Template · Articles 72 and 73 · Applies with the high-risk regime from 2 December 2027 (Annex III)
AI Act Post-Market Monitoring Plan & Incident Template
A post-market monitoring plan is the documented system by which a provider of a high-risk AI system actively and systematically collects and analyses data on the system's real-world performance throughout its lifetime, as required by Article 72 of the EU AI Act (Regulation (EU) 2024/1689); Article 73 adds the duty to report serious incidents within strict deadlines (15 days standard, 2 days for widespread infringement or critical-infrastructure disruption, 10 days for a death). Both apply with the high-risk regime from 2 December 2027 (Annex III). Following the Digital Omnibus, the Commission must adopt post-market-monitoring guidance, including a template, by 2 September 2027 — until then, providers use their own plan.
Last reviewed: 26 August 2026 · Applies with the high-risk regime from 2 December 2027 (Annex III) · Included in the kit as 23_PostMarket_Monitoring_and_Incident_Kit.docx
What this document is
Document 23 of the RegShelf kit has three parts. Part A is the post-market monitoring plan template — data sources, KPIs with thresholds and owners, review cadence and the feedback loop into your risk management system. Part B is the serious-incident procedure under Article 73: what counts, which deadline applies, who does what. Part C is a ready-to-fill Serious Incident Report form your support and engineering teams can find at 2 a.m. The plan belongs in your Annex IV technical documentation (doc 15, Section 10); the incident procedure is written so deployers can reuse it too.
Who needs it
Providers of high-risk AI systems must establish and document the monitoring plan before market placement, as part of the technical documentation. Deployers have a parallel stake: on identifying a serious incident they must inform the provider immediately (Article 26(5)), and report directly to the market surveillance authority if the provider cannot be reached — which is why Parts B and C are written to work from either role. If you sell into regulated buyers, expect this plan to be requested in procurement long before 2 December 2027.
What the law requires — precisely
Article 72 requires providers to actively and systematically collect, document and analyse relevant data — from deployers or other sources — on performance throughout the system's lifetime, including interaction with other AI systems where relevant, and to evaluate continuous compliance with the Chapter III Section 2 requirements. Passive waiting for complaints is not a monitoring system. On the template question: the former Article 72(3) empowerment for a Commission implementing act (originally due 2 February 2026, never adopted) was deleted by the Digital Omnibus; instead the Commission must adopt guidance, including a template, by 2 September 2027. For incidents, Article 73's definition is narrow — an incident or malfunctioning leading directly or indirectly to death or serious harm to health, serious and irreversible disruption of critical infrastructure, infringement of fundamental-rights obligations, or serious harm to property or the environment (Article 3(49)). Deadlines run from awareness, not from completed investigation: 15 days standard, 2 days for widespread infringement or serious and irreversible critical-infrastructure disruption, 10 days for a death — plus "immediately" once a causal link is established or reasonably likely. Reports generally go to the market surveillance authority of the Member State where the incident occurred; for AI systems based on a general-purpose AI model where system and model come from the same provider (and systems integrated into very large online platforms), the AI Office acts as market surveillance authority (Article 75(1)).
What's inside the RegShelf template
Across the three parts:
- Plan identification linking the plan to your Article 9 risk file;
- A data-sources table — deployer feedback and complaints, logs and telemetry, incident reports, sampled case review, public sources, and interaction with other AI systems, each with collection method and frequency;
- KPI table with action thresholds — e.g. live-sample accuracy, human override rate (both too high and too low are warnings), complaints per 1,000 cases, demographic performance gaps — because a KPI without a threshold and an owner is decoration;
- Review cadence and feedback loop, including the note to restructure onto the Commission's template once the 2 September 2027 guidance lands;
- The Article 73 procedure — the Article 3(49) definition, the 15/2/10-day deadline table with statutory bases, a six-step internal procedure (detect and log awareness time, triage same day, report, preserve evidence, investigate and correct, deployer path), and the rule against altering the system or incident data in ways that could affect cause evaluation before informing the authority (Article 73(6));
- The 17-field incident report form, supporting initial-then-complete filing under Article 73(5).
How to use it
Complete Part A per high-risk system before market placement and file it in your Annex IV documentation. Adopt Part B as your incident procedure, name the roles, and log the moment of awareness for any potential incident — the clock runs from it, and when in doubt you start the clock and close the event as a non-incident after investigation, because a missed deadline cannot be recovered. Keep submitted reports and evidence for at least 10 years with the technical documentation, and rehearse the procedure annually with a fictional incident.
Related reading
- Annex IV Technical Documentation template
- Human Oversight Protocol template
- Timeline & deadlines
- Article 50 transparency
Frequently asked
What are the serious incident reporting deadlines under the AI Act?+
Report immediately after establishing a causal link (or its reasonable likelihood), and in any event within 15 days of becoming aware of a serious incident; within 2 days for a widespread infringement or serious and irreversible disruption of critical infrastructure; within 10 days in the event of a death. An incomplete initial report followed by a complete one is permitted (Article 73(5)).
What counts as a serious incident under the EU AI Act?+
Under Article 3(49): an incident or malfunctioning of an AI system that directly or indirectly leads to the death of a person or serious harm to their health, a serious and irreversible disruption of critical infrastructure, infringement of Union-law obligations protecting fundamental rights, or serious harm to property or the environment. A merely wrong or embarrassing output does not automatically qualify.
Is there an official post-market monitoring plan template?+
Not yet. The original Article 72(3) implementing act was never adopted and its empowerment was deleted by the Digital Omnibus (Regulation (EU) 2026/1744); the Commission must instead adopt guidance including a template by 2 September 2027. Until then, providers document their own plan — this template is designed to map onto the guidance once published.
Who do we report AI serious incidents to?+
Generally the market surveillance authority of the Member State where the incident occurred. Exception: for AI systems built on a general-purpose AI model where system and model come from the same provider, and for systems integrated into very large online platforms, the AI Office acts as the market surveillance authority (Article 75(1)). Deployers report to the provider first (Article 26(5)), and directly to the authority if the provider is unreachable.
Primary sources
- Regulation (EU) 2024/1689 (consolidated)
- Commission AI Act Service Desk — Article 72
- AI Act Explorer — Article 73 (serious incident reporting)
This template ships in the EU AI Act Kit
24 fill-in documents in Word and Excel — launch price €149, twelve months of updates included.
See the full kit