Article 17
EU AI Act Article 17 — Quality Management System (QMS)
Article 17 of Regulation (EU) 2024/1689 requires providers to have a quality management system. The thirteen QMS aspects, ISO 9001 / ISO 42001 alignment, and the SME proportionality.
Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review
What Article 17 actually requires
Article 17 of Regulation (EU) 2024/1689 requires providers of high-risk AI systems to put in place a quality management system (QMS) that ensures compliance with the Regulation. The QMS must be documented in a systematic and orderly manner in the form of written policies, procedures and instructions.
Reg text — Article 17(1): "Providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation."
The thirteen QMS aspects
Article 17(1) lists the aspects the QMS must cover (paraphrased):
- (a) A strategy for regulatory compliance, including compliance with conformity-assessment procedures and procedures for the management of modifications to the high-risk AI system.
- (b) Techniques, procedures and systematic actions for the design, design control and design verification of the AI system.
- (c) Techniques, procedures and systematic actions for the development, quality control and quality assurance of the AI system.
- (d) Examination, test and validation procedures to be carried out before, during and after development.
- (e) Technical specifications, including standards, to be applied; where harmonised standards are not applied, the means used to ensure compliance.
- (f) Systems and procedures for data management, covering data acquisition, collection, analysis, labelling, storage, filtration, mining, aggregation, retention.
- (g) The Article 9 risk-management system.
- (h) The setting-up, implementation and maintenance of a post-market monitoring system.
- (i) Procedures for the reporting of serious incidents.
- (j) Communication with national competent authorities, notified bodies, customers and other relevant actors.
- (k) Systems and procedures for record-keeping.
- (l) Resource management, including security-of-supply measures.
- (m) An accountability framework setting out responsibilities of management and other staff.
Article 17(2) — proportionality
Article 17(2) explicitly states the QMS must be proportionate to the size of the provider's organisation. SMEs and start-ups can comply in a simplified manner. The Commission is required to publish guidance on simplified QMS for SMEs.
Article 17(3) — sector overlay
Where providers are subject to QMS obligations under sector-specific Union law (e.g., medical devices under MDR), Article 17(3) allows integration. The AI-specific elements layer on top of the existing sector QMS rather than replacing it.
Who is covered
All providers of high-risk AI systems. Article 25-promoted entities inherit the obligation for the modified variant.
What to do
- Build the QMS on top of an existing system if you have one — ISO 9001, ISO 27001, or sector-specific QMS regimes are good starting points.
- Map each Article 17(1) aspect to a specific document in your QMS — most teams use a one-row-per-aspect mapping spreadsheet.
- For the AI-specific aspects (data management, risk management, post-market monitoring, incident reporting), align with ISO/IEC 42001:2023 and ISO/IEC 23894:2023.
- Document an accountability matrix naming who owns what.
Inline crosswalk
- ISO/IEC 42001:2023 Clauses 4–10 (the entire AIMS) — the Article 17 QMS is its EU AI Act mandated form.
- NIST AI RMF GOVERN 1.2 — Trustworthy-AI characteristics integrated into organisational policies, processes, procedures.
- NIST AI RMF GOVERN 2.1 — Roles, responsibilities, lines of communication documented.
Common mistakes
- Building a QMS in parallel with rather than on top of existing systems. Article 17(3) explicitly invites integration.
- Skipping the accountability matrix (Article 17(1)(m)).
- No documented data-management procedure (Article 17(1)(f)).
- Generic post-market monitoring reference instead of an actual operational system.
Penalties
Article 99(4) — up to €15 million or 3% of worldwide annual turnover.
Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.
Reference checklist
From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.
Article 17 · Starter tier · medium
Set up quality management system (QMS)
Covers development, testing, validation, change management, post-market monitoring. Can build on ISO 9001 if you have it.
Annex IV · Pro tier · medium
List ISO/IEC 42001 + 23894 + 24029 alignment
Annex IV(2)(h) requires a list of harmonised standards applied in full or in part. ISO 42001 (AIMS), 23894 (risk), 24029 (robustness) are the core trio.
ISO 42001 + NIST AI RMF crosswalk
Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.
ISO/IEC 42001:2023
| Checklist item | ISO 42001 control | Rationale |
|---|---|---|
art17-qms | ISO/IEC 42001:2023 Clause 4 — Context of the organisation | Article 17 QMS includes scope, interested parties and AIMS boundaries — the substance of Clause 4 context. |
art17-qms | ISO/IEC 42001:2023 Clause 5 — Leadership and AI policy | A QMS that names accountable leadership and approves an AI policy satisfies the Clause 5 leadership requirements. |
art17-qms | ISO/IEC 42001:2023 Clause 9 — Performance evaluation | QMS internal audit, management review and KPI monitoring are exactly the practices required by Clause 9. |
annexiv-harmonised-standards | ISO/IEC 42001:2023 Clause 4.4 — AI management system | Listing harmonised-standard alignment (ISO 42001/23894/24029) is the AIMS-establishment evidence of Clause 4.4. |
NIST AI RMF 1.0
| Checklist item | NIST AI RMF subcategory | Rationale |
|---|---|---|
art17-qms | NIST AI RMF GOVERN 1.2 — The characteristics of trustworthy AI are integrated into organizational policies, processes, and procedures | A QMS that integrates trustworthy-AI characteristics across product lifecycle is the practice expected by GOVERN 1.2. |
art17-qms | NIST AI RMF GOVERN 2.1 — Roles, responsibilities, and lines of communication for AI risk management are documented | QMS organisational charts and accountability matrices are the documented roles GOVERN 2.1 expects. |
annexiv-harmonised-standards | NIST AI RMF GOVERN 1.1 — Legal and regulatory requirements involving AI are understood, managed, and documented | Listing harmonised-standard alignment (ISO 42001/23894/24029) is the documented standards landscape GOVERN 1.1 expects. |
Related
Pro feature
Generate Article 11 with AI
LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.
Pro template
Download FRIA template
15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.
Get the 30-item EU AI Act compliance checklist
Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.
Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.