Guide · Requirements · Article 17

What must a quality management system cover under Article 17 of the EU AI Act?

A provider of a high-risk AI system must have a documented quality management system that ensures compliance with the Regulation and covers at least the thirteen aspects listed in Article 17(1), from a regulatory compliance strategy to an accountability framework. The duty applies from 2 December 2027 for Annex III systems and from 2 August 2028 for systems under Section A of Annex I (Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744, read with Article 2(2), as replaced).

Written and last checked 9 October 2026 against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. Article 17(2) was replaced by Regulation (EU) 2026/1744; Article 17(1), (3) and (4) were not amended.

The short answer

  • Providers only: Article 16, point (c) has providers of high-risk AI systems keep one in place that complies with Article 17; a deployer carries it only if Article 25(1) makes it the provider.
  • At least thirteen aspects, in writing: every point of Article 17(1), from the compliance strategy in point (a) to the accountability framework in point (m).
  • Proportionate, not optional: implementation scales to the size of the provider's organisation, in particular for an SME, including a start-up, or an SMC; the degree of rigour and the level of protection still apply (Article 17(2), as replaced).
  • Existing systems count: a provider with quality management obligations, or an equivalent function, under sectoral Union law may include the aspects in that system (Article 17(3)); financial institutions subject to "requirements regarding their internal governance, arrangements or processes under Union financial services law" meet the duty through those rules, except for points (g), (h) and (i) (Article 17(4)).

What must the system include?

Article 17(1) requires a system "documented in a systematic and orderly manner in the form of written policies, procedures and instructions" that includes "at least the following aspects":

Points (g), (h) and (i) tie the system to Article 9's risk management system, Article 72's post-market monitoring and Article 73's serious incident reporting. For a provider under the AI Office's exclusive competence in Article 75(1), as replaced by Regulation (EU) 2026/1744, Article 75(1a) sends serious incident reports to the AI Office instead, by way of derogation from Article 73, with Article 73(2) to (9) applying mutatis mutandis. Our guide to EN 18286:2026 works through point (e) for one standard.

How much does a small provider have to do?

Article 17(2), as replaced by Regulation (EU) 2026/1744, makes the implementation of the aspects in paragraph 1 "proportionate to the size of the provider’s organisation, in particular, if the provider is an SME, including a start-up, or an SMC". Set against the 2024 wording, the words from "in particular" to "an SMC" are the only change. The unchanged second sentence holds every provider, "in any event", to "the degree of rigour and the level of protection required to ensure the compliance of their high-risk AI systems with this Regulation". The paragraph scales how the aspects are implemented and removes none. Article 3, points (14a) and (14b), inserted by the same Regulation, define an SME and an SMC by reference to Commission Recommendations.

Article 63(1), also replaced, now reads: "SMEs, including start-ups, may comply with certain elements of the quality management system required by Article 17 in a simplified manner, provided that they do not have partner enterprises or linked enterprises within the meaning of Recommendation 2003/361/EC." The 2024 text gave this to microenterprises only. Commission guidelines are to name the elements, "without affecting the level of protection or the need for compliance with the requirements in respect of high-risk AI systems". Article 63(1) sets them no date, so check whether they exist. It does not name SMCs. Article 63(2) adds that paragraph 1 exempts no one from any other requirement or obligation, including those in Articles 9 to 15, 72 and 73.

Can an existing quality management system carry Article 17?

Article 17(3) lets a sectoral system carry it: "Providers of high-risk AI systems that are subject to obligations regarding quality management systems or an equivalent function under relevant sectoral Union law may include the aspects listed in paragraph 1 as part of the quality management systems pursuant to that law." For systems under Section A of Annex I, Article 43(3), as replaced by Regulation (EU) 2026/1744, now provides: "Assessment of the quality management system set out in Article 17 shall also be undertaken, and points 3, 4.3, 4.4. and 4.5, the fifth paragraph of point 4.6 and point 5 of Annex VII shall apply." The 2024 wording had neither that assessment nor points 3 and 5. For systems high-risk under Article 6(1), Article 2(13), added by the same Regulation, provides that "the application of specific requirements or obligations laid down in Articles 9 to 15 and 17 to 25 may be limited, where and to the extent that" the Section A legislation provides an equivalent or higher level of protection of health, safety or fundamental rights and the limitation does not reduce the Regulation's overall level of protection. The Commission is to specify the systems, the requirements or obligations, the conditions and the scope by delegated acts by 2 August 2027; check whether it has. Commission guidelines on the practical implementation of Article 8(2), Article 9(10) and Article 17(3) alongside that legislation are due by 1 August 2027 (Article 96(1), first subparagraph, point (g), as added).

Article 17(4) deems the duty fulfilled for financial institutions, except for three points: "For providers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law, the obligation to put in place a quality management system, with the exception of paragraph 1, points (g), (h) and (i) of this Article, shall be deemed to be fulfilled by complying with the rules on internal governance arrangements or processes pursuant to the relevant Union financial services law. To that end, any harmonised standards referred to in Article 40 shall be taken into account." The risk management system, the post-market monitoring system and the serious incident procedures are therefore met under Article 17 itself.

When does Article 17 apply?

Article 17 is in Chapter III, Section 3, which Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744, applies from 2 December 2027 for systems high-risk under Article 6(2) and Annex III and from 2 August 2028 for systems high-risk under Article 6(1) and Annex I. The conformity assessment precedes placing on the market or putting into service (Article 16, point (f)) and verifies the quality management system (point 2 of Annex VI and point 3 of Annex VII), so the quality management system has to exist by then.

