Article 9 requires a risk management system across the whole lifecycle. This is that system as a working register: 18 scenarios pre-written, scored, and tied to the article each answers to.
Delivered by email immediately after payment. Excel file, one named user.
Article 9 does not ask for a risk assessment. It asks for a system — continuous, documented, running across the entire lifecycle of a high-risk AI system, identifying risks, estimating them, evaluating them post-market, and adopting measures.
The gap between those two things is where most programmes sit. A one-off assessment produces a document. Art. 9 wants a process that keeps producing evidence.
Eighteen risk scenarios, already written. Data unrepresentative of the deployment population, historical bias reproduced from past decisions, drift after deployment, the reviewer who rubber-stamps, the deployer who silently becomes a provider under Art. 25, the vendor who will not supply Annex IV information, the serious incident with no path to Art. 73. Each carries the article it answers to and a mitigation to start from.
The first review is then a conversation about your situation rather than a blank page and a facilitator.
Scoring that means something. Likelihood × impact, where impact means impact on health, safety or fundamental rights — Art. 9(2) is not asking about your P&L. Residual risk is scored after mitigation and recorded with the name of whoever accepted it, because Art. 9(2)(d) expects exactly that.
An Annex III scope tab with the carve-outs, so the register is not filled in for a system that was never high-risk.
A dashboard that recalculates: how many risks are high, how many are still open, and how they distribute across the eight themes.
A register with no accepted residual risk has not finished its job. The file says so on the dashboard. Art. 9 anticipates that some risk remains and asks you to judge it acceptable and say so — not to reach zero.
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗A risk management system that runs across the entire lifecycle of a high-risk AI system: identifying and analysing known and foreseeable risks, estimating risks that may emerge in use, evaluating risks from post-market monitoring data, and adopting appropriate measures. It is a continuous process, not a one-off assessment.
No. Art. 9(2) is concerned with risks to health, safety and fundamental rights. Financial impact to your organisation is a legitimate thing to track, but it is not what this article is asking about.
No. Art. 9 expects residual risk to remain and asks you to judge it acceptable and communicate it. A register where nothing has been accepted has not finished the exercise.