“A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems.”Parlamentul European și Consiliul Uniunii Europene · Regulamentul (UE) 2024/1689 de stabilire a unor norme armonizate privind inteligența artificială · 2024 · Regulamentul (UE) 2024/1689 (regulamentul privind inteligența artificială), art. 9 alin. (1) — sistemul de management al riscurilor
The harmonized structure allows one management system with two risk registers, not two parallel systems.
Regulation (EU) 2024/1689 applies in tiers. The prohibited practices and the general provisions apply from 2 February 2025, the duties for general-purpose models from 2 August 2025, and the regulation's general application from 2 August 2026. For the high-risk systems of Annex III, the "digital omnibus" package deferred the obligations to 2 December 2027 — the state of play in September 2026. Article 9 requires a risk management system established, implemented, documented and maintained across the whole life cycle of the high-risk system: an iterative process, not a folder. This is where the harmonized structure of management system standards pays off. ISO/IEC 42001:2023, the standard for artificial intelligence management systems, uses the same clauses 4-10 as ISO/IEC 27001, so context, roles, internal audit and management review are run once. What is added is specific: the inventory of systems, the impact assessment on people, training data, human oversight.
Why it matters Whoever treats artificial intelligence compliance as a separate project pays twice for exactly the same management clauses.