Article 17 quality management pack
An Article 17 operating pack for connecting written procedures to named owners, review decisions, and the records your team keeps.
Contents and evidence map
Use this reference while adapting the operating pack. The evidence should show how each procedure works in your organization.
Section a
Regulatory compliance strategy + change/modification management
- Supporting material
- Compliance mapping + scope statement; Change control procedure and thresholds for "material modification"; Release approval records
Section b
Design control + design verification
- Supporting material
- Design inputs/outputs, architecture decisions, design reviews; Verification results against requirements
Section c
Development controls + quality control/assurance
- Supporting material
- SDLC controls, code review rules, CI/CD logs; QA sign-offs and defect management records
Section d
Examination, test and validation procedures (before/during/after)
- Supporting material
- Test plans, acceptance criteria, evaluation reports; Re-validation triggers after change or drift signals
Section e
Technical specifications and standards used (or equivalents)
- Supporting material
- Standards register, deviation rationales; Versioned references to internal engineering standards
Section f
Data management systems and procedures
- Supporting material
- Data lineage, dataset documentation, labeling guidelines; Access control + retention policy evidence
Section g
Risk management system integration
- Supporting material
- Risk register, hazard analysis, mitigations and residual risk sign-off; Linkage from monitoring findings back to risk review
Section h
Post-market monitoring system
- Supporting material
- Monitoring plan, signals/thresholds, review cadence; Monitoring reports + escalation records
Section i
Serious incident reporting procedures
- Supporting material
- Incident classification procedure + drill records; Escalation matrix and reporting workflow records
Section j
Communication with authorities, notified bodies, operators/customers
- Supporting material
- Communication procedure, regulatory correspondence log; Customer/operator notification templates and records
Section k
Record-keeping systems and procedures
- Supporting material
- What you log, retention periods, integrity controls; Traceability from requirements -> changes -> tests -> approvals -> runtime behavior
Section l
Resource management (including security of supply)
- Supporting material
- Training records, staffing/role definitions; Supplier assessments, dependency inventory, continuity planning
Section m
Accountability framework (management + staff responsibilities)
- Supporting material
- RACI ownership, management review minutes; Internal audit results + corrective actions
| Section | Subject | Supporting material |
|---|---|---|
| a | Regulatory compliance strategy + change/modification management | Compliance mapping + scope statement; Change control procedure and thresholds for "material modification"; Release approval records |
| b | Design control + design verification | Design inputs/outputs, architecture decisions, design reviews; Verification results against requirements |
| c | Development controls + quality control/assurance | SDLC controls, code review rules, CI/CD logs; QA sign-offs and defect management records |
| d | Examination, test and validation procedures (before/during/after) | Test plans, acceptance criteria, evaluation reports; Re-validation triggers after change or drift signals |
| e | Technical specifications and standards used (or equivalents) | Standards register, deviation rationales; Versioned references to internal engineering standards |
| f | Data management systems and procedures | Data lineage, dataset documentation, labeling guidelines; Access control + retention policy evidence |
| g | Risk management system integration | Risk register, hazard analysis, mitigations and residual risk sign-off; Linkage from monitoring findings back to risk review |
| h | Post-market monitoring system | Monitoring plan, signals/thresholds, review cadence; Monitoring reports + escalation records |
| i | Serious incident reporting procedures | Incident classification procedure + drill records; Escalation matrix and reporting workflow records |
| j | Communication with authorities, notified bodies, operators/customers | Communication procedure, regulatory correspondence log; Customer/operator notification templates and records |
| k | Record-keeping systems and procedures | What you log, retention periods, integrity controls; Traceability from requirements -> changes -> tests -> approvals -> runtime behavior |
| l | Resource management (including security of supply) | Training records, staffing/role definitions; Supplier assessments, dependency inventory, continuity planning |
| m | Accountability framework (management + staff responsibilities) | RACI ownership, management review minutes; Internal audit results + corrective actions |
Identify the people who approve changes, review performance, and handle incidents. Record what they reviewed, what they decided, and which system version the decision concerns.
Change review
- Change
- New release of the claims triage assistant
- Owner
- Quality lead
- Review
- Evaluation results and updated operating procedure
- Record
- Release decision, approved version, monitoring plan
Source: Regulation (EU) 2024/1689. Review the requirements applicable to your system with the people responsible for its legal and operational assessment.
Questions and details
Is Article 17 QMS required for all AI systems?
No. Article 17 applies to providers of high-risk AI systems under the EU AI Act.
Can we reuse ISO 9001 or ISO/IEC 42001 work?
Often yes. Many teams integrate Article 17 into an existing quality management system. However, you must explicitly cover the AI Act elements and keep evidence.
Where does prEN 18286 fit?
prEN 18286 is a draft European standard focused on a QMS for EU AI Act regulatory purposes. It is explicitly relevant to Article 17 and will likely influence auditor expectations.
How "big" should our QMS be?
Right-sized to your organization, but not vague. Minimal is fine; missing controls is not. Your QMS should be small enough to run and strict enough to prove.
What should we prepare before conformity assessment?
At minimum: scope statement, QMS manual/policies/procedures, records demonstrating operation (change approvals, tests/validation, monitoring reviews, internal audits, management reviews), and a traceability story for evidence integrity.
