Lifecycle & third parties
Incidents & corrective action: what AI regulations require
Detection, notification to authorities, corrective action.
21 requirements · 12 regulations · 12 checks
Requirements by regulation
EUAI Act4
EX-013
Corrective actions Art. 20
EX-021
Post-market monitoring Art. 72
EX-022
Serious incident reporting Art. 73
EX-032
EURGPD1
GDPR-08
Breach notification within 72 hours Art. 33, 34
EUNIS21
NIS2-23
EUCRA1
COColorado AI Act1
CO-04
Report to the Attorney General within 90 days §6-1-1702(5), 1703(7)
CASB 531
BRPL 23381
BR-15
Serious incidents Arts. 25 §7, 42
KRAI Basic Act1
KR-06
Safety of high-compute models Art. 32
CNChina GenAI1
CN-05
Handle illegal content and correct the model GenAI Art. 14
Checks in this theme
Most shared first
| Code | Check | Used by |
|---|---|---|
| VER-022-F-01 | Risk and incident response procedure | |
| VER-022-D-01 | Serious incident reporting procedure | |
| VER-013-F-04 | Communication to market surveillance authorities in the event of risk | |
| VER-032-G-03 | Serious incidents documented and reported to the AI Office | |
| VER-AUTO-01 | Suspension procedure in the event of risk | |
| VER-013-F-01 | Documented non-conformity management procedure | |
| VER-013-F-02 | Immediate notification of stakeholders in the event of non-conformity | |
| VER-013-F-03 | Corrective actions traced and documented | |
| VER-032-G-05 | Corrective measures for serious incidents documented | |
| NEW-GDPR-03 | 72-hour notification procedure to the DPA | |
| NEW-US-CO-02 | 90-day Attorney General reporting procedure | |
| NEW-DORA-01 | DORA major incident reporting procedure |
Related themes
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.