AESIA Guidelines on the AI Act – Guide No. 5: Risk Management

The Spanish Agency for the Supervision of Artificial Intelligence (AESIA) has published its fifth guideline under the Spanish AI regulatory sandbox, dedicated to risk management under Article 9 of the AI Act.
While Guides No. 3 and No. 4 address the conformity assessment procedure and the quality management system applicable to high-risk AI systems, Guide No. 5focuses on how providers should establish, implement, document and maintain a risk management system throughout the lifecycle of a high-risk AI system. The Guide is non-binding and is intended to provide practical recommendations for implementing the requirements of the AI Act. It has also been updated to reflect the amendments introduced by the Digital Omnibus.
Article 9requires providers of high-risk AI systems to establish, implement, document and maintain a risk management system. AESIA emphasises that this should not be understood as a one-off assessment carried out before the system is placed on the market. Rather, risk management is conceived as a continuous and iterative process that accompanies the system throughout its entire lifecycle and is regularly reviewed and updated.
The risk-management process consists essentially of four interconnected stages.First, providers must identify and analyse known and reasonably foreseeable risks to health, safety and fundamental rights that may arise from the intended use of the system. Secondly, they must estimate and assess risks that may arise under conditions of reasonably foreseeable misuse. Thirdly, risks identified through post-market monitoring must be incorporated into the assessment.Finally, appropriate risk-management measures must be adopted to eliminate or mitigate the risks identified. The assessment focuses on risks that can reasonably be addressed through the design and development of the system or through the provision of adequate technical information. Both individual residual risks and the overall residual risk must ultimately be assessed for acceptability.
The primary responsibility under Article 9 lies with the provider of the high-risk AI system. Article 9 does not itself impose equivalent risk-management obligations on deployers. Nevertheless, where a deployer is also involved in the development of the system, AESIA indicates that the same measures should be implemented. More generally, deployers are expected to use AI systems responsibly and ethically.
The measures required by the risk-management system may be both organisational and technical, although AESIA emphasises the importance of organisational measures.The extent and complexity of the risk-management process should be proportionate to the circumstances of the organisation, including its size,needs and resources. This does not, however, reduce the importance of fundamental-rights risks. Irrespective of the size of the provider, risk saffecting health, safety and fundamental rights must receive appropriate consideration. The principle of proportionality is therefore particularly relevant to SMEs and start-ups, which are not expected to establish risk-management structures identical to those of large organisations.
A central element of the framework is the organisation's risk appetite, understood as the level of risk that it is prepared to accept in relation to health, safety and fundamental rights. Risk appetite provides a reference point against which identified risks can be assessed and determines when mitigation measures are required. AESIA explains that the level of acceptable risk will depend significantly on the nature and criticality of the AI system. A system controlling insulin dosage, for example, would require a very low tolerance for risk, whereas a recommendation system for films, where the consequences for health, safety or fundamental rights are substantially lower, may justify a different level of tolerance.
Before identifying individual risks, providers should establish the broader context in which the AI system is designed, developed and used. This includes economic,technological, organisational and cultural factors, but also, importantly, the fundamental rights that may be affected by the system. AESIA refers in this respect to recital 28 of the AI Act, which identifies a number of rights and interests that may be particularly exposed to high-risk AI systems. These include human dignity, private and family life, data protection, freedom of expression and assembly, non-discrimination, consumer protection, workers'rights, the rights of persons with disabilities, effective judicial protection,the rights of defence, good administration, the rights of children and environmental protection.
The Guide illustrates these risks through a number of examples. Biometric identification and emotion-recognition systems may affect privacy and human dignity.Employment-related scoring systems may produce discriminatory outcomes where they fail to distinguish between different types of absence or leave.Risk-assessment systems used in criminal justice may reproduce or amplify existing forms of discrimination, as illustrated by controversies surrounding tools such as COMPAS. Automated assessment systems may also produce unequal outcomes where historical data reflects existing structural inequalities, as illustrated by the UK's 2020 A-level grading system.
Once the relevant context has been established, risk identification proceeds by examining the different components of the AI system and the ways in which vulnerabilities may arise. This may involve consideration of the training data,data sources and owners, the model, the interface and other elements of the system. Risks may result, for example, from manipulated or biased training data, insufficient protection of personal information or weaknesses in the design of the system.
Identified risks must then be analysed and assessed. AESIA recommends considering both the probability of a risk occurring and the severity of its potential impact. These elements allow the provider to determine the significance of a particular risk and compare it with the level of risk that the organisation is prepared to accept. The purpose of this assessment is not simply to identify risks, but to determine which risks require intervention and which residual risks can reasonably be accepted.
