Data Governance
High-Risk AI Data Governance and Bias Management
What this control does
Govern training, validation and testing data for suitability, quality, representativeness and bias management.
How to implement
Providers should apply this control to the data relevant to their high-risk AI system. Deployers should focus on input data under their control.
- Record data sources, permitted uses, preparation steps and assumptions, and assign a data owner.
- Define checks for relevance, completeness, errors and representation in the intended setting. Include the people or groups affected where relevant.
- Examine harmful bias and material gaps, document mitigation and decide whether the data is fit for use. Protect sensitive data and separately assess any Article 4a processing route.
- Reassess when datasets, populations or operating conditions change, and retain the decision history. The provider's training, validation and testing duties and the deployer's input-data duty are different. For systems not using model training, check the specific testing-data scope in Article 10(6).
Suggested timing and triggers
Before relevant data is used; throughout development and operation as appropriate; after data, population, purpose or context changes.
Evidence examples
Data-source register and preparation history Quality and representation criteria with test results Bias and gap assessments with mitigation decisions Approvals, unresolved limitations and change history Input-data checks for data controlled by a deployer
How to check this control
Sample a dataset or controlled input stream. Trace its source and preparation to the approved use, review results against the stated criteria and follow one identified bias or quality issue through remediation and recheck.
Related EU AI Act obligations
Article 10
Establish Appropriate Data Governance for High-Risk AI Systems
Article 10(1)-(2)
Establish Data Governance and Management Practices for High-Risk AI Data Sets
Sub-obligation of Article 10: Establish Appropriate Data Governance for High-Risk AI Systems
Article 10(2)(f)-(g)
Examine, Detect, Prevent and Mitigate Bias in Relevant High-Risk AI Data
Sub-obligation of Article 10: Establish Appropriate Data Governance for High-Risk AI Systems
Article 10(3)
Ensure High-Risk AI Data Sets Are Relevant, Representative and Sufficiently Complete
Sub-obligation of Article 10: Establish Appropriate Data Governance for High-Risk AI Systems
Article 10(4)
Account for the Intended Geographic, Contextual, Behavioural and Functional Setting
Sub-obligation of Article 10: Establish Appropriate Data Governance for High-Risk AI Systems
Article 17(1)(f)
Maintain High-Risk AI Data Management Procedures
Sub-obligation of Article 17; Article 63(1)-(2): Maintain a Quality Management System for High-Risk AI
Article 26(4)
Ensure Controlled Input Data Is Relevant and Sufficiently Representative