Article 17: the quality management system
Article 17 is the requirement that ties every other obligation together into something auditable. It is also the article most often assumed to be covered by an existing certificate, and the one CEN-CENELEC decided needed a purpose-built European standard rather than an existing ISO one.
The thirteen elements
Article 17(1) says the QMS shall include at least the following, documented in a systematic and orderly manner as written policies, procedures and instructions.
| Element | Where it usually already exists | |
|---|---|---|
| 1 | Strategy for regulatory compliance, including compliance with conformity assessment procedures and management of modifications | Rarely exists. Usually the first thing to write. |
| 2 | Techniques, procedures and systematic actions for design, design control and design verification | Engineering design review, if it is documented. |
| 3 | Techniques, procedures and systematic actions for development, quality control and quality assurance | SDLC and QA process. |
| 4 | Examination, test and validation procedures before, during and after development, and their frequency | Test strategy. Frequency is usually the missing part. |
| 5 | Technical specifications, including standards applied, and where standards are not applied in full, the means used to meet requirements | New. See standards status. |
| 6 | Data management systems and procedures, acquisition, collection, analysis, labelling, storage, filtration, mining, aggregation, retention | Feeds directly from Article 10. |
| 7 | The Article 9 risk management system | Article 9 → |
| 8 | Setting up, implementing and maintaining post-market monitoring per Article 72 | Article 72 → |
| 9 | Procedures for reporting serious incidents per Article 73 | Article 73 → |
| 10 | Handling communication with authorities, notified bodies, customers and other operators | Usually informal. Needs to be a procedure with named owners. |
| 11 | Systems and procedures for record keeping of all relevant documentation and information | Ten-year horizon under Art. 18. |
| 12 | Resource management, including security-of-supply measures | Compute, data and third-party model dependencies. |
| 13 | An accountability framework setting out the responsibilities of management and other staff | The named-humans requirement. Maps closely to ISO/IEC 42001 A.3. |
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
Proportionality and sectoral relief
Article 17(2): implementation of these elements shall be proportionate to the size of the provider’s organisation. Proportionate to size, not to appetite: a three-person team documents all thirteen, briefly.
Providers already subject to quality management system obligations under relevant sectoral Union law may satisfy Article 17 through those, and financial institutions subject to internal governance requirements under Union financial services law are deemed to fulfil the QMS obligation, with certain exceptions. Financial services guide →
Why not ISO/IEC 42001?
CEN-CENELEC JTC 21 assessed ISO/IEC 42001 against Article 17, concluded its goals and definitions were not aligned with what the Article requires, and wrote prEN 18286 instead. Article 17 is a product-oriented QMS inside a conformity assessment regime; ISO/IEC 42001 is an organisation-level management system.
42001 is not wasted — prEN 18286 contains a mapping annex precisely so certified organisations reuse rather than rebuild. But a plan that says “42001 covers Article 17” is wrong today and will remain wrong. The full mapping → · prEN 18286 →
Status labels on this page
Verified fact: The thirteen enumerated elements, the Art. 17(2) proportionality provision, the financial services deeming rule, and the JTC 21 assessment of ISO/IEC 42001.
Expert analysis: The column indicating where each element usually already exists in an organisation.
Unsettled: The final content and Official Journal citation date of EN 18286.
Thirteen elements, one system
The efficient path is not thirteen separate documents. It is one management system with thirteen addressable elements, built so the same evidence serves Article 17, your certification audit and your customer questionnaires.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Questions
What is the Article 17 quality management system?
Article 17 requires providers of high-risk AI systems to put in place a quality management system ensuring compliance with the Regulation, documented in a systematic and orderly manner in the form of written policies, procedures and instructions. It lists at least thirteen elements, including a strategy for regulatory compliance, design control and verification procedures, development and quality assurance procedures, examination test and validation procedures, technical specifications and standards applied, data management systems, the Article 9 risk management system, post-market monitoring under Article 72, serious incident reporting under Article 73, communication with authorities, record keeping, resource management including security of supply, and an accountability framework.
Does ISO/IEC 42001 satisfy Article 17?
No. CEN-CENELEC JTC 21 assessed ISO/IEC 42001 against the Article 17 requirement, concluded its goals and definitions were not aligned, and developed a separate European standard, prEN 18286, for this purpose. ISO/IEC 42001 provides organisational management system structure that transfers, and prEN 18286 includes an annex mapping to ISO/IEC 42001 Annex A controls, but it does not satisfy Article 17 on its own.
Is the Article 17 QMS proportionate to company size?
Yes. Article 17(2) provides that implementation of the elements listed must be proportionate to the size of the provider's organisation. Providers may comply through compliance with rules on quality management systems under relevant sectoral Union law, and financial institutions subject to requirements on internal governance under Union financial services law are deemed to fulfil the quality management system obligation, with certain exceptions.
What is the difference between Article 17 and ISO 9001?
ISO 9001 is a general quality management system standard oriented to consistently meeting customer and regulatory requirements. Article 17 is a specific regulatory obligation whose elements are enumerated in the Regulation and which sits inside the AI Act's conformity assessment regime. prEN 18286 includes an annex mapping to ISO 9001 for organisations already operating a quality management system, so an existing ISO 9001 QMS provides transferable structure.
Obligations, article by article
- Art. 5 prohibitions
- Art. 4 AI literacy
- Art. 50 transparency
- Art. 9 risk management
- Art. 10 data governance
- Art. 11 / Annex IV
- Arts. 12–13 logging
- Art. 14 human oversight
- Art. 15 accuracy & security
- Arts. 43–48 conformity
- Art. 49 registration
- Art. 57 sandboxes
- Open source
- Art. 72 monitoring
- Art. 73 incidents
- Arts. 51–56 GPAI
- Art. 99 penalties
- Compliance checklist
- FRIA template (Art. 27)
- When Annex III does not apply →