AI Assurance Institute Logo AI Assurance Institute

The Scope of the Quality Management System (QMS)
under the EU AI Act (EN 18286)

AI Quality Management Systems Series

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) continues its phased implementation, with the full suite of high-risk AI obligations - including the Quality Management System (QMS) mandated by Article 17 - scheduled to apply from 2 August 2026. The QMS is a foundational, lifecycle-spanning requirement for providers of high-risk AI systems (as listed in Annex III, spanning biometrics, critical infrastructure, education, employment, law enforcement, migration, justice, and essential services). Its scope is deliberately broad and integrative: it encompasses the entire AI system lifecycle (from design and development through deployment, monitoring, to decommissioning) and serves as the overarching framework to ensure and demonstrate ongoing compliance with all essential requirements in Chapter III, Section 2 (risk management, data governance, transparency, human oversight, robustness, accuracy, cybersecurity, etc.). This article explores the QMS scope from regulatory, lifecycle, operational, and boundary perspectives, incorporating insights from the draft harmonized standard EN 18286 and practical nuances for implementation.

Regulatory Scope: What the QMS Covers and Why It Is Broad

Under Article 17(1), providers of high-risk AI systems must establish, implement, document, and maintain a QMS that ensures compliance with the entire Regulation. The scope is explicitly holistic and preventive: it addresses not only initial conformity but also continuous compliance across the system's lifecycle, including adaptation to changes, emerging risks, and post-market realities. Article 17(1) mandates that the QMS be documented systematically (policies, procedures, instructions) and cover at least 13 enumerated aspects, which collectively integrate and operationalize the Act's core high-risk obligations.

The QMS is not a narrow quality-control checklist; it is the procedural and governance backbone that makes self-assessment (Annex VI), notified-body conformity assessment (Annex VII), CE marking, and market access possible. Its broad scope reflects the Act's risk-based philosophy: high-risk systems demand systematic, auditable accountability across all phases and actors.

The 13 Mandatory Elements: Detailed Scope of Coverage (Article 17(1))

The Act lists 13 aspects that the QMS must address, providing concrete delineation of its scope. These elements are mandatory minimums; providers may expand them as needed. Grouped thematically for clarity:

  1. Regulatory compliance strategy (conformity assessment procedures, modification/change management).
  2. Design, design control, and design verification techniques/procedures.
  3. Development, quality control, and quality assurance techniques/procedures (including testing, validation, and examination at defined frequencies).
  4. Technical specifications, standards/solutions chosen to meet essential requirements, and data management systems (analysis, labeling, storage, aggregation, retention - linking to Article 10 data quality).
  5. Risk management system integration (lifecycle risk identification, evaluation, mitigation - per Article 9).
  6. Post-market monitoring system and ongoing compliance evaluation (Article 72).
  7. Incident reporting and management procedures (serious incidents to authorities per Article 73, with timelines).
  8. Communication protocols (with competent authorities, notified bodies, users/deployers, customers).
  9. Record-keeping and documentation management (including 10-year retention per Article 18).
  10. Resource management (ensuring adequate competence, training, and resources - human, technical, financial).
  11. Accountability framework (clear roles, responsibilities, top-management commitment and oversight).
  12. Corrective and preventive actions (non-conformity handling, continuous improvement).
  13. Supplier and third-party controls (supply-chain governance for components, data, services).
  14. Overall documented quality policy endorsed by senior management.

Edge cases within scope: Continuously learning/adaptive systems require explicit change-control and re-validation procedures; substantial modifications may re-classify the entity as a provider and trigger full QMS re-application. The scope is product- and lifecycle-centric, not merely organizational.

Boundaries and Applicability: What the QMS Scope Does NOT Cover

While broad, the QMS scope has defined limits under the Act:

The QMS scope is high-risk-provider-specific and lifecycle-focused; it does not impose organization-wide AI governance for all AI uses, though many providers extend similar principles voluntarily to lower-risk or non-EU contexts.

EN 18286 Draft and Emerging Guidance on QMS Scope

The draft harmonized standard EN 18286 ("Quality Management System for EU AI Act Regulatory Purposes") elaborates the Article 17 scope with a lifecycle-centric, product-focused framework compatible with ISO 9001, ISO 13485, and ISO/IEC 42001. It reinforces broad coverage (design to retirement), emphasizes competence/training, supply-chain controls, feedback from affected persons, environmental considerations, and auditability. The draft failed the January 2026 enquiry vote due to insufficient support; with 1,288 comments under review, discussions continue in early March 2026, with potential revisions and further voting expected soon. Final publication (likely late 2026 or beyond) will grant presumption of conformity once cited in the Official Journal.

Content based on the EU AI Act (Regulation (EU) 2024/1689) and EN 18286 draft standard. Always consult official sources, the EU AI Office, and legal experts for compliance. High-risk provisions, including Article 17 QMS, become fully applicable on 2 August 2026.