Manage and monitor all compliance controls
Maintain documented RM program for each high-risk AI system.
Update RM when training data/model/process changes.
Maintain documented dataset lineage & quality criteria.
Perform documented bias/equality assessment on training data.
Maintain Annex IV-aligned technical documentation bundle.
Capture and retain automatic logs of AI system events & outcomes.
Define human-in-loop review steps & escalation for high-risk AI.
Implement secure-by-design & threat-model for high-risk AI.
Collect post-market incidents & performance monitoring reports.
Ensure AI system registered in EU database before placing on market.
Provide SBOM for all compiled binaries & 3rd-party libs.
Maintain documented coordinated vuln-disclosure & patch process.
Continuously monitor SBOM for new disclosed vulns.
Provide cyber-related labeling incl. update/patch procedures.
Maintain structured threat-model & mitigation tracking.