AI Governance 14 min read

Do You Need a Separate AI Governance Program If You Run a QMS?

J

September 13, 2026

If you already run a working quality management system, the short answer is no. You do not need a second management system for AI, a separate governance office, or a new binder of policies that nobody in production will read. ISO/IEC 42001:2023 was written on the same Annex SL structure as ISO 9001 and ISO 13485, so its clauses 4 to 10 ask for things your QMS already does, from scope and policy through internal audit, management review and corrective action. The AI-specific material sits in Annex A, and nearly all of it lands on a process you already own: document control, change control, supplier qualification, training, CAPA and management review. What you need is to extend the system you have to cover a new kind of tool.

I have come to think of AI governance as quality management applied to a system that writes. The rest of this article is the map: where each 42001 requirement already lives in a quality system, what is genuinely new, and why an investigator's questions about an AI-written procedure are the ones she has always asked.

What FDA said in April 2026

In April 2026 FDA issued a warning letter to Purolea that cited "inappropriate use of artificial intelligence" under 21 CFR 211.22(c). AI-written specifications, procedures and master records had been released without qualified review. It was the first time AI-generated quality records drew an FDA citation, and the regulation FDA reached for is older than any AI tool.

Section 211.22(c) makes the quality control unit responsible for approving or rejecting all procedures and specifications that affect the identity, strength, quality and purity of the drug product. That is the whole citation. FDA did not need an AI rule and did not write one. The failure was a document in use without the approval the regulation has required for decades. The author could have been a contractor, a new hire, or a template pulled off the internet, and the finding would have read the same way.

That is the thesis of this article in one warning letter. When an investigator finds an AI-written record, she asks who approved this output, what record shows the approval, and how the tool was validated for this use. Each is a quality-system question, and each has a clause in ISO 42001 that reads like one you have already implemented.

Same clause structure, new subject

ISO 42001 was published in December 2023 as an Annex SL management-system standard. Annex SL is the common clause structure ISO now uses for 9001, 27001, 14001, 45001 and the rest; 13485 keeps the older layout but covers the same ground. A quality professional who opens 42001 for the first time will recognise the table of contents before reading a single requirement.

Clause ISO 9001:2015 ISO 13485:2016 ISO 42001:2023 What changes for AI
4 Context and scope 4.1 to 4.4 4.1, 4.2 4.1 to 4.4 Scope names each AI system and your role for it (builder, configurer of a bought model, or plain user)
5 Leadership and policy 5.1 to 5.3 5.1 to 5.5 5.1 to 5.3 An AI policy, usually one section in the quality manual
6 Planning and risk 6.1 to 6.3 5.4, 7.1 6.1 to 6.3 Risk assessment and treatment plus an impact assessment on people affected
7 Support 7.1 to 7.5 4.2, 6.1 to 6.3 7.1 to 7.5 Competence for people who use and review AI; AI records under document control
8 Operation 8.1 to 8.7 7.1 to 7.6 8.1 to 8.4 Operational control; the risk and impact assessments run in practice
9 Performance evaluation 9.1 to 9.3 5.6, 8.2 9.1 to 9.3 Monitoring, internal audit and management review with AI on the agenda
10 Improvement 10.1 to 10.3 8.5 10.1, 10.2 Continual improvement (10.1), nonconformity and corrective action (10.2)

Apart from the impact assessment in clauses 6.1.4 and 8.4, which I come back to below, everything at the clause level is scope extension. (One small trap: 42001 puts continual improvement at 10.1 and corrective action at 10.2, the reverse of 9001:2015.) We keep the full walk-through at ISO 42001 clause by clause.

Where each Annex A control area already lives in your QMS

Annex A carries the AI-specific controls in nine areas. Here is where each lands in a GMP or ISO quality system, with the reference you would cite today.

42001 Annex A area Where it already lives Reference you already cite What you add
A.2 AI policy Quality policy and quality manual 9001 5.2; 13485 5.3; 211.22 Permitted and prohibited AI uses, and who owns each
A.3 Internal organisation, roles, reporting of concerns Quality unit responsibilities, organisation chart, deviation reporting 211.22; 9001 5.3; 13485 5.5 A named owner per AI system; a route to report a bad output
A.4 Resources (data, tooling, computing, people) Equipment and system inventory, training records 211.68; 211.25; 13485 6.2, 6.3 An inventory of AI tools and the data each touches
A.5 AI system impact assessment Risk management ICH Q9; ISO 14971; 9001 6.1 Assessment of impact on people outside the organisation
A.6 AI system life cycle (design, validation, deployment, monitoring, logs) Design controls, computer system validation, change control, audit trails 13485 7.3, 4.1.6, 7.5.6; 211.68; 21 CFR Part 11 Validation for a tool that is probabilistic and can change under you
A.7 Data (quality, provenance, preparation) Data integrity programme 211.68(b); 211.180 to 211.198; ALCOA+ Provenance and fitness of data going into and out of the model
A.8 Information for interested parties, incident communication Labelling, customer information, complaint handling, field reporting 211.198; 13485 8.2.2 Telling users what the AI does and reporting AI-related incidents
A.9 Responsible use, intended use Intended use statements, SOPs and work instructions 13485 7.3.3; 211.100 A written intended use and procedure for each AI tool
A.10 Third-party and customer relationships Supplier qualification, quality agreements 211.84; 9001 8.4; 13485 7.4 AI vendor qualification and a written split of responsibilities

