Documentation and version control are not peripheral administrative tasks under prEN 18286 - they are foundational, normative requirements that underpin the entire Quality Management System (QMS) and its integration with the risk management system (Article 9). Without robust, traceable, and controlled documentation, it is impossible to demonstrate that risks to health, safety, and fundamental rights have been systematically identified, evaluated, mitigated, and monitored throughout the AI lifecycle.
Regulatory Foundation: Why Documentation and Version Control Are Mandatory
Article 17 requires the QMS to be "documented in a systematic and orderly manner in the form of written policies, procedures and instructions" and maintained throughout the lifecycle. prEN 18286 (primarily Clause 7.5 - Documented Information, supported by Clauses 6-10) elevates this into a normative pillar:
- Traceability & Accountability: Every risk decision, mitigation measure, validation result, post-market finding, and change must be traceable to its origin, rationale, approver, and evidence.
- Auditability & Defensibility: Notified bodies, market surveillance authorities, and affected persons (via transparency rights) must be able to verify compliance; undocumented or uncontrolled records constitute major non-conformities.
- Continual Improvement & Learning: Only version-controlled records allow comparison over time, trend analysis, and demonstration that corrective actions were effective.
- Risk Management Integration: The risk management system (RMS) relies on documented risk registers, mitigation plans, residual risk evaluations, and monitoring results - all of which must be controlled under QMS document management.
Structural Requirements: How prEN 18286 Mandates Documentation & Version Control
Clause 7.5 (Documented Information) and related clauses typically require the following controls:
- Identification & Control: All QMS documents must be uniquely identified, versioned, dated, approved, and protected against unintended changes/loss.
- Approval & Review: Documents require defined approval authorities; changes must be reviewed, approved, and recorded before implementation.
- Version History & Traceability: Maintain revision history showing what changed, why, when, and by whom; link versions to risk assessments, change requests, and management reviews.
- Retention & Availability: Retain records for at least 10 years (Article 18); ensure current versions are accessible to relevant personnel while obsolete versions are archived and clearly marked.
- Integration with RMS: Risk management outputs must be version-controlled and referenced in technical documentation (Annex IV) and post-market monitoring records.
In summary
prEN 18286 positions documentation and version control as the backbone of both the QMS and regulatory compliance risk management - ensuring that every risk decision, mitigation action, and lifecycle change is traceable, verifiable, and defensible, thereby achieving the EU AI Act's core objective of safe, transparent, and rights-respecting high-risk AI throughout its entire lifecycle.
Content based on the EU AI Act (Regulation (EU) 2024/1689), Articles 9 & 17, and the prEN 18286 draft standard. The standard remains under revision; always consult the latest CEN/CENELEC drafts, EU AI Office guidance, and legal experts for implementation. High-risk provisions become fully applicable on 2 August 2026.