Our Solutions
A fully auditable Quality Management System for high-risk AI—aligned with EU AI Act Article 17 and structured around EN 18286.
Providers of high-risk AI systems must put a quality management system (QMS) in place under Article 17 of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). The QMS is not a single policy document—it is the operating system that ensures essential requirements are designed in, controlled through the lifecycle, evidenced in writing, and improved after market placement.
Data Protection Schemes delivers a technology-enabled AI QMS aligned with EN 18286 (European standard for a quality management system for AI systems). The platform is purpose-built so protection of health, safety, and fundamental rights is embedded in every process, record, and decision—supporting providers and Authorised Representative workflows with continuous, auditable control.
Article 17 requires providers to establish, implement, document, and maintain a QMS that ensures compliance with the AI Act. In practical terms, the QMS must cover—among other elements—regulatory strategy, design and development, verification and validation, data and data governance, technical documentation, risk management, post-market monitoring, serious incident handling, communication with authorities, and the resource and competence base that makes those processes effective.
Conformity assessment pathways (including internal control under Annex VI) expect the provider to be able to demonstrate that the QMS exists and that it is effective for the high-risk system in question—not merely described in a manual.
EN 18286 specifies requirements for a quality management system for AI systems under the EU AI Act framework. It follows the architecture of modern QMS standards (context, leadership, planning, support, operation, performance evaluation, improvement) but tailors them to AI:
EN 18286 also groups the AI Act’s essential requirements for high-risk systems (Chapter III, Section 2) into QMS “essentials,” so compliance strategy is coherent across risk, data, documentation, logging, transparency, oversight, and accuracy/robustness/cybersecurity.
At a high level, EN 18286 expects the QMS strategy to address the essential requirements for high-risk AI systems:
| EN 18286 essential | AI Act | Focus |
|---|---|---|
| (a) Risk management | Art. 9 | Continuous lifecycle risk process for health, safety, fundamental rights |
| (b) Data & data governance | Art. 10 | Data quality, governance, and training/validation/testing data controls |
| (c) Technical documentation | Art. 11 + Annex IV | Documented evidence of conformity for authorities and assessment |
| (d) Record-keeping | Art. 12 (+ 18/19) | Logging, retention, and controlled documented information |
| (e) Transparency | Art. 13 | Information to deployers; instructions for use |
| (f) Human oversight | Art. 14 | Oversight measures designed into the system and processes |
| (g) Accuracy, robustness, cybersecurity | Art. 15 | Performance, resilience, and security appropriate to the risk |
Internal/external issues, interested parties (including those whose rights may be affected), QMS scope, applicable regulatory requirements, compliance strategy, and control of documented information.
Top management commitment, quality policy, assignment of authority and accountability—including clear responsibilities for risk management addressing health, safety, and fundamental rights.
Actions to address risks to the QMS itself, quality objectives that are verifiable and monitored, and controlled planning of changes to the management system.
Resources, competence (including regulatory knowledge and awareness of risks to affected persons), communication, and documented information control throughout the lifecycle.
Operational planning and control; design and development; verification and validation; data processes; product documentation (including technical documentation aligned with Annex IV); control of nonconforming outputs. This is where AI-specific product realization is made auditable.
Deployment, operation, and support; supply chain controls; change management (including substantial modification); post-market monitoring; serious incident handling—linking real-world performance back into the QMS and risk management.
Monitoring and measurement of QMS effectiveness, internal audit, management review, nonconformity and corrective action, and continual improvement.
EN 18286-aligned practice emphasises that quality is not a one-off checklist. Across governance, design, operation, and monitoring, the same control disciplines should apply continuously:
Every significant record links to the AI system, version, purpose, and responsible parties—an unbroken chain for inspection and Authorised Representative cooperation.
Competent review and sign-off before release of controlled outputs—leadership accountability made operational, not symbolic.
Written evidence of planning, operation, and control; retention suitable for AI Act documentation and log-keeping duties.
Issues that could affect health, safety, or rights are captured, analysed, corrected, and checked for effectiveness—with links back to risk management.
Controlled evolution of systems and of the QMS itself—including assessment of substantial modifications and updates to technical documentation.
Clause 8 is the operational heart of EN 18286. At high level it requires providers to plan and control how AI systems are realized, including:
A QMS that stops at launch is incomplete under both Article 17 and EN 18286. High-level operational control includes:
DPS provides a comprehensive, real-time, fully auditable QMS environment aligned with EN 18286 and integrated with our Authorised Representative service:
Start with a Readiness Assessment to see QMS maturity gaps, or explore The DPS Advantage for the full compliance ecosystem.
Note: This page is a high-level overview for providers and stakeholders. EN 18286 and the AI Act contain detailed normative requirements. Harmonised-standard status and Annex ZA correspondence should be confirmed against the Official Journal for any presumption-of-conformity claims. DPS implements these frameworks in software and service practice; organisational configuration, training, and operational discipline remain essential to conformity.
ISO 9001 provides useful quality foundations, but Article 17 and EN 18286 expect AI-specific controls: lifecycle realization, essential requirements integration, risk management for health/safety/rights, technical documentation, human oversight, post-market monitoring, and AI-appropriate change control. Most generic QMS setups need substantial AI-specific extension.
Providers of high-risk AI systems. Non-EU providers typically combine the QMS with an EU Authorised Representative mandate (Articles 22/54 context) so authorities can access documentation and engage a responsible EU contact.
Technical documentation (Article 11 / Annex IV) is both an essential requirement and a product of controlled QMS processes. EN 18286 expects the QMS to generate and maintain that evidence—not to treat documentation as a one-time marketing pack.
Yes. DPS offers technology-enabled QMS as part of a complete compliance ecosystem alongside Authorised Representation, readiness assessment, and impact assessment—so mandate, evidence, and operational control stay coherent.
Talk to Data Protection Schemes about an EN 18286-aligned Quality Management System under Article 17—integrated with risk, impact assessment, and EU Authorised Representative services.
Get in Touch