QM-002HighProviderPreventive
Regulatory Compliance Strategy
Providers must establish and document a strategy for achieving and maintaining compliance with applicable regulatory requirements, including the EU AI Act, GDPR, and applicable national sector laws, with defined responsibilities and timelines.
Articles:Article 17(1)(a)
Evidence Examples
- Regulatory compliance roadmap
- Legal requirement register
- Compliance owner assignment matrix
Standards
ISO 42001:2023 §6.1ISO/IEC 27001:2022
Related controls
- QM-001Quality Management System EstablishmentArticle 17(1) requires providers of high-risk AI systems to put in place a quality management system that ensures compliance with the requirements of the…
- QM-003Design Control ProceduresProviders must implement documented design control procedures that ensure regulatory and performance requirements are systematically incorporated from the…
- QM-004Data Management ProceduresProviders must have documented data management procedures covering the acquisition, preparation, use, and retention of data throughout the AI system…
- QM-005Staff Training and Competency ProceduresArticle 17(1)(d) requires providers to implement procedures for training personnel involved in AI system development, testing, and monitoring, with…
- QM-006Pre-Market Testing and Validation ProceduresProviders must implement documented procedures for pre-market testing and validation of high-risk AI systems, including the metrics to be achieved, the…
- QM-007Post-Market Monitoring PlanArticle 17(1)(f) requires providers to implement a post-market monitoring plan that specifies the data to be collected, the monitoring frequency, the…
Related EU AI Act terms
Upgrade when it needs to be
The free questionnaire returns preliminary signals. The Full Assessment turns real system material into a governed decision record - extraction, component separation, evidence, national overlays, and a review-ready dossier.
Start free risk preview