Contact

What are you looking for?

EN 18286 – AI Quality Management for EU AI Act Regulatory Purposes

Build an AI quality management system (QMS) and strengthen your EU AI Act readiness with SGS.

Organizations providing high-risk AI systems face growing pressure to translate EU AI Act requirements into practical, compliant processes. EN 18286 sets out a structured quality management system (QMS) framework for managing AI systems throughout their life cycle, covering governance, controls, documentation, monitoring and continual improvement.

We help you understand, implement and prepare for EN 18286 through training, gap assessments, advisory and AI assurance solutions, supporting you in determining the applicable route and assessing readiness for the corresponding requirements.

Discover the benefits of our EN 18286 services

  • Accelerate EU AI Act readiness

    We provide a practical framework for translating Article 17’s QMS requirements into organizational processes, roles, controls and documented evidence.

  • Strengthen AI governance

    Establish clear accountability structures, responsibilities, communication processes and management oversight for AI development and deployment.

  • Build confidence in AI systems

    Demonstrate that AI systems are managed responsibly through robust controls that address transparency, human oversight, performance, robustness and cybersecurity.

  • Reduce regulatory and business risks

    Integrate risk management, monitoring, incident handling and supplier oversight into a unified framework.

  • Enhance operational consistency

    Establish repeatable processes across AI projects and scalable governance mechanisms.

  • Prepare for future assessments

    Develop documentation, traceability and monitoring records that support conformity assessments, audits and regulatory reviews.

Our EN 18286 services

  • Awareness and foundation training

    We help you understand the standard, its objectives and relationship to the EU AI Act.

  • Gap assessments

    We evaluate your current practices and identify areas requiring improvement.

  • AI governance advisory

    We help you develop EN 18286-aligned governance structures, processes and controls.

  • EU AI Act readiness assessments

    We assess your readiness against European AI regulatory requirements and supporting standards.

  • AI testing and assurance

    We validate AI system performance, robustness, transparency and trustworthiness.

World-class AI expertise and digital trust specialists

As the world's leading testing, inspection and certification company, we combine AI governance expertise, regulatory knowledge, AI testing capabilities and certification experience with our global digital trust specialists to support your EU AI Act readiness.

Our services help you move confidently from AI governance maturity to EU AI Act readiness, giving you access to integrated expertise spanning regulatory interpretation, technical assurance and quality management.

Global World Network and Telecommunication

FAQs

EN 18286 is a European standard specifying requirements and guidance for organizations providing AI systems. The standard focuses on establishing, implementing, maintaining and continually improving an AI quality management system (QMS) that supports compliance throughout the AI life cycle. This includes:

  • Design and development
  • Data governance
  • Verification and validation
  • Technical documentation
  • Supplier management
  • Deployment and operation
  • Post-market monitoring
  • Incident reporting
  • Change management
  • Continual improvement

By uniting these elements into a single management system, organizations can move from fragmented compliance activities to a systematic and repeatable approach to AI governance and quality management.

Under EU AI Act Article 16, providers of high-risk AI systems must implement a quality management system (QMS) in accordance with Article 17, which specifies the QMS requirements. EN 18286 provides a structured framework to support their implementation.

For AI systems involving Annex I-listed products, applicability must be assessed alongside Article 6 and the relevant sector legislation. Coverage under Annex I Section B does not mean that the QMS requirement applies unless the relevant sector legislation requires or integrates it.

Under EU AI Act Article 6, an AI system may be classified as high-risk through two main routes:

  • AI systems used as safety components of products, or AI systems that are themselves products, covered by the EU harmonization legislation listed in Annex I, where the product is required to undergo third-party conformity assessment
  • AI systems falling within the use cases listed in Annex III, subject to the EU AI Act’s classification rules and applicable exceptions

Examples include:

  • Machinery and safety components for machinery
  • Medical devices and in vitro diagnostic medical devices
  • Toys
  • Lifts and safety components for lifts
  • Radio equipment
  • Personal protective equipment
  • Motor vehicles and their trailers, including two- or three-wheel vehicles
  • Agricultural and forestry vehicles
  • Rail systems and marine equipment
  • Aircraft and civil aviation products
  • Recreational craft and personal watercraft
  • Pressure equipment, cableway installations and equipment for potentially explosive atmospheres
  • Appliances burning gaseous fuels

For these products, an embedded AI system may be classified as high-risk when it is a safety component or is itself a regulated product, and the product is required to undergo third-party conformity assessment under the applicable EU harmonization legislation.

  • Biometrics, including certain remote biometric identification, biometric categorization and emotion recognition systems
  • Critical infrastructure, including safety components used in the management or operation of critical digital infrastructure, road traffic or supplies of water, gas, heating or electricity
  • Education and vocational training, including admission, assessment, placement and monitoring during tests
  • Employment, worker management and access to self-employment, including recruitment, selection, work allocation, performance monitoring and decisions affecting employment relationships
  • Access to and enjoyment of essential private services and public services, and benefits, including certain creditworthiness, insurance, public benefit and emergency-response decisions
  • Law enforcement, including certain risk assessments, evidence evaluation, profiling and crime-related assessments
  • Migration, asylum and border control management, including certain risk assessments and decisions concerning entry, visas, residence and asylum
  • Administration of justice and democratic processes, including assistance in researching and interpreting facts and law, and certain systems intended to influence election or referendum outcomes

Whether a particular AI system is high-risk depends on its intended purpose, the applicable classification criteria and any exclusions or exceptions under the EU AI Act.

 

Organizations already implementing ISO/IEC 42001 can use EN 18286 as a natural next step toward EU AI Act readiness.

The standards are complementary but apply different perspectives: ISO/IEC 42001 takes an organization-wide AI management system (AIMS) view while EN 18286 takes a provider-, product-, AI system life cycle- and regulatory-compliance-oriented view.

ISO/IEC 42001 focuses on:

  • Organization-wide AI governance
  • Management systems
  • Organizational accountability
  • AI risk management
  • Continual improvement across the organization’s roles as an AI provider, developer or user

EN 18286 focuses on AI systems as products or components embedded in products, complementing ISO/IEC 42001’s broader organizational view. Its product and life cycle focus includes:

  • AI quality management for specific AI systems within the QMS scope
  • Regulatory compliance for AI systems placed on the market or put into service
  • Product and technical documentation
  • Design and development controls
  • Verification and validation
  • Supply chain and externally provided components, data and services
  • Post-market monitoring, incident reporting and change control
  • EU AI Act operational requirements

Together, ISO/IEC 42001 provides the organization-wide governance foundation while EN 18286 adds product-, provider- and life cycle-specific quality controls to support regulatory readiness for high-risk AI systems.

News & Insights

  • SGS – Kuwait – Ahmadi

Office 11, Ahmadi Center, Building 100, Block 7, East Ahmadi,

61008,

Al Ahmadi, Kuwait