ISO 42001 clause 7.5 asks for the same three things ISO 9001 clause 7.5 asks for. Keep the documents the standard names and the ones you decide you need, create them with proper identification, format, review and approval, and control them so they are available, protected, version-managed and retained. If you already run a certified quality system, the control mechanics are done. What is new is the list of record types, and for regulated manufacturers in 2026, one question that did not exist before: when the record itself was written by AI, who reviewed it, and can you prove it? FDA answered that question in April 2026 with a warning letter.
What clause 7.5 says
ISO/IEC 42001:2023 is an Annex SL standard, so clause 7.5 reads almost word for word like the documented information clause in ISO 9001, ISO 27001 and ISO 14001. Three sub-clauses:
| Sub-clause | What it requires |
|---|---|
| 7.5.1 General | Keep the documented information the standard requires, plus what the organization determines is necessary for the AI management system to work |
| 7.5.2 Creating and updating | Identification (title, date, author, reference), suitable format and media, and review and approval for suitability and adequacy |
| 7.5.3 Control | Available where and when needed, protected against loss of confidentiality and integrity, with defined distribution, access, storage, change control, retention and disposal; externally sourced documents identified and controlled |
The standard names documented information explicitly in about a dozen places. The scope statement (4.3), the AI policy (5.2), the AI risk assessment process and its results (6.1.2 and 8.2), the risk treatment plan and Statement of Applicability (6.1.3 and 8.3), AI system impact assessment results (6.1.4 and 8.4), AI objectives (6.2), evidence of competence (7.2), operational planning records (8.1), monitoring and measurement results (9.1), the internal audit program and results (9.2), management review outputs (9.3), and the nature of nonconformities and corrective actions taken (10.2). Annex A adds controls that each need evidence of implementation once they appear in your Statement of Applicability.
That list is the easy half. The harder half is 7.5.1(b), the documented information the organization "determines as being necessary." An auditor will not accept that you decided nothing beyond the named documents was necessary for a system that manages AI.
The five record families an auditor will ask to see
In our experience preparing management systems for audit, the AI-specific records sort into five families. Each ties back to a clause or an Annex A control, and each has a recognizable shape when it is done well.
| Record family | Where it comes from | What good looks like |
|---|---|---|
| AI system inventory | 4.1 context, 8.1 operational control, A.4.2 resource documentation | One controlled list of every AI system in scope, with owner, intended use, supplier, model version and lifecycle stage |
| Impact assessments | 6.1.4, 8.4, the A.5 controls | Dated assessments per system, covering individuals, groups and society, with the decisions they drove |
| Decisions and approvals | 5.3 roles, 7.5.2(c), 8.1 | Who approved deployment, changes, exceptions and retirement, on what basis, and when |
| Model and data provenance | A.7.5 data provenance, A.6.2.7 technical documentation, A.6.2.8 event logs | Where training and input data came from, what was done to it, which model version is running and since when |
| Human oversight evidence | A.6 life cycle controls, A.9 responsible use controls | Records showing a person actually reviewed, overrode or escalated AI outputs as the procedure says they should |
The AI system inventory comes first because nothing else can be controlled until it exists. In our experience the real inventory usually turns out longer than leadership had in mind once you count the AI features inside SaaS products, the vendor models embedded in lab or ERP software, and the general-purpose assistants staff use to draft documents. The inventory itself should be a controlled document under 7.5, because auditors read its change log to judge whether the organization is actually tracking what it deploys.
Impact assessments are the record type with no direct equivalent in ISO 9001. The standard asks you to assess the potential consequences of each AI system for individuals, groups and society, and to retain the results. A good assessment is short, specific to one system, and ends in a decision (deploy, deploy with conditions, do not deploy) that someone signed. A generic assessment copied across ten systems is one of the most common findings we see here. See which Annex A controls apply for how the assessment feeds the Statement of Applicability.
Decisions and approvals are where 42001 quietly borrows from quality systems. The approval to put a model into production, the approval of a change to its inputs or thresholds, the approval to keep running after an incident, and the decision to retire it are all records. If your change control procedure already captures who, what, why and when, it will carry these without modification.
Model and data provenance answers the question an auditor asks when something goes wrong: what data was this trained on, who supplied it, what was done to it, and which version produced this output? For most organizations the honest answer is that the vendor holds this and you hold the vendor's documentation, which is acceptable if you have identified it as externally sourced documented information under 7.5.3 and controlled it: a copy or reference in your system, a record of the version you relied on, and a trigger to revisit it when the vendor updates it.
