Skip to content
Store / AI Governance / Quality Management System Checklist
AI Governance AI Act Art. 17

Quality Management System Checklist (AI Act Art. 17)

The 13 mandatory elements, cross-referenced to the risk management, post-market monitoring and incident reporting work you probably already have — plus a starter template for the 3 that almost nobody has covered yet.

Based on AESIA Guide 4 (Spain's AI Supervision Agency), born out of its regulatory sandbox and adapted to the Digital Omnibus — the practical reference standard for compliance in Spain.
€39
VAT included · one-time payment
Coming soon → ← Back to store
Referenced article by article with the AI Act, GDPR and DAMA-DMBOK

What's included

  • Excel file with the 13 elements of Art. 17, the exact legal text for each, and which of your existing documents already covers it
  • Starter template (concrete questions) for the 3 elements with no product yet: design, development/quality assurance, resource management
  • Self-assessment log — owner and review date for each element
  • PDF guide with the full table of the 13 elements
  • Legal Notice

Why this document exists

Art. 17 of Regulation (EU) 2024/1689 requires providers of high-risk AI systems to establish a documented quality management system with at least 13 elements. AESIA's own guide points this out clearly: most of those elements should already be developed in other pieces of your documentation — risk management (Art. 9), post-market monitoring (Art. 72), incident reporting (Art. 73). This document doesn't repeat that work — it connects it into a single framework, and adds what's missing.

The 13 elements, at a glance

  • a) Regulatory compliance — conformity strategy and change management.
  • b) Design and verification — no product yet, template included.
  • c) Development and quality assurance — no product yet, template included.
  • d) Examination, testing and validation — connects to system accuracy and robustness.
  • e) Harmonized standards — connects to your frameworks mapping.
  • f) Data management — connects to your Art. 10 Pack and Data Catalog.
  • g) Risk management (Art. 9) — connects to ISO 23894 and your Art. 10 Pack.
  • h) Post-market monitoring (Art. 72) — connects to your existing template.
  • i) Incident reporting (Art. 73) — connects to your existing template.
  • j) Communication with authorities — connects to your Inspection Response Kit.
  • k) Record keeping — connects to your AI Systems Registry.
  • l) Resource management and supply — no product yet, template included.
  • m) Accountability framework — connects to your Charter and RACI.

Proportionate to your company's size

Art. 17 itself establishes that applying these elements should be proportionate to the size of the organization — an SME doesn't need the same level of formalization as a large company. The document includes this consideration explicitly, so you don't over-build a heavier system than your organization needs.