| Risk | Art. 9 | Continuous process connected to hazards, intended use, foreseeable misuse and residual risk | Replay a scenario, verify metrics and thresholds, retain results and acceptance |
| Data | Art. 10 | Governance of data used for training, validation or testing, as applicable | Examine lineage, quality criteria, relevance, representativeness and relevant bias |
| Documentation | Art. 11 · Annex IV | Technical file consistent with the system presented for examination | Reconcile architecture, versions, performance, limitations and cited records |
| Logs | Art. 12 | Recording capabilities suited to system traceability | Trigger events; verify integrity, timestamps and retrieval |
| Information | Art. 13 | Accurate instructions that a deployer can actually use | Perform a task, limitation and incident response from the instructions alone |
| Human oversight | Art. 14 | Measures designed to understand, monitor, disregard, override or stop as applicable | Test permissions, response time, degraded modes and intervention record |
| Performance and security | Art. 15 | Declared accuracy, robustness and cybersecurity levels maintained | Run relevant nominal, boundary, error, attack and drift scenarios |
| Quality system | Arts. 16–21 · 72–73 | Ownership, change, retention, correction, monitoring and incidents organised | Sample one change and one incident end to end through the decision |