Human oversight evidence is the family most often written into procedure and least often produced as a record. The procedure says a person reviews every AI-generated output before release. The auditor asks for the last twenty reviews. If the answer is an approval click with no indication of what was checked, the control exists on paper only. Oversight records need to show what the reviewer looked at, what they changed, and what they escalated.
If you already run ISO 9001 or GMP document control, most of this exists
The document control procedure your organization wrote for ISO 9001, ISO 13485 or 21 CFR 211 already handles the mechanics of clause 7.5. Document numbering, revision history, review and approval routing, controlled distribution, obsolete document handling and retention schedules are the same activities in every Annex SL standard, and the auditor will accept the same procedure.
| ISO 42001 clause 7.5 requirement | ISO 9001 equivalent | GMP equivalent (21 CFR 211) |
|---|---|---|
| Identification and description | 7.5.2(a) | 211.100(a) written procedures; 211.186 master records |
| Review and approval | 7.5.2(c) | 211.22(c) quality unit approval of procedures and specifications |
| Control of changes | 7.5.3 change control | 211.100(b) procedures followed, deviations recorded and justified; 211.68 for computerized systems |
| Retention | 7.5.3 retention and disposition | 211.180(a) at least one year past expiry, or three years past distribution for certain OTC products |
| Protection and integrity | 7.5.3 protection | 211.68(b) backup of electronic data, and Part 11 for electronic records |
The additions are all content; the control side stays as it is. Three things in practice:
- A record category for AI, with a few extra identification fields: AI system identifier, model version, data version, lifecycle stage. These let an auditor trace a record back to the system and version it describes.
- Event-driven review triggers. ISO 9001 review cycles are usually calendar-based. AI records need reviewing when the model is retrained, when the supplier changes the version, after an incident, and when intended use changes. Add those triggers to the existing review procedure rather than inventing a new one.
- The AI inventory as a controlled document, owned by a named role under clause 5.3, and referenced from the Statement of Applicability.
In my experience the gap is rarely the procedure. The gap is that AI entered the organization outside the quality system, through a vendor feature, a department's subscription, or an individual's habit, and the documents it produced never passed through document control at all. The procedure was sound; it just never saw the work. What 42001 adds to a certified ISO 9001 system is mostly the discipline of bringing those systems inside the boundary.
When AI wrote the record
For most organizations the records above are about AI systems. For a regulated manufacturer there is a second case, and in 2026 it is the one that draws enforcement: the AI did not just get documented, it did the documenting.
In April 2026 FDA issued a warning letter to Purolea citing "inappropriate use of artificial intelligence" under 21 CFR 211.22(c). The facility had used AI to write specifications, procedures and master production records, and released them without qualified review. It was the first time AI-generated quality records drew an FDA citation, and the regulation FDA reached for tells you how the agency thinks about it.
21 CFR 211.22(c) says the quality control unit is responsible for approving or rejecting all procedures and specifications that affect the identity, strength, quality and purity of the drug product. It does not say who has to write them. A contractor can draft an SOP, and so can a template or a language model. The regulation lands on the approval, and the approval has to be a real review by people qualified to judge whether the document is right. What FDA found was documents that had been generated and then released without qualified review.
Master production and control records carry an additional requirement under 211.186(a): they must be prepared, dated and signed by one person and independently checked, dated and signed by a second. When the draft came from a model, the person who signs as preparer is taking responsibility for content they did not write, which is allowed, but only if they actually verified it. The independent check by a second person has to be independent of the model too. Having the same AI tool review its own draft is not a second-person check, whatever the software vendor calls the feature.
Clause 7.5.2(c) and 211.22(c) say the same thing in different words: review and approval for suitability and adequacy on one side, quality unit approval on the other, and neither cares about the drafting tool so long as a qualified person stood behind the document before it took effect. ISO 42001 adds one thing Part 211 does not: it makes the drafting tool itself a managed AI system, with an inventory entry, an intended use, and competence requirements for the people who use it. That is what turns "we let people use ChatGPT for SOPs" into something an auditor can examine. We cover the broader overlap in ISO 42001 meets FDA expectations.
What review and approval evidence looks like for an AI-drafted document
An FDA investigator or ISO auditor who finds an AI-drafted procedure will ask three questions: who wrote it, who checked it, and what did they check it against? The evidence that answers them is what a good document control system already produces, with two additions.
- The tool is in the AI inventory with an intended use that covers document drafting, and the document control procedure names it as an acceptable drafting method with the conditions that apply.
- The draft is identified as AI-generated at the point it enters document control. A metadata field or a line in the revision history: generated with (tool and version), from (source documents or prompt reference), on (date). This is the 7.5.2(a) identification requirement applied to a new kind of author.
