GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

AIG-036 AI Quality Management System

Tier 3+AIProviderhigh-risk-annex-iii

Description

A documented quality management system governs how AI systems are developed, tested, released and kept in conformity. Each of its elements names the procedure or control that implements it. The system covers the regulatory compliance strategy including the conformity assessment route and the handling of modifications, design control and verification techniques, development and quality assurance procedures, examination, testing and validation procedures with the frequency each runs at, the technical specifications and standards applied, data management, the AI risk management process, post-market monitoring, serious incident reporting, communication with authorities and with operators, record keeping, resource allocation and accountability. It is approved by a named owner, versioned and reviewed at defined intervals. Each review record states which elements changed and why.

Rationale

The quality management system is the binder rather than a further procedure. Most of its elements already exist as controls (AIG-005 risk management, AIG-008 verification and validation, AIG-009 deployment and change, AIG-012 data management, AIG-015 technical documentation, AIG-018 monitoring, AIG-021 incident response), so the work is an index that points each element at the procedure implementing it and states the frequency that procedure runs at. AIG-001 states the principles; AIG-036 is what carries them into procedures with owners, frequencies and records, which is the requirement a policy alone does not meet. The depth of each element is proportionate to the size of the organisation, which does not lower the rigour required of the output. EN 18286 is the harmonised standard being prepared for this requirement; once it is cited in the Official Journal it becomes the presumption route and the element list here should be re-read against it. Provider seat (ADR-031).

Applicability (9 profiles)

SaaS AI Providerstableconditionalrisk class duty

Condition: ai_risk_class in high-risk-annex-iii

Art.17 quality management system binds providers of high-risk systems.

Enterprise AI Deployerstablenot-applicableout of scope

Art.17 binds providers of high-risk systems. A deployer that triggers Art.25 becomes the provider and moves to high-risk-provider-eu.

GPAI Model Providerstablenot-applicableout of scope

A general-purpose model is not a high-risk system; the conformity duties attach to the provider seat where the organisation also places a high-risk system on the market (saas-ai-provider, high-risk-provider-eu).

High-Risk Provider (EU)stablerequiredrisk class duty

The base makes this conditional on the risk class. Here the class is settled by the profile's facets, so the quality management system is a standing duty: Art.16(c) and Art.17(1) require it in writing as policies, procedures and instructions covering the elements Art.17 lists. The conformity assessment route and the handling of modifications are two of them. Art.17(2) as amended by Regulation (EU) 2026/1744 makes implementation proportionate to the size of the organisation, in particular for an SME, a start-up or a small mid-cap, while requiring the same degree of rigour and level of protection compliance needs. That proportionality reaches how an element is implemented, not which elements exist.

Public Body Deployer (EU)stablenot-applicableout of scope

Art.17 binds providers of high-risk systems. A deployer that triggers Art.25 becomes the provider and moves to high-risk-provider-eu.

Data Act Cloud Provider (EU)stableconditionalrisk class duty

Condition: ai_risk_class in high-risk-annex-iii

Art.17 quality management system binds providers of high-risk systems.

DORA ICT Provider (EU)stableconditionalrisk class duty

Condition: ai_risk_class in high-risk-annex-iii

Art.17 quality management system binds providers of high-risk systems.

HIPAA Business Associate (US)stableconditionalrisk class duty

Condition: ai_risk_class in high-risk-annex-iii

Art.17 quality management system binds providers of high-risk systems.

NIS2 Cloud Provider (EU)stableconditionalrisk class duty

Condition: ai_risk_class in high-risk-annex-iii

Art.17 quality management system binds providers of high-risk systems.

Framework Mappings (7)

EU-AI-Art.16.3Provider Obligations — Quality Management Systemfull
EU-AI-Art.17.1Quality Management System — Establishment and Documentationfull
EU-AI-Art.17.2Quality Management System — Proportionality for SMEs and Small Mid-Capsinformative
EU-AI-Art.43.4Conformity Assessment — Annex I Safety Components Under the Sectoral Procedureinformative
GV-4.1-003Safety-First Organisational Culture | GV-4.1-003informative
GV-5.1-001External Stakeholder Feedback Integration | GV-5.1-001informative
MP-4.1-003AI Technology and Legal Risk Mapping | MP-4.1-003full

Evidence (3)

policydocumentmanual

The approved quality management system document set, covering each element the control names, with a version, an approval date, a named owner and an index from element to implementing procedure.

Example: AI Quality Management System Manual v2.1, approved 12 March 2026 by the VP of Engineering, with the element-to-procedure index at annex A.

Test: Verify: (1) the document set is approved and carries a version and an approval date inside the defined review interval, (2) every element the control names is present and carries content rather than a heading alone, (3) each element names the procedure or control that implements it and the person accountable for it, (4) the examination, testing and validation element states the frequency each procedure runs at.

recorddocumentmanual

Management review record for the quality management system, showing the elements reviewed, the findings raised, their owners and the status of findings carried from the previous review.

Example: AI QMS management review minutes, 4 February 2026, with the open-findings log at appendix B.

Test: Verify: (1) a review record exists dated inside the defined interval, (2) it covers every element rather than a subset, (3) each finding carries an owner and a target date, (4) findings raised at the previous review are shown as closed or carried forward with a stated reason.

system_exporttechnicalautomated

Export from the document or governance management system listing each quality management system element, the procedure document it resolves to, that document's current version and its last review date.

Example: Governance platform export aiqms-element-index-2026-03.csv, generated 31 March 2026.

Test: Verify: (1) every element resolves to a procedure document that exists in the system, (2) no referenced procedure is past its own review date, (3) the versions in the export match the versions named in the manual index, (4) where one procedure is referenced by more than one element, the element descriptions do not contradict each other about what it does.

Questions (3)

boolean

Is there a documented quality management system covering how your AI systems are developed, tested and released?

Answer yes only where a single approved document set exists that names procedures and owners. An AI policy on its own, or a set of procedures with nothing binding them together, is a no here and is covered by AIG-001 and by the lifecycle controls instead.

multi

Which of the following does your AI quality management system cover?

Regulatory compliance strategy, including the conformity assessment route and how modifications are handledDesign control and verification techniquesDevelopment, quality control and quality assurance proceduresExamination, testing and validation procedures with the frequency each runs atThe technical specifications and standards appliedData management proceduresThe AI risk management processPost-market monitoring and serious incident reportingCommunication procedures with authorities and with operatorsRecord keeping, resource allocation and accountabilityNone of the above

Options are listed in the order the elements appear in a typical manual, not in order of importance. Tick an element only where the system names the procedure that implements it; a heading with no procedure behind it does not count.

select

How often is the quality management system reviewed with the review recorded?

At least quarterlyAt least twice a yearAt least annuallyAt a defined interval longer than a yearThere is no scheduled review

Options run from the most frequent to the least. Answer on the recorded reviews rather than the interval the manual states: a documented annual cycle with no minutes from the last cycle is the last option.