Testing & Validation
High-Risk AI Testing and Validation
What this control does
Test high-risk AI against predefined performance and risk metrics before release and at appropriate lifecycle points.
How to implement
For a high-risk AI provider, connect testing to the intended purpose and the risks the system is meant to control.
- Set acceptance criteria and appropriate metrics before testing, including relevant thresholds and representative test conditions.
- Test normal use, foreseeable misuse and material failure scenarios at suitable development stages and before release.
- Record the system version, data, methods, results and limitations so the decision can be reviewed.
- Assign owners to failures, retest corrections and document the release or restriction decision. Use separate approval processes for real-world testing where applicable. A successful test or a benchmark result is not, by itself, evidence of compliance with every linked requirement.
Suggested timing and triggers
At appropriate development stages; before market placement or putting into service; after material changes; thereafter as defined by the quality process.
Evidence examples
Approved test plan and predefined acceptance criteria Versioned test data, environment and execution records Results against thresholds, including failures and limitations Corrective actions and retest results Release, restriction or escalation decisions
How to check this control
Choose a test that influenced release. Check that its criteria existed before execution, its environment reflects intended use and failures were not simply removed from the report. Trace one correction to a completed retest.
Related EU AI Act obligations
Article 9(6)-(8)
Test High-Risk AI Systems Against Defined Metrics and Thresholds
Sub-obligation of Article 9: Establish and Maintain a Risk Management System for High-Risk AI
Article 15(1)-(3)
Define, Validate and Declare Appropriate Accuracy Levels and Metrics
Sub-obligation of Article 15: Ensure High-Risk AI Accuracy, Robustness and Cybersecurity
Article 17(1)(b)-(d)
Control High-Risk AI Design, Development, Quality Assurance, Testing and Validation
Sub-obligation of Article 17; Article 63(1)-(2): Maintain a Quality Management System for High-Risk AI