- A named reviewer with competence on file for that document type. Clause 7.2 already requires evidence of competence. For an AI-drafted batch record, that means someone who has run the process, not someone who is good with the software.
- A record of what the review compared the draft against. For a specification that is the validated analytical method; for an SOP, the previous approved revision and the actual process; for a master record, the registered formulation and the executed batch history. Keep the reviewer checklist or annotated comparison with the document.
- The corrections, along with the clean copy. Auditors read redlines to see whether the review was real. A draft that went through review with zero changes on a first pass invites the question of whether anyone read it.
- Quality unit approval that satisfies 211.22(c), signed by someone with the authority the procedure gives them, and meeting 21 CFR Part 11 if the signature is electronic.
- For master records, the second-person independent check required by 211.186(a), performed by a person, on the content, after the preparer's verification.
Two habits make this hold up over time: treat a change in the AI tool's model version as a review trigger for the documents it produced, and keep the review evidence in the same repository as the document, because review evidence that lives in an email thread is evidence you will not find during an inspection.
Retention, protection and the rest of 7.5.3
The remaining 7.5.3 requirements need less adaptation than the record families above, but two points are worth settling before an audit rather than during one.
Retention should follow the strictest rule that applies. For GMP records that is 211.180(a): at least one year past the expiry date of the batch, or three years past distribution for certain OTC products without expiry dating. For AI-specific records with no regulatory retention period, keeping them for the life of the AI system plus the period your existing records procedure uses for quality records is a defensible default. If the EU AI Act reaches your products, its high-risk logging and documentation obligations arrive, under the 2026 revisions, in December 2027 and August 2028, and an ISO 42001 certificate does not give a presumption of conformity with the Act, so plan retention around the regulation itself.
Protection takes on a wider meaning for AI records. Training data documentation may contain personal data, prompt libraries and model configurations may be trade secrets, and impact assessments may describe risks you would rather a competitor not read. The existing classification scheme in your information security or document control procedure handles this; the work is deciding which class each AI record family falls into and writing it down.
Where to start
The order that works is inventory, then record category, then review of what AI has already written. Build the AI system inventory first, including the drafting assistants, because you cannot control records for systems you have not listed. Then add the AI record category and its extra fields to the document control procedure you already have. Then, and this is the step regulated manufacturers cannot skip after April 2026, pull every specification, procedure and master record that was drafted with AI back through review, and produce the evidence described above for each one.
For manufacturers under FDA or ISO 13485 who want that third step done for them, our AI-in-the-quality-system review is a fixed $5,000 and covers AI-generated records, specifications and procedures inside the quality system. For organizations building toward certification, the ISO 42001 gap assessment at $9,750 covers clause 7.5 alongside the rest of the standard, and the full documentation requirements article lists every document and record by clause. Either way, the question to answer before anyone else asks it is the same one FDA asked Purolea: who reviewed this, and can you show me?
Frequently Asked Questions
What documented information does ISO 42001 clause 7.5 require?
Two things. The documents and records the standard names in its own clauses (scope, AI policy, risk assessment and treatment results, AI system impact assessments, the Statement of Applicability, objectives, competence evidence, monitoring results, internal audits, management reviews and corrective actions), plus whatever else your organization decides it needs to run the system. In practice that second category means an AI system inventory, decision and approval records, model and data provenance, and evidence that human oversight actually happened.
Can we use our ISO 9001 document control procedure for ISO 42001?
Usually yes. Clause 7.5 in ISO 42001 is the same Annex SL text as clause 7.5 in ISO 9001, so numbering, revision control, review and approval, distribution and retention carry over unchanged. What you add is a record category for AI, a few extra fields such as AI system identifier and model version, and review triggers tied to model or supplier changes.
Does FDA allow AI to write SOPs and specifications?
Nothing in 21 CFR 211 forbids drafting a document with AI, but 211.22(c) makes the quality unit responsible for approving or rejecting every procedure and specification that affects product quality. In April 2026 FDA issued a warning letter to Purolea for releasing AI-written specifications, procedures and master records without qualified review, the first citation of its kind. What FDA cited was the absence of qualified review.
What evidence shows an AI-generated quality record was properly reviewed?
A named reviewer whose competence for that document type is on file, a record of what the draft was checked against (source data, the previous approved revision, the validated method), the corrections that were made, and a dated approval by the quality unit that meets 21 CFR Part 11 if it is electronic. A clean final copy with one signature and no trace of the review will not satisfy an investigator.
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.