How should teams operate post-market monitoring evidence under ISO/IEC 42001?
For AIMS , define each question, measure, method, data source, population, system version, period, owner, review cadence, and threshold before collecting results. Monitor AIMS performance and control effectiveness as well as relevant system behaviour and impacts. Route each threshold to a named action such as risk or impact reassessment, incident handling, supplier escalation, correction, restricted use, rollback, or retirement.
Choose measures that fit the task and consequence. Examples include false-positive and false-negative rates for classification, unresolved-task rates for an assistant, unsafe tool executions for an agent, performance across relevant groups, complaint trends, override timeliness, data or concept drift, and supplier-service changes. A single global accuracy score can hide the error type, population, or operating condition that matters.
If the organisation is an EU AI Act provider of a high-risk AI system, Article 72 separately requires a documented system proportionate to the technology and risks. It must actively and systematically collect, document, and analyse relevant performance data throughout the system's lifetime and support evaluation of continuing compliance. The plan belongs in the technical documentation and can use relevant deployer data or other sources. Existing sector systems can incorporate the required elements in the cases and conditions stated in Article 72(4).
Article 73 reporting for a is a separate process. Providers report to the market-surveillance authority where the incident occurred immediately after establishing a causal link or reasonable likelihood and no later than 15 days after awareness. The outside limit is two days for a widespread infringement or serious irreversible critical-infrastructure disruption and 10 days after awareness when a death is involved and causation is established or suspected. An incomplete initial report may be followed by a complete report when needed for timeliness.
- Monitor intended outcomes, production performance, impacts, risks, data or concept drift, and control effectiveness.
- Use complaints, adverse-impact reports, incidents, event logs, overrides, supplier notices, changes, and customer or deployer information where relevant and lawful.
- Separate a metric threshold from the action threshold: define when to investigate, when to correct, and when to suspend or retire.
- Route thresholds to named risk, incident, supplier, corrective-action, rollback, and suspension authorities.
ISO/IEC 42001:2023 Clauses 8.1 and 9.1 require monitoring of control effectiveness and AIMS performance; Annex A.6.2.6 and B.6.2.6 address ongoing system operation, performance monitoring, repairs, updates, support, and drift.
Article 72 is the binding source for provider post-market monitoring of high-risk AI systems and the required plan; Article 73 separately governs serious-incident reporting.