AI Governance, Risk & Red Teaming
Strategic · M14 · lesson 14 of 25 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Building the Article 17 Quality Management System (QMS) for AI
📖
now learning

Building the Article 17 Quality Management System (QMS) for AI

15 min

In late February 2026 Acme Inc's newly appointed Chief AI Officer and the Chief Quality Officer sat across a 1990s-era ISO 9001 quality manual in a conference room above the Stuttgart factory floor. The Stage 1 audit for ISO 42001 was 90 days out. The Annex VII Module H pre-audit by the notified body was scheduled for Q3 2026. The CQO had spent twenty-eight years building a quality system with an unbroken record across BS 5750, every ISO 9001 revision, and German DAkkS surveillance audits feeding industrial machinery and medical-device businesses. The manual was 412 pages, the SOP library was 230 documents, and document control had withstood the MDR transition in 2021 without a single major nonconformity. None of it, not one of the thirteen elements, addressed any requirement in EU AI Act Article 17(1)(a) through (m) specifically. The compliance-strategy element existed, but it didn't reference Article 9 risk management, Article 10 data governance, Article 14 oversight, or Article 72 post-market monitoring for AI. The design-control SOPs assumed mechanical-engineering V-models, not ML-eval suites. Data-management procedures were physical-sample chains-of-custody, not lineage-tracked training datasets. The CQO closed the manual and asked the question every quality professional in Europe is asking in 2026: "Do we extend the existing QMS, or do we build a parallel AI-QMS and reconcile them later?" This lesson is the L4 leadership-tier answer: how to build a defensible Article 17(1) QMS satisfying the thirteen elements, the Annex VII Module H assessed-entity expectation, ISO/IEC 42001:2023 AIMS, ISO 9001:2015, ISO/IEC 27001:2022 ISMS, and ISO/IEC 27701:2019 PIMS through one integrated management system delivering one audit binder, one document-control regime, and one surveillance cycle. The integration economics, 30-50% reduction in audit-evidence redundancy, are the difference between a 4-month build and a 12-month rebuild after a failed Stage 1.

Article 17 - The Thirteen Elements and Why the QMS Is Itself the Module H Assessed Entity

EU AI Act Article 17(1) requires every provider of a high-risk AI system to "put in place a quality management system that ensures compliance with this Regulation." The Article doesn't suggest, recommend, or encourage. It requires. The QMS is mandatory, written, kept up to date, and proportionate to the size of the provider's organisation. The provision then enumerates thirteen elements the QMS shall include, Article 17(1)(a) through (m). These are not framework suggestions; they are statutory minima against which a notified body will audit under Annex VII point 3 (assessment of the quality management system) and against which a competent authority will assess penalty exposure under Article 99(3) for material QMS gaps.

The thirteen elements, in the order the Regulation lists them, map to discrete documentation deliverables and operational evidence. (a) Regulatory compliance strategy: the provider's overall approach to meeting AI Act obligations, including the cross-walk register naming each obligation, each documentary deliverable, each control owner, and each evidence cadence (lessons 070 vendor-pattern cross-walks; lesson 077 CAF charter cross-walk). (b) Techniques, procedures, and systematic actions for design, design control, and design verification: the SDLC governing AI/ML model development, design-review records, design-change control, ML-engineering work instructions. (c) Examination, test, and validation procedures: the evaluation-suite registry, V&V plan, red-team library (lessons 059-066), IMV operating evidence (lesson 068). (d) Technical specifications, including standards, to be applied and, where the relevant harmonised standards are not applied in full, the means to ensure conformity: the standards-applied register, gap-analysis log, and means-of-conformity justification. (e) Systems and procedures for data management: datasheets (lesson 028), Article 10 data-governance documentation, provenance records (lesson 037), data-quality framework. (f) The risk management system referred to in Article 9: the AI risk-management plan, risk register, FRIA where applicable (lessons 044-048), model-risk policy. (g) The establishment, implementation, and maintenance of a post-market monitoring system in accordance with Article 72: PMM plan, KPI dashboard, drift-detection methodology, review cadence (lesson 080). (h) Procedures related to the reporting of a serious incident in accordance with Article 73: incident-classification rubric, 15-day standard / 2-day critical-infrastructure widespread / 10-day serious-and-irreversible-disruption timelines (lesson 025), templates, escalation paths. (i) The handling of communication with national competent authorities, notified bodies, other operators, customers, or other interested parties, communications register including the Annex XII downstream-deployer package and the Article 86 whistleblower channel. (j) Systems and procedures for record-keeping of all relevant documentation and information: document-control regime, evidence-retention plan (10+ years per Article 18 for technical documentation, declarations, and certificates). (k) Resource management, including security-of-supply-related measures: trained staff inventory, AI literacy operating evidence (lesson 033), independent-challenge capability for second-line review. (l) An accountability framework setting out the responsibilities of the management and other staff with regard to all aspects listed in this paragraph: role assignments, reporting lines, sign-off matrices, RACI register. (m) Where applicable, the application of relevant standards and technical specifications: ISO/IEC 42001:2023, ISO/IEC 23894:2023, ISO/IEC 5338:2023 (AI system lifecycle), ISO/IEC 22989:2022 (AI concepts and terminology), and harmonised standards under Article 40 once CEN-CENELEC JTC 21 finalises them (current expectation Q4 2027 / Q1 2028).

