8.1 Determining the Stages of the Life Cycle
The provider shall determine the stages of the life cycle and establish, document, implement and maintain processes and procedures appropriate to ensure that the AI system requirements are met and maintained across the AI system life cycle, needed to meet the requirements for the provision of each AI system, and needed to implement the actions determined in Clause 6.
These processes and procedures shall include techniques, procedures and systematic actions for design, design control and design verification; development, quality control and quality assurance; data management; examination, test and validation; post-market monitoring; and support.
8.2 Actions to Address Risks of AI Systems
The provider shall establish, implement, document and maintain a risk management system throughout the life cycle of each AI system, in accordance with regulatory requirements, aimed at achieving a high level of protection for health, safety, and fundamental rights. prEN 18228 can be used for this, in whole or in part.
8.3 Inception, Design, and Development
8.3.1 Inception
The provider shall determine the intended purpose of the AI system. The provider should consider consultation with interested parties regarding fundamental rights (see Annex A).
8.3.2 Design and Development
The provider shall determine AI system requirements for the intended purpose (including reasonably foreseeable misuse) that translate the applicable regulatory requirements into dimensions of explicit features. Requirements shall include accuracy, robustness, cybersecurity, transparency, human oversight, data and data governance, and record keeping according to the intended purpose, applicable regulatory requirements, requirements related to risk control measures, and other requirements essential for design and development. Requirements shall be reviewed for adequacy and approved. Design and development controls shall be applied.
8.4 Verification and Validation
The provider shall perform AI system verification and AI system validation. Design and development validation shall be completed prior to placing on the market or putting into service.
8.5 Data Management
The provider shall put in place a strategy to comply with applicable regulatory requirements relating to data management in accordance with 4.4. The provider shall define, document, and implement data management processes related to the design and development of each AI system, including (as appropriate and proportionate to risk) systems and procedures for data acquisition, collection, analysis, labelling, storage, filtration, mining, aggregation, retention, and any other operation regarding the data performed before and for the purpose of placing on the market or putting into service.
8.6 Retirement
The provider shall specify a mechanism for data no longer in use is destroyed, when each AI system is decommissioned. These mechanisms shall detail how data no longer in use is destroyed or archived to fulfill regulatory requirements. Data can be reused in certain situations, and destruction of data shall not conflict with the ability of the provider to comply with applicable regulatory requirements.
8.7 Identification of the AI system
8.7.1 The provider shall uniquely identify each AI system and each version of the AI system throughout its life cycle.
8.7.2 The identification shall enable unambiguous distinction between different AI systems and between different versions of the same AI system, including versions resulting from pre-determined changes (see 9.4.4).
8.7.3 The identification method shall include, as a minimum:
- a unique identifier for the AI system;
- a version identifier that changes whenever the AI system is modified in a way that can affect its performance, safety, or compliance with applicable regulatory requirements;
- where applicable, identifiers for the training data, models, and other critical components that form part of the AI system.
8.7.4 The provider shall maintain records that link the unique identification of the AI system and its versions to the corresponding technical documentation, risk management file, verification and validation records, and post-market monitoring data.
8.7.5 When an AI system is modified, the provider shall ensure that the identification is updated and that the updated identification is reflected in the technical documentation and, where applicable, in the instructions for use.
NOTE: Clear identification is necessary to support traceability, configuration management, change control, and communication with deployers, notified bodies, and competent authorities.
8.8 Continuous learning AI systems
Where an AI system is designed to continue learning after being placed on the market or put into service, the provider shall establish and maintain specific controls for continuous learning. The provider shall determine and document the boundaries of acceptable continuous learning (pre-determined changes). Pre-determined changes shall be subject to documented controls. The provider shall implement monitoring processes capable of detecting when the AI system moves outside those boundaries; any such excursion is treated as a change requiring the full modification process.
8.9 Product Documentation
8.9.1 Technical Documentation
For each AI system, the provider shall establish and maintain technical documentation. When the specifications for or characteristics of an AI system are changed, the provider shall ensure that outdated technical documentation is amended and communicated to interested parties, as applicable.
8.9.2 Instructions for Use
For each AI system, the provider shall establish and maintain instructions for use with information on how to use each AI system and its outputs. The instructions for use shall be written in a clear and accessible manner for the intended deployers and shall contain information, specifications and procedures for deploying and using each AI system so that it can operate in a manner that is fit for its intended purpose.