Eight of the nine areas already have an owner, a procedure and a record type in the building. The gap assessment work is mostly extending scope statements, adding AI-specific criteria to existing forms, and writing a few new procedures where the tool behaves unlike equipment you are used to validating. Which controls you can mark not applicable depends on your role and tools; see which 42001 controls apply.

Six quality processes and what AI changes in each

Document control

An AI-written SOP is a document like any other. It needs an author of record, a qualified reviewer, an approver with the authority that 211.22(c) or 13485 4.2.4 assigns, a controlled copy and a revision history. What changes is the author field. In my view the cleanest practice is to record the tool and the prompt in the draft's history, as you would note a document adapted from a supplier's template, and then require the reviewer to attest that they read the whole thing. The Purolea letter is, at bottom, a document control finding.

Change control

Change control assumes you know when the thing changed. A hosted AI tool can be updated by the vendor overnight with no change request on your side, and the outputs your procedure depends on can shift. Your procedure needs a trigger for vendor model updates, a periodic re-check of outputs against a fixed reference set, and a rule about which tool version is approved for GMP use. It is the logic you already apply under 211.68 to self-updating software, applied to a tool whose behaviour is harder to pin to a version number.

Supplier qualification

You cannot audit a foundation model vendor the way you audit an API supplier, so do what supplier qualification has always done for suppliers you cannot visit: define what you are buying and what it may touch, collect the vendor's documentation of testing and controls, and write a quality agreement that says who is responsible for what. 42001's A.10 asks for exactly that split. Where a vendor cannot give you what you need, the answer is the one you give a component supplier who will not share a test method: restrict the scope of use or find another supplier.

Training and competence

Under 211.25 and 9001 7.2, the people who perform and review work must be qualified to do it. A reviewer who cannot tell a plausible AI paragraph from a correct one is not a qualified reviewer for that document, and training records should show that anyone using an AI tool in GMP work has been trained on its intended use, its known failure modes and the review standard expected. 42001 says this in clause 7.2 and again in A.4.6. In our experience this is the cheapest gap to close and the one most often skipped.

CAPA and deviations

An AI output that was wrong and reached a controlled record is a deviation. It gets investigated under 211.192 or 13485 8.5.2 like any other, and the root cause is usually not that the model made a mistake but that a review step failed to catch it or the tool was used outside its intended use. 42001 clause 10.2 is your CAPA procedure with AI outputs added as a category, and A.3.3's route for staff to report concerns about an AI system is your deviation and near-miss reporting once people know it applies.

Management review

Clause 9.3 of 42001 reads like 9.3 of 9001. Add AI to the standing agenda (tools in use, impact assessment results, AI-related incidents and CAPAs, vendor changes, whether the AI policy still fits) and the record is the same minutes and action list you produce today.

Validation is where the real work is

Validation is the one place you should expect to learn something new rather than extend something old. Computer system validation and computer software assurance both assume the system gives the same output for the same input. A language model does not, and a hosted one can change without notice. A.6.2.4 asks for verification and validation of the AI system, and the honest answer for most manufacturers is a validation approach built around the use rather than the model: a written intended use (A.9.4), a fixed reference set of inputs with known-good outputs, acceptance criteria for accuracy and for the errors that matter in your context, a re-run after vendor updates and on a schedule, and a review step that stays in the process however good the outputs look. Event logs (A.6.2.8) and Part 11 audit trails answer the record question. If the tool cannot log what it was asked and what it produced, it is hard to see how it can be used for a GMP record at all. We go deeper in AI and 21 CFR Part 11.

The three questions, answered from your QMS

Who approved this output? The approver named in your document control procedure, with a signature and a date. 42001 clause 5.3 and A.3.2 ask for named roles; 211.22(c) has asked for it all along.

What is the record? The controlled document with its revision history, the review attestation, and the tool's log of the prompt and the output. 42001 clause 7.5, A.6.2.8 and Part 11 cover it between them.

