Article 17 — Quality management system
Source: EUR-Lex · CELEX 32024R1689
Verified 2026-07-16
Providers must run a documented quality management system that keeps their high-risk systems compliant. Written policies should cover the compliance strategy, design and development controls, testing, data governance, risk management, post-market monitoring, incident reporting, record-keeping, resourcing, and accountability. The effort can scale to the organisation's size while keeping the necessary rigour. Providers meeting equivalent duties under sectoral Union law may fold these elements in, and financial institutions can rely on their internal-governance rules for most parts.
This provision's application date moved under the Omnibus. It now applies from 2027-12-02 (originally 2026-08-02). Source: Omnibus final text (OJ pending) · verified 2026-07-16