← Back to all articles
Insights

EU AI Act Article 17: A Plain-English Guide to the Quality Management System for High-Risk AI

Generated image

If you build or place a high-risk AI system on the EU market, Article 17 of the EU AI Act is the provision that turns your compliance intentions into a documented, auditable operating system. It is not a one-off checklist. It is the organisational backbone that holds every other high-risk obligation together - from risk management to incident reporting - and it is the first thing a notified body or national authority will ask to see.

This guide walks through what Article 17 actually requires, what proportionality means for a startup versus an enterprise, how the QMS connects to conformity assessment and CE marking, and what you should be building right now.

TL;DR - Article 17 requires providers of high-risk AI systems to put a quality management system in place, documented in written policies, procedures and instructions, covering 13 specific elements across the full AI lifecycle. Implementation must be proportionate to your organisation's size, but the required level of protection cannot be scaled down. The QMS is assessed as part of conformity assessment and is the organisational wrapper around your Article 9 risk management, Article 72 post-market monitoring, and Article 73 incident reporting obligations.


What Article 17 Actually Says

The core obligation is straightforward. Providers of high-risk AI systems must put a quality management system in place that ensures compliance with the AI Act. That system must be documented in a systematic and orderly manner in the form of written policies, procedures and instructions.

"Written" matters. Informal processes, tribal knowledge, and undocumented practices do not satisfy Article 17. If it is not written down and version-controlled, it does not exist for compliance purposes.

The official text is available at artificialintelligenceact.eu/article/17 and the EU AI Act Service Desk at ai-act-service-desk.ec.europa.eu.


The 13 Elements: What Your QMS Must Cover

Article 17(1) lists the minimum content of the QMS. Think of these as the chapter headings of your compliance operating manual - each one needs at least one written policy or procedure behind it.

Article 17(1) QMS Elements at a Glance
RefElementWhat it means in practice
(a)Regulatory compliance strategyA documented plan for how you achieve and maintain compliance, including conformity assessment procedures and how you manage modifications to the AI system.
(b)Design, design control & design verificationStructured procedures and quality gates for the design phase — no more 'move fast and break things' for high-risk AI.
(c)Development, quality control & quality assuranceTechniques and systematic actions covering the full development process, including QA checkpoints.
(d)Examination, test & validation proceduresTesting and validation before, during and after development — with documented frequency for each type of test.
(e)Technical specifications & standardsWhich harmonised standards or common specifications you apply, and — where they do not fully cover requirements — what alternative means you use.
(f)Data management systems & proceduresDocumented processes for data acquisition, collection, analysis, labelling, storage, filtration, mining, aggregation and retention — covering all data operations performed before placing the system on the market.
(g)Article 9 risk management systemYour risk management system (see our Article 9 guide) must be embedded in the QMS, not run as a separate exercise.
(h)Post-market monitoring system (Article 72)Procedures for setting up, implementing and maintaining post-market monitoring — the QMS is where your PMS plan lives.
(i)Serious incident reporting (Article 73)Documented procedures for reporting serious incidents to national competent authorities under Article 73.
(j)Communication with authorities & customersHow you handle communication with national competent authorities, notified bodies, and customers — including who is authorised to speak and on what timeline.
(k)Record-keeping systems & proceduresSystems for creating, storing and retrieving the documentation the Act requires you to keep.
(l)Resource management & security of supplyHow you ensure adequate resources — people, tools, third-party components — including measures to manage supply-chain risks.
(m)Accountability frameworkA documented framework defining the responsibilities of management and staff for each of the elements above.

A few elements deserve extra attention.

Element (f) - data management is broader than most teams expect. It covers every operation performed on data before and for the purpose of placing the system on the market. That means your data pipeline documentation - from raw collection through to the training set used for the final model - needs to be captured here. This element works hand-in-glove with Article 10 data governance obligations.

Elements (g), (h) and (i) are the three elements that cross-reference other Articles directly. Your QMS does not replace those obligations - it is the organisational home for them. If you have already built an Article 9 risk register or an Article 72 post-market monitoring plan, those documents slot into your QMS rather than sitting separately.

Element (m) - the accountability framework is often the last thing organisations write and the first thing auditors look for. It should name roles (not just job titles), assign ownership of each QMS element, and define escalation paths.

lightbulb Tip

Start with a single compliance manual. Map each Article 17(1) element to an existing or new standard operating procedure (SOP). Version-control every document from day one. A simple spreadsheet tracking element → SOP → owner → last-reviewed date is a defensible starting point for a small team.


