Annex IV §4
Annex IV §4 — Risk Management System Description (EU AI Act)
Annex IV §4 of Regulation (EU) 2024/1689 requires a description of the Article 9 risk management system in the technical file. Structure, evidence, and what regulators expect.
Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Hand-edited 2026-04-28
What Annex IV §4 actually requires
Annex IV §4 of Regulation (EU) 2024/1689 requires the technical documentation to include:
"A detailed description of the risk management system in accordance with Article 9."
That's it — one line. The work sits behind it: the Article 9 system itself, which is a continuous, iterative process running across the system's lifecycle.
The Annex IV §4 entry is a description of the system, not the full risk register. The register is a referenced artefact that a competent authority can request under Article 21. But the description in the technical file must be detailed enough that a market surveillance officer can understand the methodology, the cadence, the ownership and the integration with other Article 11 sections without leaving Annex IV §4.
Who is covered
Annex IV §4 applies to providers of high-risk AI systems. Deployers under Article 25 (substantial modification, brand-on-it, intended-purpose change) inherit the obligation for the modified variant.
SMEs filing under Article 11(1) second subparagraph (simplified form) still owe an Annex IV §4 description, but compressed. The simplified-form template is a Commission draft as of mid-2026; until it lands, SMEs should target one well-structured page covering the methodology, the cadence and the ownership.
What to include in Annex IV §4
A defensible Annex IV §4 description, in our experience, has six paragraphs:
- Methodology. What risk-assessment framework you use (qualitative, quantitative, hybrid; ISO/IEC 23894 alignment; severity × likelihood matrix or another scheme). Two paragraphs maximum.
- Risk identification scope. The categories you cover: health and safety risks, fundamental-rights risks, discrimination risks, foreseeable-misuse risks, vulnerable-group risks (Article 9(9)). Reference the actual risk taxonomy you maintain.
- Mitigation hierarchy. State explicitly: design fix → guardrail → operational control → instructions for use. This signals you've internalised Article 9(5).
- Review cadence. Who reviews, how often, with what trigger. Real cadences: quarterly for high-priority risks, annual for low-priority, ad-hoc on incident under Article 79. Name the accountable person or role.
- Integration points. How Article 9 feeds into and is fed by:
- Annex IV §3 (human oversight) — risks identified here drive oversight measures. - Annex IV §8 / Article 72 (post-market monitoring) — operational data updates the register. - Article 79 (serious incidents) — incidents trigger register updates and possible re-classification. - Annex IV §5 (lifecycle changes) — material changes trigger re-assessment.
- Reference to the live register. State where the register lives, the version-control identifier, and how a regulator can access it on request.
A worked paragraph
For a Dutch logistics company deploying a driver-scoring high-risk system:
"Risk management runs as a continuous process under our internal procedure RMS-2026 v1.4, anchored on a 5×5 likelihood-severity matrix and aligned with ISO/IEC 23894:2023. The Article 9 register currently holds 41 active risks across four categories: safety (driver and third-party harm), fundamental rights (employment effects, especially Article 9(9) for under-25 drivers as a vulnerable group), discrimination (sex, age, regional), and foreseeable misuse (the model being used for dismissal decisions despite the intended-purpose exclusion in §1 of this file). Mitigation follows the Article 9(5) hierarchy: design fix first (e.g., model retraining with re-balanced data), guardrails second (e.g., score capping), operational controls third (e.g., dual-reviewer for borderline scores), instructions for use last. The register is reviewed monthly by the Head of Driver Operations and quarterly by the AI Governance Committee (CTO + Compliance Director + safety officer); ad-hoc reviews are triggered by any Article 79 serious-incident report. The current register lives in our internal GRC system at GRC-RMS-DriverScore-v2.4 and is available to a competent authority on 14 days' notice under Article 21."
That paragraph, plus the cross-references to other Annex IV sections, is what Annex IV §4 should look like. It's specific. It names tools, frameworks, people and cadences. It does not paraphrase Article 9.
What regulators look at first
A market surveillance officer opening Annex IV §4 looks for:
- Whether the description is generic or system-specific. Generic is a red flag; the file gets de-prioritised toward "looks back-filled."
- Whether the cadence is realistic. "Quarterly" with no entries from the last quarter in the linked register is a non-conformity.
- Whether vulnerable groups are addressed. Article 9(9) requires it where applicable.
- Whether the integration with Article 72 is explicit. Article 9(2)(c) requires the post-market loop.
- Whether Article 79 incidents update the register. Show the link.
Inline crosswalk to ISO 42001 and NIST AI RMF
- ISO/IEC 42001:2023 Clause 6.1.2 — AI risk assessment.
