Once harmonized, full conformance with EN 18286 will provide providers of high-risk AI systems a presumption of conformity with Article 17 of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), including the explicit requirements for documented roles, responsibilities, authorities, and competence under Article 17(1)(m) and related elements.
EN 18286 (primarily Clause 5.3 on organizational roles, responsibilities and authorities, supported by competence/resource clauses such as 7.2) requires that job descriptions (or equivalent documented role definitions) be established for all personnel involved in the QMS and high-risk AI lifecycle. These descriptions must clearly define responsibilities, authorities, required competence, and reporting lines, ensuring traceability and alignment with regulatory compliance objectives. This article articulates the requirement for job descriptions from regulatory, structural, practical, and strategic perspectives, with expanded practical examples illustrating real-world application in high-risk AI contexts, including content expectations, documentation formats, linkage to other QMS elements, edge cases, and implications for high-risk AI providers.
Regulatory Foundation: Why Job Descriptions Are Mandatory
Article 17(1)(m) requires a documented accountability framework that assigns responsibilities to management and other staff for all aspects of the QMS. EN 18286 operationalizes this through normative requirements (typically Clause 5.3) that mandate documented definitions of roles, responsibilities, and authorities. Job descriptions serve as the primary vehicle for this documentation, ensuring:
- Clear, unambiguous assignment of duties across the 13 QMS elements (risk management, data governance, post-market monitoring, incident reporting, etc.).
- Traceable accountability for compliance with health, safety, and fundamental rights obligations throughout the AI lifecycle.
- Linkage between assigned duties and required competence, enabling verification during conformity assessment and market surveillance audits.
- Prevention of responsibility gaps, especially in complex, multi-disciplinary, or outsourced high-risk AI projects.
Job descriptions are not optional HR paperwork; they form an auditable component of the QMS and must be maintained, communicated, and reviewed as part of continual improvement and management oversight (typically Clause 9).
Content Requirements: What Job Descriptions Must Include under EN 18286
While EN 18286 does not prescribe a rigid template, it requires job descriptions (or equivalent role definition documents) to be sufficiently detailed and systematic. Core elements typically include:
- Role Title & Organizational Placement: Clear title and position within the structure.
- Key Responsibilities: Specific duties tied to Article 17 elements and lifecycle stages.
- Authorities: Decision-making power and escalation rights.
- Competence & Qualification Requirements: Minimum education, training, experience, and skills needed.
- Reporting Lines & Interfaces: Who the role reports to, who reports to the role, and key internal/external interfaces.
- Link to Quality Policy & Objectives: Reference to how the role contributes to the quality policy and specific quality objectives.
Below are practical examples showing how these elements appear in real high-risk AI contexts:
Example 1: AI Risk Management Lead (in a healthcare diagnostic AI provider)
- Title: Senior AI Risk & Compliance Lead
- Reports to: Chief Quality & Regulatory Officer
- Key Responsibilities: Lead implementation and maintenance of the Article 9 risk management system; conduct and document bias and robustness risk assessments for every training/validation cycle; approve risk mitigation plans before model updates.
- Authorities: Authority to pause model training/deployment if residual risk exceeds acceptable levels; request cross-functional resources for risk investigations.
- Competence: Degree in statistics/machine learning + 5+ years in AI safety/risk management + certified ISO/IEC 42001 Lead Implementer or equivalent.
- Link to Objective: Directly supports Quality Objective 2 - "Achieve zero critical residual risks to patient safety in validation datasets by Q4 2026".
Example 2: Post-Market Monitoring Coordinator (in an employment screening AI company)
- Title: Post-Market Surveillance & Performance Analyst
- Reports to: Head of AI Governance
- Key Responsibilities: Collect and analyze real-world performance data per Article 72 plan; detect and document performance degradation or bias drift; prepare monthly performance reports for management review.
- Authorities: Escalate detected serious incidents to top management within 24 hours; initiate corrective action plans for detected weaknesses.
- Competence: Degree in data science + experience with statistical process control + training in EU AI Act post-market obligations.
- Link to Policy: Fulfills quality policy commitment to "ongoing protection of fundamental rights through proactive performance monitoring".
Example 3: Data Governance Specialist (in a law enforcement facial recognition system)
- Title: Data Quality & Governance Engineer
- Reports to: Chief Data Officer
- Key Responsibilities: Ensure training/validation/test datasets meet Article 10 quality criteria; maintain data provenance logs; perform representative sampling checks for protected characteristics.
- Authorities: Reject datasets that fail minimum quality thresholds; require re-collection or augmentation before proceeding to model training.
- Competence: Degree in data engineering + GDPR/AI Act data protection training + practical experience in fairness auditing tools.
- Link to Objective: Supports Quality Objective 4 - "Maintain =98% demographic parity in validation datasets across all protected groups".
Practical Implementation: Creating, Communicating, and Maintaining Job Descriptions
Providers implement the requirement proportionally while ensuring audit-ready substance:
- Development: Map all QMS/lifecycle activities to roles via responsibility assignment matrices (RACI); translate into individual job/role descriptions; involve role incumbents and top management for accuracy.
- Formats & Tools: Use standardized templates, organizational charts with annotations, RACI matrices supplemented by detailed role profiles, or integrated HR/QMS platforms; include version control and approval signatures.
- Communication & Training: Distribute descriptions during onboarding, role changes, and periodic refresher training; ensure personnel understand their duties, authorities, competence expectations, and how they support regulatory compliance.
- Review & Update: Review descriptions during management reviews, after substantial AI system modifications, organizational changes, or audit findings; update to reflect new risks, objectives, or regulatory clarifications.
Edge case: In continuously learning systems, job descriptions for monitoring/validation roles must explicitly include responsibility for detecting and escalating uncontrolled adaptation or drift. For outsourced functions, providers must ensure supplier job/role descriptions align with QMS requirements via contracts and controls (supplier management clause).
Integration, Nuances, and Strategic Implications
EN 18286 is compatible with ISO 9001 (Clause 5.3), ISO/IEC 42001 (leadership and competence clauses), and sectoral QMS frameworks (e.g., ISO 13485); organizations extend existing job description templates with AI Act-specific elements (named accountability for risk/incident functions, rights/safety focus). This layered approach avoids redundancy while preparing for presumption of conformity.
Benefits include enhanced clarity (reducing miscommunication), stronger audit defensibility (traceable duties), and cultural reinforcement (personnel understand their compliance impact). Challenges: administrative burden for SMEs, resistance to detailed documentation, and transition uncertainty until citation. Best practice: conduct a gap analysis against draft EN 18286 Clause 5.3, standardize role templates for high-risk AI projects, and monitor CEN updates/EU AI Office guidance closely.
Summary
In essence, EN 18286 elevates job descriptions from administrative records to critical QMS instruments: they must clearly, comprehensively, and verifiably define who does what, with what authority, and with what competence - ensuring every high-risk AI activity is performed by accountable, qualified personnel aligned with regulatory objectives.
Content based on the EU AI Act (Regulation (EU) 2024/1689), Article 17, and the EN 18286 QMS draft standard. The standard remains under revision; always consult the latest CEN/CENELEC drafts, EU AI Office guidance, and legal experts for implementation. High-risk provisions, including Article 17 QMS, become fully applicable on 2 August 2026.