EN 18286:2026 Published

Quality management system for AI systems
Practical guide — clause structure and text taken from the published illustration
Supports EU AI Act Regulation (EU) 2024/1689

Introduction

0.1 General · 0.2 Fundamental rights

0.1 General

The EU’s Artificial Intelligence (AI) Act regulates AI systems through the product safety system established under the New Legislative Framework. An AI system subject to the EU AI Act can be a product or a component of a product.

AI systems must be in compliance with applicable regulatory requirements at the moment that the AI system is placed on the market or put into service.

  • An AI system is placed on the market when it is supplied for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge.
  • An AI system is put into service when it is supplied for the first use directly to the deployer or for own use in the Union for its intended purpose.

A quality management system, while being implemented by a provider, can be directly associated with one or more AI systems that are intended to be put into service or placed on the market. Quality, in this context, can be understood as compliance with all of the regulatory requirements of the EU AI Act that apply to providers.

Depending on the context of the AI system, the provider can be required to show conformity with industry-specific quality management system requirements under sector-specific legislation. This document does not require the provider to maintain a separate quality management system, but can be used as complementary to existing requirements.

0.2 Fundamental rights

Fundamental rights are universal legal guarantees without which individuals and groups cannot secure their fundamental freedoms and human dignity and which apply equally to every human being regardless of nationality, place of residence, sex, national or ethnic origin, colour, religion, language or any other status.

The EU Charter of Fundamental Rights describes the European view on these fundamental rights. Further information about their scope and strength can be found in the Charter and in prEN 18228: Annex F.

4 Quality Management System

4.1 · 4.2 · 4.3 · 4.4 · 4.5

4.1 General

The provider shall establish, maintain, and continually improve the quality management system in accordance with the requirements of this document, and in order to protect health, safety, and fundamental rights.

The provider shall establish, document, implement, and maintain any process, procedure, and activity necessary to maintain the quality management system and its effectiveness in meeting applicable regulatory requirements throughout the applicable stages of the life cycle.

4.2 Identifying Regulatory Requirements

The provider shall determine and systematically review the regulatory requirements that these AI systems must comply with, at any point of their life cycle. This includes at least the essential requirements. The regulatory requirements identified shall be integrated into the strategy for regulatory compliance referred to in 4.4.

4.3 Determining the Scope of the Quality Management System

The provider shall determine the scope of the quality management system by:

  1. determining the set of AI system(s) that are covered under the quality management system;
  2. defining the boundaries, taking into account:
    1. the regulatory requirements referred to in 4.2;
    2. the intended purpose of the AI system(s).

4.4 Strategy for Regulatory Compliance

4.4.1 Determining the Strategy

The provider shall determine a strategy for compliance with regulatory requirements including at least the following elements:

  1. compliance with the regulatory requirements for this quality management system, in accordance with this document;
  2. compliance with essential requirements (see 4.4.2);
  3. compliance with the regulatory requirements for post-market monitoring, in accordance with 9.5;
  4. compliance with the regulatory requirements in relation to serious incidents, in accordance with 9.6;
  5. the strategy for data management, in accordance with 8.5.

The strategy shall be available as documented information, in accordance with 4.5.

4.4.2 Essential Requirements

Applicable Union harmonization legislation defines the essential requirements of products. They are written in a way that supports conformity assessment.

4.4.3 Selecting and Documenting Measures to Demonstrate Compliance

The provider selects approaches and documents the measures used to demonstrate compliance with each essential requirement.

4.5 Documented Information

Documented information required by the quality management system and this document shall be controlled. Retention periods shall satisfy applicable regulatory requirements.

5 Leadership

5.1 · 5.2 · 5.3

5.1 General

Top management shall ensure that the quality policy and quality objectives are established, that the resources needed for the quality management system are available, and that other relevant roles can carry out their roles effectively within their areas of responsibility.

5.2 Quality Policy

Top management shall establish a quality policy that is appropriate to the purpose of the organisation, includes a commitment to satisfy applicable requirements and to continually improve the QMS, and is communicated and understood within the organisation.

5.3 Roles, Responsibility, and Authorities

The provider shall assign supervision and responsibility for the quality management system. The assignment of roles and responsibilities shall ensure that the QMS is established, implemented, maintained and continually improved. Top management shall assign the responsibility and authority for ensuring that the QMS conforms to this document and for reporting on its performance. Roles may be outsourced; the provider retains accountability.

