An inspector asks a quality lead at a pharmaceutical manufacturer a narrow question about a batch decision made four months ago. Not whether the decision was right, which is documented, but which version of which standard operating procedure the team was working from when they made it. The quality lead can answer, because that process runs on controlled documents. Then the inspector asks a follow-up nobody has prepared for: the team used an AI tool to find the relevant procedure, so which documents was that tool drawing on, and who decided it could?
That second question is arriving in regulated sectors faster than most AI deployments anticipated, and it is not really a question about AI. It is the same question regulated industries have asked about records for decades, pointed at a new part of the stack. Answering it requires knowing what the AI was permitted to use, and that is a decision somebody has to have made on purpose. This post sets out what auditors actually ask, why the default behaviour of general-purpose AI tools fails those questions, and the three records that make an AI tier defensible. It sits within our guide to curated knowledge for regulated organisations, which covers the underlying discipline in full.
What an auditor actually asks about an AI answer
The instinct in most organisations is to prepare for a question about accuracy. Auditors and inspectors rarely lead with accuracy, because accuracy is unfalsifiable after the fact. They lead with reconstruction. For a specific answer, on a specific date, they want four things:
- Which document produced the answer.
- Which version of that document was in force when the answer was given.
- Who approved that version as suitable for the AI to use.
- Who received the answer, and what they did next.
Every one of those is a question about records rather than about models. None of them can be answered by a system that treats the corpus as whatever happens to be reachable. And the reason they matter is not procedural fussiness: the four together are what let a firm demonstrate that a decision was made on the basis it claims. Without them, an AI-assisted decision is one an organisation made and cannot account for, which is a materially worse position than not having used the tool.
Standards are converging on the same expectation from a different direction. ISO 30401:2018, the knowledge management systems standard, requires an organisation to define the scope of the knowledge it manages and assign ownership of it, and the EU AI Act expects documented control rather than asserted good practice. We work through the standards mapping in our guide to ISO 30401 knowledge management.
Why "connect everything" fails a compliance audit
The dominant pattern in enterprise AI deployment is to connect the AI to as many sources as possible and let each user's existing permissions govern what it will answer from. As an engineering decision this is reasonable and fast. As a compliance posture it fails, for one specific reason: nobody decided anything.
Permission inheritance is not an approval mechanism. Folder permissions in most organisations were set years ago, by people solving access problems that had nothing to do with whether a document was current, correct, or appropriate to inform a regulated decision. Inheriting them hands the most consequential governance choice in the system to a historical accident. When the inspector asks who decided the AI could use a document, there is no answer, because the question was never posed.
The failure mode this produces is specific and easy to picture. A superseded procedure sits in a folder somebody still has access to. The AI finds it, cites it accurately, and presents it with the same confidence as the current version. Nothing malfunctioned. The tool did exactly what it was built to do, and the organisation has no record that would let it distinguish that answer from a correct one. In a sector where an inspector may sample a decision from a year ago, that is not a theoretical exposure.
Curated knowledge for compliance: the three records
Curated knowledge for compliance is the alternative posture, and the practical test of whether a platform delivers it comes down to three records it should produce without being asked.
The eligibility record. A list, reconstructible for any past date, of the documents the AI was permitted to answer from. This is the artefact that turns "the AI searches our SharePoint" into a defined, bounded corpus. If it can only be assembled by querying a sync log, it is not an eligibility record.
The approval record. For each eligible document, a named person who marked it suitable and the date they did so. The name matters more than the mechanism. Accountability that cannot be attributed to a person is not accountability, and an approver who is a service account is a gap an inspector will find.
The answer record. For any given answer, the documents and versions it drew on, and the recipient. This is the one most often mistaken for a query log. Knowing that a user asked a question at 14:32 is not the same as knowing what the response was built from.
The distinguishing property of all three is that they have to be by-products of normal operation. A record assembled on request is a reconstruction, and reconstructions are exactly what an audit is testing. If producing the three requires a project, the organisation does not have them.
What this looks like across three sectors
The mechanism is identical in each; the framework names and the inspection style differ.
Pharma and life sciences
Controlled-document discipline is already mature here, which makes the gap more visible rather than less. Teams work from approved procedures as a matter of routine, so an AI tool that answers from an uncontrolled superset of those procedures is a conspicuous break in an otherwise tight chain. The bar to meet is the one the organisation already applies to its own documents, extended to the tool that reads them.
Financial services
The pressure arrives through third-party risk and operational resilience rather than product quality. An AI knowledge platform that reads policies and client files is an information and communications technology service supporting important functions, with the evidence expectations that follow. Our guide to DORA Article 28 covers what that means for the platform decision, and the financial services use case sets out the sector picture.
Legal and professional services
The constraint is confidentiality and matter separation as much as regulation. An answer that silently draws on a document from another client's matter is a problem no accuracy metric detects, which makes the eligibility record the control that matters most. The wider regulatory context across all three sectors is in our guide to AI knowledge management for regulated industries.
How AnswerVault delivers a trusted AI knowledge base
AnswerVault is a governed AI knowledge layer that connects an organisation's existing document sources, including SharePoint, Google Drive, and Confluence, and delivers source-backed answers through web chat, Microsoft Teams, Slack, CLI, and API. The three records above are not features within it. They are what its architecture produces by operating.
A document becomes eligible because a named subject-matter expert approves it, and the approval is written into the audit trail at the moment it happens, which is the eligibility and approval records in one act. When a document is superseded, the new version takes over and the record of which version was canonical on which date is preserved, so the superseded-procedure failure described above does not have a route in. Citations resolve to specific documents and versions, so the answer record exists per answer rather than per session.
This matters more here than the general case because of where the product came from. AnswerVault was originally built for a global pharmaceutical company with strict data governance requirements, and the controls above are the ones that engagement demanded rather than ones added afterwards for a compliance page. AnswerVault is ISO 27001 aligned and ISO 42001 underway, AI is included in every plan with no separate model or API-key requirement, and customer data is never used to train models. The procurement-grade detail, including subprocessors, attestations and the certifying entity, is on our security and compliance page. Where jurisdiction is itself part of the compliance question, that is a tier decision rather than a setting, and the Enterprise sovereign tier is the one to assess.
Where to start
The fastest way to find out where you stand is to pick one AI-assisted decision from the past quarter and try to produce the three records for it. Most organisations discover within an hour which of the three they have. That exercise is more informative than any vendor demonstration, because it tests your position rather than the tool's capabilities.
If the answer is that you have none of them, a trusted AI knowledge base is the shortest route to all three, and our guide to curated knowledge explains how approval and currency work in practice.
AnswerVault is built by Catapult CX, an enterprise technology consultancy. The product was originally developed for a global pharmaceutical company with strict data governance requirements; the same architecture now powers the SaaS platform.