The architectural detail most providers miss in 2026 is the Annex VII Module H interplay. Module H is "full quality assurance." Annex VII point 3 explicitly makes the QMS itself the assessed entity, not merely supporting evidence behind the technical file. Point 3.1 requires the provider to lodge an application for QMS assessment with a notified body of its choice. Point 3.2 requires documentation covering all aspects listed in Article 17. Point 3.3 requires the notified body to determine whether the QMS satisfies Article 17. Point 3.4 requires the QMS audit team to have proven AI Act knowledge. Point 4 then specifies the technical-documentation assessment as a separate workstream within the same engagement. A defensible Article 17 QMS does double duty, operating system for daily compliance and certified deliverable under the conformity-assessment route. A weak QMS fails the assessment outright, blocking certificate issuance even where the technical file is strong.

Two further regulatory hooks tighten expectations. Article 17(2) authorises the Commission to specify additional aspects through implementing acts, expect harmonised-standard-driven elaboration during 2027-2028. Article 17(3) provides a calibration: credit institutions regulated under Directive 2013/36/EU may have their existing QMS deemed to fulfil parts of the AI Act QMS requirement. This is the principal sectoral integration provision; the SR 11-7 model-risk governance pillar fulfils a similar function under U.S. prudential supervision (lesson 067). Outside banking, no such deeming exists, every Annex III provider builds its own Article 17 QMS. The Acme dilemma has one defensible answer: a single integrated management system (IMS) mapping Article 17 elements onto an ISO 42001 AIMS chassis with ISO 9001 quality, ISO 27001 security, and ISO 27701 privacy controls integrated as cross-walked sub-systems. The 412-page legacy manual becomes one section among sixteen, not the chassis itself.

ISO 42001 + ISO 9001 Coordination and the QMS Manual - The Sixteen-Section Template

The standards landscape for an Article 17 QMS pulls from three sources. ISO 9001:2015 is the general QMS baseline: clauses 4-10 cover context, leadership, planning, support, operations, performance evaluation, improvement. Necessary but insufficient for AI: nothing in ISO 9001 addresses ML data lifecycle, model risk, or AI-specific oversight. ISO/IEC 42001:2023 is the AI-specific AIMS: clauses 4-10 mirror ISO 9001's Annex SL high-level structure; Annex A enumerates 38 controls across nine objectives covering AI-specific risk, data lifecycle, third-party AI, customer obligations, transparency, and impact assessment. ISO/IEC 23894:2023 provides the AI risk-management methodology (referenced by ISO 42001 Clause 6.1.2/6.1.3 and operationalising AI Act Article 9). Two further AI standards supply terminology and lifecycle scaffolding: ISO/IEC 22989:2022 (AI concepts and terminology) and ISO/IEC 5338:2023 (AI system life cycle processes). For security and privacy, ISO/IEC 27001:2022 (ISMS) and ISO/IEC 27701:2019 (PIMS) supply controls the Article 17 QMS reuses rather than duplicates.

The Article 17 QMS sits at the intersection. The defensible architecture is one QMS manual with sixteen sections, eleven mirroring Annex SL high-level structure (familiar to any ISO-9001/27001-certified organisation) and five providing AI-specific extensions Article 17 requires.

