Deployment Governance
High-Risk AI Deployment Governance
What this control does
Govern deployer use against provider instructions, input-data requirements, monitoring, human oversight and escalation.
How to implement
For deployers of high-risk AI, connect the provider's instructions to the organization's actual operating process.
- Assign a system owner and document intended use, trained overseers, required support and relevant input-data checks.
- Confirm that the deployment conditions match the instructions. Route any required data protection impact assessment to the privacy lead and use the provider information; assess a fundamental-rights impact assessment separately.
- Put monitoring, user information and escalation arrangements in place. Follow the applicable suspension or incident-notification route when a relevant risk or serious incident is identified.
- Review changes in use, personnel, data or instructions and document decisions before continuing the affected activity. Do not assume all deployers have every specialist duty; check each linked obligation's conditions.
Suggested timing and triggers
Before deployment; throughout use as applicable; on instructions, data, role or purpose changes; immediately at a relevant escalation trigger.
Evidence examples
Deployment assessment and accountable-owner approval Current provider instructions and operating procedures Oversight assignments and controlled-input checks Impact-assessment decisions and provider-information records Monitoring, notices, escalation and change records
How to check this control
Select a live deployment and walk through the instructions with its owner. Check oversight authority, relevant inputs and required notices. Trace one change or alert to a reviewed decision, including whether suspension or external escalation was considered.
Related EU AI Act obligations
Article 26(1)
Use High-Risk AI Systems in Accordance With Provider Instructions
Article 26(2)
Assign Qualified and Supported Human Oversight for High-Risk AI Use
Article 26(4)
Ensure Controlled Input Data Is Relevant and Sufficiently Representative
Article 26(5)
Monitor High-Risk AI Operation and Escalate Risks or Serious Incidents
Article 26(5), first subparagraph
Monitor High-Risk AI Operation Against Provider Instructions
Sub-obligation of Article 26(5): Monitor High-Risk AI Operation and Escalate Risks or Serious Incidents
Article 26(5), first subparagraph
Suspend High-Risk AI Use and Notify Required Parties When a Relevant Risk Is Identified
Sub-obligation of Article 26(5): Monitor High-Risk AI Operation and Escalate Risks or Serious Incidents
Article 26(9)
Use Provider Information to Support an Applicable Data Protection Impact Assessment
Article 26(11)
Inform Individuals When Annex III High-Risk AI Is Used to Make or Assist Decisions About Them