Once risk shave been assessed, providers must determine an appropriate response. Risks maybe mitigated through additional safeguards or controls; they may be accepted where the residual risk is considered sufficiently low; they may be avoided,for example by discontinuing a particular activity; or, in certain circumstances, they may be transferred, including through mechanisms such as insurance. The chosen response must be implemented in a planned and documented manner, and residual risks must remain visible within the overall risk-management process rather than being left implicit.
The risk-management system must also be documented and maintained throughout the lifecycle of the AI system. AESIA refers in particular to the technical documentation required under Annex IV of the AI Act. Risk management should also involve communication and consultation with relevant internal and external stakeholders. The system should be periodically reviewed so that new risks can be identified and existing risks reassessed as the system, its context or its use changes.
Senior management has an important role in this process. AESIA emphasises that effective AI risk management requires organisational commitment and should be integrated into the organisation's broader risk-management framework. This includes establishing an AI risk-management policy, allocating appropriatere sources and defining clear responsibilities and lines of accountability.
Article 9is also connected to the testing and monitoring of high-risk AI systems.Providers must test systems to determine whether they function as intended and comply with the applicable requirements. Testing should be based on appropriate metrics and thresholds established in advance and may take place at different stages before the system is placed on the market. Under the relevant provisions of the AI Act, testing may in certain circumstances also take place under real-world conditions. Where this occurs, specific safeguards apply, including informed consent that may be withdrawn and obligations concerning serious incidents and harm caused to participants.
Risk management does not end once the system has been placed on the market. The post-market monitoring system required under Article 72 provides an additional source of information about risks emerging from actual use. Risks identified through monitoring must feed back into the risk-management process and may require the provider to reassess existing risks or introduce additional mitigation measures. In this respect, Article 9 establishes a feedback loop between risk identification, system deployment and subsequent monitoring.
AESIA also draws particular attention to risks affecting persons under the age of 18 and other vulnerable groups. Where reasonably foreseeable, providers should assess whether their systems may be misused to generate non-consensual intimate content or child sexual abuse material and should consider whether the safeguards incorporated into the system are effective against such misuse.
The Guide further notes that providers may already be subject to risk-management obligations under other areas of EU sectoral legislation. In such cases, the Article 9 framework does not necessarily require the creation of an entirely separate system. Existing procedures may, where appropriate, incorporate the measures necessary to comply with the AI Act.
The Guide is accompanied by a series of practical annexes. These provide examples of relevant contextual factors, common components of AI systems, categories of AI-related risks and possible controls. The examples cover areas such as governance, inclusion, transparency, controllability, cybersecurity, data protection, data quality, model design and robustness. The supporting material also includes examples of indicators that may be used to assess the effectiveness of these controls, a glossary, a template AI risk-management policy, a self-assessment questionnaire and an illustrative Excel tool.
The practical examples are based on two use cases also considered in AESIA's earlier guidance: an AI system used to assess applications for financial assistance and a smart insulin pump. These examples illustrate how the same general risk-management framework can apply to very different systems, while the nature and seriousness of the risks will depend on the context in which the system operates.
The Guide also refers to emerging technical standards, including prEN 18228 and ISO/IEC23894, as potentially relevant foundations for future harmonised standards concerning AI risk management.
Taken together, AESIA's Guide No. 5 presents Article 9 as a continuous,lifecycle-based risk-management framework. Providers are expected to identify the relevant context, including the fundamental rights potentially affected;identify known and reasonably foreseeable risks, including risks arising from foreseeable misuse; assess their probability and potential impact; adopt appropriate measures to mitigate or otherwise address them; document residual risks; and continuously review the system in light of new information emerging during deployment and post-market monitoring.
For providers, the practical starting point is therefore straightforward. Define a risk appetite proportionate to the system’s criticality; map the context in which the system operates, including the fundamental rights it may affect; keep an inventory of the system’s components and the threats that could exploit them; score each identified risk by probability and impact; and choose and document a response — mitigate, accept, avoid or transfer — before the system is placed on the market or put into service. None of this needs to be built from scratch: the self-assessment questionnaire and the illustrative Excel tool that accompany the Guide walk through each of these steps for the two reference use cases, and providers already subject to risk-management obligations under other EU legislation can extend their existing procedures rather than setting up a parallel system.
Guide No. 5should not be read in isolation. The risk management system draws directly on requirements addressed in AESIA’s other technical guides — data and data governance, technical documentation, transparency and provision of information,human oversight, accuracy, robustness and cybersecurity — and its outputs feed into the conformity assessment procedure described in Guide No. 3 and the quality management system described in Guide No. 4. Providers preparing for compliance with Article 9 are advised to consult the corresponding guide for each of these related requirements as they work through the process set out here, and to treat risk management not as a document to be filed away, but as a system that is kept alive, tested and updated for as long as the AI system remains on the market.
Are you ready to transform the Data in value for your business?

