Quality Management (QMS): ISO/IEC 42001 controls and Art. 17
The organisation-wide AI management system workspace under Frameworks → ISO/IEC 42001: the Annex A control catalogue, the QMS profile, the Statement of Applicability, and the tick-only sync into every Art. 17 checklist.
Frameworks → ISO/IEC 42001 (under Configure) is the organisation-wide AI management system workspace — the page titled Quality. Where obligations live per system, the QMS is the umbrella above them: the policies, roles and processes that Art. 17 expects a provider of high-risk AI to run as a quality management system, and that ISO/IEC 42001 turns into a certifiable management system.
Frameworks and Controls are absent from the rail while the frameworks-crosswalk switch is off — the cross-mapping of ISO/IEC 42001, ISO/IEC 27001 and NIST AI RMF lands by 13 October. Once on, the ISO/IEC 42001 programme is included in the Manage plan from 13 October 2026, when paid plans open, and bought as a programme on Govern.
Art. 17 is not the programme
The quality management system is a statutory duty for providers of high-risk systems, so its obligations ship inside the plan as engine obligations — you never buy your own legal obligation back. What the ISO/IEC 42001 programme adds is the certifiable management system: the Annex A catalogue, the Statement of Applicability, the internal audit and management review records.
The workspace
- QMS profile — scope, and the certification cycle (a certificate is granted by an accredited body, never by Veritome).
- The control catalogue — a paraphrased ISO/IEC 42001:2023 Annex A catalogue whose control keys mirror the Annex A numbering, so an auditor can follow along. Controls are grouped by the nine Annex A objectives — A.2 AI policies through A.10 third parties — each with a status, an owner and notes. The counts show controls implemented against the catalogue size.
- Statement of Applicability — every clause of each enabled framework with the control that satisfies it. It is a view, generated from your controls and clauses, and its programme step opens pre-filled from what the programme has already implemented; excluding a clause needs a written justification. See The Statement of Applicability, generated from what you did.
- Reviews — the internal audits and management reviews, also listed on Assessments.
- PDCA narrative — Plan · Do · Check · Act, for the auditor's reading.
The Art. 17 sync
The reason the QMS lives inside your compliance tool rather than in a spreadsheet: implemented controls tick the matching items on your Art. 17 obligation checklists, organisation-wide. Implement "AI policy" once at the management-system level and every high-risk system's Art. 17 checklist reflects it. The sync is deliberately tick-only — it never un-ticks work you recorded manually, so a QMS reorganisation cannot silently regress a system's record.
How it fits the rest
- The per-system Art. 17 obligation (Implement phase) stays the compliance record; this workspace is where the underlying management system is built and maintained.
- A programme step approved under Obligations produces a control on Controls, carrying its evidence — see Steps: Aria drafts, a person approves, then it counts.
- The Act's own text lets a provider already under a sectoral Union-law quality-management duty fold Art. 17 into that system (Art. 17(3)), and deems a financial institution's internal governance rules to fulfil most of it (Art. 17(4)). Those routes are recorded on the Art. 17 obligation and never change its status — and a voluntary standard, ISO/IEC 42001 included, is not sectoral Union law.