Risk Management & Fundamental-Rights Impact Assessment

AI Center › Risk Management & Fundamental-Rights Impact Assessment

Global · The AI Lifecycle — Stage 7 of 14

Risk Management & Fundamental-Rights Impact Assessment

Stage 7 of 14 in The AI Lifecycle. Once a system is classified high-risk, Article 9 of the EU AI Act requires a continuous risk-management system across its lifecycle, and Article 27 requires certain deployers to assess its impact on fundamental rights before use.

This stage sets out the risk-management system of Regulation (EU) 2024/1689 (Articles 9 and 60) and the fundamental-rights impact assessment of Article 27, read against the GDPR data protection impact assessment (Regulation (EU) 2016/679, Article 35), and situates them alongside guidance in ISO/IEC 23894:2023, ISO/IEC 42005:2025 and the MANAGE function of the NIST AI Risk Management Framework (NIST AI 100-1). Applicability follows Article 113 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744: the Chapter III requirements set out here apply from 2 December 2027 for systems high-risk under Article 6(2) and Annex III, and from 2 August 2028 for systems high-risk under Article 6(1) and Annex I.

What risk-management system does Article 9 of the EU AI Act require for a high-risk AI system?

Article 9(1) requires a risk-management system to be established, implemented, documented and maintained in relation to a high-risk AI system. Article 9(2) frames it as a continuous iterative process planned and run throughout the entire lifecycle, subject to regular systematic review and updating.

The obligation falls on the provider of the high-risk system. Article 9(2) states the system is "a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, requiring regular systematic review and updating." Article 9(3) confines the system to risks "which may be reasonably mitigated or eliminated through the development or design of the high-risk AI system, or the provision of adequate technical information" — it does not extend to risks outside the provider's design control. Article 9(10) permits providers already subject to internal risk-management obligations under other Union law to combine the Article 9 aspects with those existing procedures. The requirement sits in Chapter III, Section 2 of Regulation (EU) 2024/1689. Under Article 113 of that Regulation, as amended by Regulation (EU) 2026/1744, it applies from 2 December 2027 for systems high-risk under Article 6(2) and Annex III, and from 2 August 2028 for systems high-risk under Article 6(1) and Annex I.

Source: EU AI Act, Art. 9 — Regulation (EU) 2024/1689 ↗

What are the four steps of the Article 9(2) risk-management process?

Article 9(2) sets out four steps that the continuous iterative process must comprise, running from risk identification through the adoption of risk-management measures.

Step (Art. 9(2)) What the Regulation requires
(a) Identification and analysis Identification and analysis of the known and the reasonably foreseeable risks the high-risk AI system can pose to health, safety or fundamental rights when used in accordance with its intended purpose.
(b) Estimation and evaluation Estimation and evaluation of the risks that may emerge when the system is used in accordance with its intended purpose, and under conditions of reasonably foreseeable misuse.
(c) Evaluation of other risks Evaluation of other risks possibly arising, based on the analysis of data gathered from the post-market monitoring system referred to in Article 72.
(d) Risk-management measures Adoption of appropriate and targeted risk-management measures designed to address the risks identified pursuant to point (a).

What residual-risk rule and hierarchy of measures does Article 9(5) impose?

Article 9(5) requires that the residual risk associated with each hazard, and the overall residual risk of the high-risk system, be judged acceptable. It fixes a sequence for selecting the most appropriate measures.

Under Article 9(5) the measures adopted under Article 9(2)(d) must ensure, in order: (a) elimination or reduction of identified risks as far as technically feasible through adequate design and development; (b) where appropriate, adequate mitigation and control measures addressing risks that cannot be eliminated; and (c) provision of the information required under Article 13 and, where appropriate, training to deployers. In selecting measures, due consideration is given to the technical knowledge, experience, education and training to be expected of the deployer and the presumable context of intended use. Article 9(9) additionally requires providers to consider whether, in view of its intended purpose, the system is likely to have an adverse impact on persons under the age of 18 and, as appropriate, other vulnerable groups. The Regulation does not define a numeric acceptability level; it states the residual risk must be "judged to be acceptable."

Source: EU AI Act, Art. 9(5) — Regulation (EU) 2024/1689 ↗

What testing does Article 9 require, and how does it connect to real-world testing?

Article 9(6) requires high-risk systems to be tested to identify the most appropriate risk-management measures and to confirm consistent performance for the intended purpose. Article 9(8) requires testing against prior-defined metrics and probabilistic thresholds, and Article 9(7) allows testing in real-world conditions under Article 60.

