QM-011MediumProviderPreventive
Document Control Procedures
Providers must implement document control procedures that ensure QMS documents are current, approved, accessible to relevant personnel, and subject to version control, with obsolete documents retired from active use.
Articles:Article 17(1)Article 11(3)
Evidence Examples
- Document control procedure
- Document register with version history
- Obsolete document archive policy
Standards
ISO 42001:2023 §7.5ISO 9001:2015 §7.5
Related controls
- QM-001Quality Management System EstablishmentArticle 17(1) requires providers of high-risk AI systems to put in place a quality management system that ensures compliance with the requirements of the…
- QM-002Regulatory Compliance StrategyProviders must establish and document a strategy for achieving and maintaining compliance with applicable regulatory requirements, including the EU AI…
- QM-003Design Control ProceduresProviders must implement documented design control procedures that ensure regulatory and performance requirements are systematically incorporated from the…
- QM-004Data Management ProceduresProviders must have documented data management procedures covering the acquisition, preparation, use, and retention of data throughout the AI system…
- QM-005Staff Training and Competency ProceduresArticle 17(1)(d) requires providers to implement procedures for training personnel involved in AI system development, testing, and monitoring, with…
- QM-006Pre-Market Testing and Validation ProceduresProviders must implement documented procedures for pre-market testing and validation of high-risk AI systems, including the metrics to be achieved, the…
Related EU AI Act terms
- Quality Management SystemA documented system that providers of high-risk AI systems must establish, implement, document, and maintain covering: the regulatory compliance strategy, design and development processes, data governance procedures, risk management, post-market monitoring, and incident reporting.
- Technical DocumentationThe documentation that providers of high-risk AI systems must draw up before placing the system on the market, containing all necessary information to assess compliance with the Regulation, including a general description, design specifications, training data information, risk management records, and performance metrics. Content requirements are set out in Annex IV.
Upgrade when it needs to be
The free questionnaire returns preliminary signals. The Full Assessment turns real system material into a governed decision record - extraction, component separation, evidence, national overlays, and a review-ready dossier.
Start free risk preview