Answer · Manufacturing
Can AI write or change a quality record?
It can draft one. It cannot be the approver, and an audit will ask who approved it rather than who typed it.
Drafting, yes. Approving, no. A controlled record has to be reviewed and approved by an identified competent person, and an auditor's question is who approved it — a question a generated record cannot answer.
The requirement is about control, not about authorship. A quality management system requires documented information to be reviewed and approved for suitability and adequacy, to be identifiable, to carry version control, and to remain legible and retrievable. Section 7.5 of the standard sets this out, and none of it says a human must compose the text. What it does say is that somebody approved it, that the somebody is identifiable, and that changes are controlled — which means a generated draft is unremarkable and an unapproved generated record is a nonconformity.
The competence requirement is the second half and it is the one that decides the practical answer. Persons doing work affecting quality performance have to be competent on the basis of education, training or experience, and the organisation has to retain evidence of it. A system has no competence record and cannot acquire one. The approval therefore has to attach to a person who does, which is why the workable arrangement is generation plus named approval and never generation plus automatic release.
Aerospace and defence variants of the standard tighten this further rather than relaxing it, because they add explicit expectations about authority to approve, about the control of records supporting product conformity, and about traceability from the record back to the article. A shop working to those requirements has less room to experiment here, not more, and should assume any record touching product conformity carries an approval that a person owns.
Where these tools are genuinely valuable in a quality function is upstream and downstream of the controlled record. Drafting a work instruction from an engineer's notes, restating a procedure in the language the operators actually use, summarising a month of nonconformance reports to find the pattern nobody had time to look for, preparing a first draft of a corrective action investigation, or reading an inspection standard and telling you which clauses your procedure never addressed. All of that is preparation and analysis, and none of it is the record.
One class of use deserves an explicit no. Retrospectively generating or completing records — filling gaps in an inspection log, reconstructing a traceability chain, drafting a corrective action that describes an investigation nobody performed — is falsification whatever produced the text, and the ease with which these tools produce plausible records is precisely why the line needs stating. The characteristic risk is not that somebody sets out to falsify; it is that a record which should have said the data is missing gets written as though it were not.
Practically, the control worth adding is small: any document that a model contributed to should be identifiable as such in the system until it has been approved, and the approval step should require the approver to have opened it. Quality systems already have both mechanisms, because they were built for the same problem in its human form — a procedure copied from another site and released without anybody reading it is the failure this is a faster version of.
An auditor does not ask how a record was written. They ask who approved it, on what basis, and whether that person was competent to — and none of those has a machine-shaped answer.
Siddharth Sharma, Context Theory
Related questions
Can AI perform the review rather than the approval?
It can perform a check that precedes the review and it is good at some of them: whether the document references a superseded revision, whether a required section is missing, whether the terminology matches the controlling specification. Those are useful and they narrow what the reviewer has to think about. They do not constitute the review, because the review is a judgement about suitability and adequacy that the approval record attributes to a person.
What about generating a certificate of conformance?
The document can be assembled automatically — most already are, from inspection data — and that is not what the question is really about. The certificate asserts that the product conforms, so the assertion has to rest on results that exist and were within limits. A generated certificate is safe exactly to the extent that it is a rendering of data the system holds, and unsafe the moment it can produce a statement the data does not support.
METHOD
Every figure below carries its source and the date it was verified. Nothing on this page is asserted.
The numbers on this page.
| What | Value | Specific to |
|---|---|---|
| Realistic monthly lead-gen software spend | $1,500–$5,000 | Category-wide |
| All-industry average search CPC | $5.42 | Category-wide |
2026 real estate operating cost survey · plus $1,000–$8,000 variable · verified
LocaliQ / WordStream Search Advertising Benchmarks 2026 · Google + Microsoft Ads, 20 industries · Apr 2025–Mar 2026 · verified
What is specific to this page.
| Kind | Claim | Check it against |
|---|---|---|
| Regulation | A quality management system requires documented information to be reviewed and approved for suitability and adequacy, to be identifiable and version-controlled, and to remain legible and retrievable, without specifying who or what composes the text. | Section 7.5 of the quality management system standard the organisation is certified to, and its own document control procedure. |
| Licensing | Persons whose work affects quality performance must be competent on the basis of education, training or experience with retained evidence of that competence, which a system cannot hold and which is therefore why approval has to attach to a named person. | The competence clause of the standard, and the training records the organisation retains for approvers. |
| Constraint | Retrospectively generating or completing records — filling an inspection log, reconstructing traceability, or drafting a corrective action describing an investigation that did not occur — is falsification regardless of what produced the text. | Comparing record creation timestamps in the quality system against the dates of the activities the records describe. |
| Workflow | The characteristic risk is not deliberate falsification but a record that should have reported missing data being written as though the data existed, because a generated draft has no mechanism for reporting an absence it was not told about. | Seeding a drafting workflow with an incomplete data set and observing whether the output states the gap or fills it. |
Each row would be wrong on another industry's page. Where a sourced figure exists it is in the table above instead; these are the constraints that shape the work and do not happen to be numbers.
Start with the measurement.
Reading about a benchmark is not the same as knowing your own number. The audit produces yours, measured rather than estimated.
$497 · delivered in 5 business days · credited against month one