Proportionality: What It Means for Startups vs. Enterprises

Article 17(2) contains an important qualifier: implementation of the QMS elements shall be proportionate to the size of the provider's organisation. But the same paragraph adds a hard floor - providers must, in any event, respect the degree of rigour and the level of protection required to ensure compliance of their high-risk AI systems with the Act.

In plain English: you can scale how you implement the QMS, but you cannot scale down the protection it delivers.

What does this look like in practice?

Dimension Startup / SME Large enterprise
Documentation format Single compliance manual with cross-referenced SOPs Separate policy documents per element, with a master QMS index
Governance structure Named individual owns each element; founder signs off Dedicated AI governance function; board-level accountability
Risk management Lightweight risk register reviewed quarterly Formal risk committee, automated monitoring tooling
Testing cadence Documented test plan with defined frequency; manual execution Automated test pipelines with continuous integration
Post-market monitoring Structured feedback loop and incident log Dedicated monitoring system with dashboards and alert thresholds
Audit trail Version-controlled documents in a shared drive Integrated compliance management platform

The key point for startups: all 13 elements must be addressed. You cannot omit element (m) because you are a team of ten. What you can do is implement it proportionately - a one-page accountability matrix beats a 50-page governance charter that nobody reads.


Integration: If You Already Have a QMS

Article 17(3) provides a practical shortcut for providers already operating under sectoral EU law that imposes QMS obligations. If you are subject to the Medical Devices Regulation (MDR), the In Vitro Diagnostic Regulation (IVDR), or any other relevant sectoral Union law that requires a quality management system or equivalent, you may incorporate the Article 17(1) elements into your existing system rather than building a parallel one.

This is not a free pass. You still need to ensure all 13 elements are covered - you are adding AI-specific content to an existing framework, not substituting it. A medical device company, for example, might extend its ISO 13485-aligned QMS with AI-specific SOPs covering model testing, data governance, and human oversight.

Financial institutions get a further simplification. For providers that are financial institutions subject to internal governance, arrangements or processes requirements under Union financial services law, the obligation to put in place a QMS - with the exception of elements (g), (h) and (i) - is deemed to be fulfilled by complying with the internal governance rules under the relevant Union financial services law. Note the carve-out: elements (g) risk management, (h) post-market monitoring, and (i) incident reporting still need to be addressed separately, even for financial institutions.


How the QMS Connects to Conformity Assessment and CE Marking

The QMS is not just an internal governance document - it is a core input to the conformity assessment process that every high-risk AI provider must complete before placing a system on the market.

Article 43 of the AI Act provides two conformity assessment routes:

  • Annex VI - Internal control: The provider self-assesses. The provider verifies that the established quality management system is in compliance with Article 17, examines the technical documentation, and draws up the EU declaration of conformity. No notified body is involved. This is the default route for most Annex III high-risk systems (points 2-8) where harmonised standards are fully applied.

  • Annex VII - QMS and technical documentation assessment by a notified body: A notified body audits both the QMS and the technical documentation. The approved quality management system for the design, development and testing of AI systems pursuant to Article 17 is examined and subject to ongoing surveillance. This route is mandatory for biometric identification systems (Annex III, point 1) and for any provider who cannot fully apply harmonised standards or common specifications.

Under Annex VII, the notified body will carry out periodic audits to ensure the provider maintains the quality management system. Any intended change to the approved QMS must be brought to the notified body's attention - so your change management procedures (element (a)) need to be robust from the start.

Under either route, the QMS must be ready before the assessment begins. A QMS that exists only on paper - without evidence of implementation - will not pass.

star Important

The draft harmonised standard prEN 18286 (Artificial Intelligence — Quality Management System for EU AI Act Regulatory Purposes) entered CEN public enquiry on 30 October 2025. Once finalised and cited in the Official Journal, compliance with it will give providers a presumption of conformity for the Article 17 QMS requirements. Until then, it is a strong signal of what notified bodies and authorities will expect — and worth using as a structural template now. Note that prEN 18286 is built around Article 17's product-oriented obligations, not the organisation-wide structure of ISO 9001 or ISO/IEC 42001, though it maps to both.


