Skip to content
Store / AI Governance / AI System Robustness Checklist
AI Governance AI Act Art. 15

AI System Robustness Checklist (AI Act Art. 15)

The 9 robustness evaluation areas AESIA checks, with a metrics and guaranteed-threshold log — the table an auditor will actually ask for, and the direct complement to your accuracy checklist.

Based on AESIA Guide 10 (Spain's AI Supervision Agency), born out of its regulatory sandbox and adapted to the Digital Omnibus — the practical reference standard for compliance in Spain.
€29
VAT included · one-time payment
Coming soon → ← Back to store
Referenced article by article with the AI Act, GDPR and DAMA-DMBOK

What's included

  • Excel file with the 9 robustness evaluation areas, each with a guiding question and a practical recommendation
  • Metrics log: what you measure, the guaranteed minimum threshold, the measured value, and whether you're within range — the table an auditor will ask for
  • Self-assessment: owner and last review date for each area
  • PDF guide summarizing the 9 areas
  • Legal Notice

Why robustness isn't a test you pass once

Art. 15 of Regulation (EU) 2024/1689 requires high-risk systems to achieve an appropriate level of accuracy, robustness and cybersecurity, and to perform consistently throughout their entire lifecycle. That nuance is the one most often missed: validating the model before deployment isn't enough. A system that retrains, or whose input data changes over time, can degrade silently — with nobody noticing until it's already a serious problem.

The 9 areas it covers

  • Lifecycle and robustness — which phases it's evaluated in, not just before deployment.
  • Metric selection — which ones apply to your model type and its intended purpose.
  • Validation and verification — the process for confirming they're met before every deployment.
  • System efficiency — compute, memory and response-time consumption.
  • Performance — comparison against the state of the art or previous versions.
  • Continuous monitoring — robustness dashboards in production, not just in testing.
  • Error resilience — detection and alerting when behavior falls outside documented limits.
  • Redundancy and fallback plans — what happens if the system fails or degrades below the minimum.
  • Degradation over time — the most overlooked area, and the one that matters most for systems that keep learning.

Fits what you already have

If you already use the ISO/IEC 23894 Checklist for risk management, this one covers the technical part that leaves out. And if you have the Quality Management System Checklist, this one develops its element 17.1.d (examination, testing and validation).