Section 1 - Purpose. States the QMS ensures conformity with AI Act Article 17, ISO/IEC 42001:2023, ISO 9001:2015, ISO/IEC 27001:2022, ISO/IEC 27701:2019 through one integrated management system. Names scope, issuing authority (CEO + CQO co-signed), and identifies the policy as apex document. Section 2 - Scope. Defines systems (named AI products against Annex III), legal entities (subsidiaries by country), geographies (EU + UK + extraterritorial under Article 2), exclusions (research-only, internal-only pre-market). The scope statement is the audit boundary, tight definition halves evidence collection. Section 3 - Terms and definitions. References ISO/IEC 22989:2022, ISO/IEC 5338:2023, AI Act Article 3 definitions (provider, deployer, distributor, importer, authorised representative), ISO 9001 general terms, avoids redefining terms upstream sources already define. Section 4 - Normative references. ISO/IEC 42001:2023, ISO 9001:2015, ISO/IEC 27001:2022, ISO/IEC 27701:2019, ISO/IEC 23894:2023, ISO/IEC 22989:2022, ISO/IEC 5338:2023, ISO 19011:2018, harmonised standards under Article 40 as published.

Section 5 - Context of the organisation. Internal/external context (clause 4.1), interested parties (4.2), determined scope (4.3). External context includes Annex III categorisation, harmonised-standard maturity, notified-body availability, Omnibus VII timeline, competing jurisdictions (Colorado AI Act, Texas TRAIGA, NYC LL-144, lessons 013-015). Section 6 - Leadership. Top-management commitment (5.1), AI policy (5.2), roles/responsibilities/authorities (5.3). Article 17(1)(l) accountability framework lives here. Names the Responsible AI Officer / CAIO with explicit authority. References the AI Governance Committee charter (lessons 077, 042). Section 7 - Planning. Actions for risks/opportunities (6.1), AI objectives (6.2), planning of changes (6.3). Article 17(1)(f) and Article 9 risk-management plan live here; ISO/IEC 23894:2023 is the cited methodology. Section 8 - Support. Resources (7.1), competence (7.2), awareness (7.3), communication (7.4), documented information (7.5). Article 17(1)(i) communications and (k) resource management live here. AI literacy (Article 4) operating evidence (lesson 033) is competence proof.

Section 9 - Operations. Operational planning/control (8.1), AI requirements (8.2), AI system design/development (8.3), control of externally provided processes/products/services (8.4). Article 17(1)(b) design-control, (c) verification, (d) quality-control technical specifications, and (e) data-management procedures all attach to Section 9 SOPs. Section 10 - Performance evaluation. Monitoring/measurement/analysis/evaluation (9.1), internal audit (9.2), management review (9.3). Article 17(1)(g) post-market monitoring is one of the monitoring streams. Section 11 - Improvement. Nonconformity and corrective action (10.2), continual improvement (10.3). Article 17(1)(h) Article 73 serious-incident reporting is the most critical corrective-action workflow. Section 12 - AI-specific risk management. Article 9 plan; ISO/IEC 23894:2023 methodology; Article 27 FRIA where applicable; model-risk policy adapted from SR 11-7 (lesson 067). Risk register, treatment plan, residual-risk acceptance, escalation thresholds, signatory authority.

Section 13 - Data lifecycle. Article 10 data and data governance; datasheets (lesson 028); provenance and TDM opt-out (lesson 037); special categories under Article 10(5) (lesson 040); cross-border transfer (lesson 039); ISO 42001 Annex A.7 controls. Section 14 - Third-party and supply chain. Article 25 value-chain obligations; Annex XII downstream-deployer package; AI vendor risk policy (lesson 024); ml-BOM under CycloneDX 1.7 (lesson 029); ISO 42001 Annex A.10; integration with ISO 27036 supplier security. Section 15 - Transparency and communications. Article 50 transparency (lessons 030-032); Annex XII deployer documentation; Article 13 information to deployers; Article 26 deployer obligations; whistleblower channel (Article 86); regulator-engagement log; ISO 42001 Annex A.8. Section 16 - Document and record control. ISO 9001 Clause 7.5.3 documented-information control extended to AI records. Article 18 ten-year retention for technical documentation, declarations, certificates. ISO 19011:2018 audit-trail expectations. Document-master register: owner, version, approval, review cadence, retention, location, access. Article 12 automatic-recording logs cross-walked to A.6.1.7 event-log control.

Each section names scope, normative references, owner, related SOPs and work instructions, evidence-collection cadence, audit-trail location, and review/approval matrix. The manual sits at version 1.0 at approval, increments semi-annually on minor revisions, on structural change for majors. CQO and CAIO co-sign Section 1; the board AI committee approves at adoption and reviews biennially.

The Six-Phase QMS Implementation Plan - Typical 4-7 Month Build for a Mid-Size Enterprise

Building a defensible Article 17 QMS from scratch takes a mid-size enterprise (~500-5,000 employees, 1-10 high-risk AI systems in scope) four to seven months. The six phases below are sequenced to land Stage 1 (ISO 42001) and the notified-body Module H pre-audit on the same documentation baseline, a single binder served twice. Compressing below four months requires either an existing ISO 9001 + ISO 27001 baseline to extend, or an external implementation partner. Stretching past seven months typically reflects scope creep, internal stakeholder misalignment, or a board that hasn't committed to the integrated-management-system architecture.

