The organisation should establish and document a process for monitoring the operation of any deployed high-risk AI systems, based on the provider's instructions for use. This process should define the steps for identifying and reacting to potential risks or serious incidents. The procedure should include actions for suspending the system's use and for notifying the provider, distributor, and relevant authorities without undue delay.
Clear responsibilities for the continuous monitoring of deployed high-risk AI systems should be assigned. The designated personnel or roles must be made aware of their duties, which include following the provider's instructions for use and adhering to the internal procedures for reporting risks and incidents.
Sensitive operational data in cases where the organisation is a law enforcement authority are excluded from these obligations