Operate a quality management system
Under EU AI Act, Article 17
What does it require?
Providers of high-risk AI systems must put in place a documented quality management system covering regulatory-compliance strategy, design and development procedures, testing and validation, technical specifications and standards, data management, the risk-management system, post-market monitoring, incident reporting, communication with authorities, record keeping, resource management and an accountability framework.
Practical action
Extend an existing ISO 9001 or ISO/IEC 42001 management system to cover the Article 17 elements.
Who does it apply to?
Providers of high-risk AI systems; may be integrated into sector QMS requirements.
- Actors
- Provider / developer
- Sectors
- Cross-sector / all sectors
Applies from:
Evidence examples
- QMS manual and procedures (document)
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Whole management system (Clauses 4–10) | ISO/IEC 42001 is a certifiable AI management system standard; certification is not a legal presumption of conformity under the AI Act. | high |
| NIST AI RMF 1.0 | GOVERN function | Governance structures and policies. | medium |
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.