Article 9(8) provides that testing is carried out, as appropriate, at any time throughout development and, in any event, prior to placing on the market or putting into service, "against prior defined metrics and probabilistic thresholds that are appropriate to the intended purpose." Article 9(7) states that testing procedures may include testing in real-world conditions in accordance with Article 60. Article 60 governs testing of Annex III high-risk systems in real-world conditions outside AI regulatory sandboxes: it is conducted by providers or prospective providers under a real-world testing plan whose detailed elements the Commission specifies by implementing acts, subject to the conditions in Article 60 and without prejudice to the prohibitions in Article 5. Article 3(57) defines this testing as temporary, outside a laboratory or simulated environment, and clarifies it does not qualify as placing on the market or putting into service.

Source: EU AI Act, Arts. 9(6)–(8), 60 — Regulation (EU) 2024/1689 ↗

What is a fundamental-rights impact assessment and which deployers must perform one?

Article 27(1) requires certain deployers, prior to deploying an Article 6(2) high-risk system, to perform an assessment of the impact on fundamental rights that its use may produce.

The duty applies to deployers that are bodies governed by public law, or private entities providing public services, and to deployers of the high-risk systems referred to in Annex III points 5(b) and 5(c). Annex III point 5(b) covers AI systems used to evaluate the creditworthiness of natural persons or establish their credit score (excluding systems used to detect financial fraud); point 5(c) covers AI systems used for risk assessment and pricing in relation to natural persons in life and health insurance. Systems intended to be used in the area listed in Annex III point 2 (critical infrastructure) are expressly excepted from the Article 27(1) obligation. Article 27(2) ties the obligation to the first use of the system and allows a deployer, in similar cases, to rely on previously conducted fundamental-rights impact assessments or on existing impact assessments carried out by the provider, with a duty to update where any element has changed or is no longer up to date.

Source: EU AI Act, Art. 27(1) — Regulation (EU) 2024/1689 ↗

What must a fundamental-rights impact assessment contain under Article 27(1)?

Article 27(1)(a)–(f) sets out six elements the assessment must contain, from a description of the deployer's processes through the measures to take if identified risks materialise.

The assessment consists of: (a) a description of the deployer's processes in which the high-risk system will be used in line with its intended purpose; (b) a description of the period of time within which, and the frequency with which, each system is intended to be used; (c) the categories of natural persons and groups likely to be affected by its use in the specific context; (d) the specific risks of harm likely to affect those categories, taking into account the information given by the provider under Article 13; (e) a description of the implementation of human-oversight measures, according to the instructions for use; and (f) the measures to be taken in the case of the materialisation of those risks, including the arrangements for internal governance and complaint mechanisms. The assessment draws on the provider-supplied information under Article 13 for point (d) and on the human-oversight arrangements addressed under Article 14 for point (e).

Source: EU AI Act, Art. 27(1)(a)–(f) — Regulation (EU) 2024/1689 ↗

When must the assessment be performed and to whom are its results notified?

Article 27(2) attaches the obligation to the first use of the system, with reliance on prior assessments permitted in similar cases and updates required on change. Article 27(3) requires the deployer to notify the market surveillance authority of the results, submitting the standardised questionnaire developed by the AI Office.

Under Article 27(3), once the assessment has been performed the deployer notifies the market surveillance authority of its results, submitting the filled-out questionnaire referred to in Article 27(5) as part of the notification; in the case referred to in Article 46(1), deployers may be exempt from that notification obligation. Article 27(5) tasks the AI Office with developing a standardised questionnaire, including through an automated tool, to facilitate deployers in complying in a simplified manner. Article 27(2) permits a deployer, in similar cases, to rely on previously conducted fundamental-rights impact assessments or existing provider assessments, and requires the deployer to take the necessary steps to update the information where, during use, any of the Article 27(1) elements has changed or is no longer up to date. Article 27 sits in Chapter III, Section 3, and under Article 113 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744, it applies from 2 December 2027, the date set for systems high-risk under Article 6(2) and Annex III.

Source: EU AI Act, Art. 27(2)–(3), (5) — Regulation (EU) 2024/1689 ↗

How does the fundamental-rights impact assessment relate to the GDPR data protection impact assessment?

Article 27(4) provides that where any Article 27 obligation is already met through a data protection impact assessment under Article 35 of the GDPR (or Article 27 of Directive (EU) 2016/680), the fundamental-rights impact assessment complements that data protection impact assessment rather than replacing it.

