Annex IV §8 (Article 72 plan)

Annex IV §8 — Post-Market Monitoring Plan (EU AI Act)

How to document the Article 72 post-market monitoring plan in Annex IV §8 of Regulation (EU) 2024/1689. Performance review cadence, drift, complaints, and incident triage.

Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review

What §8 actually requires

Annex IV §8 of Regulation (EU) 2024/1689 requires:

"A detailed description of the system in place to evaluate the AI system performance in the post-market phase in accordance with Article 72, including the post-market monitoring plan referred to in Article 72(3)."

Article 72(3) requires the Commission to adopt, by 2 August 2026, an implementing act laying down the template for the post-market monitoring plan. Use the template if it has been published; until then, structure the plan as below.

What to include

  • Performance review cadence. At minimum monthly aggregate review for high-risk systems with active deployments. Quarterly drift report. Annual re-assessment of the Article 9 risk register.
  • Drift indicators. Specific metrics monitored (input distribution shift, output distribution shift, accuracy decay) with alert thresholds.
  • Complaint channel. How affected persons reach the provider; SLA for response.
  • Deployer feedback channel. How deployers report incidents under Article 26(5); SLA for triage.
  • Incident triage tied to Article 79. Severity-classification decision tree; 72h/10d/15d reporting windows under Article 73.
  • Feedback loop into §4 risk management. Article 9(2)(c) requires post-market data to feed the register.
  • Feedback loop into §5 lifecycle changes. Identified issues that lead to retrains or fixes are entered in §5.
  • Reports to authorities. Cadence and content of any periodic reports the provider sends to market surveillance authorities (where required for the specific system class).

A worked structure

A post-market monitoring plan typically runs 3–5 pages and contains:

  1. Scope and accountabilities (named owner; named on-call rotation).
  2. Performance metrics and thresholds.
  3. Drift detection (statistical methodology + tooling).
  4. Complaint channel + SLA.
  5. Deployer feedback channel + SLA.
  6. Incident triage and Article 79 escalation.
  7. Reporting cadence to provider's Article 9 register and (where required) to authorities.
  8. Annual review of the plan itself.

Inline crosswalk

  • ISO/IEC 42001:2023 Clause 9.1 — Monitoring, measurement, analysis and evaluation.
  • ISO/IEC 42001:2023 Annex A.6.2.8 — Operation and monitoring of AI systems.
  • NIST AI RMF MEASURE 4.1 — Identified risks tracked over time.
  • NIST AI RMF MANAGE 4.1 — Post-deployment monitoring plans implemented.

Common mistakes

  • §8 entry referring to a non-existent monitoring system.
  • No SLA on the complaint channel.
  • No 24/7 on-call to handle 72-hour incident reporting.
  • No feedback loop into §4 / §5.

Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.

Reference checklist

From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.

  • Article 72 · Starter tier · medium

    Establish post-market monitoring plan

    Collect and analyse data on system performance after deployment. Feeds into your Article 9 risk review.

  • Article 73 · Starter tier · low

    Prepare serious incident reporting process

    Report within 15 days to the market surveillance authority (72h for severe cases involving death or serious harm).

  • Article 79 · Pro tier · medium

    Internal severity-classification procedure for AI incidents

    Article 3(49) defines "serious incident" tiers. Your internal triage decides 72-hour vs 15-day reporting windows — write the decision tree down.

ISO 42001 + NIST AI RMF crosswalk

Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.

ISO/IEC 42001:2023

Checklist itemISO 42001 controlRationale
art72-monitoringISO/IEC 42001:2023 Clause 9.1 — Monitoring, measurement, analysis and evaluationArticle 72 post-market monitoring delivers operational evidence required by Clause 9.1.
art72-monitoringISO/IEC 42001:2023 Annex A.6.2.8 — Operation and monitoring of AI systemsContinuous post-market monitoring is the lifecycle-control objective in Annex A.6.2.8.
art73-incidentISO/IEC 42001:2023 Clause 10.2 — Nonconformity and corrective actionA serious-incident reporting workflow is the corrective-action loop demanded by Clause 10.2.
art79-severity-classificationISO/IEC 42001:2023 Clause 10.2 — Nonconformity and corrective actionA documented severity-classification triage tree is the nonconformity decision-process required by Clause 10.2.

NIST AI RMF 1.0

Checklist itemNIST AI RMF subcategoryRationale
art72-monitoringNIST AI RMF MEASURE 4.1 — Approaches and metrics for measurement of AI risks are followed; identified risks are tracked over timePost-market monitoring is the over-time risk-tracking method MEASURE 4.1 requires.
art72-monitoringNIST AI RMF MANAGE 4.1 — Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI ActorsThe Article 72 plan is the literal post-deployment monitoring plan demanded by MANAGE 4.1.
art73-incidentNIST AI RMF MANAGE 4.3 — Incidents and errors are communicated to relevant AI Actors, including affected communitiesArticle 73 serious-incident reporting to authorities is the communication channel MANAGE 4.3 specifies.
art79-severity-classificationNIST AI RMF MANAGE 2.3 — Procedures are followed to respond to and recover from a previously unknown risk when it is identifiedA documented severity triage tree is the structured response/recover procedure MANAGE 2.3 expects.

Pro feature

Generate Article 11 with AI

LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.

Pro template

Download FRIA template

15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.

Get the 30-item EU AI Act compliance checklist

Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.


Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.