Skip to content

EN 18286 clauses 4–7 and 10: the QMS layer

This page walks the organization layer of EN 18286:2026: the clauses where the quality management system itself resides. In Modulos these clauses are carried by the OFF-19 template's 13 Requirements. The per-AI-system clauses (8 and 9.1–9.5) are on Lifecycle and operations, and the incident and non-compliance clauses (9.6–9.7), which also sit at organization level, have their own page.

The Requirements on this page

RequirementClausesOwns
ORF-4104.1Establishing and maintaining the QMS
ORF-4114.2Identifying regulatory requirements
ORF-4124.3Scope of the QMS
ORF-4134.4Strategy for regulatory compliance
ORF-4144.5Documented information
ORF-4155.1Management responsibility
ORF-4165.2Quality policy
ORF-4175.3Roles, responsibilities and authorities
ORF-4186.1, 6.2QMS risk planning and quality objectives
ORF-4197.1–7.4Resources, competence, communication, awareness
ORF-42210.1, 10.2Management review and planning of changes

The QMS as an operating cycle

Read as a running system rather than a clause list, the QMS is a cycle: the organization identifies what applies and plans against it, each AI system is realized under the resulting processes, operation generates monitoring and incident signals, and management review turns those signals into controlled change. The standard has no continual-improvement clause; keeping this cycle turning is how effectiveness is maintained.

Clause 4 — Quality management system

4.1 General (ORF-410). Clause 4.1 sets the base obligation: a quality management system exists, follows the standard, and serves the protection of health, safety and fundamental rights that the applicable regulatory requirements demand. Whatever processes, procedures and activities it takes to keep that system effective across the relevant life cycle stages, the provider supplies. In Modulos this reuses the EU AI Act QMS-existence control OCF-13 and the management-system establishment control OCF-57.

4.2 Identifying regulatory requirements (ORF-411). The provider identifies the regulatory requirements applicable to the in-scope AI systems, reviews them systematically so the picture stays current, and integrates them into the compliance strategy. Carried by the reused regulatory-requirements control OCF-7; the integration limb lands in the clause 4.4 strategy.

4.3 Scope (ORF-412). The provider determines which AI system, or set of AI systems, the QMS covers and defines its boundaries, taking the identified regulatory requirements and the systems' intended purpose into account. One QMS can govern a portfolio; the scope decision is what the MFF-19 project structure mirrors.

4.4 Strategy for regulatory compliance (ORF-413). The strategy is the high-level approach to achieving compliance, documented and covering at least: the essential requirements, post-market monitoring, serious incidents, data management, selection and application of conformity assessment procedures, and modifications. Clause 4.4.2 identifies the essential requirements with the EU AI Act's Section 2 substance (Articles 9 to 15: risk management, data and data governance, technical documentation, record-keeping, transparency, human oversight, and accuracy, robustness and cybersecurity). Clause 4.4.3 requires selecting the demonstration route per essential requirement (harmonized standards cited in the OJ, common specifications, other standards or technical specifications) and documenting, in the technical documentation, what is met through harmonized standards or common specifications and, where coverage is not full, the measures used instead with a detailed description. The strategy artifact is owned by the overlay control OCF-321; clause 4.4.3 is the sole clause behind the Article 17(1)(e) presumption row.

4.5 Documented information (ORF-414). Four duties stack here: the QMS documentation itself (scope, quality policy and objectives, references to the documented processes and their interaction), kept at the disposal of notified bodies and competent authorities, clear, version-controlled and in an official EU language; the operational documented information needed to plan and control the QMS processes; review and approval of changes by competent personnel; and document control across the life cycle (availability, format and media of the provider's choice, protection of confidentiality and integrity, storage and preservation, change control, retention and disposal, identification and description). Retention takes the longest applicable horizon: the period the regulatory requirements set, the provider-defined lifetime of a developed and tested AI system, and any longer period attached to documentation that results from it, unless the applicable regulatory requirements specify otherwise. Documents of external origin needed for the QMS are identified and controlled. Modulos carries the anchor in OCF-47 and the document-control depth in the documented-information family OCF-120OCF-126.

Clause 5 — Leadership

5.1 Management responsibility (ORF-415). Top management evidences leadership and commitment by establishing the quality policy, ensuring quality objectives exist, allocating resources, roles and responsibilities, ensuring resource availability, integrating the QMS requirements into the provider's processes and maintaining the system's effectiveness, ensuring the system achieves its objectives, and conducting management reviews. The standard notes that promoting a culture of responsible development and use of AI systems is one way to demonstrate the commitment.

5.2 Quality policy (ORF-416). The policy provides the framework for quality objectives, commits to meeting applicable and in particular regulatory requirements, aligns with the compliance strategy, commits to maintaining the QMS's effectiveness, joins the QMS documented information, and is communicated to and understood by personnel in scope. It may be embedded in a wider policy. Modulos reuses the AI-policy controls OCF-60 (establishment) and OCF-61 (review).

5.3 Roles, responsibilities and authorities (ORF-417). QMS supervision belongs with people who have the expertise and experience for it, reaching top-management level wherever applicable. Delegation has a floor: top management hands out the responsibility but keeps the accountability for three things, namely reporting on the system's performance, standing up and overseeing AI-system risk management, and tracking the regulatory requirements and the state of the art. Role design is explicit: documented, communicated, aligned with the quality policy and objectives, and covering every process the standard requires. Two guarantees close the clause: people who manage, perform and verify quality-affecting work get the authority and autonomy to intervene, and named roles own the oversight of the risk-management system's implementation and the approval of risk-control measures. The named accountabilities are owned by the overlay OCF-324, with role definition anchored in OCF-1. The published text has no separate outsourcing subclause; responsibility for work done on the provider's behalf runs through the supply-chain and governance clauses instead.

