Riaan Kleynhans
Engine öffnen

EU-KI-Verordnung · Pflichten, Kontrollen, Nachweise

Was greift, wer es verantwortet, und der Test, der darüber entscheidet

Eine Einstufung, die „hoch riskant“ sagt und dort endet, sagt nichts Umsetzbares. Dies ist die Kette darunter: jede Vorschrift als Kontrolle, verantwortet von einer Rolle, getragen von einer SOP, belegt durch benannte Nachweise und entschieden durch einen Test.

Greifende Pflichten

14

Kontrollen, die halten

0%

Geschrieben, nicht gebaut

0

Eine Richtlinie ohne technische Kontrolle ist ein Dokument.

Fehlgeschlagen oder abgelaufen

0

Eine Kontrolle, die niemand erneut geprüft hat, ist keine Kontrolle.

Provision and requirementControl and SOPOwnerEvidenceTest that decides itStatus
Article 9

A risk-management system established, implemented, documented and maintained across the lifecycle.

Risks identified, assessed and mitigated before release, and re-assessed on material change.

SOP: Assess and re-assess AI system risk

AI_RISK_LEAD
  • risk_register
  • assessment_record
  • review_date
A material change reopens the assessment before release.
Article 10

Training, validation and testing data subject to appropriate governance and quality criteria.

Data sources, lawful basis, quality checks and bias examination recorded per dataset.

SOP: Qualify a dataset for AI use

DATA_OWNER
  • data_lineage
  • lawful_basis
  • bias_examination
Every dataset in use traces to a source and a lawful basis.
Article 11

Technical documentation drawn up before placing on the market and kept up to date.

A maintained system passport with version, purpose, architecture and limitations.

SOP: Maintain the system passport

CTO
  • system_passport
  • version_history
The documentation matches the version actually deployed.
Article 12

Automatic recording of events over the lifetime of the system.

Append-only logs sufficient to reconstruct a decision, retained and readable.

SOP: Operate and retain AI event logs

CTO
  • log_sample
  • retention_policy
  • reconstruction_test
A past decision can be reconstructed from logs alone.
Article 13

Operation sufficiently transparent for deployers to interpret and use the output.

Instructions for use stating capability, limitations and required oversight.

SOP: Issue and update instructions for use

PRODUCT_OWNER
  • instructions_for_use
  • acknowledgement
A deployer can state the system's limitations from the documentation given.
Article 14

Designed to be effectively overseen by natural persons while in use.

A named qualified reviewer approves high-impact output, and can stop the system.

SOP: Review and approve high-impact AI output

AI_RISK_LEAD
  • review_record
  • approval_timestamp
  • decision_trace
A high-impact action is blocked without an approval.
Article 15

An appropriate level of accuracy, robustness and cybersecurity.

An evaluation suite with declared metrics, run on release and on change.

SOP: Run the AI evaluation suite

CTO
  • evaluation_results
  • thresholds
  • run_date
The declared metric is measured, not asserted.
Article 17

A quality-management system ensuring compliance.

Documented procedures, responsibilities and change control for AI systems.

SOP: Govern AI change

CHANGE_LEAD
  • procedure_register
  • change_log
A change reached production through the recorded route.
Article 26

Deployers use the system in accordance with the instructions and assign competent oversight.

Oversight assigned to a named competent role, with input data controlled.

SOP: Operate a high-risk AI system

JOURNEY_OWNER
  • oversight_assignment
  • competence_record
The named overseer exists, is competent and is available in operating hours.
Article 27

A fundamental-rights impact assessment, where applicable to the deployer.

Affected persons, risks to rights and mitigations recorded before use.

SOP: Assess fundamental-rights impact

DPO
  • fria_record
  • affected_persons
Affected persons are identified, not assumed.
Article 50

People are informed they are interacting with AI, and synthetic content is marked.

A disclosure notice designed, tested for visibility, and version-preserved.

SOP: Design and preserve the AI disclosure notice

PRODUCT_OWNER
  • notice_wording
  • visibility_test
  • approved_version
A user sees the notice before interacting, in the tested position.
Article 73

Serious incidents reported to the market-surveillance authority.

An incident register with a defined route, owner and reporting clock.

SOP: Detect, record and report a serious AI incident

AI_RISK_LEAD
  • incident_register
  • report_record
  • timestamps
A drill reaches the authority route inside the clock.
Article 72

A post-market monitoring system proportionate to the risk.

Drift, override rate, complaint volume and evidence expiry monitored on a cadence.

SOP: Monitor an AI system in operation

PRODUCT_OWNER
  • monitoring_plan
  • metric_history
The last monitoring run is inside the cadence.
Article 99

Information given to authorities and notified bodies is correct and complete.

No single-person unreviewed response; the submitted version is preserved verbatim.

SOP: Respond to an authority request

LEGAL
  • request_record
  • source_references
  • submitted_version
  • reviewers
Every material statement in a submission traces to a source record.

Article references follow the Regulation as commonly published and are given so a reader can find the provision. Check them against the Official Journal text before relying on them in a filing.

14 obligations in the library. Only those that attach to the selected classification and role are shown.

Stufe 4 · Govern → Stufe 5 · Prove

Dann sehen Sie es an einem echten Datenbestand laufen — jede Zeile wird im Lauf abgeleitet.