Phase 1 - Charter, scope definition, Article 17 element mapping (weeks 1-3). The board (or executive committee) charters the QMS build naming sponsor (typically CEO or CAIO), accountable owner (Chief Quality Officer or VP of AI Governance), workstream leads (AI engineering, data, security, privacy, regulatory affairs, legal, HR for literacy), scope (systems, entities, geographies), target standards (ISO 42001 + ISO 9001 + ISO 27001 + ISO 27701 minimum), and target certification milestones (Stage 1 / Stage 2 / Module H pre-audit / Module H audit). The Article 17 element mapping table is the first deliverable: thirteen rows, each naming the element, the existing document/control that addresses it (or "gap"), the target document/SOP, the owner, and the target completion date. The mapping table is the single most useful artefact in the entire build, auditors will request it on Day 1 of Stage 1 and Module H.

Phase 2 - Gap assessment (weeks 3-6). Against the ISO 9001 baseline (if held), against ISO 42001 (always), against ISO 27001 / 27701 (where in scope). The gap assessment produces a finding register: ISO 42001 Annex A control by control (38 controls), Article 17 element by element (13 elements), with current state (Implemented / Partially implemented / Not implemented / Not applicable with justification) and gap-closure action. Mid-size providers extending an ISO 9001 baseline typically find 40-60% of clauses 4-10 substantially reusable (context, leadership, document control, internal audit, management review) and 40-60% requiring AI-specific extension. Annex A controls are typically 10-30% reusable from ISO 27001 (A.6.1.1, A.10 third-party overlaps), 70-90% requiring new build for the AI-specific elements.

Phase 3 - Documentation buildout (weeks 6-16). The longest phase. Writes the QMS manual (sixteen sections), the SOP library (typically 25-35 SOPs at mid-size: data management, model development, evaluation, deployment, change control, post-market monitoring, incident response, vendor management, transparency, FRIA, risk register, document control, internal audit, management review, communications, training, literacy, whistleblower, accountability), the procedures (typically 50-80 procedures elaborating SOPs at workflow level), the work instructions (typically 100-150 task-level instructions), and the records templates (typically 30-50 forms, logs, registers, sign-off sheets). Document-control discipline is established here: every document gets an ID, owner, version, approval-by, review cadence, retention, and storage location. The document master register is the audit-day reference.

Phase 4 - Pilot in one product (weeks 14-20). A pilot product, typically the flagship high-risk system the company most cares about certifying, runs through the new QMS end-to-end. Data-management SOPs are exercised on the pilot's training data. Design-control SOPs are exercised on the pilot's most recent model release. Evaluation procedures are exercised on the pilot's eval suite. Risk-management procedures produce the pilot's risk register and (where applicable) FRIA. Post-market monitoring SOPs configure the pilot's dashboard. Incident response procedures table-top a serious-incident scenario. The pilot generates 60-90 days of operating evidence, the minimum auditors expect for Stage 1.

Phase 5 - Internal audit + management review (weeks 18-22). The internal audit team (independent of operating teams; typically an internal-audit function or external partner) audits the pilot QMS against ISO 19011:2018 audit guidelines. Findings are classified, corrective actions opened, root-cause analysis documented. The management review (board AI committee or executive AI committee) reviews internal-audit findings, post-market monitoring KPIs, risk register changes, customer/regulator feedback, opportunities for improvement. Management review minutes become operating evidence under ISO 42001 Clause 9.3 and Article 17(1)(j) record-keeping.

Phase 6 - Stage 1 + Stage 2 audit (or notified-body submission) (weeks 22-28). Stage 1 documentation review by the ISO 42001 certification body (Schellman, A-LIGN, BSI, KPMG, BSI EU, DEKRA-IS) audits the AIMS against ISO/IEC 42001:2023 Clauses 4-10 and Annex A. Findings memo issued; 4-8 weeks to close minor and major findings before Stage 2. Stage 2 operating-effectiveness audit (8-15 days on-site/remote over 3-6 weeks elapsed) tests the operating evidence. Certificate issued 30-90 days post-Stage 2. For Module H, the notified-body submission and pre-audit (lesson 078) run in parallel where the same firm holds both designations (BSI, DEKRA, TÜV SÜD's certified-management-systems and product-certification arms), cutting the on-site audit-day cost 20-35%.

