Context, scope & strategy
Process catalogue, applicable requirements determination, QMS scope and systems in scope, compliance strategy, and essentials approach.
Modules work as a single management system around each AI system: identity, risk, realisation, operation, monitoring, and improvement — with shared traceability and evidence.
Establish the organisation, people, and documented information that EN 18286 expects before and during AI delivery.
Process catalogue, applicable requirements determination, QMS scope and systems in scope, compliance strategy, and essentials approach.
Quality policy and commitment, role catalogue, authorities, lifecycle RACI, outsourcing accountability, and decision rights.
Quality objectives, QMS-level risks and opportunities, resources, competence system, and authority communications.
Controlled documents, record registers, mandatory evidence matrices, retention schedules, and objective evidence libraries.
Stable identity for every AI system — identifier, reference, intended purpose, version — used as the spine for all linked records.
Operational outcomes: open CAPA, audit status, competence gaps, lifecycle progress, and management-review inputs.
Plan and control design, data, release, and runtime duties for each system in scope.
High-risk classification decisions, risk management file structure, residual risk acceptance, and continuous risk re-evaluation triggers.
Threat and control evidence for AI systems, linked to residual risk and operational logging expectations.
Stage models from concept through decommission, with verification and validation evidence before progression.
Requirements and design records, external provider control, nonconforming outputs, technical documentation and instructions for use.
Data lineage, quality metrics, drift signals, and governance roles for data used in development and operation.
Deployment and version control, operational monitoring, logging design, support services for deployers, and human oversight measures.
Keep the QMS alive after release — when models, suppliers, or field performance change.
Due diligence, monitoring and re-evaluation, component inventory, and change control when third-party models or tools update.
Planned and unintended changes, substantial modification assessment, impact on risk files and technical documentation, approval chains.
Post-market plans, feedback, performance issues, serious incident handling, nonconformity, and corrective action.
Structured records for transparency obligations, including machine-readable marking and related process evidence where applicable.
Conformity assessment route tracking, examination packages, and EU declaration / registration readiness fields.
Immutable second-copy archive, retention policies, disposition, and pack export for inspection or transfer of obligations.
EN 18286 expects core QMS processes to run continuously across activities — not only at project milestones.
Book a demo focused on your high-risk systems, or speak with us about programme rollout.