Clause 6 — Planning (ORF-418)

Clause 6.1 addresses risks to the functioning of the QMS itself, which the standard distinguishes explicitly from AI-system risk management under clause 8.2: determine, from the identified regulatory requirements, the risks to the system's intended results, plan and integrate actions against them, and evaluate their effectiveness, considering at least the compliance strategy, the AI technologies used, reliance on other parties, and available resources and expertise. Clause 6.2 requires verifiable quality objectives at the relevant functions, levels, products and processes, consistent with the quality policy, regularly reviewed and updated to maintain regulatory compliance, with a documented plan for what will be done, by whom, against which quality criteria. The overlays OCF-325 (QMS risk planning) and OCF-327 (objectives and planning) own the artifacts.

Clause 7 — Support (ORF-419)

7.1 Resources. Personnel and their competences, application- and technology-specific knowledge, infrastructure for design, development and testing, and security-of-supply measures. Owned by the overlay OCF-323; with clause 7.2 and the supply chain (9.3), this is the organization half of the Article 17(1)(l) row.

7.2 Competence. Determine the competences of personnel whose work affects the QMS, keep them competent on the basis of education, training or experience, and document the processes. Clause 7.2.3 makes the competency bar risk-sensitive: the intended purpose and reasonably foreseeable misuse, the AI technologies and data, the risks including significant effects on affected persons, and usability and accessibility for diverse users, including persons with disabilities, all shape what competence is needed. Owned by the overlay OCF-328.

7.3 Communication. Plan internal and external communication (what, when, with whom, how), and keep it accessible: communication must not exclude interested parties on grounds of disability, proficiency or age. Clause 7.3.2 adds the regulatory procedures: standing channels with national competent authorities, other authorities, notified bodies, other operators and customers including deployers (7.3.2.1); informing relevant interested parties of non-compliance, of AI systems presenting a risk, and of serious incidents (7.3.2.2); responding to a competent authority's reasoned request within an appropriate time frame (7.3.2.3); and a standing process to identify, collect and transmit the information demonstrating each AI system's initial and continuous compliance, including provider-controlled automatically generated logs (7.3.2.4, owned by the overlay OCF-329). Clause 7.3 carries the Article 17(1)(j) communication row together with the market-surveillance notification duty in 9.7.2.2.

7.4 Awareness. Persons working under the provider's responsibility within the QMS scope know the quality policy, their contribution to the system's effectiveness, and the implications of not conforming. Awareness is a standalone clause in the published text and contributes to the Article 17(1)(m) accountability row.

Clause 10 — Performance evaluation (ORF-422)

10.1 Management review. Management review is where the provider finds out whether the QMS still works. The clause requires documented procedures, a planned cadence, and clear, measurable criteria (quantitative or qualitative) for judging whether the system remains suitable, adequate and effective, explicitly including how well it protects health, safety and fundamental rights. Top management joins periodically, the cadence stays proportionate to the risks the AI systems can present without lowering the bar, and one trigger is unconditional: a serious-incident investigation that concludes the QMS or its measures fell short forces an additional review. In scope are the quality policy and objectives, adherence to policies and procedures, the performance of risk-control measures, interested parties (affected persons in particular), the clause 6.1 risk actions, and regulatory change; the reviews and their recommendations are retained. Recommended inputs (10.1.2) run from interested-party feedback and complaints through audits, process and AI-system performance monitoring, and corrective actions to new or revised regulatory requirements and standards; outputs (10.1.3) record the improvements needed, the changes regulatory developments force, and the resource implications. Clause 10.1.1.2 permits, without requiring, a concern-reporting process; where the provider creates one, it should offer confidentiality or anonymity, qualified staffing, escalation, and protection from reprisals. Modulos carries it with the reused OCF-64.

10.2 Planning of changes. QMS change is controlled work: procedures define how changes happen, execution is planned, and a record of what changed is kept. Two situations force a look at the processes themselves: a new AI system entering the QMS, or an existing one being substantially modified. In either case the provider checks whether the processes still fit that system's characteristics and revises them where the check says so. Before a process change lands, its impact is weighed twice: on the management system, and on every AI system running under it. The overlay OCF-326 owns the documented review-and-change-control artifact.

How the QMS layer maps in Modulos

Attach OFF-19 to the organization project. The 11 Requirements on this page resolve to 33 distinct Controls: reused governance and management-system controls that other platform frameworks also map (OCF-1, OCF-7, OCF-11OCF-13, OCF-44, OCF-47, OCF-52, OCF-57OCF-61, OCF-63, OCF-64, OCF-68, OCF-70, OCF-72, the documented-information family OCF-120OCF-126) plus the eight EN-specific overlays OCF-321 and OCF-323OCF-329 (the ninth organization overlay, OCF-322, sits with ORF-420). The serious-incident and non-compliance Requirements (ORF-420, ORF-421) complete the template and are covered on Incidents and non-compliance.

Source attribution

EN 18286:2026, Artificial intelligence — Quality management system for EU AI Act regulatory purposes, clauses 4 to 7 and 10, restated in the documentation's own words with the Modulos template mapping as of templates 1.0.26. For conformity-assessment purposes, verify against the published standard.

Disclaimer

This page is for general informational purposes and does not constitute legal advice.