6 Planning

6.1 · 6.2

6.1 Actions to Address Risks Related to the Functioning of the Quality Management System

When planning for the quality management system, the provider shall determine the risks that need to be addressed to ensure the QMS can achieve its intended results, prevent or reduce undesired effects, and achieve continual improvement. The provider shall plan actions to address these risks, integrate and implement the actions into the QMS processes, and evaluate the effectiveness of the actions.

6.2 Quality Objectives and Planning to Achieve Them

The provider shall establish quality objectives at relevant functions, levels and processes. The objectives shall be consistent with the quality policy, measurable, take into account applicable requirements, and be monitored, communicated and updated as appropriate. When planning how to achieve quality objectives the provider shall determine what will be done, what resources will be required, who will be responsible, when it will be completed, and how the results will be evaluated.

7 Support

7.1 · 7.2 · 7.3 · 7.4

7.1 Resources

The provider shall determine and provide the resources needed for the establishment, implementation, maintenance and continual improvement of the QMS.

7.2 Competence

The provider shall determine the necessary competence of persons doing work under its control that affects the performance and effectiveness of the QMS and the quality of AI systems, ensure those persons are competent, take actions to acquire necessary competence, evaluate effectiveness of the actions, and retain appropriate documented information as evidence of competence.

7.3 Communication

The provider shall determine the internal and external communications relevant to the QMS, including what, when, with whom and how to communicate. This includes communication for regulatory purposes with competent authorities, notified bodies, deployers and other interested parties.

7.4 Awareness

Persons doing work under the provider’s control shall be aware of the quality policy, relevant quality objectives, their contribution to the effectiveness of the QMS, and the implications of not conforming with QMS requirements.

8 AI System Realization

8.1 · 8.2 · 8.3 · 8.4 · 8.5 · 8.6 · 8.7 · 8.8 · 8.9

8.1 Determining the Stages of the Life Cycle

The provider shall determine the stages of the life cycle and establish, document, implement and maintain processes and procedures appropriate to ensure that the AI system requirements are met and maintained across the AI system life cycle, needed to meet the requirements for the provision of each AI system, and needed to implement the actions determined in Clause 6.

These processes and procedures shall include techniques, procedures and systematic actions for design, design control and design verification; development, quality control and quality assurance; data management; examination, test and validation; post-market monitoring; and support.

8.2 Actions to Address Risks of AI Systems

The provider shall establish, implement, document and maintain a risk management system throughout the life cycle of each AI system, in accordance with regulatory requirements, aimed at achieving a high level of protection for health, safety, and fundamental rights. prEN 18228 can be used for this, in whole or in part.

8.3 Inception, Design, and Development

8.3.1 Inception

The provider shall determine the intended purpose of the AI system. The provider should consider consultation with interested parties regarding fundamental rights (see Annex A).

8.3.2 Design and Development

The provider shall determine AI system requirements for the intended purpose (including reasonably foreseeable misuse) that translate the applicable regulatory requirements into dimensions of explicit features. Requirements shall include accuracy, robustness, cybersecurity, transparency, human oversight, data and data governance, and record keeping according to the intended purpose, applicable regulatory requirements, requirements related to risk control measures, and other requirements essential for design and development. Requirements shall be reviewed for adequacy and approved. Design and development controls shall be applied.

8.4 Verification and Validation

The provider shall perform AI system verification and AI system validation. Design and development validation shall be completed prior to placing on the market or putting into service.

8.5 Data Management

The provider shall put in place a strategy to comply with applicable regulatory requirements relating to data management in accordance with 4.4. The provider shall define, document, and implement data management processes related to the design and development of each AI system, including (as appropriate and proportionate to risk) systems and procedures for data acquisition, collection, analysis, labelling, storage, filtration, mining, aggregation, retention, and any other operation regarding the data performed before and for the purpose of placing on the market or putting into service.

8.6 Retirement

The provider shall specify a mechanism for data no longer in use is destroyed, when each AI system is decommissioned. These mechanisms shall detail how data no longer in use is destroyed or archived to fulfill regulatory requirements. Data can be reused in certain situations, and destruction of data shall not conflict with the ability of the provider to comply with applicable regulatory requirements.

8.7 Identification of the AI system

8.7.1 The provider shall uniquely identify each AI system and each version of the AI system throughout its life cycle.

8.7.2 The identification shall enable unambiguous distinction between different AI systems and between different versions of the same AI system, including versions resulting from pre-determined changes (see 9.4.4).

