iterative process running throughout the AI system's lifecycle - from design through development, testing, deployment, and post-market operation; Article 9(2) - the risk management system must cover: (a) identification and analysis of the known and reasonably foreseeable risks associated with the high-risk AI system; (b) estimation and evaluation of risks that may emerge when the AI system is used in accordance with its intended purpose and under conditions of reasonably foreseeable misuse; (c) evaluation of other possibly arising risks based on analysis of post-market monitoring data; (d) adoption of appropriate and targeted risk management measures; Article 9(3) - risk management measures must give due consideration to the effects and possible interaction of the measures implemented to minimise cumulative side effects; Article 9(4) - providers must implement testing to identify the most appropriate risk management measures; testing must be performed against predefined metrics and probabilistic thresholds appropriate to the intended purpose; Article 9(5) - the risk management system must specifically consider the risks to health, safety, and fundamental rights of persons who may be particularly vulnerable due to age, disability, or social/economic situation; Article 9(6) - providers must adopt measures to ensure adequate levels of accuracy, robustness, and cybersecurity and minimise risks arising from inaccuracies; the Article 9 risk management system documentation feeds directly into the technical documentation under Article 11 and Annex IV and is reviewed as part of conformity assessment under Article 43.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
    "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-risk-management-system.json"
  },
  "crosswalks": {
    "_available_keys": [
      "gdpr",
      "iso_27001",
      "nist_csf"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "eu-ai-act-2024",
    "eu-ai-act-article-3-definitions",
    "eu-ai-act-article-113-entry-into-force-application",
    "eu-ai-act-provider-obligations-high-risk",
    "eu-ai-act-technical-documentation-requirements",
    "eu-ai-act-conformity-assessment-procedure",
    "eu-ai-act-post-market-surveillance-monitoring"
  ],
  "primary_citations_count": 5
}