VeritomeHelp Center
/

Risk register, Art. 9 risks and review schedules

Log and score Art. 9 risks with the guided wizard, run Art. 27 FRIAs, and complete scheduled reviews that leave a tamper-evident entry in the regulator dossier.

Updated 15.07.2026

Two assessments sit at the heart of high-risk compliance: the ongoing risk management system (Art. 9) and, for certain deployers, the fundamental rights impact assessment (Art. 27). Both live off the Risk Register in the sidebar.

Article 9 — the risk-management system

For high-risk systems, Art. 9 requires a continuous, iterative process — not a one-off document. You identify and analyse the known and foreseeable risks to health, safety and fundamental rights, adopt measures to manage them, and keep the process alive across the system's life.

Open the Risk Register and read the Assessments required strip at the top: one row per system × assessment type — Art. 9 risk management, Art. 27 FRIA, and (for GPAI) Art. 55(1) model evaluation — each with a Start or Continue action. The heat-map (severity × likelihood) and the KPI row show your portfolio risk posture at a glance.

Log and score a risk

Click Add risk (or open a system's Risks tab) to launch the guided wizard, one step per screen:

  1. Describe — the hazard and who it affects.
  2. Severity — how bad the harm would be.
  3. Likelihood — how probable it is (the inherent score is severity × likelihood).
  4. Treatment — the type of control you will apply (mitigate, transfer, avoid or accept).
  5. Treatment plan — the specific measures and owners.
  6. Residual — the risk that remains after the control, which must be judged acceptable.
  7. Evidence — attach the proof that the control is real.

Because the process is iterative, you revisit the register across the system's lifetime — especially after incidents or changes. Filter the register by severity, treatment or system, and click a row to open its detail drawer.

Article 27 — the FRIA

A FRIA is a deployer duty for certain high-risk systems, done before the system is put into use. When your role and classification trigger it, Veritome surfaces the FRIA as a guided obligation. See FRIA: the fundamental-rights impact assessment, step by step for the full editor.

Review schedules

When a system is classified, Veritome generates a review schedule matched to its role and risk tier. Every system gets an annual classification review and an AI-literacy programme review; high-risk systems add more — a semi-annual log-retention check for deployers, or annual risk-management, post-market-monitoring and QMS reviews for providers. Reviews appear on the Calendar with their due dates.

Completing a review → the dossier audit entry

Open a review from the calendar, add notes recording the outcome, adjust the due date if needed, and click Mark as completed. Completing a review does three things:

  • records who completed it and when;
  • auto-creates the next occurrence (so an annual review re-schedules itself); and
  • drops an ANNUAL_REVIEW entry (status Submitted) into that system's classification dossier — a dated, attributed footprint in the chain of custody, written to the audit log.

That last step is what makes your routine reviews build their own audit trail: you can later prove not just that a review happened, but when, by whom, and in sequence with every other dossier event.

Need to act on this?Open Veritome