Does Provisions on the Management of Algorithmic Recommendations require Risk Assessment?
China • enforcing
Yes — 1 provision
Requirements at a glance
This regulation imposes 4 specific requirements for Risk Assessment across 1 provision:
- Periodic review — Must periodically review, evaluate, and verify algorithms, models, data, and outcomes (Art. 8)
- Security governance and content handling — Maintain security assessment and monitoring plus incident-response systems (Art. 7); maintain an illegal/undesirable-content feature database, stop and report illegal information, and handle undesirable information under the prescribed content-governance rules (Art. 9)
- User controls — Provide users either a non-personalized option or a convenient option to turn off algorithmic recommendations (Art. 17)
- Filing and security assessment — Providers with public-opinion properties or social-mobilization capabilities must file with an algorithm self-assessment report (Art. 24) and separately conduct a security assessment under applicable national rules (Art. 27)
Algorithmic Risk Assessment
Requirements
| Requirement | Details |
|---|---|
| Periodic review | Must periodically review, evaluate, and verify algorithms, models, data, and outcomes (Art. 8) |
| Security governance and content handling | Maintain security assessment and monitoring plus incident-response systems (Art. 7); maintain an illegal/undesirable-content feature database, stop and report illegal information, and handle undesirable information under the prescribed content-governance rules (Art. 9) |
| User controls | Provide users either a non-personalized option or a convenient option to turn off algorithmic recommendations (Art. 17) |
| Filing and security assessment | Providers with public-opinion properties or social-mobilization capabilities must file with an algorithm self-assessment report (Art. 24) and separately conduct a security assessment under applicable national rules (Art. 27) |
Penalties
| Violation | Fine |
|---|---|
| Listed governance, review, and filing violations | Where no other law or administrative regulation governs, Article 31 provides warnings, circulated criticism, correction orders, and, for refusal to correct or serious violations, suspended updates and an RMB 10,000-100,000 fine |
| Security-assessment and special filing violations | Article 32 routes Article 27 violations to applicable law; Article 33 addresses fraudulent filing and cancellation failures, not every risk-assessment breach |
Sources: CAC Official Text