AIG-036 AI Quality Management System
Description
A documented quality management system governs how AI systems are developed, tested, released and kept in conformity. Each of its elements names the procedure or control that implements it. The system covers the regulatory compliance strategy including the conformity assessment route and the handling of modifications, design control and verification techniques, development and quality assurance procedures, examination, testing and validation procedures with the frequency each runs at, the technical specifications and standards applied, data management, the AI risk management process, post-market monitoring, serious incident reporting, communication with authorities and with operators, record keeping, resource allocation and accountability. It is approved by a named owner, versioned and reviewed at defined intervals. Each review record states which elements changed and why.
Rationale
The quality management system is the binder rather than a further procedure. Most of its elements already exist as controls (AIG-005 risk management, AIG-008 verification and validation, AIG-009 deployment and change, AIG-012 data management, AIG-015 technical documentation, AIG-018 monitoring, AIG-021 incident response), so the work is an index that points each element at the procedure implementing it and states the frequency that procedure runs at. AIG-001 states the principles; AIG-036 is what carries them into procedures with owners, frequencies and records, which is the requirement a policy alone does not meet. The depth of each element is proportionate to the size of the organisation, which does not lower the rigour required of the output. EN 18286 is the harmonised standard being prepared for this requirement; once it is cited in the Official Journal it becomes the presumption route and the element list here should be re-read against it. Provider seat (ADR-031).
Applicability (9 profiles)
Condition: ai_risk_class in high-risk-annex-iii
Art.17 quality management system binds providers of high-risk systems.
Art.17 binds providers of high-risk systems. A deployer that triggers Art.25 becomes the provider and moves to high-risk-provider-eu.
A general-purpose model is not a high-risk system; the conformity duties attach to the provider seat where the organisation also places a high-risk system on the market (saas-ai-provider, high-risk-provider-eu).
The base makes this conditional on the risk class. Here the class is settled by the profile's facets, so the quality management system is a standing duty: Art.16(c) and Art.17(1) require it in writing as policies, procedures and instructions covering the elements Art.17 lists. The conformity assessment route and the handling of modifications are two of them. Art.17(2) as amended by Regulation (EU) 2026/1744 makes implementation proportionate to the size of the organisation, in particular for an SME, a start-up or a small mid-cap, while requiring the same degree of rigour and level of protection compliance needs. That proportionality reaches how an element is implemented, not which elements exist.
Art.17 binds providers of high-risk systems. A deployer that triggers Art.25 becomes the provider and moves to high-risk-provider-eu.
Condition: ai_risk_class in high-risk-annex-iii
Art.17 quality management system binds providers of high-risk systems.
Condition: ai_risk_class in high-risk-annex-iii
Art.17 quality management system binds providers of high-risk systems.
Condition: ai_risk_class in high-risk-annex-iii
Art.17 quality management system binds providers of high-risk systems.
Condition: ai_risk_class in high-risk-annex-iii
Art.17 quality management system binds providers of high-risk systems.
Framework Mappings (7)
| EU-AI-Art.16.3 | Provider Obligations — Quality Management System | full |
| EU-AI-Art.17.1 | Quality Management System — Establishment and Documentation | full |
| EU-AI-Art.17.2 | Quality Management System — Proportionality for SMEs and Small Mid-Caps | informative |
| EU-AI-Art.43.4 | Conformity Assessment — Annex I Safety Components Under the Sectoral Procedure | informative |
| GV-4.1-003 | Safety-First Organisational Culture | GV-4.1-003 | informative |
| GV-5.1-001 | External Stakeholder Feedback Integration | GV-5.1-001 | informative |
| MP-4.1-003 | AI Technology and Legal Risk Mapping | MP-4.1-003 | full |
Evidence (3)
The approved quality management system document set, covering each element the control names, with a version, an approval date, a named owner and an index from element to implementing procedure.
Example: AI Quality Management System Manual v2.1, approved 12 March 2026 by the VP of Engineering, with the element-to-procedure index at annex A.
Test: Verify: (1) the document set is approved and carries a version and an approval date inside the defined review interval, (2) every element the control names is present and carries content rather than a heading alone, (3) each element names the procedure or control that implements it and the person accountable for it, (4) the examination, testing and validation element states the frequency each procedure runs at.
Management review record for the quality management system, showing the elements reviewed, the findings raised, their owners and the status of findings carried from the previous review.
Example: AI QMS management review minutes, 4 February 2026, with the open-findings log at appendix B.
Test: Verify: (1) a review record exists dated inside the defined interval, (2) it covers every element rather than a subset, (3) each finding carries an owner and a target date, (4) findings raised at the previous review are shown as closed or carried forward with a stated reason.
Export from the document or governance management system listing each quality management system element, the procedure document it resolves to, that document's current version and its last review date.
Example: Governance platform export aiqms-element-index-2026-03.csv, generated 31 March 2026.
Test: Verify: (1) every element resolves to a procedure document that exists in the system, (2) no referenced procedure is past its own review date, (3) the versions in the export match the versions named in the manual index, (4) where one procedure is referenced by more than one element, the element descriptions do not contradict each other about what it does.
Questions (3)
Is there a documented quality management system covering how your AI systems are developed, tested and released?
Answer yes only where a single approved document set exists that names procedures and owners. An AI policy on its own, or a set of procedures with nothing binding them together, is a no here and is covered by AIG-001 and by the lifecycle controls instead.
Which of the following does your AI quality management system cover?
Options are listed in the order the elements appear in a typical manual, not in order of importance. Tick an element only where the system names the procedure that implements it; a heading with no procedure behind it does not count.
How often is the quality management system reviewed with the review recorded?
Options run from the most frequent to the least. Answer on the recorded reviews rather than the interval the manual states: a documented annual cycle with no minutes from the last cycle is the last option.