Risk management system
A continuous, iterative process across the lifecycle identifying and evaluating reasonably foreseeable risks to health, safety and fundamental rights, and adopting targeted mitigation.
Data and data governance
Training, validation and testing sets must be relevant, sufficiently representative and to the best extent possible free of errors and complete for the intended purpose, with examination for bias and documented provenance.
Technical documentation
Prepared before placing on the market and kept current, demonstrating conformity and giving authorities the information to assess it. Annex IV sets the minimum content.
Record-keeping
Automatic logging of events over the lifetime of the system, at a level appropriate to the intended purpose, retained by the deployer for at least six months unless other law says otherwise.
Transparency to deployers
Instructions for use enabling the deployer to interpret output and use it appropriately, including characteristics, capabilities, limitations, expected accuracy and known risks.
Human oversight
Designed so it can be effectively overseen by natural persons, who can understand capacity and limits, remain alert to automation bias, interpret output correctly, decide not to use it and intervene or stop it.
Accuracy, robustness, cybersecurity
Appropriate levels across the lifecycle, resilient to errors and to attempts to alter use or performance, including protection against data poisoning, model poisoning, adversarial examples and model evasion.
Quality management system
A documented QMS covering regulatory compliance strategy, design and verification, testing, data management, post-market monitoring, incident reporting and accountability.
Registration and conformity
Annex III systems registered in the EU database before placing on the market or putting into service, with the relevant conformity assessment completed and the CE marking affixed.