Article 17

EU AI Act Article 17 — Quality Management System (QMS)

Article 17 of Regulation (EU) 2024/1689 requires providers to have a quality management system. The thirteen QMS aspects, ISO 9001 / ISO 42001 alignment, and the SME proportionality.

Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review

What Article 17 actually requires

Article 17 of Regulation (EU) 2024/1689 requires providers of high-risk AI systems to put in place a quality management system (QMS) that ensures compliance with the Regulation. The QMS must be documented in a systematic and orderly manner in the form of written policies, procedures and instructions.

Reg text — Article 17(1): "Providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation."

The thirteen QMS aspects

Article 17(1) lists the aspects the QMS must cover (paraphrased):

  • (a) A strategy for regulatory compliance, including compliance with conformity-assessment procedures and procedures for the management of modifications to the high-risk AI system.
  • (b) Techniques, procedures and systematic actions for the design, design control and design verification of the AI system.
  • (c) Techniques, procedures and systematic actions for the development, quality control and quality assurance of the AI system.
  • (d) Examination, test and validation procedures to be carried out before, during and after development.
  • (e) Technical specifications, including standards, to be applied; where harmonised standards are not applied, the means used to ensure compliance.
  • (f) Systems and procedures for data management, covering data acquisition, collection, analysis, labelling, storage, filtration, mining, aggregation, retention.
  • (g) The Article 9 risk-management system.
  • (h) The setting-up, implementation and maintenance of a post-market monitoring system.
  • (i) Procedures for the reporting of serious incidents.
  • (j) Communication with national competent authorities, notified bodies, customers and other relevant actors.
  • (k) Systems and procedures for record-keeping.
  • (l) Resource management, including security-of-supply measures.
  • (m) An accountability framework setting out responsibilities of management and other staff.

Article 17(2) — proportionality

Article 17(2) explicitly states the QMS must be proportionate to the size of the provider's organisation. SMEs and start-ups can comply in a simplified manner. The Commission is required to publish guidance on simplified QMS for SMEs.

Article 17(3) — sector overlay

Where providers are subject to QMS obligations under sector-specific Union law (e.g., medical devices under MDR), Article 17(3) allows integration. The AI-specific elements layer on top of the existing sector QMS rather than replacing it.

Who is covered

All providers of high-risk AI systems. Article 25-promoted entities inherit the obligation for the modified variant.

What to do

  • Build the QMS on top of an existing system if you have one — ISO 9001, ISO 27001, or sector-specific QMS regimes are good starting points.
  • Map each Article 17(1) aspect to a specific document in your QMS — most teams use a one-row-per-aspect mapping spreadsheet.
  • For the AI-specific aspects (data management, risk management, post-market monitoring, incident reporting), align with ISO/IEC 42001:2023 and ISO/IEC 23894:2023.
  • Document an accountability matrix naming who owns what.

Inline crosswalk

  • ISO/IEC 42001:2023 Clauses 4–10 (the entire AIMS) — the Article 17 QMS is its EU AI Act mandated form.
  • NIST AI RMF GOVERN 1.2 — Trustworthy-AI characteristics integrated into organisational policies, processes, procedures.
  • NIST AI RMF GOVERN 2.1 — Roles, responsibilities, lines of communication documented.

Common mistakes

  • Building a QMS in parallel with rather than on top of existing systems. Article 17(3) explicitly invites integration.
  • Skipping the accountability matrix (Article 17(1)(m)).
  • No documented data-management procedure (Article 17(1)(f)).
  • Generic post-market monitoring reference instead of an actual operational system.

Penalties

Article 99(4) — up to €15 million or 3% of worldwide annual turnover.


Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.

Reference checklist

From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.

  • Article 17 · Starter tier · medium

    Set up quality management system (QMS)

    Covers development, testing, validation, change management, post-market monitoring. Can build on ISO 9001 if you have it.

  • Annex IV · Pro tier · medium

    List ISO/IEC 42001 + 23894 + 24029 alignment

    Annex IV(2)(h) requires a list of harmonised standards applied in full or in part. ISO 42001 (AIMS), 23894 (risk), 24029 (robustness) are the core trio.

ISO 42001 + NIST AI RMF crosswalk

Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.

ISO/IEC 42001:2023

Checklist itemISO 42001 controlRationale
art17-qmsISO/IEC 42001:2023 Clause 4 — Context of the organisationArticle 17 QMS includes scope, interested parties and AIMS boundaries — the substance of Clause 4 context.
art17-qmsISO/IEC 42001:2023 Clause 5 — Leadership and AI policyA QMS that names accountable leadership and approves an AI policy satisfies the Clause 5 leadership requirements.
art17-qmsISO/IEC 42001:2023 Clause 9 — Performance evaluationQMS internal audit, management review and KPI monitoring are exactly the practices required by Clause 9.
annexiv-harmonised-standardsISO/IEC 42001:2023 Clause 4.4 — AI management systemListing harmonised-standard alignment (ISO 42001/23894/24029) is the AIMS-establishment evidence of Clause 4.4.

NIST AI RMF 1.0

Checklist itemNIST AI RMF subcategoryRationale
art17-qmsNIST AI RMF GOVERN 1.2 — The characteristics of trustworthy AI are integrated into organizational policies, processes, and proceduresA QMS that integrates trustworthy-AI characteristics across product lifecycle is the practice expected by GOVERN 1.2.
art17-qmsNIST AI RMF GOVERN 2.1 — Roles, responsibilities, and lines of communication for AI risk management are documentedQMS organisational charts and accountability matrices are the documented roles GOVERN 2.1 expects.
annexiv-harmonised-standardsNIST AI RMF GOVERN 1.1 — Legal and regulatory requirements involving AI are understood, managed, and documentedListing harmonised-standard alignment (ISO 42001/23894/24029) is the documented standards landscape GOVERN 1.1 expects.

Pro feature

Generate Article 11 with AI

LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.

Pro template

Download FRIA template

15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.

Get the 30-item EU AI Act compliance checklist

Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.


Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.