**Article 9**

**Implementation of the Risk Management System**  
Horizon Learning Analytics has established a risk management system constituting a continuous, iterative framework applied throughout the entire lifecycle of the Horizon Learning Analytics Competency Evaluation Framework. The system encompasses the stages of risk identification, estimation, evaluation, risk control, and post-market monitoring integration. This system is documented through version-controlled engineering protocols and compliance reports that are updated quarterly or upon significant system revisions, such as model retraining or feature engineering adjustments, ensuring traceability and governance over risk mitigation activities.

**Identification and Analysis of Known and Foreseeable Risks**  
The risk identification process focuses specifically on technical accuracy risks inherent to the system’s operation. Horizon Learning Analytics conducted empirical studies involving a dataset comprising over 75,000 anonymized vocational trainee records with balanced representation across multiple skill domains. Performance metrics revealed an average classification accuracy of 87.3% (±2.1% standard deviation in cross-validation folds). Risk identification prioritized false negatives, i.e., underestimated competency scores, due to their operational impact on curriculum adjustments. The scope of risks identified excludes fundamental rights-related concerns such as potential discrimination against minority or vulnerable learner groups and does not formally address psychological impacts such as stress or demotivation arising from misclassification.

**Risk Estimation and Evaluation in Intended and Foreseeable Misuse Conditions**  
Risk estimation employs statistical performance evaluation and stress testing under simulated distributional shifts, such as reduced data quality scenarios reflective of incomplete interaction logs or sensor inaccuracies. For misuse scenarios, defined as user input manipulations or context changes (e.g., attempted data poisoning through interaction record falsification), adversarial robustness tests were conducted on 10,000 synthetic record perturbations. The results confirm stable prediction variance within acceptable bounds (less than 3% performance degradation). Risks resulting in misclassification are quantitatively evaluated through confusion matrices and error rate distributions. Residual risk thresholds were established to maintain false negative rates below 12%, balancing sensitivity and specificity inherent to the GBDT classifier’s probabilistic outputs.

**Integration of Post-Market Data into Risk Evaluations**  
Post-market monitoring leverages anonymized aggregated user feedback and system performance logs collected via secure telemetry from deployed systems in 23 vocational centers. Monthly reports analyze error rate trends and identify deviations from initial evaluation metrics. An automated alert mechanism flags performance drops exceeding 5% from baseline accuracy, triggering immediate review and model retraining cycles. However, the feedback focuses exclusively on stability and accuracy metrics, without incorporating annotations relating to user psychological states or fairness across demographic variables.

**Design and Development Measures for Risk Minimization**  
The Horizon Learning Analytics system incorporates design strategies to mitigate identified technical risks, including the use of gradient boosted decision trees selected for their robustness to heterogeneous data and interpretability via SHAP (SHapley Additive exPlanations) values. Feature engineering prioritizes stable, invariant competency metrics, reducing sensitivity to noisy input. Hyperparameter optimization aimed to minimize overfitting, verified through nested cross-validation with a calibration step ensuring well-calibrated probability scores. Comprehensive unit and integration testing verify component functioning and prevent regressions. Documentation includes detailed model behavior reports to support deployers in understanding system limitations.

**Mitigation and Control Measures for Non-Eliminable Risks**  
For risks that cannot be eliminated by design, the provider supplies extensive technical documentation describing model confidence intervals and inherent uncertainty in competency scoring, enabling deployers to interpret results cautiously. The system outputs include alert flags when scores fall close to decision thresholds, recommending human review. The provider’s guidelines emphasize that competency scores should complement, not replace, instructor judgment. Training materials outline typical error modes, promoting informed deployment decisions. While tailored to the technical capabilities of typical vocational educators, no specialized training in psychological or fairness risk evaluation is currently included.

**Provision of Technical Information and Training to Deployers**  
Information delivered to deployers consists of a detailed user manual, technical specifications, and an interactive online knowledge base featuring scenario-based guidance. Training sessions provided by Horizon Learning Analytics focus strictly on system functionalities, data input preparation, and interpretation of competency scores and feature importance outputs. The training assumes baseline technical proficiencies common among vocational educators but does not encompass socio-psychological training or awareness of potential discriminatory impacts. The documentation specifies that responsibility for broader risk assessment, including ethical or psychological considerations, resides with the system deployer.

**Testing Strategies and Compliance Verification**  
Prior to market release and upon subsequent updates, the system underwent structured testing phases incorporating both synthetic benchmark datasets and controlled pilot deployments. Benchmarks consisted of stratified vocational training subgroups, ensuring performance metrics represented typical case distributions. Testing adhered to predefined acceptance criteria, including a minimum overall accuracy of 85%, false negative rates below 12%, and robustness metrics above 90% for key skill area predictions. Performance tests extended to stress conditions simulating data inconsistencies common in real-world logging systems. Testing reports demonstrate consistent performance and compliance with the system’s technical specifications. Real-world testing did not extend to user experience metrics or fundamental rights impact assessments.

**Consideration of Impact on Vulnerable Groups and Minors**  
The risk management process incorporated a demographic metadata review indicating approximately 18% of the corpus involved trainees under 18 years of age. Despite this data, the provider’s risk analysis and mitigation measures are confined strictly to technical performance criteria, without differentiated evaluations or tailored safeguards relating to minors or other vulnerable categories. No specific testing or monitoring was performed to detect potential discriminatory bias or differential psychological harm across demographic strata. The provider advises deployers to conduct supplementary assessments tailored to the social and educational contexts in which the system is used.

**Alignment with Overlapping Legal Risk Management Requirements**  
Where Horizon Learning Analytics’ risk management processes intersect with requirements from other Union law provisions on internal risk controls, procedures are designed to be modular and interoperable. This facilitates integration with deployer-implemented compliance frameworks that may incorporate fundamental rights and psychological harm assessments beyond the provider’s scope. The risk management documentation explicitly delineates the boundaries of the provider’s responsibility, focusing on mitigating technical accuracy risks through design, testing, and technical information provision.