The organization must establish and maintain a formal process for identifying, managing, and correcting any nonconformities within its AI Management System (AIMS).
When a nonconformity is identified, this process must ensure the organization takes the following steps:
- Reacts to the nonconformity by taking immediate action to control and correct it and to deal with its consequences.
- Evaluates the need for further action by performing a root cause analysis to understand why the nonconformity occurred and to see if similar issues exist or could arise elsewhere.
- Implements any necessary corrective actions to eliminate the root cause and prevent the issue from recurring.
- Reviews the effectiveness of the corrective actions taken to ensure the fix was successful.
- Updates the AI management system itself, if necessary, based on the findings.
The organization must maintain documented information (records) for every nonconformity, detailing what happened, the actions taken in response, and the results of the corrective actions.