- ISO/IEC 42001:2023 Clause 6.1.3 — AI risk treatment.
- NIST AI RMF GOVERN 1.1 — Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMF MANAGE 1.3 — Responses to the AI risks deemed high priority are developed, planned, and documented.
A team running ISO/IEC 23894:2023 already produces 80% of the Annex IV §4 substance. The remaining 20% is the AI-Act-specific scaffolding: the Article 9(5) mitigation hierarchy, the vulnerable-groups paragraph (Article 9(9)), and the explicit integration with Annex IV §3, §5, §8 and Article 79.
What to do
- Maintain the live register. Annex IV §4 is the abstract; without the live register it is fiction.
- Adopt a documented methodology. ISO/IEC 23894 is the cleanest reference; CEN-CENELEC JTC 21 harmonised standards are emerging in 2026.
- Bind documentation events to engineering events. Every retrain, every architectural change, every incident updates the register.
- Quarterly review minimum for high-priority risks. Document attendees and decisions.
- Cross-reference the FRIA (where applicable under Article 27) — same risks, deployer perspective.
Common mistakes
- Static description with no live register. Annex IV §4 is a description of a process; if the process doesn't run, the description is false.
- Paraphrasing Article 9 instead of describing your system. Regulators have read Article 9. They want to see your implementation.
- No vulnerable-groups paragraph where Article 9(9) applies.
- Generic mitigation hierarchy — "we will mitigate risks." State the hierarchy explicitly.
- No link to Article 72 / Article 79 — both are required integration points.
Generate Article 11 documentation with AI
Governancer Pro includes an LLM-assisted Article 11 drafting tool that pre-fills the Annex IV §4 description based on your system characteristics and risk-register snapshot. The output is a defensible v0.1 paragraph; you fill in the system-specific details.
Disclaimer. This page is a reference summary of EU AI Act Annex IV §4. It is not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text from Regulation (EU) 2024/1689.
Reference checklist
From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.
Article 9 · Starter tier · high
Establish risk management system
A continuous iterative process. Identify foreseeable risks, estimate impact, document mitigations, review at least quarterly.
Article 79 · Pro tier · medium
Internal severity-classification procedure for AI incidents
Article 3(49) defines "serious incident" tiers. Your internal triage decides 72-hour vs 15-day reporting windows — write the decision tree down.
ISO 42001 + NIST AI RMF crosswalk
Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.
ISO/IEC 42001:2023
| Checklist item | ISO 42001 control | Rationale |
|---|---|---|
art9-risk-mgmt | ISO/IEC 42001:2023 Clause 6.1.2 — AI risk assessment | A continuous Article 9 risk management process is the EU-AI-Act realisation of Clause 6.1.2 risk assessment. |
art9-risk-mgmt | ISO/IEC 42001:2023 Clause 6.1.3 — AI risk treatment | Article 9 mitigation, residual-risk recording and quarterly review provide the risk-treatment evidence required by Clause 6.1.3. |
art79-severity-classification | ISO/IEC 42001:2023 Clause 10.2 — Nonconformity and corrective action | A documented severity-classification triage tree is the nonconformity decision-process required by Clause 10.2. |
NIST AI RMF 1.0
| Checklist item | NIST AI RMF subcategory | Rationale |
|---|---|---|
art9-risk-mgmt | NIST AI RMF GOVERN 1.1 — Legal and regulatory requirements involving AI are understood, managed, and documented | EU AI Act Article 9 risk management explicitly captures the regulatory requirements GOVERN 1.1 wants documented. |
art9-risk-mgmt | NIST AI RMF MANAGE 1.3 — Responses to the AI risks deemed high priority are developed, planned, and documented | Article 9 mitigation plans for residual high-priority risks are exactly the responses MANAGE 1.3 expects. |
art79-severity-classification | NIST AI RMF MANAGE 2.3 — Procedures are followed to respond to and recover from a previously unknown risk when it is identified | A documented severity triage tree is the structured response/recover procedure MANAGE 2.3 expects. |
Related
Article 9
EU AI Act Article 9 — Risk Management System Requirements
Article 11
EU AI Act Article 11 — Technical Documentation Requirements
Annex IV §1
Annex IV §1 — General Description of the AI System (EU AI Act)
Annex IV §8 (Article 72 plan)
Annex IV §8 — Post-Market Monitoring Plan (EU AI Act)
Article 79
EU AI Act Article 79 — Procedure for AI Systems Presenting a Risk
Article 27
EU AI Act Article 27 — Fundamental Rights Impact Assessment (FRIA)
Pro feature
Generate Article 11 with AI
LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.
Pro template
Download FRIA template
15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.
Get the 30-item EU AI Act compliance checklist
Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.
Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.