Resources

Article 17 quality management pack

An Article 17 operating pack for connecting written procedures to named owners, review decisions, and the records your team keeps.

Contents and evidence map

Use this reference while adapting the operating pack. The evidence should show how each procedure works in your organization.

Section a

Regulatory compliance strategy + change/modification management

Supporting material
Compliance mapping + scope statement; Change control procedure and thresholds for "material modification"; Release approval records

Section b

Design control + design verification

Supporting material
Design inputs/outputs, architecture decisions, design reviews; Verification results against requirements

Section c

Development controls + quality control/assurance

Supporting material
SDLC controls, code review rules, CI/CD logs; QA sign-offs and defect management records

Section d

Examination, test and validation procedures (before/during/after)

Supporting material
Test plans, acceptance criteria, evaluation reports; Re-validation triggers after change or drift signals

Section e

Technical specifications and standards used (or equivalents)

Supporting material
Standards register, deviation rationales; Versioned references to internal engineering standards

Section f

Data management systems and procedures

Supporting material
Data lineage, dataset documentation, labeling guidelines; Access control + retention policy evidence

Section g

Risk management system integration

Supporting material
Risk register, hazard analysis, mitigations and residual risk sign-off; Linkage from monitoring findings back to risk review

Section h

Post-market monitoring system

Supporting material
Monitoring plan, signals/thresholds, review cadence; Monitoring reports + escalation records

Section i

Serious incident reporting procedures

Supporting material
Incident classification procedure + drill records; Escalation matrix and reporting workflow records

Section j

Communication with authorities, notified bodies, operators/customers

Supporting material
Communication procedure, regulatory correspondence log; Customer/operator notification templates and records

Section k

Record-keeping systems and procedures

Supporting material
What you log, retention periods, integrity controls; Traceability from requirements -> changes -> tests -> approvals -> runtime behavior

Section l

Resource management (including security of supply)

Supporting material
Training records, staffing/role definitions; Supplier assessments, dependency inventory, continuity planning

Section m

Accountability framework (management + staff responsibilities)

Supporting material
RACI ownership, management review minutes; Internal audit results + corrective actions

Identify the people who approve changes, review performance, and handle incidents. Record what they reviewed, what they decided, and which system version the decision concerns.

Change review
Change
New release of the claims triage assistant
Owner
Quality lead
Review
Evaluation results and updated operating procedure
Record
Release decision, approved version, monitoring plan

Source: Regulation (EU) 2024/1689. Review the requirements applicable to your system with the people responsible for its legal and operational assessment.

Questions and details

Is Article 17 QMS required for all AI systems?

No. Article 17 applies to providers of high-risk AI systems under the EU AI Act.

Can we reuse ISO 9001 or ISO/IEC 42001 work?

Often yes. Many teams integrate Article 17 into an existing quality management system. However, you must explicitly cover the AI Act elements and keep evidence.

Where does prEN 18286 fit?

prEN 18286 is a draft European standard focused on a QMS for EU AI Act regulatory purposes. It is explicitly relevant to Article 17 and will likely influence auditor expectations.

How "big" should our QMS be?

Right-sized to your organization, but not vague. Minimal is fine; missing controls is not. Your QMS should be small enough to run and strict enough to prove.

What should we prepare before conformity assessment?

At minimum: scope statement, QMS manual/policies/procedures, records demonstrating operation (change approvals, tests/validation, monitoring reviews, internal audits, management reviews), and a traceability story for evidence integrity.

Quality System Operating Pack | Article 17 Playbook | KLA