The 4-7 month range is empirical, drawn from the first wave of ISO 42001 certifications globally (~150 organisations certified in 2024-2025; ~1,500-3,000 expected by end-2026 driven by Article 17 pressure). Compressing below four months works only where an existing ISO 9001 + ISO 27001 baseline can carry context, leadership, document control, and internal audit / management review with light AI-specific extension, typical for mature regulated manufacturers like Acme. Greenfield builds (the more common case for software-first providers) take 6-9 months.

The Integrated Management System - ISMS + QMS + PIMS + AIMS Under One Roof, and Document-Control Discipline

The economics that justify the integrated-management-system (IMS) architecture are concrete. Audit-evidence redundancy across ISO 9001 + ISO 27001 + ISO 27701 + ISO 42001 is 30-50% in typical providers: the same context analysis serves all four standards, the same leadership commitment serves all four, the same document-control regime serves all four, the same internal audit serves all four with discipline-specific sampling, the same management review serves all four with disciplined-specific agenda items. Running four parallel management systems with four parallel binders generates four times the document-control workload, four times the internal-audit workload, four times the management-review workload, and four times the evidence-collection cost, without producing any incremental compliance assurance. The IMS architecture writes once, cites four times.

The practical mapping in 2026: ISO 42001 chassis hosts the AI-specific overlay. Annex SL clauses 4-10 are written once and reference the AI Act, the GDPR, the relevant ISO 27001 controls, and the relevant ISO 9001 quality controls. ISO 9001 quality controls attach to Sections 9 (operations), 10 (performance evaluation), 11 (improvement), and 16 (document and record control), quality discipline most familiar to manufacturing-rooted organisations. ISO 27001 information-security controls attach to Section 12 (risk management), Section 13 (data lifecycle), Section 14 (third-party / supply chain), Section 15 (transparency / communications), and Section 16 (record control with retention and access). ISO 27701 privacy controls attach to Section 13 (data lifecycle), Section 14 (third-party), and Section 15 (transparency), particularly where Article 10 data overlaps with GDPR Article 6 lawful basis and Article 9 special categories (lesson 040).

The cross-walk register is the operating artefact. Sample row: "EU AI Act Article 17(1)(g) post-market monitoring ↔ ISO 42001 A.6.1.5 operation and monitoring of AI systems ↔ ISO 9001:2015 Clause 9.1.3 analysis and evaluation ↔ ISO 27001:2022 Clause 9.1 monitoring, measurement, analysis, and evaluation, single SOP-PMM-001 'Post-Market Monitoring of AI Systems' satisfies all four; owner Head of AI Operations; reviewed quarterly; retention 10 years per Article 18." Each Article 17 element produces 5-15 such rows across all four standards. A complete cross-walk register at a mid-size provider runs 200-400 rows.

Document-control discipline is the second non-negotiable. ISO 9001:2015 Clause 7.5 and ISO 42001 Clause 7.5 require documented information to be controlled: every QMS document has a unique identifier, a current version, an approving authority, a review cadence, a retention period, a storage location, and an access-control profile. ISO 19011:2018 (audit guidelines) sets the auditor's expectation: any document an auditor pulls during sampling must be traceable end-to-end, the prior version available, the change history readable, the approval chain verifiable. The CQO's Stuttgart-era 230-document SOP library, controlled rigorously since 1998 under DAkkS surveillance, is the discipline model the CAIO's team adopts.

The minimum document-master-register schema, in practice: Doc ID (alphanumeric, schema-prefixed e.g. SOP-PMM-001), Title, Type (Manual, Policy, SOP, Procedure, Work Instruction, Form, Record), Version (e.g. 2.3), Status (Draft / In Review / Approved / Superseded), Effective Date, Next Review Date, Owner Role, Approving Authority, Approval Date, Retention Period (1 / 3 / 5 / 10 / Permanent), Storage Location (URI to controlled-document-management-system), Cross-Walks (Article 17 element, ISO 42001 Annex A control, ISO 9001 clause, ISO 27001 Annex A control), Linked Records (where operating evidence is stored), Change Log Pointer (URI to revision history). The register lives in a controlled-document-management system (Confluence with controlled spaces, SharePoint with Records Management, MasterControl, ETQ, or specialised AI-QMS platforms emerging in 2026), never in a spreadsheet outside formal version control. Auditors who see "QMS_master_register_v17_final_FINAL.xlsx" on Day 1 of Stage 1 form an immediate impression that costs the provider weeks of remediation.