GDPR Article 35(1) requires a controller to carry out a data protection impact assessment, prior to processing, where a type of processing — in particular using new technologies, and taking into account the nature, scope, context and purposes — is likely to result in a high risk to the rights and freedoms of natural persons. Article 35(3) requires one in particular for a systematic and extensive automated evaluation of personal aspects, including profiling, on which decisions producing legal or similarly significant effects are based; for large-scale processing of special-category data; and for systematic large-scale monitoring of a publicly accessible area. Where such an assessment already discharges part of the Article 27 duty, Article 27(4) states the fundamental-rights impact assessment complements it — the two remain distinct instruments addressing, respectively, data-protection risk and the broader fundamental-rights impact.

Source: GDPR, Art. 35 — Regulation (EU) 2016/679 ↗

What does ISO/IEC 23894:2023 provide on AI risk management?

ISO/IEC 23894:2023 gives guidance on how organizations that develop, produce, deploy or use AI-based products, systems and services can manage AI-specific risk, and on integrating risk management into their AI-related activities and functions.

Paraphrasing the standard's Clause 1 (Scope): it addresses risk management specifically related to AI and describes processes for its effective implementation and integration. The document is written to be used in connection with ISO 31000:2018, and its Principles, Framework and Process clauses follow the ISO 31000 structure, extending that guidance where AI raises distinct considerations. Informative annexes support application — one annex sets out common AI-related objectives, another lists common AI-related risk sources, and a further annex gives a mapping example. ISO/IEC 23894 is a voluntary guidance standard; it has not been cited in the Official Journal of the European Union as a harmonised standard under the AI Act, and therefore does not confer the Article 40 presumption of conformity. The full normative text is available through the ISO Online Browsing Platform.

Source: ISO/IEC 23894:2023, Information technology — Artificial intelligence — Guidance on risk management ↗

What does ISO/IEC 42005:2025 provide on AI system impact assessment?

ISO/IEC 42005:2025 gives guidance for organizations performing AI system impact assessments — how an AI system and its reasonably foreseeable uses may affect individuals, groups of individuals and society — and how to document those assessments across the lifecycle.

Paraphrasing the standard's structure: Clause 5 addresses developing and implementing an AI system impact assessment process, with subclauses on documenting the process, integration with other organizational management processes, timing, scope, allocation of responsibilities, thresholds for sensitive and restricted uses, performing and analysing the assessment, recording and reporting, an approval process, and monitoring and review. Clause 6 addresses documenting the AI system impact assessment itself. Informative annexes provide a harms-and-benefits taxonomy, guidance on aligning the assessment with other assessments, and a worked example for documenting the assessment. The standard is positioned as a companion to ISO/IEC 42001:2023 on AI management systems. Like ISO/IEC 23894, it is voluntary guidance and has not been cited as a harmonised standard under the AI Act. The full text is available through the ISO Online Browsing Platform.

Source: ISO/IEC 42005:2025, Information technology — Artificial intelligence (AI) — AI system impact assessment ↗

What does the MANAGE function of the NIST AI Risk Management Framework require?

In NIST AI 100-1, the MANAGE function allocates risk resources to the risks mapped and measured earlier, on a regular basis and as defined by the GOVERN function. Its four categories cover prioritising and responding to risks, planning benefit-and-impact strategies, managing third-party risk, and documenting and monitoring risk treatments.

The framework describes MANAGE as entailing the allocation of risk resources to mapped and measured risks, where risk treatment comprises plans to respond to, recover from and communicate about incidents or events. MANAGE 1 requires that risks based on MAP and MEASURE outputs be prioritised, responded to and managed, including a determination whether development or deployment should proceed (1.1), prioritisation of treatment based on impact, likelihood and available resources (1.2), and documentation of negative residual risks defined as the sum of all unmitigated risks (1.4). MANAGE 2 addresses strategies to maximise benefits and minimise negative impacts; MANAGE 3 addresses risks and benefits from third-party entities; and MANAGE 4 requires that risk treatments, including response, recovery and communication plans, be documented and monitored regularly, with post-deployment monitoring plans implemented (4.1). The AI RMF is a voluntary framework and does not impose binding legal obligations.

Source: NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (January 2023) ↗

From when do the Article 9 and Article 27 obligations apply?

The general application date under Article 113 of Regulation (EU) 2024/1689 is 2 August 2026, but as amended by Regulation (EU) 2026/1744 that Article sets the application of Articles 9 and 27 at 2 December 2027 for systems high-risk under Article 6(2) and Annex III, and at 2 August 2028 for systems high-risk under Article 6(1) and Annex I. No harmonised standards for the AI Act have yet been cited in the Official Journal.