How was the tool validated? The package above: intended use, reference set, acceptance criteria, periodic re-checks, and change control tied to vendor updates. 42001 A.6.2.4 and clause 6.3; 211.68 and 13485 4.1.6 in the system you run today.

If you can answer all three for every AI tool that touches a controlled record, you would have passed the inspection that produced the Purolea letter.

What is genuinely new, said plainly

I do not want to oversell the overlap. Four things in 42001 have no direct equivalent in a quality system, and they are where the new procedures go:

  1. The AI system impact assessment (6.1.4, 8.4, A.5), which looks outward at the people affected by outputs rather than inward at the product. Your ICH Q9 or ISO 14971 process gives you the method; the new part is the direction.
  2. Data provenance and quality for model inputs (A.7), which extends data integrity to data you did not generate and may not own.
  3. Life cycle controls for a tool that is probabilistic and can change under you (A.6), where validation and change control need real redesign.
  4. Information for interested parties (A.8): telling users, customers and regulators what the AI does and how to report a problem with it.

Everything else is scope. In our experience a manufacturer with a mature 9001 or 13485 system finds most of clauses 4 to 10 already met on paper, and the gap assessment spends its time on those four areas and on evidence that the extended scope actually operates. For the 9001 delta, see what 42001 adds to a 9001 system.

What to do next quarter

Three situations, three paths.

You use AI in quality work and are not chasing a certificate. Most GMP manufacturers are here. The immediate exposure is the one FDA has already cited: records written or revised with AI without qualified review, or a tool with no intended use and no validation. A focused review of the AI-generated records, specifications and procedures inside your quality system is the right size. We offer that as a fixed-fee AI-in-the-quality-system review at $5,000; details by sector are on the GMP manufacturers page.

A customer or a tender is asking for ISO 42001. Then you need the certificate, and a working 9001 or 13485 system puts you at the short end of the four-to-twelve-month range we see from gap assessment to certificate. Certification bodies are reporting auditor backlogs, and some Stage 2 audits have waited six months or more, so book the registrar early. Our ISO 42001 gap assessment is $9,750, fixed fee, and the full path is in the implementation guide.

You are deciding whether AI governance belongs to quality, legal or IT. In my view it belongs to quality, with legal and IT as interested parties, because the evidence an auditor or investigator asks for is quality-system evidence. The field is young (fewer than 100 certificates worldwide in January 2026, roughly 350 by spring), and in our experience the organisations moving fastest did not build a parallel program.

Two cautions. ISO 42001 is not required by any US law, and certification does not give a presumption of conformity with the EU AI Act: EN ISO/IEC 42001:2026 became a European standard in March 2026, but it has not been cited in the Official Journal as a harmonised standard, and the one being drafted for that job is prEN 18286. Under the 2026 revisions the Act's high-risk obligations now start in December 2027 and August 2028. Neither changes the answer for a manufacturer, because each regime asks for the kind of evidence a quality system produces; more at ISO 42001 vs the EU AI Act for US companies.

The investigator does not care that a model wrote the record. She cares who signed it, what the record shows, and whether the tool was fit for the job. Those were the questions before AI, and a quality system that can answer them was governing AI before anyone gave it that name.

Frequently Asked Questions

Do we need a separate AI management system if we are already ISO 9001 or 13485 certified?

No. ISO 42001 uses the same Annex SL clause structure, so a working 9001 or 13485 system already covers most of clauses 4 to 10. The work is extending scope, risk assessment, document control, supplier qualification and training to cover AI tools, then adding the Annex A controls that have no QMS equivalent, mainly the AI system impact assessment.

Has FDA actually cited a company for using AI in its quality system?

Yes. In April 2026 FDA issued a warning letter to Purolea citing inappropriate use of artificial intelligence under 21 CFR 211.22(c), after AI-written specifications, procedures and master records were released without qualified review. The citation was for the missing quality-unit approval rather than for the use of AI itself.

Does ISO 42001 certification satisfy the EU AI Act?

No. EN ISO/IEC 42001:2026 was adopted as a European standard in March 2026, but it has not been cited in the Official Journal as a harmonised standard, so certification gives no presumption of conformity. The standard being written for that purpose is prEN 18286, and the Act's high-risk obligations were pushed back under the 2026 revisions.

Can the quality unit own AI governance without a data science team?

In most regulated manufacturers, yes. The skills 42001 asks for are risk assessment, document control, validation, supplier qualification, training, CAPA and management review, which the quality unit already runs. Technical help is needed for model-specific questions such as validation design and data provenance, but the system belongs with quality.

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.