Retention is the third lever. Article 18 requires technical documentation, the QMS documentation, changes approved by notified bodies, decisions, and other documents to be kept for ten years after placing the system on the market, or for the operational lifetime of the system where longer. Article 12 logs retained per Article 19, generally six months at minimum, extending to the periods required by Union or national law. Article 47 declaration of conformity retained ten years. The retention regime is operationalised in Section 16 of the manual and the document-master-register retention column. Loss of records, even inadvertent, falls under Article 99(5) €7.5M/1% misleading-record-keeping exposure where the provider misrepresents what records exist; under Article 99(3) €15M/3% where the QMS itself fails Article 17.

Cloud-Native Auditability - CI/CD-as-QMS-Evidence in the 2026 AI Shop, and the Acme Worked Example

The 2026 emerging challenge most ISO 9001-rooted CQOs underestimate is auditability in a cloud-native, CI/CD-automated AI development shop. The classical ISO 9001 audit-evidence model assumes physical or signed-PDF records: design-review minutes initialled by participants, batch records signed by operators, calibration certificates filed by lab technicians. The classical model breaks where the AI pipeline is fully automated: every git commit signed, every model training run logged in an experiment tracker (Weights & Biases, MLflow, Neptune), every dataset version pinned by content hash, every eval suite run logged with metrics, every deployment promotion gated by automated checks, every API call audit-trailed in cloud-provider logs. The auditor's question becomes: how does the QMS evidence that the design-control SOP was followed when no human signed anything?

The defensible answer in 2026 is CI/CD-as-QMS-evidence, automated pipeline outputs treated as primary records, with the QMS document-control regime extending to the pipeline configuration itself. Three patterns matter. Signed commits with traceability: every code change is signed by a verified developer identity (Sigstore, GitHub commit signing, GitLab signed-pushes), every commit references a JIRA / Linear ticket, every ticket maps to an approved design-review record. This is Article 17(1)(b) design-control evidence and ISO 42001 A.6.1.2 (AI system architecture) operating evidence. Automated test logs with attribution: every eval suite runs through CI, producing test logs stored immutably (cloud object storage with versioning enabled and write-once-read-many retention), referenced by model version, tied to the deploying engineer's identity, and pinned to the model artefact's content hash. This is Article 17(1)(c) verification, Article 17(1)(d) quality-control, and ISO 42001 A.6.1.3 (AI system verification and validation) evidence. Deployment gates as records: every production deployment passes through approval gates configured in the CI/CD platform (GitHub Environments, GitLab Environments, ArgoCD, Spinnaker), the approver named, the timestamp recorded, the conditions met (eval-suite passing, security scan clean, model-card up-to-date, FRIA reviewed). This is Article 17(1)(b) design-change control evidence.

The QMS document-control regime extends to the pipeline configuration. Pipeline definitions (GitHub Actions YAML, GitLab CI YAML, Tekton, Argo Workflows) are themselves documents controlled under Section 16 of the manual: owner, version, approval, review cadence, retention. Changes to the pipeline configuration trigger document-change-control workflows the same way changes to a written SOP would. The Article 17(1)(j) record-keeping element treats the cloud-provider audit logs (AWS CloudTrail, GCP Cloud Audit Logs, Azure Monitor) as evidence repositories under retention configuration that meets Article 18 ten-year expectation. The internal-audit team samples pipeline runs (random sampling 1-3% of deployments per quarter) the same way an ISO 9001 auditor sampled batch records, except the samples are reproducible and the chain-of-custody is cryptographic.

Acme's worked example, building the Article 17 QMS through the six phases over 22 weeks (January-June 2026). Scope: two Annex III high-risk systems: the AI-assisted machinery-safety-classification system (Annex I product-extension, machinery regulation), and the HR-screening AI used in candidate ranking (Annex III point 4, employment). Two legal entities (Acme AG Germany, Acme Inc. U.S. only the German entity placing AI on the EU market). Geographies: EU + UK + extraterritorial for any deployer-side service.

Architecture: sixteen-section QMS manual (apex document, 78 pages); 28 SOPs (data management, model development, eval, deployment, change control, post-market monitoring, incident response, vendor management, transparency, FRIA, risk register, document control, internal audit, management review, communications, training, literacy, whistleblower, accountability: plus seven AI-specific SOPs for the machinery system and three for the HR system); 67 procedures (workflow-level elaboration); 142 work instructions (task-level); 38 record templates; ISO 42001 SoA for 38 Annex A controls; cross-walk register with 312 rows mapping Article 17(1)(a)-(m), ISO 42001 Annex A, ISO 9001:2015 clauses, ISO 27001:2022 Annex A, ISO 27701:2019, ISO/IEC 23894:2023; document-master-register with 297 controlled documents; evidence retention plan (10 years Article 18, with 25-year retention for the machinery system per MDR-equivalent product lifecycle).