Article 113 provides that the Regulation applies from 2 August 2026, with earlier dates for Chapters I and II, which have applied since 2 February 2025, and for Chapter III Section 4, Chapters V, VII and XII and Article 78, which have applied since 2 August 2025. Article 9 sits in Chapter III, Section 2 and Article 27 in Chapter III, Section 3, and Article 113 as amended by Regulation (EU) 2026/1744 sets their application at 2 December 2027 for systems high-risk under Article 6(2) and Annex III, and at 2 August 2028 for systems high-risk under Article 6(1) and Annex I. That amendment was made by Regulation (EU) 2026/1744, published in the Official Journal of 24 July 2026 (OJ L 2026/1744) and in force since 27 July 2026, which replaces points (a) and (c) of the third paragraph of Article 113 and adds a new point (d). It defers Chapter III Sections 1, 2 and 3 — Articles 6 to 27, with the exception of Article 6(5) — while Chapter III Section 5 (Articles 40 to 49, on standards, conformity assessment, certificates and registration), Article 6(5), Article 50 and Chapter IX are not deferred and apply from 2 August 2026. As of 31 July 2026 no harmonised standard had been cited (EN 18286 being the first candidate, approved by CEN and CENELEC in June 2026 but not cited in the Official Journal), so the Article 40 presumption of conformity rests on no cited standards yet; ISO/IEC 23894 and ISO/IEC 42005 are not harmonised standards.

Source: EU AI Act, Art. 113 — Regulation (EU) 2024/1689 ↗

Terms defined at this stage

Risk-management system (Art. 9)
The system, established, implemented, documented and maintained for a high-risk AI system, understood under Article 9(2) as a continuous iterative process planned and run throughout the entire lifecycle and requiring regular systematic review and updating; it comprises risk identification and analysis, estimation and evaluation, evaluation of post-market data, and the adoption of risk-management measures.
Residual risk
The risk remaining after risk-management measures have been applied; under Article 9(5) the residual risk associated with each hazard, as well as the overall residual risk of the high-risk system, must be judged to be acceptable.
Testing in real-world conditions
The temporary testing of an AI system for its intended purpose in real-world conditions outside a laboratory or otherwise simulated environment, with a view to gathering reliable and robust data and to assessing and verifying conformity; Article 3(57) states it does not qualify as placing on the market or putting into service, and Article 60 governs its conduct.
Market surveillance authority
The national authority carrying out the activities and taking the measures pursuant to Regulation (EU) 2019/1020; under Article 27(3) deployers notify it of the results of a fundamental-rights impact assessment using the standardised questionnaire developed by the AI Office.
MANAGE function
One of the four core functions of the NIST AI Risk Management Framework; it allocates risk resources to mapped and measured risks on a regular basis and as defined by the GOVERN function, covering the prioritisation and treatment of risks, third-party risk, and the documentation and regular monitoring of risk treatments.
Risk source
Paraphrasing ISO/IEC 23894 (used in connection with ISO 31000:2018): an element that, alone or in combination with others, has the potential to give rise to risk; the standard provides common AI-related risk sources in an informative annex to support their identification.

Cite this page

1BusinessWorld AI Center, "Risk Management & Fundamental-Rights Impact Assessment — The AI Lifecycle." https://1businessworld.com/ai-center/risk-management-and-fundamental-rights/ Version as of July 26, 2026.

The AI Center is informational only. It is provided by 1BusinessWorld strictly for general informational and educational purposes. Nothing in the AI Center constitutes, or should be construed as, legal, regulatory, compliance, technical, engineering, security, investment, financial, or other professional advice, or a recommendation, endorsement, solicitation, or offer regarding any technology, product, model, provider, framework, or course of action. 1BusinessWorld is not a law firm, regulatory authority, standards body, conformity-assessment or certification body, or investment adviser, and nothing in the AI Center creates any advisory, fiduciary, attorney-client, or other professional relationship with 1BusinessWorld. Although the AI Center references official materials published by legislatures, regulators, standards bodies, research organizations, and other named authorities, 1BusinessWorld makes no representation or warranty, express or implied, as to the accuracy, completeness, timeliness, or fitness for any purpose of any content, and, to the fullest extent permitted by law, disclaims all liability for any loss or damage of any kind arising directly or indirectly from the use of, or reliance on, any information presented. Laws, regulations, standards, technical practices, and AI capabilities change frequently and differ by jurisdiction; readers must verify all information against the current official text or source and consult qualified legal, compliance, technical, and other professional advisors before acting. Any decision relating to the development, deployment, procurement, or governance of AI systems is made solely at the reader's own risk. Last reviewed: July 26, 2026.