Article 17 does not reach systems related to products under Section B of Annex I. The provisions Article 2(2), as replaced, applies to them are Article 6(1), Article 60a and Articles 102 to 112, with Articles 57, 58 and 59 only in so far as the high-risk requirements have been integrated in that legislation. Regulation (EU) 2026/1744 deleted Directive 2006/42/EC on machinery from Section A and added Regulation (EU) 2023/1230 on machinery to Section B (point (41) of its Article 1). Its Article 3 has the Commission add health and safety requirements to Annex III to Regulation (EU) 2023/1230, by delegated acts, for AI systems that are high-risk under Article 6(1) as a safety component of a machinery product or as such a product, and those requirements must reflect the relevant Chapter III, Section 2 requirements and Articles 17, 19, 72 and 73.

Three provisions Article 17 relies on keep 2 August 2026. Articles 72 and 73, in Chapter IX, take the general date (Article 113, second paragraph); Article 43, the conformity assessment, sits in Chapter III, Section 5, which point (c) does not defer. Regulation (EU) 2026/1744 does not say how they operate while the classification rules in Section 1 are not yet in application. That question is open, and we leave it open.

For a high-risk system placed on the market or put into service before the date of application of Chapter III, other than the systems Article 111(1) covers, Article 111(2), as replaced, applies the Regulation only if, as from that date, the system is subject to significant changes in its design; if it is intended to be used by public authorities, its providers and deployers take the necessary steps to comply by 2 August 2030 in any case. Article 111(2) names that date in the singular while Article 113 now gives two, and the text does not resolve which governs.

What does Complipath do here, and what does it not?

The AI inventory records each system with its classification and the article behind it. Each duty that follows carries an owner, a status and a date; evidence is linked with the passage and its page; Annex IV documentation is drafted from the register and says which limbs it could not answer; and a change to a provision your records cite is emailed per affected system.

Three aspects of Article 17(1) rest on processes the status table marks Not supported. Point (g): Article 9 is listed as a duty with its date, and there is no risk register to run the cycle in. Point (h), post-market monitoring (Article 72): we found no support for this in what we have built. Point (i), serious incident reporting (Article 73): the same. Conformity assessment (Article 43), where the quality management system is verified: we found no support for this in what we have built either. The full table is on what Complipath is.

What this means for you

If you're a provider: write a procedure under each of the thirteen points; Article 17(1) asks for written policies, procedures and instructions. Include the aspects in a quality management system, or an equivalent function, you already keep under sectoral Union law (Article 17(3)) rather than build a second one; under Article 17(4), points (g), (h) and (i) stay on your own list. An SME should confirm it has no partner or linked enterprises before counting on Article 63(1).

If you're a deployer: Article 17 is yours only if Article 25(1) makes you the provider: you put your name or trademark on a high-risk system already on the market or in service, without prejudice to contracts allocating the obligations otherwise; you substantially modify such a system so that it remains high-risk; or you change the intended purpose of a system already on the market or in service that was not classified as high-risk, including a general-purpose AI system, so that it becomes high-risk. When a deployer becomes a provider has the detail.

FAQ

Does a start-up need a full quality management system? It must cover every aspect of Article 17(1), but Article 17(2), as replaced, scales implementation to the organisation's size, in particular for an SME, including a start-up, or an SMC, while keeping the degree of rigour and the level of protection. An SME without partner or linked enterprises may comply with certain elements in a simplified manner under Article 63(1).

Can we reuse the quality management system we already have? Yes. Under Article 17(3), a provider with quality management obligations, or an equivalent function, under sectoral Union law may include the Article 17(1) aspects in that system. Under Article 17(4), financial institutions subject to "requirements regarding their internal governance, arrangements or processes under Union financial services law" meet the duty through those rules, except for points (g), (h) and (i).

Who checks our quality management system? For points 2 to 8 of Annex III, the provider itself, by internal control under Annex VI, with no notified body. For biometric systems in point 1, Article 43(1) requires or allows Annex VII, under which a notified body assesses it. Systems under Section A of Annex I have it assessed in their legislation's procedure (Article 43(3), as replaced).

How long must we keep the quality management system documentation? For a period ending 10 years after the system has been placed on the market or put into service, at the disposal of the national competent authorities (Article 18(1), point (b)). Each Member State sets conditions under which it stays available if the provider or its authorised representative established there goes bankrupt or ceases its activity first (Article 18(2)).

Sources: Regulation (EU) 2024/1689 (EUR-Lex), Article 2(2) and (13), Article 3, points (14a) and (14b), Article 6(1) and (2), Article 8(2), Article 9, Article 16, Article 17, Article 18, Article 25(1), Article 40, Article 43, Article 63, Article 72, Article 73, Article 75(1) and (1a), Article 96(1), Article 111(1) and (2), Article 113, point 2 of Annex VI and point 3 of Annex VII; as amended by Regulation (EU) 2026/1744 (EUR-Lex), which replaced Article 2(2), Article 17(2), Article 43(3), Article 63(1), Article 72(3), Article 75(1), Article 111(2) and Article 113, third paragraph, point (c). It inserted Article 3, points (14a) and (14b), Article 6(1a), (1b) and (1c) and Article 75(1a). It added Article 2(13) and Article 96(1), first subparagraph, point (g). Point (41) amended Annex I, and its Article 3 amends Regulation (EU) 2023/1230. Article 17(1), (3) and (4) were not amended.

Where this question meets the product: AI Act technical documentation software. Answering it in a customer's questionnaire: how to answer AI questions in a supplier questionnaire.

Read nextAI Act declaration of conformity (Article 47)Article 47 and Annex VEU AI Act post-market monitoring (Article 72)Article 72AI Act serious incident reporting (Article 73)Article 73

See which of your AI systems the Act covers.

No account needed. Every answer cites the article it rests on.

Get your free readiness review

Check your AI systems, free