Integration: existing ISO 9001:2015 certificate (held since 2017) extended via the integrated-management-system architecture; existing ISO 27001:2022 certificate (held since 2023) extended; ISO 27701:2019 added in scope; ISO 42001:2023 new build. Single audit binder; single document-control regime; single document-master-register; single internal-audit programme; single management-review cycle (quarterly); one audit per cycle (BSI as combined ISO 42001 + ISO 27001 + ISO 27701 certification body; TÜV SÜD as notified body for the machinery system Annex I product-extension under Article 43(3) and the HR Annex III point 4 system under Module H).

Timeline: Phase 1 weeks 1-3 (charter, scope, Article 17 mapping); Phase 2 weeks 3-6 (gap assessment); Phase 3 weeks 6-16 (documentation buildout); Phase 4 weeks 14-20 (pilot in the HR system; the more complex of the two); Phase 5 weeks 18-22 (internal audit + management review); Phase 6 weeks 22-28 (Stage 1 ISO 42001 + ISO 27001 + ISO 27701 + ISO 9001 surveillance combined; Stage 2 follows weeks 28-34; notified-body Module H pre-audit weeks 26-30 with formal Module H audit weeks 38-42).

Outcomes: Stage 1 cleared with two minor findings (Section 15 transparency: Annex XII deployer package not yet templated for the HR system; Section 12 risk management: residual-risk acceptance authority not specified for FRIA-Medium escalations). Both closed within 30 days. Stage 2 certificate issued for ISO 42001 + ISO 27001 + ISO 27701 in a single combined certificate from BSI; ISO 9001 surveillance maintained. Module H pre-audit findings: three majors (§2(b) design-specification depth on the HR system; §2(d) bias-examination methodology on the HR system; Article 9 residual-risk acceptance vagueness, the same Module H pattern lesson 078 catalogued). All three closed within the 30-90 day major-finding window. Module H certificate issued Q4 2026 for the machinery system; the HR system certificate issued Q1 2027. Both ahead of the Dec 2, 2027 Annex III deadline.

Audit-evidence economics: integrated-management-system architecture reduced audit-evidence preparation effort by ~42% versus the parallel-binder counterfactual (estimated by the CQO from comparable ISO 27001 / ISO 27701 integration in 2023-2024). Combined certification body / notified body coordination (BSI for ISO certifications; TÜV SÜD for Module H, with cross-recognition of the BSI-issued ISO 42001 certificate as supporting evidence) cut notified-body auditor-days from an estimated 18 days standalone to 11 days coordinated, ~€60K saving on the Module H engagement. One audit per surveillance cycle going forward; recertification at Year 3.

Penalty Exposure and the Cross-Walk - Articles 9, 10, 11, 13, 14, 15, 16, 17, 18, 26, 27, 43, 47, 71, 72, 73, 86; ISO 42001 + 9001 + 27001 + 27701 + 23894; SR 11-7

The penalty cascade for Article 17 failure is concentrated and material. Article 99(3), €15M or 3% of worldwide annual turnover (whichever higher). Failure to put in place or maintain a QMS satisfying Article 17(1)(a)-(m) sits squarely here. Material gaps, entire missing elements, document-control failing ISO 19011 audit-trail expectation, retention failure under Article 18, post-market-monitoring absence, all attract this exposure. Article 99(4), €15M or 3%. Operator (deployer) obligations under Article 26 and notified-body obligations under Article 33 are tiered separately; a Module H notified body issuing a certificate against a QMS that materially fails Article 17 falls under Article 99(4). Article 99(5), €7.5M or 1%. Misleading information to notified bodies or competent authorities, including misrepresentation about what QMS records exist, what version is current, what was reviewed by whom, attracts the misleading-record-keeping tier. Article 99(2), €35M or 7%. Article 5 prohibited-practices breaches; a defensible Article 17(1)(a) compliance strategy includes Article 5 prohibited-use vigilance (lessons 001-018).

