Seven requirements, one system
Articles 8 to 15 set out the requirements a high-risk AI system must meet. Read separately they look like seven compliance workstreams. Read properly they describe one system built to a standard, and the interlocks between them are what make the set coherent.
A risk management system running continuously across the lifecycle. Data and data governance. Technical documentation. Record-keeping through logging. Transparency and provision of information to deployers. Human oversight. And accuracy, robustness and cybersecurity.
Two framing points before the detail.
These are outcome requirements, not prescribed methods. The Act says a high-risk system must achieve an appropriate level of accuracy; it does not say which metric or what threshold. That is deliberate, and it means the burden of justifying your choices sits with you.
And they apply to the provider. A deployer of a purchased high-risk system does not build these; it relies on the provider having done so, which is why the transparency requirement in Article 13 is the hinge between the two roles.

