The word that does the work in Article 9 is continuous. The Act describes "a continuous iterative process planned and run throughout the entire lifecycle", which rules out the artefact most organisations actually hold: a risk assessment completed before launch and never reopened. A risk management system is a thing that runs. The evidence that it ran is not the register — it is the second entry in the register, and the third.
The provision people miss is Article 9(5), which requires a judgement that the residual risk is acceptable. That is a decision, not a rating. Ratings are produced by a methodology; decisions are made by a person who can be asked why. In practice this is the single most common gap an assessor finds, because a heat map shaded green looks like an acceptance until you ask whose acceptance it was and on what date.
Article 9 does not stand alone. Risks you identify here must be measured somewhere, and that somewhere is Article 15, which requires the levels of accuracy and the relevant accuracy metrics to be declared in the instructions for use; the robustness and cybersecurity levels the system was tested against reach those same instructions through Article 13(3)(b)(ii). A risk register naming "model degrades on under-represented groups" with no corresponding subgroup performance figure is an identified risk with no measurement behind it. Equally, field data gathered under post-market monitoring has to re-enter this process; monitoring that never changes a risk rating is running alongside the risk management system rather than inside it.
One timing point worth stating plainly, because it is widely misread in both directions: the Digital Omnibus — Regulation (EU) 2026/1744, in force 27 July 2026 — moved the high-risk dates without touching Article 9 itself. The Annex III standalone deadline moved to December 2027 and the Annex I embedded deadline to August 2028, as set out below. But "only the dates changed" is not a safe reading of the instrument as a whole: it amends some forty articles, narrowing what counts as a safety component under the new Article 6(1a) to (1c), deleting Article 10(5), and trimming the registration data required by Annex VIII. What Article 9 itself demands is a judgement rather than a threshold: it sets no number for acceptable residual risk, which is why the evidence below turns on who made the call and on what basis rather than on what score was reached. Our note on building an AI risk profile sets out one way to structure that.