# Quality management system for AI development and supply

- **Record type**: Control
- **Kind**: Policy
- **Owner**: Quality lead
- **Frequency**: Annual
- **Duties served**: 3

## What the control achieves

Binds the organisation's AI processes into one documented, audited management system so that compliance is repeatable across products rather than reinvented for each one.

## How it is typically implemented

Building on an existing quality or information-security management system, the organisation documents the procedures that cover the AI lifecycle: how regulatory requirements are identified, how systems are designed, built, tested and released, how data and documentation are managed, how post-market monitoring and incidents are run, how suppliers are controlled and how corrective action is tracked. Roles and resources are assigned, internal audits check that procedures are followed, and management reviews the system's performance at least annually. Records of the system itself are retained for the period authorities expect.

## Evidence it produces

- AI quality management system manual (policy_document): Scope, procedures, roles and records that make up the management system.
- Internal audit of the AI management system (audit_report)
- Management review minutes (meeting_record)

## Legal duties this control serves

- Operate a quality management system — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-quality-management-system
- Complete conformity assessment, CE marking and EU database registration — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-conformity-assessment-registration
- Providers must meet the full set of provider duties for high-risk AI — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-16-provider-obligations

## Standards clauses it corresponds to (clause numbers only)

- ISO/IEC 42001:2023: Clause 4 to 10 — The management-system structure as a whole; certification is optional.
- NIST AI RMF 1.0: GOVERN 1.4, 1.5, 1.7

## MIT AI Risk Repository subdomains addressed

6.5, 7.3

## Provenance

- **Record page**: https://aipolicytracker.org/controls/ai-quality-management-system
- **Official source**: none recorded — this record is incomplete, see https://aipolicytracker.org/gaps
- **Review status**: pending review
- **Confidence**: high
- **Facts last confirmed**: never confirmed against the official source
- **Retrieved**: 2026-09-24
- **Licence**: https://creativecommons.org/licenses/by/4.0/

> This record is a structured summary with a link to the official text. It is not legal advice. Open the official source before relying on any date or duty. How current each record type must be is published at https://aipolicytracker.org/verification; what a record must carry at all is published at https://aipolicytracker.org/coverage.