8.7.3 The identification method shall include, as a minimum:

  1. a unique identifier for the AI system;
  2. a version identifier that changes whenever the AI system is modified in a way that can affect its performance, safety, or compliance with applicable regulatory requirements;
  3. where applicable, identifiers for the training data, models, and other critical components that form part of the AI system.

8.7.4 The provider shall maintain records that link the unique identification of the AI system and its versions to the corresponding technical documentation, risk management file, verification and validation records, and post-market monitoring data.

8.7.5 When an AI system is modified, the provider shall ensure that the identification is updated and that the updated identification is reflected in the technical documentation and, where applicable, in the instructions for use.

NOTE: Clear identification is necessary to support traceability, configuration management, change control, and communication with deployers, notified bodies, and competent authorities.

8.8 Continuous learning AI systems

Where an AI system is designed to continue learning after being placed on the market or put into service, the provider shall establish and maintain specific controls for continuous learning. The provider shall determine and document the boundaries of acceptable continuous learning (pre-determined changes). Pre-determined changes shall be subject to documented controls. The provider shall implement monitoring processes capable of detecting when the AI system moves outside those boundaries; any such excursion is treated as a change requiring the full modification process.

8.9 Product Documentation

8.9.1 Technical Documentation

For each AI system, the provider shall establish and maintain technical documentation. When the specifications for or characteristics of an AI system are changed, the provider shall ensure that outdated technical documentation is amended and communicated to interested parties, as applicable.

8.9.2 Instructions for Use

For each AI system, the provider shall establish and maintain instructions for use with information on how to use each AI system and its outputs. The instructions for use shall be written in a clear and accessible manner for the intended deployers and shall contain information, specifications and procedures for deploying and using each AI system so that it can operate in a manner that is fit for its intended purpose.

9 Operation and Control

9.1 · 9.2 · 9.3 · 9.4 · 9.5 · 9.6 · 9.7

9.1 Deployment, Operation, and Monitoring

The provider shall put into place procedures to ensure that the version of each AI system is controlled at deployment and is linked to the corresponding technical documentation, instructions for use, components, datasets and economic operators. Operation and monitoring procedures shall be maintained.

9.2 Support Services

The provider shall identify and provide the support necessary for deployers and end-users so that health, safety and fundamental rights continue to be protected during use.

9.3 Supply Chain

The provider shall evaluate, select, monitor and re-evaluate external providers of processes, products, components, data and services. Requirements shall be communicated and controls applied proportionate to risk. The provider retains accountability.

9.4 Modification to AI Systems

A change-management process shall cover planned and unintended changes. Consequences shall be reviewed against the risk-management system. Pre-determined changes (including those arising from continuous learning) shall follow documented verification/validation and impact assessment. Technical documentation and instructions for use shall be updated.

9.5 Post-Market Monitoring

A post-market monitoring system shall be established from the moment of placing on the market or putting into service until the system is no longer in use. Real-world data shall be collected and reviewed, new and emerging risks identified, and interaction with deployers maintained where direct monitoring is not possible.

9.6 Reporting Serious Incidents

The provider shall document, implement and maintain procedures for investigating serious incidents for causal links and for reporting them to competent authorities within the timelines required by the AI Act.

9.7 Non-compliance

When a nonconformity occurs, the provider shall react to it, evaluate the need for corrective action, implement any necessary action, review effectiveness, and update the QMS if required. Documented information on nonconformities and actions taken shall be retained.

10 Performance Evaluation

10.1 · 10.2

10.1 Management Review

The quality management system shall be reviewed at planned intervals to ensure its continuing suitability, adequacy and effectiveness. The review shall cover the quality policy, quality objectives, adherence to policies and procedures, effectiveness of risk-control measures, interested parties (particularly affected persons), and opportunities for improvement. A review shall also be conducted when an investigation of a serious incident finds the QMS or its measures inadequate. Applicable regulatory requirements shall be periodically reviewed for changes. Review documentation shall be retained.

Review outputs shall include decisions and actions related to improvement of the QMS and of AI systems, changes needed for new or revised regulatory requirements, and resource needs.

10.2 Planning of Changes

When the provider determines the need for changes to the quality management system, the provider shall specify and document the procedures required to manage the changes, carry out the changes in a planned and controlled manner, and systematically keep written evidence on implemented changes. Changes to scope and changes to processes shall be evaluated for their impact on the QMS and on each AI system and controlled accordingly.