Deadlines and the Digital Omnibus: What You Need to Know Right Now

The original high-risk applicability date for Article 17 (and all other high-risk obligations) was 2 August 2026 for Annex III systems.

The Digital Omnibus on AI - a package of targeted amendments to the AI Act - has now completed its legislative journey. The Council of the EU gave its final green light on 29 June 2026, following the European Parliament's formal endorsement on 16 June 2026. The regulation is pending publication in the Official Journal, after which it enters into force three days later.

Once published, the new deadlines will be:

  • Annex III high-risk AI systems (standalone use-case systems: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice): deferred to 2 December 2027
  • Annex I high-risk AI systems (AI embedded in regulated products such as medical devices): deferred to 2 August 2028
warning Warning

Do not treat the deadline extension as a pause button. The Omnibus is a deferral, not a dismantling. The fundamental architecture of the Act — its risk-based approach, its governance structure, and its core obligations — remains intact. The extra time is an opportunity to build your QMS properly, not to defer starting. Organisations that begin now will be better positioned for conformity assessment, and the QMS work itself does not get easier with time.

A practical planning horizon for most providers:

Now -> Q4 2026 Q1-Q4 2027 By 2 December 2027
Gap analysis against Article 17(1) elements Draft and implement all SOPs; run internal audits QMS complete, tested, and ready for conformity assessment
Appoint QMS owner and accountability framework Integrate Article 9 risk management and Article 72 PMS plan EU declaration of conformity signed; CE marking applied
Map existing processes to QMS elements Engage notified body if Annex VII route required System registered in EU database (Article 49)

If you are on the Annex VII route (notified body required), engage early. Notified body capacity is finite, and queue times will grow as the December 2027 deadline approaches.


How Article 17 Connects to the Rest of the Act

The QMS is the organisational wrapper around the technical obligations in Articles 9-15. Each of those articles feeds into a specific QMS element:

  • Article 9 (Risk Management) -> QMS element (g). Your risk management system must be embedded in the QMS, not run as a separate exercise. See our Article 9 guide for the full breakdown.
  • Article 10 (Data Governance) -> QMS element (f). Data management procedures must cover the full data lifecycle before market placement.
  • Article 11 (Technical Documentation) -> The QMS is part of the evidence base that populates your Annex IV technical documentation bundle.
  • Article 72 (Post-Market Monitoring) -> QMS element (h). Your post-market monitoring plan lives inside the QMS.
  • Article 73 (Incident Reporting) -> QMS element (i). Serious incident reporting procedures must be documented and tested before deployment.

Think of it this way: Articles 9-15 tell you what your AI system must do. Article 17 tells you how your organisation must be structured to ensure it keeps doing it, throughout the system's entire lifecycle.


Article 17 QMS Readiness Checklist

Use this before your next compliance review or before engaging a notified body.

Foundation

  • A named QMS owner with documented authority and accountability
  • A master compliance manual or QMS index mapping each Article 17(1) element to a written SOP
  • All documents version-controlled with review dates

Element coverage

  • (a) Regulatory compliance strategy documented, including conformity assessment route decision and change management procedure
  • (b) Design control procedures with defined quality gates
  • (c) Development QA/QC procedures documented
  • (d) Test and validation plan with documented frequency for each test type
  • (e) List of harmonised standards applied; alternative means documented where standards not fully applied
  • (f) Data management SOPs covering acquisition, labelling, storage, retention and all pre-market data operations
  • (g) Article 9 risk management system integrated into QMS
  • (h) Article 72 post-market monitoring plan integrated into QMS
  • (i) Article 73 serious incident reporting procedure documented and tested
  • (j) Communication protocols for national authorities, notified bodies and customers
  • (k) Record-keeping system operational and retention periods defined
  • (l) Resource management plan including supply-chain risk measures
  • (m) Accountability framework naming roles and responsibilities for each element

Conformity assessment readiness

  • Conformity assessment route confirmed (Annex VI or Annex VII)
  • If Annex VII: notified body identified and engagement initiated
  • QMS implementation evidenced (not just documented)
  • Change management procedure tested against at least one hypothetical modification scenario

This guide is for informational purposes only and does not constitute legal advice. The EU AI Act is a complex regulation and its supporting standards are still being finalised. Always verify your obligations against the official text of Regulation (EU) 2024/1689 and the latest guidance from the EU AI Office.