Platform

Capabilities for an operational AI QMS

Modules work as a single management system around each AI system: identity, risk, realisation, operation, monitoring, and improvement — with shared traceability and evidence.

Management system foundation

Establish the organisation, people, and documented information that EN 18286 expects before and during AI delivery.

4

Context, scope & strategy

Process catalogue, applicable requirements determination, QMS scope and systems in scope, compliance strategy, and essentials approach.

5

Leadership & accountability

Quality policy and commitment, role catalogue, authorities, lifecycle RACI, outsourcing accountability, and decision rights.

6–7

Planning & support

Quality objectives, QMS-level risks and opportunities, resources, competence system, and authority communications.

4.5

Documented information

Controlled documents, record registers, mandatory evidence matrices, retention schedules, and objective evidence libraries.

ID

AI system register

Stable identity for every AI system — identifier, reference, intended purpose, version — used as the spine for all linked records.

KPI

Performance dashboards

Operational outcomes: open CAPA, audit status, competence gaps, lifecycle progress, and management-review inputs.

AI system realisation & control

Plan and control design, data, release, and runtime duties for each system in scope.

Risk classification & RMS

High-risk classification decisions, risk management file structure, residual risk acceptance, and continuous risk re-evaluation triggers.

Cybersecurity framework

Threat and control evidence for AI systems, linked to residual risk and operational logging expectations.

Lifecycle stages & gates

Stage models from concept through decommission, with verification and validation evidence before progression.

Design, release & documentation

Requirements and design records, external provider control, nonconforming outputs, technical documentation and instructions for use.

Data quality & governance

Data lineage, quality metrics, drift signals, and governance roles for data used in development and operation.

Operation & human oversight

Deployment and version control, operational monitoring, logging design, support services for deployers, and human oversight measures.

Supply chain, change, and post-market

Keep the QMS alive after release — when models, suppliers, or field performance change.

Suppliers & components

Due diligence, monitoring and re-evaluation, component inventory, and change control when third-party models or tools update.

Modification control

Planned and unintended changes, substantial modification assessment, impact on risk files and technical documentation, approval chains.

Monitoring, incidents & CAPA

Post-market plans, feedback, performance issues, serious incident handling, nonconformity, and corrective action.

Transparency & marking

Structured records for transparency obligations, including machine-readable marking and related process evidence where applicable.

Conformity & declaration

Conformity assessment route tracking, examination packages, and EU declaration / registration readiness fields.

Archive & handover

Immutable second-copy archive, retention policies, disposition, and pack export for inspection or transfer of obligations.

Five processes that never stop

EN 18286 expects core QMS processes to run continuously across activities — not only at project milestones.

  • 1
    Traceability
    AI system identity, version, and linked records visible at the point of work.
  • 2
    Review & approval
    Competent sign-off, separation of duties, and re-approval rules for controlled information.
  • 3
    Evidence & records
    Objective evidence packages, attachments, and retention for regulatory time horizons.
  • 4
    Nonconformity & corrective action
    Capture issues from design, operation, or audit and drive CAPA to closure.
  • 5
    Change management
    Every material modification logged with context, impact, and follow-through.
  • +
    Audit, management review, competence, communication
    Performance evaluation and improvement cycles close the PDCA loop.

Map these capabilities to your AI portfolio

Book a demo focused on your high-risk systems, or speak with us about programme rollout.

Request a Demo Contact Us