Build a board-ready risk heatmap in minutes — free, no account required

Open tool

Post-Market Monitoring

High-Risk AI Post-Market Monitoring

What this control does

Operate a proportionate lifecycle post-market monitoring system and plan for high-risk AI.

How to implement

For high-risk AI providers, connect post-market monitoring to the technical file and risk process.

  1. Define the monitoring plan, responsible owner, data sources and review arrangements for the system's lifetime.
  2. Collect and analyze relevant performance information, deployer feedback, incidents and other data needed to evaluate continuing compliance. Include relevant interactions with other AI systems.
  3. Set practical escalation criteria, assign owners to findings and connect them to risk reassessment, investigation or corrective action.
  4. Review the plan as the system and operating conditions change, retaining evidence of decisions and follow-up. Do not include sensitive operational data of law-enforcement deployers in this collection. Assess any permitted integration with existing sectoral monitoring rather than assuming it removes the AI-specific work.

Suggested timing and triggers

Active monitoring throughout the system lifetime; systematic analysis at defined intervals; immediate escalation where a finding triggers another duty.

Evidence examples

Approved monitoring plan linked to the technical file Data-source, metric and responsibility records Performance analysis and deployer feedback Escalation decisions and linked corrective actions Plan updates and follow-up effectiveness reviews

How to check this control

Select a monitoring period and trace a significant finding into the risk assessment or corrective-action process. Check that the planned data was actually collected and reviewed, and that a closed issue was reassessed where needed.

Recognized by G2 as a Leader

Trusted by customers and rated highly across all categories

High-Risk AI Post-Market Monitoring | EU AI Act Suggested Control | Tracker Networks