What Art. 17 Requires
Any provider placing a high-risk AI system on the market cannot get around Art. 17 AI Act: it mandates the establishment of a quality management system (QMS) that ensures compliance with the Regulation. The key phrase is “documented in a systematic and orderly manner in the form of written policies, procedures and instructions” – an informal approach that exists only in people’s heads is not sufficient. The QMS is not a one-off document but an ongoing organisational framework that applies across the entire lifecycle of the system.
The Thirteen Mandatory Building Blocks at a Glance
Art. 17(1) exhaustively lists the minimum aspects that the QMS must cover. These include, among others:
- a strategy for regulatory compliance, including a change-management process (point (a)),
- procedures for design, development, quality control and quality assurance (points (b), (c)),
- examination, testing and validation procedures before, during and after development, including their frequency (point (d)),
- how technical specifications and harmonised standards are applied, particularly where these are not fully applicable (point (e)),
- systems for data management across the entire data lifecycle (point (f)),
- the integration of the risk management system under Art. 9 (point (g)),
- a post-market monitoring system in accordance with Art. 72 (point (h)),
- reporting procedures for serious incidents under Art. 73 (point (i)),
- communication with authorities, notified bodies, customers and other interested parties (point (j)),
- record-keeping systems for documentation and information (point (k)),
- resource management, including security of supply (point (l)),
- and finally an accountability framework setting out the responsibilities of management and staff for all these aspects (point (m)).
The QMS is therefore not an isolated document but the organisational framework that ties together risk management, documentation, market monitoring and incident reporting.
Proportionality, Not a One-Size-Fits-All Template
Art. 17(2) clarifies that implementation must be “proportionate to the size of the provider’s organisation”. A start-up with five employees does not need a QMS structure like a large corporation – but the Regulation nonetheless demands the same degree of rigour and level of protection in every case. Providers that already operate a quality management system under sector-specific Union law may integrate the aspects listed in paragraph 1 into that system (paragraph 3). Financial institutions subject to internal governance requirements under financial services law are deemed to comply with the QMS obligation – with the exception of the risk management system (point (g)), post-market monitoring (point (h)) and incident reporting (point (i)) – provided they comply with those governance rules (paragraph 4). These three exceptions therefore remain to be fulfilled separately even by financial institutions.
Typical Gaps in Practice
Three patterns emerge regularly during implementation:
First, the QMS is reduced to technical documentation without covering organisational elements such as the accountability framework (point (m)) or communication procedures with authorities (point (j)). A mere test log does not amount to a QMS.
Second, the link to the risk management system under Art. 9 and to post-market monitoring under Art. 72 is missing. Both are integral parts of the QMS under Art. 17(1), points (g) and (h), yet they are often run as separate, disconnected processes – with the result that operational insights are not systematically fed back into change management.
Third, the reporting obligation for serious incidents (Art. 73) is not embedded as a procedure within the QMS but handled on an ad hoc basis. Without a documented process – who reports what, to whom, and within what timeframe – delays arise in an emergency that can no longer be made up for legally.
Particularly among smaller providers, the proportionality clause in paragraph 2 is often misunderstood: it allows for leaner processes, but not for omitting individual aspects from paragraph 1.
Conclusion
A QMS under Art. 17 is more than paperwork – it is the structure that ties risk management, data quality, market monitoring and incident reporting into a verifiable whole. Anyone who is not yet sure whether their system even qualifies as high-risk AI, and what obligations follow from that, will find a free risk assessment as a first step at /einstufung.