Annex IV §8 (Article 72 plan)
Annex IV §8 — Post-Market Monitoring Plan (EU AI Act)
How to document the Article 72 post-market monitoring plan in Annex IV §8 of Regulation (EU) 2024/1689. Performance review cadence, drift, complaints, and incident triage.
Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review
What §8 actually requires
Annex IV §8 of Regulation (EU) 2024/1689 requires:
"A detailed description of the system in place to evaluate the AI system performance in the post-market phase in accordance with Article 72, including the post-market monitoring plan referred to in Article 72(3)."
Article 72(3) requires the Commission to adopt, by 2 August 2026, an implementing act laying down the template for the post-market monitoring plan. Use the template if it has been published; until then, structure the plan as below.
What to include
- Performance review cadence. At minimum monthly aggregate review for high-risk systems with active deployments. Quarterly drift report. Annual re-assessment of the Article 9 risk register.
- Drift indicators. Specific metrics monitored (input distribution shift, output distribution shift, accuracy decay) with alert thresholds.
- Complaint channel. How affected persons reach the provider; SLA for response.
- Deployer feedback channel. How deployers report incidents under Article 26(5); SLA for triage.
- Incident triage tied to Article 79. Severity-classification decision tree; 72h/10d/15d reporting windows under Article 73.
- Feedback loop into §4 risk management. Article 9(2)(c) requires post-market data to feed the register.
- Feedback loop into §5 lifecycle changes. Identified issues that lead to retrains or fixes are entered in §5.
- Reports to authorities. Cadence and content of any periodic reports the provider sends to market surveillance authorities (where required for the specific system class).
A worked structure
A post-market monitoring plan typically runs 3–5 pages and contains:
- Scope and accountabilities (named owner; named on-call rotation).
- Performance metrics and thresholds.
- Drift detection (statistical methodology + tooling).
- Complaint channel + SLA.
- Deployer feedback channel + SLA.
- Incident triage and Article 79 escalation.
- Reporting cadence to provider's Article 9 register and (where required) to authorities.
- Annual review of the plan itself.
Inline crosswalk
- ISO/IEC 42001:2023 Clause 9.1 — Monitoring, measurement, analysis and evaluation.
- ISO/IEC 42001:2023 Annex A.6.2.8 — Operation and monitoring of AI systems.
- NIST AI RMF MEASURE 4.1 — Identified risks tracked over time.
- NIST AI RMF MANAGE 4.1 — Post-deployment monitoring plans implemented.
Common mistakes
- §8 entry referring to a non-existent monitoring system.
- No SLA on the complaint channel.
- No 24/7 on-call to handle 72-hour incident reporting.
- No feedback loop into §4 / §5.
Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.
Reference checklist
From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.
Article 72 · Starter tier · medium
Establish post-market monitoring plan
Collect and analyse data on system performance after deployment. Feeds into your Article 9 risk review.
Article 73 · Starter tier · low
Prepare serious incident reporting process
Report within 15 days to the market surveillance authority (72h for severe cases involving death or serious harm).
Article 79 · Pro tier · medium
Internal severity-classification procedure for AI incidents
Article 3(49) defines "serious incident" tiers. Your internal triage decides 72-hour vs 15-day reporting windows — write the decision tree down.
ISO 42001 + NIST AI RMF crosswalk
Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.
ISO/IEC 42001:2023
| Checklist item | ISO 42001 control | Rationale |
|---|---|---|
art72-monitoring | ISO/IEC 42001:2023 Clause 9.1 — Monitoring, measurement, analysis and evaluation | Article 72 post-market monitoring delivers operational evidence required by Clause 9.1. |
art72-monitoring | ISO/IEC 42001:2023 Annex A.6.2.8 — Operation and monitoring of AI systems | Continuous post-market monitoring is the lifecycle-control objective in Annex A.6.2.8. |
art73-incident | ISO/IEC 42001:2023 Clause 10.2 — Nonconformity and corrective action | A serious-incident reporting workflow is the corrective-action loop demanded by Clause 10.2. |
art79-severity-classification | ISO/IEC 42001:2023 Clause 10.2 — Nonconformity and corrective action | A documented severity-classification triage tree is the nonconformity decision-process required by Clause 10.2. |
NIST AI RMF 1.0
| Checklist item | NIST AI RMF subcategory | Rationale |
|---|---|---|
art72-monitoring | NIST AI RMF MEASURE 4.1 — Approaches and metrics for measurement of AI risks are followed; identified risks are tracked over time | Post-market monitoring is the over-time risk-tracking method MEASURE 4.1 requires. |
art72-monitoring | NIST AI RMF MANAGE 4.1 — Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI Actors | The Article 72 plan is the literal post-deployment monitoring plan demanded by MANAGE 4.1. |
art73-incident | NIST AI RMF MANAGE 4.3 — Incidents and errors are communicated to relevant AI Actors, including affected communities | Article 73 serious-incident reporting to authorities is the communication channel MANAGE 4.3 specifies. |
art79-severity-classification | NIST AI RMF MANAGE 2.3 — Procedures are followed to respond to and recover from a previously unknown risk when it is identified | A documented severity triage tree is the structured response/recover procedure MANAGE 2.3 expects. |
Related
Article 79
EU AI Act Article 79 — Procedure for AI Systems Presenting a Risk
Article 9
EU AI Act Article 9 — Risk Management System Requirements
Article 11
EU AI Act Article 11 — Technical Documentation Requirements
Article 26
EU AI Act Article 26 — Deployer Obligations
Annex IV §4
Annex IV §4 — Risk Management System Description (EU AI Act)
Annex IV §5
Annex IV §5 — Lifecycle Changes Log (EU AI Act)
Pro feature
Generate Article 11 with AI
LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.
Pro template
Download FRIA template
15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.
Get the 30-item EU AI Act compliance checklist
Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.
Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.