The audit-day cross-walk every CAIO and CQO should recite. AI Act: Article 9 (Section 12); Article 10 (Section 13); Article 11 / Annex IV (Sections 9, 16); Article 13 (Section 15); Article 14 (Section 9); Article 15 (Section 9); Article 16 (Section 6); Article 17 (the manual); Article 18 (Section 16); Article 26 (Section 15); Article 27 (Section 12); Article 43 (Section 9); Article 47 (Section 16); Article 71 (Section 15); Article 72 (Section 10); Article 73 (Section 11); Article 86 (Section 15). Annexes: Annex IV (Sections 9 + 16); Annex VII Module H (entire manual as assessed entity); Annex VIII (Section 15); Annex XII (Sections 14 + 15). Standards: ISO/IEC 42001:2023 (full); ISO 9001:2015 Clauses 4-10; ISO/IEC 27001:2022 (Sections 12-16); ISO/IEC 27701:2019 (Sections 13-15); ISO/IEC 23894:2023 (Section 12); ISO/IEC 22989:2022 (Section 3); ISO/IEC 5338:2023 (Section 9); ISO 19011:2018 (Section 10). U.S. equivalents: SR 11-7 governance pillar (lesson 067); NIST AI RMF Govern function as the closest management-system overlay to Article 17.

The Acme Stuttgart conversation resolves the same way every conversation like it resolves in 2026-2027: not a parallel AI-QMS bolted alongside legacy ISO 9001, but one integrated management system that retires the 412-page legacy manual, replaces it with a sixteen-section structure satisfying ISO 9001:2015 + ISO/IEC 27001:2022 + ISO/IEC 27701:2019 + ISO/IEC 42001:2023 + AI Act Article 17(1)(a)-(m) simultaneously, and produces one audit binder for certification body and notified body to share. The CQO's twenty-eight years of quality discipline doesn't translate. It transposes. The discipline is the asset; substantive content rewrites against the new requirements. CAIO contributes the AI-specific overlay; CQO contributes the document-control regime that holds the overlay together. Output is what Module H demands: a QMS that is itself the assessed entity, defensible front-to-back, retained ten years, ready for first surveillance before next March.

Key Takeaways

  • Article 17(1) mandates a thirteen-element QMS, (a) compliance strategy; (b) design-control; (c) verification; (d) quality-control technical specifications; (e) data management; (f) risk management (Article 9); (g) post-market monitoring (Article 72); (h) serious-incident reporting (Article 73); (i) communications; (j) record-keeping; (k) resource management; (l) accountability framework; (m) relevant standards/specifications. Each maps to discrete documentation deliverables and operating evidence.
  • Annex VII Module H makes the QMS itself the assessed entity, not merely supporting evidence behind the technical file. Point 3 of Annex VII requires the notified body to assess the QMS against Article 17. A weak QMS fails the assessment outright, blocking certificate issuance.
  • The defensible architecture is a single integrated management system: ISO/IEC 42001:2023 AIMS chassis with ISO 9001:2015 quality, ISO/IEC 27001:2022 security, and ISO/IEC 27701:2019 privacy controls cross-walked. ISO/IEC 23894:2023 supplies the AI risk methodology. The IMS approach reduces audit-evidence redundancy 30-50%.
  • The QMS manual sits at sixteen sections: eleven mirroring Annex SL high-level structure (purpose, scope, terms, references, context, leadership, planning, support, operations, performance evaluation, improvement) plus five AI-specific extensions (AI risk management, data lifecycle, third-party/supply chain, transparency/communications, document and record control).
  • The six-phase build runs 4-7 months for a mid-size enterprise, charter and Article 17 mapping; gap assessment; documentation buildout; pilot in flagship product; internal audit and management review; Stage 1 and Stage 2 audit (plus notified-body Module H submission for high-risk providers). The charter and Article 17 element-mapping table are the most-requested artefacts on Day 1 of every audit.
  • Cloud-native auditability requires CI/CD-as-QMS-evidence patterns: signed commits with traceability (Article 17(1)(b)), automated test logs with attribution (Article 17(1)(c)(d)), deployment gates as records (Article 17(1)(b)), pipeline definitions controlled under document-control regime (Section 16), cloud-provider audit logs configured for Article 18 ten-year retention.
  • Document-control discipline is non-negotiable: every QMS document has unique ID, owner, version, approver, review cadence, retention, storage location, access control. Document-master-register lives in a controlled-document-management system, never an uncontrolled spreadsheet. ISO 19011:2018 audit-trail expectations apply.
  • Penalty exposure concentrates in Article 99(3) €15M/3% for material Article 17 gaps; Article 99(4) €15M/3% for notified-body-specific failures; Article 99(5) €7.5M/1% for misleading record-keeping. The Acme worked example, 16-section manual, 28 SOPs, 67 procedures, 142 work instructions, 312-row cross-walk register, single combined audit, illustrates the 42% audit-evidence efficiency gain integrated-management-system architecture delivers in practice.