Compliance

Quality Management System

A documented system of policies, procedures and controls that providers of high‑risk AI systems must maintain to ensure compliance, quality, safety and ongoing monitoring.

Definition

Official/legal definition: "Providers of high‑risk AI systems shall put a quality management system in place that ensures compliance with this Regulation." (EU AI Act, Article 17). This short legal statement is the starting point: the EU AI Act requires an organised, documented set of policies, procedures and instructions to ensure that high‑risk AI systems meet the Regulation’s requirements throughout design, development, testing, deployment and post‑market monitoring.

Context and scope. The obligation in Article 17 applies to providers of AI systems classified as high‑risk under the EU AI Act (Regulation (EU) 2024/1689). The QMS required by the Act must be systematic and orderly (written policies, procedures and instructions) and is explicitly linked to other legal obligations in the Act such as the risk management system (Article 9), technical documentation (Article 11), post‑market monitoring (Article 72) and incident reporting (Article 73). The Act also permits providers already subject to sectoral Union quality regimes (or financial internal governance) to integrate AI Act QMS aspects into existing systems, subject to limited exceptions. (EU AI Act, Article 17; see also Annex VI–VII for conformity assessments based on QMS.)

Practical implications for businesses. For providers of high‑risk AI systems, a QMS is not a checklist only for engineers — it is an organisational programme that demonstrates and preserves legal compliance. In practice a QMS will require documented processes for design control, development, testing and validation, data governance, record keeping, post‑market monitoring and incident handling, clear assignment of responsibilities (an accountability framework), and procedures for managing modifications and conformity assessments. Firms will need to retain evidence and records (often for multi‑year retention periods specified elsewhere in the Regulation), train personnel, and be prepared for internal audits and, where applicable, assessment by notified bodies under the Act’s conformity assessment routes (see Annex VII). The EU provision is consistent with the general, internationally‑accepted concept of a QMS as set out in standards such as ISO 9001:2015 (which defines a QMS as the set of interrelated elements an organisation uses to direct and control quality) and can be operationalised using risk‑based frameworks such as the NIST AI RMF (Govern/Measure/Manage functions). (EU AI Act, Article 17; ISO 9001:2015; NIST AI RMF.)

Key requirements / minimum criteria (Article 17(1) — summary of points (a)–(m)):

  • Regulatory compliance strategy: procedures to ensure conformity, including management of modifications and conformity assessment interactions.
  • Design and design control: documented techniques and procedures for design, verification and design control.
  • Development, quality control and assurance: development procedures and quality assurance processes for the AI system lifecycle.
  • Testing & validation: examination, test and validation procedures before, during and after development (with defined frequency).
  • Technical specifications & standards: application of technical specs and harmonised standards or equivalent means to ensure compliance.
  • Data management: systems and procedures covering data acquisition, labelling, storage, filtration, retention and other data operations relevant to placing on the market.
  • Integration with risk management: incorporation of the risk management system (Article 9).
  • Post‑market monitoring: processes to set up, implement and maintain post‑market monitoring (Article 72).
  • Incident reporting procedures: procedures for reporting serious incidents (Article 73).
  • Communications: handling communications with competent authorities, notified bodies, data providers, customers and other stakeholders.
  • Record‑keeping: systems for retention and access to all relevant documentation and information.
  • Resource management: allocation of resources, including supply‑security measures.
  • Accountability framework: clear responsibilities for management and staff across the listed aspects.

Examples and cross‑references. A software provider placing a biometric identification model on the EU market would document design requirements, dataset sourcing and labelling procedures, testing protocols for accuracy and robustness, an incident escalation process, and a named management sponsor responsible for compliance — all recorded in the QMS. The QMS is assessed in conformity procedures (Annex VI / Annex VII) and must interoperate with: the risk management system (Article 9), technical documentation (Article 11), post‑market monitoring (Article 72) and reporting obligations (Article 73). Organisations commonly align the AI Act QMS requirements with internationally recognised quality standards (e.g., ISO 9001) and operational guidance (e.g., NIST AI RMF) to create auditable, evidence‑based systems that meet both regulatory and business governance needs.

Sources

  • EU AI Act Article 17
  • ISO 9001